Coming soonMeta Ads Manager inside Converse360
NewBuild AI Agents on WhatsApp that qualify & convert 24/7
Converse360
Industries
Retail & D2CEducationReal EstateHealthcareFinanceLogistics
View all industries

Book a one-to-one meeting with our product expert

Twenty minutes, mapped to how enquiries reach you today.

Book your demo
PricingFAQBlogAbout us
Contact

Privacy Policy

Effective 9 August 2026 · Last updated 9 August 2026

This policy explains what personal data Converse360 handles, why, who it is shared with, how long it is kept, and how to have it deleted. It covers our website, our web application, and every channel the product connects to — WhatsApp, Instagram, Facebook Pages and Meta Ads.

Who we are.

Converse360 is operated by Conceps Media Works, at No. 38/4, Hindustan College Road, Near Nava India, Sowripalayam, Coimbatore, Tamil Nadu – 641028, India. In this policy "we", "us" and "Converse360" mean that business. You can reach us about anything in this policy at support@converse360.in.

Table of Contents
  1. 1. Two different roles we play
  2. 2. What we collect
  3. 3. Data from Meta platforms
  4. 4. Why we use it
  5. 5. AI features
  6. 6. Google services integration
  7. 7. Who we share it with
  8. 8. What we send to Meta
  9. 9. How long we keep it
  10. 10. Deleting your data
  11. 11. How we protect it
  12. 12. Your rights
  13. 13. International transfers
  14. 14. Children
  15. 15. Changes to this policy
  16. 16. Contact and complaints

1. Two different roles we play

This distinction matters, because it determines who you should contact about a given piece of data.

  • For our own customers — we are the controller. When a business signs up for Converse360, we decide how their account, billing and usage data is handled. This policy governs that data directly.
  • For our customers' customers — we are a processor. When a business connects their WhatsApp or Instagram account, the messages and contact records that flow through Converse360 belong to that business. They decide what to collect and why; we only store and process it on their instructions. If you messaged a business on WhatsApp and want your data removed, contact that business first — they control it. We will help them action it, and we will act on a direct request too (see §10).

2. What we collect

From the business that signs up

DataDetail
Account identityName, email address, and a password (hashed — we never see it) or a Google sign-in. Handled by our authentication provider, Supabase.
WorkspaceWorkspace name, your role, teammates you invite, and the qualification answers given during onboarding.
BillingPlan, subscription status and renewal dates. Card details never reach our servers — they go directly to Stripe or Razorpay.
TechnicalIP address, browser and device information, and product usage events, used for security and to keep the service working.

From the business's own customers, on the business's behalf

DataDetail
Contact recordsPhone number, name, Instagram username and Instagram-scoped ID, email if provided, plus any tags, notes and custom fields the business adds.
Message contentThe full text of WhatsApp and Instagram messages sent and received, in both directions, including reactions, edits and deletions.
MediaImages, audio, video and documents exchanged in conversations. Instagram media is copied to our storage at the moment it arrives, because Instagram's own links expire.
Conversation metadataTimestamps, delivery and read status, which channel a conversation arrived on, and which ad or link referred it.
Commerce and pipelineOrders, products, deals and pipeline stages the business records against a contact.
Lead form submissionsWhatever fields a business's Facebook or Instagram lead form collects, pulled in as contacts.
Website widgetConversations started from the chat widget on a business's own site.

3. Data from Meta platforms

Because Meta requires apps to be specific about this, here is exactly what we take from each Meta surface and why.

SurfaceWhat we accessWhy
WhatsApp Business PlatformWhatsApp Business Account and phone number IDs; inbound and outbound message content and media; delivery and read receipts; message templates and their approval status; messaging tier and quality rating.To run a shared team inbox, send and receive messages, and show the business the state of their own account.
InstagramThe professional account's ID, username and profile picture; direct message content and media; message reactions, read receipts and story-reply context; comments on the business's own posts.To bring Instagram DMs into the same inbox as WhatsApp and let the business moderate and reply to comments.
Facebook Pages / Lead AdsThe list of Pages the user administers, Page name and picture, and lead form submissions.So the business can choose which Page to sync, and so new leads become CRM contacts automatically.
Meta Ads (Marketing API)Business portfolios, ad accounts, campaigns, ad sets, ads and creatives; daily aggregate performance figures such as spend, clicks and impressions.To let the business create and manage ads from our dashboard, and to report what those ads cost and produced alongside the deals they generated.

Access tokens. Connecting any of these stores an access token so we can act on the business's behalf. Every token is encrypted with AES-256-GCM before it is written to the database, is never returned to any browser, and is deleted the moment the business disconnects the channel or removes our app from their Meta settings.

4. Why we use it

  • To provide the service — deliver messages, run the inbox, execute the automations and flows a business has built, sync ad performance. This is the performance of our contract with the business.
  • To keep it secure — detect abuse, verify webhook signatures, rate-limit, and investigate incidents. This is our legitimate interest in a safe service.
  • To bill — process subscriptions and comply with tax and accounting law.
  • To support — answer questions, which sometimes means an authorised engineer looking at a specific record with the business's knowledge.

What we never do: we do not sell personal data, we do not share it with advertisers or data brokers, we do not use message content for our own marketing, and we do not use it to build profiles of the people a business talks to.

5. AI features

Converse360 includes an optional AI assistant. A business chooses which of two ways it runs on, and the choice decides where conversation content goes.

ModeWhose keyWhat that means for your data
Built-in AI
(the default)
Ours — a Converse360 account with Google GeminiWhen the assistant is used, the conversation content it needs is sent to Google under our agreement with Google, and the usage is metered against the workspace's credit balance. We use paid API tiers, whose terms prohibit the provider from using the content to train or improve its models.
Your own keyYours — OpenAI, Anthropic or GoogleThe business supplies its own API key, which we store encrypted, and content goes directly to that provider under the business's own agreement with them — never through an account of ours, and nothing is metered.

The assistant only runs when it is switched on. A workspace that never enables it sends no conversation content to any AI provider in either mode. A workspace that does enable it should assume that the messages the assistant reads in order to answer are sent to the provider for that mode.

Businesses may also upload documents (PDF, Word, plain text) or point us at a public web page to build the assistant's knowledge base. That content is stored in the workspace, converted into search embeddings, and used only to answer that workspace's own conversations.

We do not train AI models on your data. We do not use WhatsApp Business data, Instagram data, message content, contact records or anything derived from them to train, fine-tune or develop any machine-learning model — including in aggregated or anonymised form. This is both our policy and a requirement of Meta's WhatsApp Business Solution Terms.

6. Google services integration

Converse360 allows businesses to optionally connect their Google account to access specific Google services. These integrations are entirely opt-in: no Google data is accessed unless a business explicitly authorises the connection from within the Converse360 settings.

Google serviceData accessedPurpose
Gmailgmail.send — send an email as the connected account. Converse360 cannot read, search, label or delete mail, and does not request any scope that would allow it. Your mailbox is never downloaded or stored.To send follow-ups, confirmations and reminders from the business's own address as part of a workflow the business built.
Google Calendarcalendar.events, calendar.freebusy — create, update, delete and search calendar events, and read free/busy times.To book appointments with customers from a conversation and to check whether a slot is free before offering it.
Google Sheetsspreadsheets — append, find and update rows in a spreadsheet the business supplies the link to, and create a new spreadsheet on request. Converse360 does not request Drive access and cannot list or browse your files.To log leads, orders and conversation outcomes for reporting, and to look up a row to enrich a contact record.
Google Meetmeetings.space.created — create a new meeting space. This scope grants access only to meetings Converse360 itself creates; existing meetings, recordings and transcripts are not accessible.To generate a meeting link to share with a customer in a conversation.

These four are the only Google scopes Converse360 requests. All of them are classified by Google as sensitive; Converse360 deliberately does not request any restricted scope, including Gmail read access and any Google Drive scope.

How we use Google data. Data obtained through Google APIs is used only to provide the specific feature you have enabled. It is not used for advertising, not shared with any third party for their own purposes, and not used to train or improve any AI model. We do not combine Google user data with data obtained from other sources for profiling purposes.

Revoking access. You can disconnect a Google integration at any time from the Converse360 Settings page. Doing so immediately revokes our access token and stops any further access to your Google data. You can also revoke access directly from your Google Account permissions page.

Converse360's use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

7. Who we share it with

We use a small number of service providers. Each processes data only to deliver its part of the service.

ProviderWhat it handlesWhere
Meta PlatformsWhatsApp, Instagram, Facebook and Ads message and campaign deliveryGlobal
SupabaseDatabase, authentication and file storageSeoul, South Korea (AWS ap-northeast-2)
Stripe / RazorpaySubscription payments and card processingGlobal / India
Google (Gemini)AI replies in built-in AI mode, on our key, under our contract with GoogleGlobal
OpenAI, Anthropic or GoogleAI replies — only if the business has added its own key, and under that business's own contract with the providerGlobal
HostingerApplication servers and queuesMumbai, India

We also disclose data where the law requires it — a valid court order or a binding request from a competent authority — and to a successor entity in a merger or acquisition, in which case this policy travels with the data.

8. What we send to Meta

Mostly nothing beyond the messages a business chooses to send. There is one exception worth stating plainly:

Custom audiences. If a business builds an advertising audience from its CRM contacts, the customer identifiers in that audience — phone numbers, and email addresses if used — are hashed with SHA-256 on our servers before they are transmitted. Meta never receives them in plain text. The audience is flagged to Meta as the advertiser's own contacts, collected with consent. This only happens when a business deliberately creates an audience; it is never automatic.

Aggregate advertising performance data we read back from Meta — spend, clicks, impressions per campaign per day — contains no personal data.

9. How long we keep it

DataRetention
Messages, contacts and conversation historyFor as long as the workspace is active, then 90 days after the subscription ends, after which it is permanently deleted.
Access tokens for Meta channelsDeleted immediately on disconnection, deauthorisation, or account closure.
Account and workspace records90 days after closure.
Billing and tax recordsKept for as long as Indian tax and company law requires — up to 8 years from the end of the relevant financial year — even after the account closes.
Advertising records (which campaigns ran, what they spent)Retained as the business's own financial history. These contain no personal data.
Security and audit logs90 days, unless a longer period is needed to investigate a specific incident.

A business can delete individual contacts, conversations or messages from inside the product at any time, without waiting for any of the above.

10. Deleting your data

If you are a Converse360 customer

Disconnect a channel from Settings to remove its tokens immediately. To delete the whole workspace, email support@converse360.in from the address on the account. We action verified requests within 30 days.

If you messaged a business that uses Converse360

That business controls your data. Contact them first. If you cannot reach them, or they do not respond, write to us at support@converse360.in with enough detail to identify the records — the business's name and the phone number or Instagram handle you used — and we will locate and delete them.

If you removed our app from your Meta or Instagram settings

Meta notifies us automatically, and we delete the stored connection and its access tokens without you needing to do anything else. Meta will show you a confirmation code and a link to a status page confirming this.

11. How we protect it

  • All traffic is encrypted in transit over HTTPS.
  • Every third-party access token, API key and webhook secret is encrypted at rest with AES-256-GCM. Tokens are never sent to a browser.
  • Every database query is scoped to a single workspace, enforced both by row-level security policies and by explicit checks in application code. One business cannot read another's data.
  • Inbound webhooks are rejected unless their HMAC signature verifies against the raw request body, so a forged message cannot enter the system.
  • Requests to URLs supplied by users — page crawling, custom API actions — are filtered to block access to internal network addresses.
  • Access to production data by our staff is limited to what support requires and is logged.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator within the timeframes the law sets.

12. Your rights

Depending on where you live, you can ask us to:

  • tell you what personal data we hold about you, and give you a copy;
  • correct anything inaccurate;
  • delete it;
  • restrict or object to how we use it;
  • port it to another service in a machine-readable format;
  • withdraw consent, where we relied on consent.

Email support@converse360.in. We respond within 30 days and do not charge for reasonable requests. We may need to verify your identity first — the alternative is a deletion endpoint anyone can point at anyone.

If we act as a processor rather than a controller for the data in question (see §1), we will forward your request to the business that controls it and support them in answering it.

13. International transfers

We are based in India, but our providers operate globally, so your data is processed outside India. Specifically:

  • our application servers and queues are in Mumbai, India;
  • our database and uploaded files are in Seoul, South Korea, on Supabase's AWS ap-northeast-2 region — this includes contacts, messages and media;
  • Meta, Stripe, Google and any AI provider operate globally and may process data in the United States, the European Union and elsewhere.

Where data leaves a jurisdiction that restricts transfers, we rely on the transfer terms in each provider's data processing agreement — Standard Contractual Clauses or the provider's equivalent mechanism — and we require protection equivalent to this policy from every provider we use.

14. Children

Converse360 is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18, the age at which India's Digital Personal Data Protection Act 2023 stops treating a person as a child. If you believe a child's data has reached us, tell us and we will delete it.

15. Changes to this policy

We update this page when the product changes. Material changes are announced in the app and by email to workspace owners at least 30 days before they take effect. The "last updated" date at the top always reflects the current version.

16. Contact and complaints

Conceps Media Works
Privacy enquiries and data requests: support@converse360.in
Postal address: No. 38/4, Hindustan College Road, Near Nava India, Sowripalayam, Coimbatore, Tamil Nadu – 641028, India
Grievance Officer (India, DPDP Act 2023): The Grievance Officer, Conceps Media Works, at the address above or support@converse360.in

If you are unhappy with our response you can complain to your local data protection authority — in India, the Data Protection Board; in the EU or UK, your national supervisory authority.

Converse360

One AI-powered inbox for WhatsApp, Instagram, and your website. Built for businesses that sell in conversations.

Meta Tech Provider
Quick links
About usBook a free demoContact usFAQBlog
Legal & support
PricingPrivacy policyTerms & conditions
Get in touch
2nd Floor, 38/4, opp. Hindustan College Road, Paul Harris Nagar, Coimbatore, Tamil Nadu 641028
7338855082
hello@converse360.in
© 2026 Converse360. All rights reserved.
Follow us