1Who is responsible for what
Two different sets of personal data are involved, and they are not governed the same way.
- The business owner's data. The account you sign in with, and what you tell us about your business. We decide how that is used, so under India's Digital Personal Data Protection Act 2023 we are the Data Fiduciary for it.
- Your customers' data. The messages people send to your WhatsApp number, their phone numbers and names, and what they order or book. You decide why that is collected and what happens to it. You are the Data Fiduciary; we process it on your instructions and on your behalf.
That second point is the one businesses miss. Your customers' rights are owed by you. This product exists partly so you can actually honour them — see clause 7.
2What we hold
About you, the business owner:
- your email address, and the sign-in record for your account
- what you enter about your business — its name, what it does, opening hours, address, your item and price list, and anything you teach the assistant
- your WhatsApp Business connection, held as an access token issued by Meta. The token is never sent to your browser, not even to check whether it exists
About the people who message you:
- their WhatsApp phone number, or their Instagram-scoped id, and the name they give
- the messages they send and the replies the assistant sends back
- what they order or book, the amounts, and any payment screenshot they upload as proof of payment
We do not collect location, contacts, device identifiers, or anything from other apps. There is no advertising or analytics tracker on the signed-in product; the public pages count page views without cookies (clause 4).
Your browser keeps a few things for this site, used only to run it: your sign-in, which screens your menu shows (sent with each page, so the menu is right the moment it opens), and when the opening animation last played (kept on your device). None of them is used for advertising or to follow you anywhere else.
3Why we hold it
To run the service you asked for: receive your customers' messages, work out an answer, send it, record the orders and bookings that come out of it, and show you all of that. Prices and totals are calculated in our code from the list you entered — the assistant is not asked to do arithmetic.
We also keep an audit record of significant actions on your account, so that a question about what happened has an answer.
We do not sell personal data, and we do not use your customers' messages to advertise to them or to anybody else.
4Who else sees it
These companies process data so that the service works.
- Meta. WhatsApp messages travel through Meta's WhatsApp Business Platform, and Instagram messages through Instagram's. They reach us because you connected your number to us.
- OpenAI. To write a reply, the customer's message and the relevant part of what you have taught the assistant are sent to OpenAI's API. When you upload a photo of a menu or price list, that image is sent to OpenAI to read the text out of it. OpenAI's API terms state that data submitted through the API is not used to train their models.
- Supabase. Our database and file storage. Everything described in clause 2 is stored there.
- Vercel. Hosts this website. On the public pages only — never once you are signed in — Vercel counts page views without cookies and without identifying you.
- Railway. Runs our server. Every message, reply and record passes through it on the way to the database.
- Google. If you sign in with Google, Google tells us your email address, the name on your Google account and the address of its profile photo. We use them to sign you in, to show you which account you are using, and to fill in your email when you pay for a plan. We never receive your password.
- Razorpay. Takes the payment for your plan. Your card or UPI details go to Razorpay, not to us; we receive whether a payment went through.
- GitHub. Keeps our daily backup: a copy of the database and the stored files, encrypted with our passphrase before it is stored, so the stored copy cannot be read without it.
Two things are never sent to any AI model: voice notes, which are flagged for you to listen to yourself, and payment screenshots, which are stored and shown to you to approve or decline.
We disclose data to no one else, except where the law requires it of us.
5Where it is stored, and for how long
Data is stored on Supabase's managed infrastructure. Some of the processing described in clause 4 happens outside India, because that is where those services run.
- Conversations and messages are deleted 365 days after the last message in that conversation. The clock runs from the last message, not from when it started — a two-year-old conversation with a message in it yesterday is a live customer and is not touched.
- Orders, bookings and payment records are kept while your account exists. They are financial records, and keeping them is your legal obligation rather than our preference.
- Your account and business details are kept while your account exists.
- You can close your account yourself, at any time, in Settings, under Plan, with Close account. Your shop, its conversations, orders, bookings, payment records, photos and your login are then deleted from the service at once. Backups follow the line below. If you want a copy of your data, ask us before you close.
- A copy of each incoming message as Meta delivered it is kept for up to seven days so that a message can be answered after an interruption, then deleted. It is not read for any other purpose.
- Backups. Each daily backup is encrypted and kept for 7 days, then deleted. Something erased from the service stays inside the backups made before the erasure until they are deleted, and is never restored into the service except to recover it after a failure.
6Keeping it safe
Every request is authenticated, and a business can only ever read its own rows — enforced in the database itself, not only in the application. Your WhatsApp access token is never sent to a browser. Secrets are held in the server's environment and never written to logs; logs that touch a record carrying one have that value stripped before they are written.
No system is perfectly secure. If a breach affects your data we will tell you, and we will notify the Data Protection Board of India where the Act requires it.
7Your rights, and your customers' rights
Under the DPDP Act 2023 you may ask what we hold about you, have it corrected, and have it erased. Write to us at privacy@everprex.com and we will answer within 30 days.
If you remove us from Facebook. If you remove Everprex from your Facebook account's settings, or ask Facebook to delete the data it shared with us, Meta tells us. We disconnect every WhatsApp and Instagram connection you authorised, delete the access Meta issued for them, and tell you in the product. Meta shows you a page where you can check that it was done.
When one of your customers asks you. The request is yours to honour, and the product can carry it out: we can export everything held about one person, and erase it. Erasure means the record is gone, not hidden — with one deliberate exception. Their orders are anonymised rather than destroyed: the name and phone number go, the amount and date stay, because you have tax and accounting obligations that outlive the relationship, and an order with no person attached is no longer personal data. Their conversations, the alerts they raised, any reply of yours still waiting to be sent, and their number in the audit trail all go. The record that the erasure happened is kept without their number, because it is the only proof you will have that you honoured it. The seven-day copy of incoming messages expires on its own.
Tell us at privacy@everprex.com and we will run it for you.
8Children
This is a product for businesses and is not directed at children. We do not knowingly collect a child's personal data. If a customer's message reaches us it is because they wrote to a business; we have no way to verify their age and do not attempt to.
9Changes to this policy
If we change how data is handled we will update this page and change the effective date at the top. Where a change is significant we will tell account holders directly rather than relying on you to re-read it.
10Who to contact
Everprex (Sole Proprietorship)
22, Near Government High School, Village Seria, Block Beri, District Jhajjar, Haryana 124102, India
Questions about your data: privacy@everprex.com
Grievance Officer (DPDP Act 2023, section 13): Jatin, Proprietor, Everprex — grievance@everprex.com
If you are not satisfied with our answer, you may complain to the Data Protection Board of India.