1. Who is responsible for the data
For your own account (the people who sign up and use Balawari), Balawari decides how the data is used. For the data of a business’s customers — their messages, bookings and contact details, and the people a business sends campaigns to — the business decides why it is collected and Balawari processes it on the business’s behalf, only to provide the Service. If you are a customer of a business that uses Balawari, you can also contact that business directly about your data.
2. Information we collect
- Account data: name, email and business details provided at sign-up (authentication is handled by our identity provider).
- Business configuration: services, prices, FAQs, documents, branches, staff and settings you add.
- Conversation data: messages exchanged with your customers on connected channels (WhatsApp, Instagram, Facebook Messenger), including names, phone numbers or handles and message content, processed to generate replies and capture leads.
- Booking data: bookings, the customer’s name and contact details, and payment status. Card and wallet details are entered on the payment provider’s page; we keep only the payment status and reference.
- Campaign data: the recipients of a business’s email or WhatsApp campaigns (name, email address or phone number, and whether they came from chats, bookings or an imported list), contact lists a business uploads, the campaign content, delivery results, and whether an email was opened or a link in it was clicked.
- Opt-out records: email addresses and phone numbers that unsubscribed, replied STOP, stopped marketing messages in WhatsApp, bounced or marked an email as spam.
- Social publishing data: the posts you create (text, images, video, captions and schedule), the media you upload for them, and the result of each publication.
- Connected-account tokens: access tokens for the accounts you connect — Meta (WhatsApp, Instagram, Facebook), LinkedIn, X and YouTube — used only to act on your behalf.
- Usage and logs: technical logs needed to operate and secure the Service, and anonymous visit statistics for this website.
3. How we use information
- To provide the Service: answer customers, qualify leads, take bookings and route conversations.
- To send the campaigns a business creates, to the audience it chooses, and to report the results.
- To publish the posts you create to the social accounts you connect.
- To ground AI responses and drafts in your own business data, and to call AI models.
- To honour opt-outs, prevent abuse, and secure, maintain and improve the Service.
- To comply with legal obligations and platform policies.
We do not sell personal data, and we do not use a business’s customer data for our own marketing.
4. Email and WhatsApp campaigns
- A business may send campaigns only to its own customers — people who contacted it or booked with it — and to contact lists it imports after confirming those people agreed to hear from it.
- Every campaign email includes an unsubscribe link and a one-click unsubscribe header. WhatsApp recipients can reply STOP or stop marketing messages in WhatsApp. An opt-out takes effect immediately and is honoured in every later campaign from that business.
- Addresses that bounce or report an email as spam are suppressed automatically.
- Campaign emails contain a small image and rewritten links so the business can see deliveries, opens and clicks. These are tied to the individual recipient of that campaign only.
- Emails are delivered through Amazon Web Services (Amazon SES); WhatsApp messages are sent through the business’s own WhatsApp Business account on Meta’s platform.
- If you received a campaign and want to stop hearing from a business, use the unsubscribe link, reply STOP on WhatsApp, or contact us at the address below.
5. Social publishing and connected accounts
- When you connect Instagram, Facebook, LinkedIn, X or YouTube, we request only the permissions needed to publish on your behalf and to show which accounts and pages are connected.
- We publish only the posts you create and send. Video editing happens in your own browser; media is uploaded to our storage only when you publish or save it.
- Tokens are stored in our database, used only to publish for you, and deleted when you disconnect the account or delete your workspace.
- YouTube publishing uses the YouTube API Services. By connecting YouTube you agree to the YouTube Terms of Service, and Google’s handling of the data is covered by the Google Privacy Policy. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
- You can revoke our access at any time from the Channels page in Balawari, or from the platform itself: Meta (Facebook, Instagram, WhatsApp), LinkedIn, X, Google and YouTube.
6. Meta platform data
When you connect WhatsApp, Instagram or Facebook, we process messages and identifiers received from Meta solely to provide the Service to you, in accordance with Meta’s Platform Terms and developer policies.
7. Sharing and sub-processors
We share data only with the providers we need to operate the Service:
- Cloudflare — hosting, edge compute, queues and file storage.
- Neon — database.
- Amazon Web Services (Amazon SES) — delivery of campaign emails and their bounce and complaint reports.
- Meta — WhatsApp, Instagram and Messenger messaging and publishing.
- LinkedIn, X and Google (YouTube) — only when you publish to those accounts.
- AI model providers — to generate replies and drafts.
- Our authentication provider and payment providers.
8. Data retention
- Account and business data: while your account is active.
- Chat messages: for the retention period set by the business (90 days by default).
- Campaign recipients: names and addresses are erased 180 days after a campaign finishes; only the campaign’s totals remain.
- Opt-out records are kept for as long as the business uses Balawari, so an opt-out keeps working.
You can request deletion at any time — see our Data Deletion page.
9. Security
We apply industry-standard safeguards: per-business isolation of data, encryption of messaging channel tokens at rest, encrypted transport (HTTPS), signed links in emails, and least-privilege access.
10. Your rights
Depending on your location, you may have rights to access, correct, export or delete your personal data, and to object to marketing. Contact us to exercise them; if your data belongs to a business using Balawari, we will pass your request to that business and help it respond.
11. Children
Balawari is a service for businesses and is not directed to children under 16.
12. International transfers
Data may be processed in regions where our providers operate, with appropriate safeguards.
13. Changes
We will update this page when our practices change and show the date of the latest version at the top.
14. Contact
For privacy questions or requests, email ejazhussain1050@gmail.com.
This document is a template provided for convenience and is not legal advice. Please have it reviewed by qualified counsel before relying on it.