RESOURCESchevron_rightPrivacy Policy

Privacy Policy

Last updated: July 31, 2026. This Privacy Policy explains how AI CRM (“we”, “us”, or “our”) collects, uses, shares, and deletes personal data when you use our WhatsApp Business CRM and related Meta (Facebook / Instagram / WhatsApp) integrations.

Welcome to AI CRM. This privacy policy describes how we operate the platform.

1. Who we are

AI CRM is a multi-tenant business messaging and CRM platform. Business customers (“Vendors”) connect their WhatsApp Business accounts, Facebook Pages, and/or Instagram professional accounts so their teams can message end customers, run campaigns, and manage contacts.

For Meta Platform Data obtained through WhatsApp Cloud API, Messenger, or Instagram Messaging, the Vendor is typically the data controller for end-customer conversations. AI CRM processes that data on the Vendor’s instructions as a service provider / processor, except where we act as controller for Vendor account and billing data.

2. Information we collect

We collect the following categories of information:

  • Vendor account data: name, email, password (hashed), company/workspace name, team member invites and roles.
  • Billing data: plan, invoices, and payment references processed by Stripe and/or Razorpay (we do not store full card numbers).
  • WhatsApp / Meta messaging data: phone numbers or PSID/IGSID identifiers, message content and media you send or receive through the platform, delivery/read status, templates, catalogs linked to your WABA, and webhook event metadata.
  • CRM data you upload: contacts, groups, custom fields, leads, sales notes, and bot/AI conversation logs stored in your workspace.
  • Technical usage data: IP address, device/browser type, authentication cookies, API request logs, and product analytics needed to operate and secure the Service.
  • Integration credentials you choose to save: WhatsApp Cloud API tokens, Facebook/Instagram Page tokens, webhook verify tokens, and optional Shopify/WooCommerce/Sheets keys (stored for your workspace).

3. How we use information

We use information to:

  • Provide inbox, campaigns, templates, bots, CRM, and admin features you configure.
  • Authenticate users, enforce plan limits, and prevent abuse or unauthorized access.
  • Send transactional emails (for example password reset) when email delivery is configured.
  • Improve reliability, debug incidents, and develop product features.
  • Comply with law, Meta Platform Terms, WhatsApp Business policies, and valid legal requests.
security

AI processing

If you enable AI reply features, message text may be sent to your configured AI provider (for example OpenAI or Flowise) solely to generate replies for your workspace. We do not sell customer chat content and do not use one Vendor’s proprietary chat data to train models for other Vendors unless you explicitly opt in to a separate program.

4. Meta / Facebook / WhatsApp Platform Data

When you connect Meta products, we access Platform Data only as needed for the permissions you grant (for example sending and receiving WhatsApp messages, reading template status, or Messenger/Instagram conversations).

We do not use Meta Platform Data to build independent user profiles for advertising outside your CRM use case. We do not sell Platform Data. Access is limited to authorized workspace users and systems that operate the Service.

Message content handled by WhatsApp Cloud API is also subject to Meta’s retention and privacy practices described in Meta’s WhatsApp Cloud API documentation. Our copies stored in AI CRM are retained under Section 6.

5. Sharing and processors

We share data only with:

  • Meta Platforms, Inc. and WhatsApp — to deliver messaging and webhook events you initiate or receive.
  • Infrastructure and payment providers (hosting, databases, Stripe, Razorpay) under contractual safeguards.
  • AI providers you configure for bot fallback.
  • Authorities when required by law.

6. Retention

Vendor account data is kept while the workspace is active and for a reasonable period afterward for billing disputes and legal compliance.

Conversation messages, contacts, and CRM records remain until the Vendor deletes them or closes the workspace, unless a shorter retention is configured later.

After a verified deletion request (Section 8), we delete or anonymize applicable Platform Data and personal data except records we must keep for legal, security, or accounting reasons.

7. Security

We use HTTPS in production, hashed passwords, cookie-based session tokens, role-based access within workspaces, and access controls on API tokens. No method of transmission or storage is 100% secure; please protect your Meta tokens and rotate them if exposed.

8. How to request deletion of your data (required by Meta)

Meta Platform Terms require that we delete Platform Data when you request it, and that this Privacy Policy explain how to submit that request. Deletion does not have to be instantaneous or fully automated, but we will complete verified requests within a reasonable time (typically within 30 days).

  • In-app (Vendors): Sign in → Vendor Console → Settings / Profile, or delete contacts and conversations from Contacts and Chat. Workspace owners may request full account closure by emailing privacy@aicrm.com from the registered admin email with subject “Data deletion request” and your workspace name.
  • End customers of a Vendor: Contact the business you messaged first. If you cannot reach them, email privacy@aicrm.com with the business name, your phone number / Meta user id if known, and proof you control that number or account. We will coordinate deletion of data we hold for that identity where legally permitted.
  • Facebook / Instagram connected users: You may also remove the app from your Facebook settings (Settings → Apps and Websites). If Meta sends us a data-deletion callback, we process it and provide a confirmation code and status URL.
  • What we delete: messaging content and identifiers tied to your request that we store, profile fields, and integration tokens where applicable. We may retain anonymized aggregates and records required by law (for example invoices).
security

Data deletion status

After you email a deletion request, we reply with a confirmation code. You can ask for status by emailing privacy@aicrm.com with that code. If our Meta App Dashboard lists a Data Deletion Request Callback, Meta may also open a status URL we return from that callback.

9. Your rights

Depending on your location (including GDPR and similar laws), you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing. Use the contacts in Section 8 or Section 11. You may also lodge a complaint with a supervisory authority where applicable.

10. Children

AI CRM is a business service and is not directed to children under 16. We do not knowingly collect children’s data.

11. Changes

We may update this Privacy Policy. The “Last updated” date at the top will change when we do. Material changes will be highlighted on this page or via email to workspace admins when appropriate.

Contact Us

If you have any questions about this privacy policy, please contact us at:

privacy@aicrm.comLegal / Privacy, AI CRMFor Meta App Review: this page is our public Privacy Policy URL.Also see: Terms of Service (/page/terms-of-service) and Data Deletion (/page/data-deletion).