ParroByte CRM ("we", "our", or "us") is a CRM platform that helps businesses manage WhatsApp messaging, lead capture, and marketing automation. This Privacy Policy explains what information we collect, how we use it, and how you can control it. It applies to crm.parrobyte.co.in and all features of the Platform.
1. Information We Collect
- Account Information: Name, email, phone number, and password (stored as a salted hash, never in plain text).
- WhatsApp Business Data: When you connect a WhatsApp Business Account via Meta's official Cloud API, we store your access token (encrypted at rest), phone number, and the messages you send/receive through the Platform, so we can display your conversation history and power automations you configure.
- Meta Lead Ads & Page Data: If you connect a Facebook Page for Lead Ads, Click-to-WhatsApp, or Messenger/Instagram ad automation, we store the Page's access token (encrypted), the lead form questions you choose to sync, and the actual lead submissions (name, phone, email, and any custom answers) tied to ads you run.
- Facebook Page & Instagram Comment/Message Automation: If you connect a Facebook Page or Instagram professional (Business/Creator) account for comment or DM auto-reply, we store the connected account's access token (encrypted), read comments and Direct Messages on posts/media you own so they can be matched against auto-reply rules you configure, and post the replies you've authorized. We only access comments and messages on content belonging to the account you've explicitly connected.
- Social Cross-Posting: If you use the Social Cross-Posting feature, we store the photo, video, and/or caption you upload, and publish it to the Facebook Page, Instagram account, and/or Reddit account you select — only when you click Publish on content you provided in that same request.
- Enquiry Form Submissions: Data submitted through forms you build using our form builder, exactly as configured by you.
- Business-Sourced Lead Data: If you use our Google Maps business scraper, we store publicly available business listing data (name, phone, category, address) that you choose to import as leads.
- AI Configuration Data: The business context/prompt you provide for AI auto-replies, and the messages processed to generate a response.
- Email & SMTP Data: If you configure email campaigns, we store your SMTP credentials (encrypted) and email content/recipients you send.
- Payment & Billing Data: Subscription plan, billing history, and payment references. Card/payment details themselves are handled entirely by our payment processor (Razorpay) — we never receive or store your raw card details.
- Usage & Log Data: Login timestamps, IP address, API request logs, and error logs, used for security and troubleshooting.
2. How We Use Your Information
- To operate the core CRM: sending/receiving WhatsApp messages, managing your leads pipeline, and running the automations you configure.
- To automatically capture and respond to new leads from the sources you connect — Meta Lead Ads, Click-to-WhatsApp ads, Messenger/Instagram ads, your own website/forms, or the scraper — using the WhatsApp template messages and timing you set up.
- To generate AI-assisted replies and follow-up messages, when you enable that feature.
- To send you account, billing, and service notifications.
- To secure your account, including a one-time login code (OTP) emailed on every login and single-device session enforcement.
- To improve the reliability and performance of the Platform.
3. AI Processing — Self-Hosted, Not Shared With Third Parties
AI-generated replies and follow-up messages are produced by an AI model we run ourselves on our own infrastructure (Ollama, self-hosted). Message content processed for AI replies is not sent to any third-party AI provider (e.g. OpenAI, Anthropic, Google) — it is processed entirely within our own servers.
4. Data Storage & Security
All data is stored on our own servers with encryption for sensitive fields — access tokens, API keys, and SMTP credentials are encrypted at rest. Passwords are hashed, never stored in plain text. We do not sell your data or your customers' data to anyone.
5. Third-Party Services We Integrate With
- Meta Platforms — WhatsApp Business Platform (Cloud API), Facebook Graph API, Instagram Graph API (including Instagram Login), and the Meta Marketing API (Lead Ads). Used strictly to power the automations and publishing features you configure for your own connected accounts; see Meta's own Privacy Policy for how Meta separately handles data.
- Reddit — used only for the Social Cross-Posting feature, to publish content to a Reddit account you explicitly connect and authorize via Reddit's own OAuth login.
- Razorpay — payment processing for subscription billing.
We request only the permissions each feature actually needs, and only act on data belonging to accounts you have explicitly connected.
6. Data Retention & Deletion
You can delete individual leads, messages, or your entire account at any time by contacting support. Upon account deletion, your data is permanently removed within 30 days. If you disconnect a Meta-connected account (WhatsApp, Facebook Page, or Instagram), we stop syncing new data from it immediately; you can request deletion of previously stored data from that connection at any time.
Meta users can also request deletion of their data directly through Facebook's own Apps and Websites settings — Meta forwards these requests to us automatically via its Data Deletion Callback, and we process them accordingly.
7. Your Rights
- Access, correct, or delete your account data at any time.
- Disconnect any connected WhatsApp account, Facebook Page, Instagram account, or email integration from your dashboard.
- Export your leads and contacts as a CSV file.
- Revoke API keys you've created at any time.
8. Children's Privacy
The Platform is intended for business use by individuals 18 years or older. We do not knowingly collect data from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a dashboard announcement. The "Last updated" date at the top reflects the most recent revision.
10. Contact Us
If you have questions about this Privacy Policy or want to exercise any of your rights above, contact us at parrobyte@gmail.com or through the Help Center in your dashboard.