Privacy policy
Draft for pilot use. This document has not yet been reviewed by a lawyer and will change before general availability.
Who this covers
This policy describes how makchat handles data about merchants who use the service and about the customers whose conversations pass through connected channels. For customer conversation data, the merchant controls the data and makchat processes it on the merchant's instructions.
What we collect
- Account data: name, email, password hash, two-factor settings, sign-in history, IP address and security events.
- Workspace data: business settings, team members, roles, billing records, audit records, catalog, knowledge articles and order drafts.
- Connected channel data: Facebook Page IDs, WhatsApp Business Account and phone-number IDs, Instagram professional account IDs, channel health, scopes and encrypted connection credentials.
- Customer conversation data: Meta-scoped customer identifiers, names or usernames when provided, phone numbers when provided, messages, attachments, media metadata, delivery/read/status events, labels, notes and order context.
- Webhook and diagnostic data: signed webhook fragments, event identifiers, hashes, safe error codes and replay attempts used for routing, security, deduplication and support.
- Contact form data: name, email, business name, phone and message.
How we use data
We use data to provide the inbox, channel integrations, customer support workflows, catalog and order features, security controls, audit logs, billing, diagnostics and reply suggestions requested by the merchant. We do not use one merchant's customer conversations to train models or answer another merchant's customers.
Meta platform data
When a merchant connects Messenger, WhatsApp Cloud API or Instagram messaging, makchat uses the Meta permissions granted by that merchant to route inbound messages, show conversations in the workspace, send replies chosen by the merchant or their team, receive delivery/read/status events, and monitor connection health. Meta channel live use remains gated until provider review and recorded validation are complete.
Service providers
Hosting, email delivery, AI model providers, embedding providers, payment processors and Meta platform APIs may process data on our behalf or as connected services. Provider processing, regions, retention and approval status are recorded before a provider is enabled for production use. Password breach checks send only a short anonymised fragment of a password hash.
Retention and deletion
Retention defaults are under legal review. Current product controls support workspace export, customer erasure, retention jobs, credential destruction on disconnect, and deletion of retained webhook/media content according to the documented retention schedule. Deleted records are not intentionally restored from backups.
Your choices
Workspace owners can export workspace data, erase customer data where supported, disconnect channels and request deletion. Requests can be sent to privacy@makchat.makapp.co. See the data deletion instructions page for the request path used for Meta app review.