Legal

Privacy Policy

Last updated: February 10, 2025

Reply alto Bot ('Reply alto Bot', 'we', 'us', or 'our') is a SaaS platform that helps businesses manage Facebook Messenger conversations for the Pages they operate. This Privacy Policy explains what information we collect, how we use it, the legal bases we rely on, and the rights you have over your data. By using the platform you agree to the practices described here.

1. Information We Collect

We collect only the information needed to operate the Messenger management service on your behalf. This includes:

  • Facebook Page information — the name, category, and profile details of the Pages you choose to connect.
  • Page IDs — the unique identifiers Facebook assigns to each connected Page, used to route conversations to the correct workspace.
  • Messenger conversations — messages exchanged between your Page and its customers, including message content, timestamps, and sender identifiers, so we can display your inbox and power automations.
  • User account information — your name, email address, and authentication credentials (passwords are stored only as salted hashes; we never store them in plain text).
  • Organization information — your workspace name, slug, team members, and their roles, which enable our multi-tenant access model.
  • Access tokens — Facebook Page access tokens issued to us through Facebook Login. These are stored encrypted at rest and are never exposed to your browser or any client application.

2. How We Use Your Information

We use the information we collect solely to provide and improve the service:

  • Provide Messenger inbox functionality so your team can read and reply to conversations in one place.
  • Process customer messages, including delivering, organizing, and displaying them within your workspace.
  • Enable automations and notifications, such as automated replies and alerts you configure.
  • Improve platform reliability, including monitoring, debugging, preventing abuse, and maintaining service quality.

We process this data to perform our contract with you and, where applicable, on the basis of your consent or our legitimate interest in operating a secure, reliable service.

3. Facebook Data Usage Disclosure

Reply alto Bot uses the Facebook Graph API and Messenger Platform under permissions you explicitly grant during Facebook Login. We request only the permissions required to manage the Pages you connect — such as listing your Pages, reading Page engagement, and sending and receiving Messenger messages on behalf of those Pages.

Our use of information received from Facebook APIs adheres to the Facebook Platform Terms and Developer Policies, including the limitations on how Platform Data may be used. We do not use Facebook data for advertising, and we do not transfer it to data brokers or ad networks. You may disconnect a Page at any time, which revokes our stored access token for that Page.

4. We Do Not Sell Your Data

We do not sell, rent, or trade your personal information, your customers' messages, or any Facebook data to third parties. We share data only with infrastructure sub-processors (for example, our database and hosting providers) strictly as needed to run the service, and only under agreements that require them to protect your data.

5. Data Security Practices

We apply industry-standard safeguards to protect your data in transit and at rest:

  • All traffic is encrypted in transit using TLS.
  • Facebook Page access tokens are encrypted at rest using AES-256-GCM, and decryption keys are held separately from the database.
  • Access to production data is restricted to authorized personnel on a need-to-know basis.
  • Every request to your data is scoped to your organization so tenants remain isolated from one another.

6. Token Encryption & Access Control

Facebook Page access tokens are the most sensitive data we hold, and we treat them accordingly. Tokens are encrypted before they are written to the database and decrypted only server-side at the moment they are needed to call the Facebook API on your behalf. Tokens are never sent to the browser, never logged, and never returned by any API response. Our multi-tenant access controls ensure a token belonging to one organization can only be used within that organization.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide the service. When you disconnect a Page, delete content, or close your account, we delete or anonymize the associated data within a reasonable period, except where we are required to retain it to comply with legal obligations or resolve disputes.

8. Your Rights & Data Deletion Requests

Consistent with the GDPR and similar privacy laws, you have the right to access, correct, export, restrict, or delete your personal data, and to withdraw consent at any time. To exercise any of these rights — including requesting deletion of your account or of specific Facebook data we hold — contact us at privacy@bot-hm.com. We will respond within the timeframe required by applicable law.

You can also trigger deletion yourself: disconnecting a Page removes its stored access token immediately, and deleting your organization removes its associated conversations and connected Pages.

9. International Users

We may process and store data in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards such as standard contractual clauses to ensure your data remains protected in line with this policy.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you within the product. Your continued use of the service after an update constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or how we handle your data, reach us at privacy@bot-hm.com.