Privacy Policy

Last updated: September 26, 2026

NafcoReply ("we," "our," "us") provides a unified customer messaging platform that helps businesses manage WhatsApp, Instagram, and Facebook Messenger conversations. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our services.

1. Introduction

This Privacy Policy applies to NafcoReply and describes how we handle information collected through our platform, including information from:

  • Workspace owners and team members who use NafcoReply
  • Customers and contacts who communicate with businesses through our platform
  • Connected Meta platform accounts and integrations

2. Information We Collect

Account Information

When you create a NafcoReply account, we collect:

  • Name and email address
  • Password (encrypted and never stored in plain text)
  • Profile information
  • Workspace configuration

Workspace Information

When you use NafcoReply, we collect:

  • Workspace settings and preferences
  • Team member information and roles
  • Channel connections and configurations
  • Automation rules and workflows
  • Labels and tags

Contact and Customer Information

When businesses use NafcoReply to manage customer conversations, we process:

  • Customer names and contact information
  • Conversation history and message content
  • Media files shared in conversations
  • Customer metadata and interaction history

Messaging Information

Through connected messaging channels, we process:

  • Messages sent and received
  • Message metadata (timestamps, status)
  • Media attachments (images, voice notes, documents)
  • Channel-specific identifiers

Meta Platform Data

When you connect Meta platforms (WhatsApp, Instagram, Facebook), we may access:

  • Page and account information
  • Messages sent to connected accounts
  • Contact information from conversations
  • Lead information from advertising campaigns (when authorized)
  • OAuth tokens and credentials (encrypted at rest)

Lead Information

When businesses connect Meta advertising accounts, we may receive:

  • Lead form submissions
  • Contact information provided by leads
  • Campaign source information
  • Form field data

Device and Usage Information

We automatically collect:

  • IP address and browser information
  • Device type and operating system
  • Usage patterns and feature interactions
  • Performance and error logs

Cookies

We use cookies and similar technologies for authentication, preferences, and analytics. You can control cookies through your browser settings.

3. How We Use Information

We use collected information to:

  • Provide and maintain NafcoReply services
  • Enable customer conversation management
  • Facilitate messaging through connected channels
  • Process and organize lead information
  • Support team collaboration features
  • Enable automation and workflow features
  • Send service notifications and updates
  • Provide customer support
  • Improve and optimize our services
  • Ensure security and prevent fraud
  • Comply with legal obligations

We do not: sell personal data, use customer message content for advertising, or train AI models on your conversations.

4. How We Store Information

Data is stored securely using:

  • Encrypted storage at rest
  • TLS encryption for data in transit
  • Secure database infrastructure
  • Access controls and authentication
  • Regular security audits

Meta OAuth tokens and API credentials are encrypted using additional encryption layers separate from application data.

5. Data Retention

We retain information:

  • For as long as your account is active
  • As necessary to provide services
  • To comply with legal obligations
  • To resolve disputes
  • To enforce our agreements

Upon account deletion, data is retained for 30 days to allow recovery before permanent deletion, except where longer retention is required by law.

6. Data Sharing

We share information with:

Service Providers

  • Cloud hosting and storage providers
  • Payment processors (Stripe for billing)
  • Analytics and monitoring services
  • Customer support tools

Meta Platform Integrations

When you connect Meta platforms, data flows through Meta's infrastructure according to their terms and our authorized API usage.

Third-Party Services

When you authorize third-party integrations, we share data necessary for those integrations to function as you configured.

We do not: sell your data to third parties, data brokers, or advertisers.

7. Meta Platform Data

When a business connects Meta accounts (WhatsApp Business, Instagram, Facebook Pages, or advertising accounts) to NafcoReply:

  • Data is accessed only according to permissions granted by that business
  • Data is used solely to provide requested NafcoReply functionality
  • We comply with Meta Platform Terms and Policies
  • Access is limited to authorized APIs and scopes
  • Data is not used for purposes outside the messaging service

Users can disconnect Meta integrations at any time through workspace settings, which stops future data synchronization.

8. Security

We implement security measures including:

  • Encryption of data in transit and at rest
  • Secure authentication mechanisms
  • Role-based access controls
  • Regular security assessments
  • Incident response procedures
  • Employee security training

While we implement industry-standard security practices, no method of transmission or storage is 100% secure.

9. User Rights

Depending on your location, you may have rights to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data
  • Object to certain processing
  • Port your data
  • Withdraw consent

To exercise these rights, see our Data Deletion page or contact us at support@nafco.cloud.

10. Data Deletion

You can request deletion of:

  • Your account and profile information
  • Workspace data
  • Customer and contact information
  • Conversation history
  • Connected integration data

See our Data Deletion page for the complete process.

11. Account Deletion

When you delete your NafcoReply account:

  • Your account access is immediately disabled
  • Data is retained for 30 days for recovery
  • After 30 days, data is permanently deleted
  • Some data may be retained for legal compliance

12. Disconnecting Integrations

You can disconnect Meta and other integrations through workspace settings. Disconnecting:

  • Stops future data synchronization
  • Revokes access tokens
  • Preserves existing NafcoReply data unless you request deletion

13. International Data Processing

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international data transfers.

14. Children's Privacy

NafcoReply is not intended for users under 13 years of age. We do not knowingly collect information from children under 13.

15. Policy Updates

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on this page
  • Updating the "Last updated" date
  • Sending email notifications for significant changes

Continued use of NafcoReply after changes constitutes acceptance of the updated policy.

16. Contact

For questions about this Privacy Policy or our data practices, contact us: