Effective Date: September 17, 2026
Welcome to Almorsl (\”we,\” \”our,\” or \”us\”). We are committed to protecting your privacy, your business data, and the personal information of your end-users. This Privacy Policy outlines how we collect, use, process, and safeguard data when you use our platform and WhatsApp Business API integration services.
1. Information We Collect
To deliver, maintain, and optimize our messaging and automation services, we collect the following types of information:
- Account & Profile Data: Business name, contact person name, official email address, phone number, billing details, and your Meta Business Manager ID.
- Messaging & Communication Data: Message payloads, automated workflow parameters, and metadata processed via the WhatsApp Business API solely for routing, queuing, and executing your automated workflows.
- Technical & Log Data: IP addresses, browser types, API logs, webhook logs, system status events, and device information required to ensure system uptime and security.
2. How We Use Your Information
We use the collected data strictly for professional SaaS operations, including:
- Provisioning and managing your WhatsApp Business API connection and custom workflows.
- Operating our no-code engine, webhook routing, and platform integrations.
- Providing 24/7 technical onboarding, customer service, and system support.
- Monitoring infrastructure integrity, detecting security threats, and preventing unauthorized API access.
- Sending essential service updates, platform release notes, and security alerts.
3. Data Sharing & Third-Party Ecosystem
We never sell, rent, or trade your personal data or customer communications to third parties for marketing purposes. Data is disclosed only under strict operational guidelines:
- Meta Platforms, Inc. (WhatsApp): As an official service implementation layer, relevant messaging payloads are transmitted directly through Meta’s Cloud API infrastructure.
- Authorized Sub-processors: Trusted hosting providers, database managers, and security infrastructure vendors operating under strict non-disclosure and data protection agreements.
- Legal Compliance: When required by law, regulation, court order, or governmental request to protect our legal rights and system security.
4. Data Security & Encryption
We enforce enterprise-grade administrative, technical, and physical security measures to safeguard your information against unauthorized access, loss, or alteration:
- In-Transit & At-Rest Encryption: End-to-end transport layer security (SSL/TLS) for all API endpoints and webhooks, alongside AES-256 bit encryption for stored databases.
- Access Controls: Strict role-based access control (RBAC) limiting data access exclusively to authorized technical personnel.
- Continuous Monitoring: Real-time threat monitoring, automated vulnerability scanning, and routine infrastructure audits.
5. Data Retention & User Rights
- Retention: We retain account records and transactional log data only for as long as necessary to fulfill active service agreements, resolve technical issues, or satisfy legal requirements.
- Your Rights: You reserve the right to access, update, or request the full deletion of your account data and API configurations from our servers at any time by contacting support.
6. Updates to This Policy
We may update this Privacy Policy periodically to reflect technological advancements, platform feature additions, or updates to Meta’s Business Policies. Any amendments will be published directly on this page with an updated effective date and take effect immediately.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data protection rights, please reach out to our team via your official WhatsApp channel or email us at [email protected].