1. Information we collect
Depending on how you use Bizcopilot, we may collect:
- Account information, such as your name, work email address, and authentication details.
- Business configuration, including WhatsApp Business Account identifiers, phone number identifiers, agent instructions, templates, forms, and workflow settings.
- Customer conversation data that you or your connected WhatsApp Business account send to the service, including phone numbers, messages, media, form responses, lead status, and conversation summaries.
- Technical information needed to operate and protect the service, such as browser/device information, timestamps, error logs, and security events.
- Information you provide when requesting a demo or contacting support.
2. How we use information
We use information to provide and improve the service, including to:
- Authenticate users and keep each workspace separated from other workspaces.
- Connect to WhatsApp Cloud API, send and receive messages, manage templates, and process webhooks at your direction.
- Run configured AI agents, qualification rules, forms, campaigns, follow-ups, reports, and human handoffs.
- Store conversation history and business records so your team can review and act on them.
- Prevent abuse, troubleshoot failures, maintain security, and comply with legal obligations.
- Respond to demo, support, and deletion requests.
Google sign-in and Google user data
Bizcopilot offers Google sign-in through Firebase Authentication. When you choose this option, we receive basic identity information made available by Google, including your email address, name, profile picture where available, and a Google account identifier. We use this information to authenticate you, identify your Bizcopilot account, and support account linking and account security.
Our Google sign-in requests basic sign-in, email, and profile permissions. It does not request access to your Gmail messages, Google Drive files, Calendar events, or contacts. We do not receive your Google password. Google sign-in data is not used for advertising, sold to third parties, or used to train AI models.
Google identity information is processed by Google/Firebase for authentication and by our application hosting and database providers to maintain your account. Workspace access is restricted to authenticated, authorized users. We retain account identity information while your account remains active, subject to deletion requests and any security or legal records that must be retained.
You can manage Bizcopilot's Google access in your Google Account connections. Revoking Google access prevents future access through that connection; it does not itself delete your Bizcopilot account or previously stored records. To request account deletion, follow our Data Deletion Instructions or contact our privacy team below.
3. Meta and WhatsApp data
When you connect a WhatsApp Business Account, Bizcopilot receives and processes the account identifiers, access credentials/tokens, message events, contact details, media, and other information made available through the WhatsApp Cloud API. We use that information only to provide the connected messaging, automation, reporting, and support features requested by the account owner. We do not sell Meta or WhatsApp data, and we do not use it for advertising unrelated to the service.
4. When we share information
We share information only as needed to operate the service or when required by law. Service providers may process information on our behalf for:
- Cloud hosting, authentication, database, and file storage services.
- WhatsApp Cloud API and other integrations that you explicitly connect or configure.
- AI, webhook, CRM, analytics, or notification services that your workspace enables.
- Security, fraud prevention, legal, or compliance requests.
We require service providers to use information for the agreed purpose and to protect it appropriately. Your workspace may send selected conversation or business content to an enabled AI or webhook integration; review those providers' policies before enabling them.
5. Retention and deletion
Customer conversation data is subject to automatic retention rules in the service:
- Ordinary AI conversation context expires after 24 hours without activity.
- Context for an unresolved hot lead is retained until the lead is marked Done. Marking Done clears that lead's existing AI context immediately, including when an appointment record also exists. Appointment records remain available; appointment-related context is otherwise protected until the appointment date plus one day.
- Customer chats, collected responses, and associated indexed uploads are normally retained for 90 days. Unresolved hot leads and future appointments can protect associated customer history beyond this period.
- Completed hot-lead records are retained for 90 days after Done. Appointment records are normally retained for 90 days after the appointment ends, or its start date if no end date is available. Future bookings and records associated with unresolved hot leads remain protected.
Expiry is enforced through scheduled cleanup; an expired record may remain until the next cleanup run. Account details, workspace configuration, business knowledge documents, and security or legal records have separate retention purposes and are not all governed by the customer-chat 90-day rule. Deletion from active systems does not immediately erase provider backups or independent logs. Backups and provider-held records follow their own retention and deletion processes.
You can request deletion of your account and associated personal information by emailing support@incraaxaiautomation.com from the account email address. Include your name, account email, and the WhatsApp Business Account or phone number identifier concerned. See our Data Deletion Instructions for the request details. We may verify the request before acting. We will confirm the request, explain any information that must be retained, and delete or de-identify eligible information within a reasonable period.
6. Your choices and rights
You may disconnect an integration, stop sending data, update workspace settings, request access or correction, or request deletion by contacting us. You can also ask us to explain how your information is used. Some requests may be limited where fulfilling them would affect another person's privacy, security, or legal rights.
7. Security
We use reasonable technical and organizational safeguards, including authenticated access, workspace-level data scoping, protected server-side credentials, and access-controlled storage. No internet service is completely secure, so please protect your account credentials and notify us promptly of suspected unauthorized access.
8. Cookies and similar technologies
Bizcopilot uses essential browser storage and similar technologies to maintain authentication, workspace preferences, and reliable operation. We do not use these technologies to sell personal information. Your browser can restrict storage, but doing so may prevent sign-in or core features from working.
9. Children
Bizcopilot is a business service and is not directed to children. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this policy when the service or legal requirements change. We will post the updated version on this page and update the effective date. Your continued use of the service after an update means the updated policy applies to future use.
Questions or requests
Contact our privacy team
For privacy, access, correction, or data deletion requests, contact us at: