This policy explains what personal data Converse360 handles, why, who it is shared with, how long it is kept, and how to have it deleted. It covers our website, our web application, and every channel the product connects to — WhatsApp, Instagram, Facebook Pages and Meta Ads.
Who we are. Converse360 is operated by Conceps Media Works, at No. 38/4, Hindustan College Road, Near Nava India, Sowripalayam, Coimbatore, Tamil Nadu – 641028, India. In this policy "we", "us" and "Converse360" mean that business. You can reach us about anything in this policy at support@converse360.in.
This distinction matters, because it determines who you should contact about a given piece of data.
| Data | Detail |
|---|---|
| Account identity | Name, email address, and a password (hashed — we never see it) or a Google sign-in. Handled by our authentication provider, Supabase. |
| Workspace | Workspace name, your role, teammates you invite, and the qualification answers given during onboarding. |
| Billing | Plan, subscription status and renewal dates. Card details never reach our servers — they go directly to Stripe or Razorpay. |
| Technical | IP address, browser and device information, and product usage events, used for security and to keep the service working. |
| Data | Detail |
|---|---|
| Contact records | Phone number, name, Instagram username and Instagram-scoped ID, email if provided, plus any tags, notes and custom fields the business adds. |
| Message content | The full text of WhatsApp and Instagram messages sent and received, in both directions, including reactions, edits and deletions. |
| Media | Images, audio, video and documents exchanged in conversations. Instagram media is copied to our storage at the moment it arrives, because Instagram's own links expire. |
| Conversation metadata | Timestamps, delivery and read status, which channel a conversation arrived on, and which ad or link referred it. |
| Commerce and pipeline | Orders, products, deals and pipeline stages the business records against a contact. |
| Lead form submissions | Whatever fields a business's Facebook or Instagram lead form collects, pulled in as contacts. |
| Website widget | Conversations started from the chat widget on a business's own site. |
Because Meta requires apps to be specific about this, here is exactly what we take from each Meta surface and why.
| Surface | What we access | Why |
|---|---|---|
| WhatsApp Business Platform | WhatsApp Business Account and phone number IDs; inbound and outbound message content and media; delivery and read receipts; message templates and their approval status; messaging tier and quality rating. | To run a shared team inbox, send and receive messages, and show the business the state of their own account. |
| The professional account's ID, username and profile picture; direct message content and media; message reactions, read receipts and story-reply context; comments on the business's own posts. | To bring Instagram DMs into the same inbox as WhatsApp and let the business moderate and reply to comments. | |
| Facebook Pages / Lead Ads | The list of Pages the user administers, Page name and picture, and lead form submissions. | So the business can choose which Page to sync, and so new leads become CRM contacts automatically. |
| Meta Ads (Marketing API) | Business portfolios, ad accounts, campaigns, ad sets, ads and creatives; daily aggregate performance figures such as spend, clicks and impressions. | To let the business create and manage ads from our dashboard, and to report what those ads cost and produced alongside the deals they generated. |
Access tokens. Connecting any of these stores an access token so we can act on the business's behalf. Every token is encrypted with AES-256-GCM before it is written to the database, is never returned to any browser, and is deleted the moment the business disconnects the channel or removes our app from their Meta settings.
What we never do: we do not sell personal data, we do not share it with advertisers or data brokers, we do not use message content for our own marketing, and we do not use it to build profiles of the people a business talks to.
Converse360 includes an optional AI assistant. A business chooses which of two ways it runs on, and the choice decides where conversation content goes.
| Mode | Whose key | What that means for your data |
|---|---|---|
| Built-in AI (the default) |
Ours — a Converse360 account with Google Gemini | When the assistant is used, the conversation content it needs is sent to Google under our agreement with Google, and the usage is metered against the workspace's credit balance. We use paid API tiers, whose terms prohibit the provider from using the content to train or improve its models. |
| Your own key | Yours — OpenAI, Anthropic or Google | The business supplies its own API key, which we store encrypted, and content goes directly to that provider under the business's own agreement with them — never through an account of ours, and nothing is metered. |
The assistant only runs when it is switched on. A workspace that never enables it sends no conversation content to any AI provider in either mode. A workspace that does enable it should assume that the messages the assistant reads in order to answer are sent to the provider for that mode.
Businesses may also upload documents (PDF, Word, plain text) or point us at a public web page to build the assistant's knowledge base. That content is stored in the workspace, converted into search embeddings, and used only to answer that workspace's own conversations.
We do not train AI models on your data. We do not use WhatsApp Business data, Instagram data, message content, contact records or anything derived from them to train, fine-tune or develop any machine-learning model — including in aggregated or anonymised form. This is both our policy and a requirement of Meta's WhatsApp Business Solution Terms.
Converse360 allows businesses to optionally connect their Google account to access specific Google services. These integrations are entirely opt-in: no Google data is accessed unless a business explicitly authorises the connection from within the Converse360 settings.
| Google service | Data accessed | Purpose |
|---|---|---|
| Gmail | gmail.send — send an email as the connected account. Converse360 cannot read, search, label or delete mail, and does not request any scope that would allow it. Your mailbox is never downloaded or stored. |
To send follow-ups, confirmations and reminders from the business's own address as part of a workflow the business built. |
| Google Calendar | calendar.events, calendar.freebusy — create, update, delete and search calendar events, and read free/busy times. |
To book appointments with customers from a conversation and to check whether a slot is free before offering it. |
| Google Sheets | spreadsheets — append, find and update rows in a spreadsheet the business supplies the link to, and create a new spreadsheet on request. Converse360 does not request Drive access and cannot list or browse your files. |
To log leads, orders and conversation outcomes for reporting, and to look up a row to enrich a contact record. |
| Google Meet | meetings.space.created — create a new meeting space. This scope grants access only to meetings Converse360 itself creates; existing meetings, recordings and transcripts are not accessible. |
To generate a meeting link to share with a customer in a conversation. |
These four are the only Google scopes Converse360 requests. All of them are classified by Google as sensitive; Converse360 deliberately does not request any restricted scope, including Gmail read access and any Google Drive scope.
How we use Google data. Data obtained through Google APIs is used only to provide the specific feature you have enabled. It is not used for advertising, not shared with any third party for their own purposes, and not used to train or improve any AI model. We do not combine Google user data with data obtained from other sources for profiling purposes.
Revoking access. You can disconnect a Google integration at any time from the Converse360 Settings page. Doing so immediately revokes our access token and stops any further access to your Google data. You can also revoke access directly from your Google Account permissions page.
Converse360's use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
We use a small number of service providers. Each processes data only to deliver its part of the service.
| Provider | What it handles | Where |
|---|---|---|
| Meta Platforms | WhatsApp, Instagram, Facebook and Ads message and campaign delivery | Global |
| Supabase | Database, authentication and file storage | Seoul, South Korea (AWS ap-northeast-2) |
| Stripe / Razorpay | Subscription payments and card processing | Global / India |
| Google (Gemini) | AI replies in built-in AI mode, on our key, under our contract with Google | Global |
| OpenAI, Anthropic or Google | AI replies — only if the business has added its own key, and under that business's own contract with the provider | Global |
| Hostinger | Application servers and queues | Mumbai, India |
We also disclose data where the law requires it — a valid court order or a binding request from a competent authority — and to a successor entity in a merger or acquisition, in which case this policy travels with the data.
Mostly nothing beyond the messages a business chooses to send. There is one exception worth stating plainly:
Custom audiences. If a business builds an advertising audience from its CRM contacts, the customer identifiers in that audience — phone numbers, and email addresses if used — are hashed with SHA-256 on our servers before they are transmitted. Meta never receives them in plain text. The audience is flagged to Meta as the advertiser's own contacts, collected with consent. This only happens when a business deliberately creates an audience; it is never automatic.
Aggregate advertising performance data we read back from Meta — spend, clicks, impressions per campaign per day — contains no personal data.
| Data | Retention |
|---|---|
| Messages, contacts and conversation history | For as long as the workspace is active, then 90 days after the subscription ends, after which it is permanently deleted. |
| Access tokens for Meta channels | Deleted immediately on disconnection, deauthorisation, or account closure. |
| Account and workspace records | 90 days after closure. |
| Billing and tax records | Kept for as long as Indian tax and company law requires — up to 8 years from the end of the relevant financial year — even after the account closes. |
| Advertising records (which campaigns ran, what they spent) | Retained as the business's own financial history. These contain no personal data. |
| Security and audit logs | 90 days, unless a longer period is needed to investigate a specific incident. |
A business can delete individual contacts, conversations or messages from inside the product at any time, without waiting for any of the above.
Disconnect a channel from Settings to remove its tokens immediately. To delete the whole workspace, email support@converse360.in from the address on the account. We action verified requests within 30 days.
That business controls your data. Contact them first. If you cannot reach them, or they do not respond, write to us at support@converse360.in with enough detail to identify the records — the business's name and the phone number or Instagram handle you used — and we will locate and delete them.
Meta notifies us automatically, and we delete the stored connection and its access tokens without you needing to do anything else. Meta will show you a confirmation code and a link to a status page confirming this.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulator within the timeframes the law sets.
Depending on where you live, you can ask us to:
Email support@converse360.in. We respond within 30 days and do not charge for reasonable requests. We may need to verify your identity first — the alternative is a deletion endpoint anyone can point at anyone.
We are based in India, but our providers operate globally, so your data is processed outside India. Specifically:
ap-northeast-2 region — this includes contacts, messages and media;Where data leaves a jurisdiction that restricts transfers, we rely on the transfer terms in each provider's data processing agreement — Standard Contractual Clauses or the provider's equivalent mechanism — and we require protection equivalent to this policy from every provider we use.
Converse360 is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18, the age at which India's Digital Personal Data Protection Act 2023 stops treating a person as a child. If you believe a child's data has reached us, tell us and we will delete it.
We update this page when the product changes. Material changes are announced in the app and by email to workspace owners at least 30 days before they take effect. The "last updated" date at the top always reflects the current version.
Conceps Media Works
Privacy enquiries and data requests:
support@converse360.in
Postal address: No. 38/4, Hindustan College Road, Near Nava India,
Sowripalayam, Coimbatore, Tamil Nadu – 641028, India
Grievance Officer (India, DPDP Act 2023): The Grievance Officer,
Conceps Media Works, at the address above or
support@converse360.in
If you are unhappy with our response you can complain to your local data protection authority — in India, the Data Protection Board; in the EU or UK, your national supervisory authority.