Privacy Policy
1. Scope
This policy explains how AiConva, a product operated by JustTicks Platform, handles personal data. It covers two groups: our customers (the businesses and team members who use the platform) and end users (the people our customers message on WhatsApp). For end-user data, our customer is the data fiduciary under the Digital Personal Data Protection Act, 2023, and AiConva acts as a data processor on their instructions.
2. What we collect
Customer account data: name, email, phone, workspace details, and login records. Billing data: wallet transactions and an itemised message ledger. End-user data processed on behalf of customers: contact phone numbers, names, attributes and tags the customer records, opt-in records, and WhatsApp message content needed to deliver conversations. Technical data: request logs and audit trails of key actions.
We do not sell personal data. We do not use message content for advertising. The public marketing site works without trackers; the app uses a single HTTP-only session cookie for login and local storage for interface preferences (theme, dark mode, sidebar state).
3. How we use data
To operate the service: delivering messages via the WhatsApp Business API, showing conversations in your inbox, computing campaign estimates, maintaining the billing ledger, and enforcing opt-in and STOP handling. To keep the platform safe: fraud prevention, abuse detection, and audit logs. To communicate with customers about the service. Nothing else.
4. Sharing
Message payloads are shared with Meta Platforms to deliver WhatsApp messages — this is inherent to the WhatsApp Business API and covered by Meta's own terms. Payment processing for wallet top-ups is handled by our payment gateway. Infrastructure providers host encrypted data under contractual confidentiality. We disclose data to authorities only where legally required, and we tell you unless prohibited.
5. Security
Access tokens and API credentials are encrypted at rest. Webhook payloads are signature-verified. Passwords are stored as salted hashes. Access to production data is role-restricted and logged. No internet service can promise perfect security, but billing immutability and audit logs mean tampering is detectable.
6. Retention and deletion
Data is retained while your workspace is active. On cancellation we queue a complete export for you, then delete workspace data within 90 days, except billing records we must keep under Indian tax law (retained for the statutory period, then deleted). You can delete individual contacts at any time, which removes them from all segments and future campaigns immediately.
7. Your rights
Customers can access, correct, export, and delete their data self-serve from the product. End users may exercise rights (access, correction, erasure, grievance) through the business that messages them; if you contact us directly we will route your request to the responsible customer and assist. Under the DPDP Act you may also complain to the Data Protection Board of India.
8. Changes and contact
Material changes to this policy are announced in-product 15 days before taking effect. For privacy questions or requests, reach our grievance officer via the contact page or hello@aiconva.com — we respond within the timelines required by law.