CRM Privacy Policy
This policy explains how CRM collects, uses, stores, and deletes information when organizations use CRM to manage Facebook Page conversations.
1. Information we process
Account and security data. We process workspace user names, email addresses, authentication records, roles, Page assignments, support schedules, active sessions, and security audit events.
Facebook and Messenger data. When an authorized administrator connects a Facebook account, we process the Pages they choose to add, Page identifiers and profile details, access credentials supplied by Meta, customer-scoped identifiers, customer display names, Messenger conversations, message attachments, labels, reactions, delivery status, and read status.
Operational data. We process IP addresses, browser information, error logs, synchronization status, and timestamps needed to secure and operate the service.
2. How we use information
We use this information to authenticate users, apply workspace roles, display and synchronize authorized Facebook Page conversations, send replies requested by authorized agents, manage labels and assignments, deliver notifications, investigate failures, prevent abuse, and maintain audit records.
CRM does not use Messenger content for behavioral advertising and does not sell personal information.
4. Security
We use role-based access, encrypted Page credentials, transport encryption, two-step verification, session controls, audit logging, backups, and restricted administrative access. No system is perfectly secure, but we review and improve these safeguards as the service evolves.
5. Retention
We keep account, Page, and conversation data while a workspace uses the service or as required for security, contractual, or legal purposes. To control operational storage, CRM keeps the most recent message history for each Page and removes the oldest messages when the configured Page limit is exceeded. Deleted records may remain in encrypted backups until those backups expire.
6. Data deletion requests
Workspace owners and Facebook Page administrators may request access, correction, disconnection, export, or deletion of data controlled by their organization.
- Email rahmansalis@gmail.com with the subject "CRM data deletion request."
- Include the workspace name, Facebook Page name or Page ID, and the email address used for CRM.
- We will verify that the requester is authorized for the workspace or Page before acting.
- After verification, we will disconnect the relevant Meta access and delete applicable account, Page, customer, conversation, and attachment data, subject to legal retention obligations. We aim to complete verified requests within 30 days.
Removing CRM from Facebook's Business Integrations stops future access but may not automatically remove information already stored in CRM. Use the request process above for deletion from our systems.
7. Choices and rights
Depending on location, individuals may have rights to access, correct, delete, restrict, or export personal information and to object to certain processing. Requests may be submitted using the contact below. Customer message senders may also contact the Facebook Page that handled their conversation.
8. Children
CRM is a business service and is not directed to children. Workspace administrators must use the service consistently with Meta's policies and applicable law.
9. Changes to this policy
We may update this policy when the service, our providers, or legal requirements change. The effective date at the top identifies the current version.
10. Contact
Questions, privacy requests, and complaints can be sent to rahmansalis@gmail.com.