Privacy Policy
Effective 9 August 2026 · Last updated 9 August 2026
This policy explains what personal data Converse360 handles, why, who it is shared with, how long it is kept, and how to have it deleted. It covers our website, our web application, and every channel the product connects to — WhatsApp, Instagram, Facebook Pages and Meta Ads.
Who we are.
Converse360 is operated by Conceps Media Works, at No. 38/4, Hindustan College Road, Near Nava India, Sowripalayam, Coimbatore, Tamil Nadu – 641028, India. In this policy "we", "us" and "Converse360" mean that business. You can reach us about anything in this policy at support@converse360.in.
1. Two different roles we play
This distinction matters, because it determines who you should contact about a given piece of data.
- For our own customers — we are the controller. When a business signs up for Converse360, we decide how their account, billing and usage data is handled. This policy governs that data directly.
- For our customers' customers — we are a processor. When a business connects their WhatsApp or Instagram account, the messages and contact records that flow through Converse360 belong to that business. They decide what to collect and why; we only store and process it on their instructions. If you messaged a business on WhatsApp and want your data removed, contact that business first — they control it. We will help them action it, and we will act on a direct request too (see §10).
2. What we collect
From the business that signs up
| Data | Detail |
|---|---|
| Account identity | Name, email address, and a password (hashed — we never see it) or a Google sign-in. Handled by our authentication provider, Supabase. |
| Workspace | Workspace name, your role, teammates you invite, and the qualification answers given during onboarding. |
| Billing | Plan, subscription status and renewal dates. Card details never reach our servers — they go directly to Stripe or Razorpay. |
| Technical | IP address, browser and device information, and product usage events, used for security and to keep the service working. |
From the business's own customers, on the business's behalf
| Data | Detail |
|---|---|
| Contact records | Phone number, name, Instagram username and Instagram-scoped ID, email if provided, plus any tags, notes and custom fields the business adds. |
| Message content | The full text of WhatsApp and Instagram messages sent and received, in both directions, including reactions, edits and deletions. |
| Media | Images, audio, video and documents exchanged in conversations. Instagram media is copied to our storage at the moment it arrives, because Instagram's own links expire. |
| Conversation metadata | Timestamps, delivery and read status, which channel a conversation arrived on, and which ad or link referred it. |
| Commerce and pipeline | Orders, products, deals and pipeline stages the business records against a contact. |
| Lead form submissions | Whatever fields a business's Facebook or Instagram lead form collects, pulled in as contacts. |
| Website widget | Conversations started from the chat widget on a business's own site. |
3. Data from Meta platforms
Because Meta requires apps to be specific about this, here is exactly what we take from each Meta surface and why.
| Surface | What we access | Why |
|---|---|---|
| WhatsApp Business Platform | WhatsApp Business Account and phone number IDs; inbound and outbound message content and media; delivery and read receipts; message templates and their approval status; messaging tier and quality rating. | To run a shared team inbox, send and receive messages, and show the business the state of their own account. |
| The professional account's ID, username and profile picture; direct message content and media; message reactions, read receipts and story-reply context; comments on the business's own posts. | To bring Instagram DMs into the same inbox as WhatsApp and let the business moderate and reply to comments. | |
| Facebook Pages / Lead Ads | The list of Pages the user administers, Page name and picture, and lead form submissions. | So the business can choose which Page to sync, and so new leads become CRM contacts automatically. |
| Meta Ads (Marketing API) | Business portfolios, ad accounts, campaigns, ad sets, ads and creatives; daily aggregate performance figures such as spend, clicks and impressions. | To let the business create and manage ads from our dashboard, and to report what those ads cost and produced alongside the deals they generated. |
Access tokens. Connecting any of these stores an access token so we can act on the business's behalf. Every token is encrypted with AES-256-GCM before it is written to the database, is never returned to any browser, and is deleted the moment the business disconnects the channel or removes our app from their Meta settings.
4. Why we use it
- To provide the service — deliver messages, run the inbox, execute the automations and flows a business has built, sync ad performance. This is the performance of our contract with the business.
- To keep it secure — detect abuse, verify webhook signatures, rate-limit, and investigate incidents. This is our legitimate interest in a safe service.
- To bill — process subscriptions and comply with tax and accounting law.
- To support — answer questions, which sometimes means an authorised engineer looking at a specific record with the business's knowledge.
What we never do: we do not sell personal data, we do not share it with advertisers or data brokers, we do not use message content for our own marketing, and we do not use it to build profiles of the people a business talks to.
5. AI features
Converse360 includes an optional AI assistant. A business chooses which of two ways it runs on, and the choice decides where conversation content goes.
| Mode | Whose key | What that means for your data |
|---|---|---|
| Built-in AI (the default) | Ours — a Converse360 account with Google Gemini | When the assistant is used, the conversation content it needs is sent to Google under our agreement with Google, and the usage is metered against the workspace's credit balance. We use paid API tiers, whose terms prohibit the provider from using the content to train or improve its models. |
| Your own key | Yours — OpenAI, Anthropic or Google | The business supplies its own API key, which we store encrypted, and content goes directly to that provider under the business's own agreement with them — never through an account of ours, and nothing is metered. |
The assistant only runs when it is switched on. A workspace that never enables it sends no conversation content to any AI provider in either mode. A workspace that does enable it should assume that the messages the assistant reads in order to answer are sent to the provider for that mode.
Businesses may also upload documents (PDF, Word, plain text) or point us at a public web page to build the assistant's knowledge base. That content is stored in the workspace, converted into search embeddings, and used only to answer that workspace's own conversations.
We do not train AI models on your data. We do not use WhatsApp Business data, Instagram data, message content, contact records or anything derived from them to train, fine-tune or develop any machine-learning model — including in aggregated or anonymised form. This is both our policy and a requirement of Meta's WhatsApp Business Solution Terms.
6. Google services integration
Converse360 allows businesses to optionally connect their Google account to access specific Google services. These integrations are entirely opt-in: no Google data is accessed unless a business explicitly authorises the connection from within the Converse360 settings.
| Google service | Data accessed | Purpose |
|---|---|---|
| Gmail | gmail.send — send an email as the connected account. Converse360 cannot read, search, label or delete mail, and does not request any scope that would allow it. Your mailbox is never downloaded or stored. | To send follow-ups, confirmations and reminders from the business's own address as part of a workflow the business built. |
| Google Calendar | calendar.events, calendar.freebusy — create, update, delete and search calendar events, and read free/busy times. | To book appointments with customers from a conversation and to check whether a slot is free before offering it. |
| Google Sheets | spreadsheets — append, find and update rows in a spreadsheet the business supplies the link to, and create a new spreadsheet on request. Converse360 does not request Drive access and cannot list or browse your files. | To log leads, orders and conversation outcomes for reporting, and to look up a row to enrich a contact record. |
| Google Meet | meetings.space.created — create a new meeting space. This scope grants access only to meetings Converse360 itself creates; existing meetings, recordings and transcripts are not accessible. | To generate a meeting link to share with a customer in a conversation. |
These four are the only Google scopes Converse360 requests. All of them are classified by Google as sensitive; Converse360 deliberately does not request any restricted scope, including Gmail read access and any Google Drive scope.
How we use Google data. Data obtained through Google APIs is used only to provide the specific feature you have enabled. It is not used for advertising, not shared with any third party for their own purposes, and not used to train or improve any AI model. We do not combine Google user data with data obtained from other sources for profiling purposes.
Revoking access. You can disconnect a Google integration at any time from the Converse360 Settings page. Doing so immediately revokes our access token and stops any further access to your Google data. You can also revoke access directly from your Google Account permissions page.
Converse360's use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
8. What we send to Meta
Mostly nothing beyond the messages a business chooses to send. There is one exception worth stating plainly:
Custom audiences. If a business builds an advertising audience from its CRM contacts, the customer identifiers in that audience — phone numbers, and email addresses if used — are hashed with SHA-256 on our servers before they are transmitted. Meta never receives them in plain text. The audience is flagged to Meta as the advertiser's own contacts, collected with consent. This only happens when a business deliberately creates an audience; it is never automatic.
Aggregate advertising performance data we read back from Meta — spend, clicks, impressions per campaign per day — contains no personal data.
9. How long we keep it
| Data | Retention |
|---|---|
| Messages, contacts and conversation history | For as long as the workspace is active, then 90 days after the subscription ends, after which it is permanently deleted. |
| Access tokens for Meta channels | Deleted immediately on disconnection, deauthorisation, or account closure. |
| Account and workspace records | 90 days after closure. |
| Billing and tax records | Kept for as long as Indian tax and company law requires — up to 8 years from the end of the relevant financial year — even after the account closes. |
| Advertising records (which campaigns ran, what they spent) | Retained as the business's own financial history. These contain no personal data. |
| Security and audit logs | 90 days, unless a longer period is needed to investigate a specific incident. |
A business can delete individual contacts, conversations or messages from inside the product at any time, without waiting for any of the above.
10. Deleting your data
If you are a Converse360 customer
Disconnect a channel from Settings to remove its tokens immediately. To delete the whole workspace, email support@converse360.in from the address on the account. We action verified requests within 30 days.
If you messaged a business that uses Converse360
That business controls your data. Contact them first. If you cannot reach them, or they do not respond, write to us at support@converse360.in with enough detail to identify the records — the business's name and the phone number or Instagram handle you used — and we will locate and delete them.
If you removed our app from your Meta or Instagram settings
Meta notifies us automatically, and we delete the stored connection and its access tokens without you needing to do anything else. Meta will show you a confirmation code and a link to a status page confirming this.
11. How we protect it
- All traffic is encrypted in transit over HTTPS.
- Every third-party access token, API key and webhook secret is encrypted at rest with AES-256-GCM. Tokens are never sent to a browser.
- Every database query is scoped to a single workspace, enforced both by row-level security policies and by explicit checks in application code. One business cannot read another's data.
- Inbound webhooks are rejected unless their HMAC signature verifies against the raw request body, so a forged message cannot enter the system.
- Requests to URLs supplied by users — page crawling, custom API actions — are filtered to block access to internal network addresses.
- Access to production data by our staff is limited to what support requires and is logged.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator within the timeframes the law sets.
12. Your rights
Depending on where you live, you can ask us to:
- tell you what personal data we hold about you, and give you a copy;
- correct anything inaccurate;
- delete it;
- restrict or object to how we use it;
- port it to another service in a machine-readable format;
- withdraw consent, where we relied on consent.
Email support@converse360.in. We respond within 30 days and do not charge for reasonable requests. We may need to verify your identity first — the alternative is a deletion endpoint anyone can point at anyone.
If we act as a processor rather than a controller for the data in question (see §1), we will forward your request to the business that controls it and support them in answering it.
13. International transfers
We are based in India, but our providers operate globally, so your data is processed outside India. Specifically:
- our application servers and queues are in Mumbai, India;
- our database and uploaded files are in Seoul, South Korea, on Supabase's AWS
ap-northeast-2region — this includes contacts, messages and media; - Meta, Stripe, Google and any AI provider operate globally and may process data in the United States, the European Union and elsewhere.
Where data leaves a jurisdiction that restricts transfers, we rely on the transfer terms in each provider's data processing agreement — Standard Contractual Clauses or the provider's equivalent mechanism — and we require protection equivalent to this policy from every provider we use.
14. Children
Converse360 is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18, the age at which India's Digital Personal Data Protection Act 2023 stops treating a person as a child. If you believe a child's data has reached us, tell us and we will delete it.
15. Changes to this policy
We update this page when the product changes. Material changes are announced in the app and by email to workspace owners at least 30 days before they take effect. The "last updated" date at the top always reflects the current version.
16. Contact and complaints
Conceps Media Works
Privacy enquiries and data requests: support@converse360.in
Postal address: No. 38/4, Hindustan College Road, Near Nava India, Sowripalayam, Coimbatore, Tamil Nadu – 641028, India
Grievance Officer (India, DPDP Act 2023): The Grievance Officer, Conceps Media Works, at the address above or support@converse360.in
If you are unhappy with our response you can complain to your local data protection authority — in India, the Data Protection Board; in the EU or UK, your national supervisory authority.