Privacy Policy
Last updated: 16 July 2026
ExceliaBOT is an AI assistant platform that answers your customers' WhatsApp messages automatically. This policy explains what data we handle, why, who we share it with, and the choices you have. We have written it in plain language rather than legalese.
1. Who we are
ExceliaBOT is operated by Excelia Marketing ("Excelia", "we", "us"). You can reach us at [email protected] for any privacy question, request, or complaint.
2. Data we collect
2.1 Account data (from you, our client)
- Business name and contact phone number.
- Name, email address, and role of each account owner and team member.
- Your password, stored only as a bcrypt hash — we never store or see the password itself.
- Sign-in timestamps and failed sign-in counts (used to lock accounts after repeated failures).
2.2 Enquiries from our website
If you submit the contact form or request access, we store the name, phone number, email address and message you provide, so we can reply and qualify the request.
2.3 Integration credentials
To send and receive messages on your behalf we store your WhatsApp Phone Number ID, your Meta access token, and (optionally) your App Secret. Every token and secret is encrypted at rest with AES-256-GCM before it touches our database.
2.4 Conversation data (your customers)
When someone messages your WhatsApp number, we receive and store:
- Their WhatsApp number and the profile name WhatsApp provides.
- The content of their messages and of the replies sent back.
- Timestamps and WhatsApp's message identifiers (we use these to avoid processing the same message twice).
- Any information you have configured the assistant to collect as a "goal" — for example a name, phone number, address, or order details. You choose these fields; we do not decide what is asked.
2.5 Product catalog
If you enable the catalog feature, we fetch product data (name, description, price, image, link) from the product feed URL or Meta Commerce catalog that you connect, so the assistant can recommend items.
2.6 Usage and technical logs
- Per-reply metering: which AI model ran and how many tokens it consumed. This is how plan limits are enforced and how you are billed.
- System events (for example a failed webhook signature or an exhausted quota) for security, troubleshooting and audit.
- IP addresses, transiently, for rate limiting on public forms and sign-in.
We do not use advertising cookies or third-party trackers. The dashboard stores a sign-in token in your browser's local storage purely to keep you signed in.
3. Why we use it
| Purpose | Data involved |
|---|---|
| Generate and deliver AI replies to your customers | Conversation history, your prompt, catalog, goal fields |
| Route incoming messages to the right account and prevent duplicates | Phone Number ID, message identifiers |
| Enforce plan limits and bill you correctly | Token and reply counters |
| Show you conversations, leads and analytics in the dashboard | Messages, goal completions |
| Secure the platform and investigate abuse | System logs, sign-in records, IP addresses |
| Respond to your enquiries and provide support | Contact and account data |
We do not sell your data, and we do not use your conversations or your customers' data to train our own models or to market to your customers.
4. Who we share it with
We share data only with the providers needed to run the service:
| Provider | What it receives | Why |
|---|---|---|
| Google (Gemini API) | Your system prompt, recent conversation history, the incoming message, and your catalog and goal configuration | To generate each reply. Google processes this under its own API terms. |
| Meta Platforms (WhatsApp Cloud API) | The reply content and the recipient's WhatsApp number | To deliver messages. Meta is also the source of the inbound messages. |
| Our hosting provider | All platform data, at rest on the server | To host the application and database. |
These providers operate internationally, so data may be processed outside your country. We may also disclose data where the law requires it, or to establish or defend legal claims.
5. How long we keep it
- Conversations and messages are retained for as long as your account is active, so that the assistant has context and you keep your history.
- Leads captured by goals are retained until you delete them; you can delete individual leads or export them at any time.
- When an account is closed, its conversations, messages, leads, credentials and usage records are deleted along with it.
- Website enquiries are kept until we have dealt with them and are then removed.
- System logs are kept for a limited period for security and audit purposes.
If you want your data deleted sooner, ask us and we will act on it.
6. How we protect it
- Access tokens and API keys are encrypted with AES-256-GCM before storage; nobody can read them from a database dump alone.
- Passwords are hashed with bcrypt and are never recoverable.
- All traffic to the platform runs over HTTPS.
- Each account is strictly isolated: every request is scoped to its own account, and one client can never read another's data.
- Incoming WhatsApp webhooks are signature-verified so forged messages are rejected.
- Access is role-based: team members only see what their role allows, and a deactivated user loses access immediately rather than at token expiry.
- Repeated failed sign-ins lock the account.
No system is perfectly secure, but if a breach ever affects your data we will tell you promptly and explain what happened.
7. Your rights
You can ask us to:
- Access the personal data we hold about you, or receive a copy.
- Correct anything inaccurate — most account details are editable in the dashboard.
- Delete your data or your entire account.
- Export your leads — the dashboard does this to Excel on demand.
- Object to or restrict a particular use of your data.
Email [email protected] and we will respond within 30 days. If you are an end customer who messaged a business using ExceliaBOT, contact that business first — we will forward your request to them if you reach us instead.
8. Your responsibilities as our client
You are the controller of your customers' data. That means you are responsible for having a lawful basis to message them, for honouring their requests, and for what you instruct the assistant to collect. Please do not configure goals that gather more than you genuinely need, and never collect payment card details, passwords, or health information through the assistant.
9. Children
ExceliaBOT is a business tool and is not directed at children under 18. We do not knowingly collect their data; if you believe we have, contact us and we will remove it.
10. Changes to this policy
We may update this policy as the platform evolves. We will change the date at the top and, for material changes, notify account owners by email or in the dashboard before they take effect.
11. Contact
Questions, requests or complaints:
Email: [email protected]
WhatsApp: +20 103 370 7172
