This Privacy Policy explains how Aiagentcorner Automation Services ("we", "us", or "our") collects, uses, stores, and deletes information when you use the LEWA AI software application and related services (the "Service"), including our integration with Meta's WhatsApp Business Platform. By using the Service, you agree to this policy.
1. Scope of this policy
This policy applies to the LEWA AI web application, APIs, automations, inbox, broadcasts, flows, and any feature that connects to Meta or WhatsApp on your behalf. It does not replace Meta's own privacy policies for WhatsApp or Facebook.
2. Meta and WhatsApp data we process
When you connect a WhatsApp Business Account to LEWA AI, we process the following categories of Meta-related data strictly to operate the Service:
- WhatsApp Business Account ID and phone number ID
- WhatsApp user IDs (WA IDs) and contact phone numbers
- Contact profile names and avatars when provided by Meta or your team
- Message content, media metadata, delivery receipts, and read receipts
- Template names, categories, approval status, and template components
- Encrypted WhatsApp access tokens and webhook verify tokens stored for your account
- Interactive button, list, and quick-reply selections from end users
- IP addresses and user-agent data in server logs for security and abuse prevention
- Device and browser information when you use the dashboard
3. Account and billing data
- Name, email address, and password hash for authentication
- Team member roles, invitations, and account settings
- Wallet balance, usage ledger entries, and payment references from Cashfree
- AI provider configuration when you supply your own API keys
4. Vendor and Payment Gateway data
- LEWA by Aiagentcorner is liable to discontinue any payment gateway integration at any time with prior 30 days notice to existing customers/vendors.
- When integrating third-party payment accounts via our Partner OAuth system (such as Cashfree Payments), LEWA AI only requests access to authenticated session access tokens required to initiate standard gateway commands on your behalf.
- We explicitly do not access, view, log, or store your raw Merchant Client Secrets, banking passwords, or settlement account parameters on our infrastructure servers.
5. Why we process data
- Provide the Service: inbox, messaging, templates, broadcasts, flows, and automations
- Authenticate users and enforce account permissions
- Bill template messaging usage through your prepaid wallet
- Improve reliability, security, and product performance
- Respond to support requests and legal obligations
- Prevent fraud, abuse, and unauthorized API access
We do not sell personal data. We do not use WhatsApp message content for unrelated advertising profiles.
6. How data is shared
- Meta / WhatsApp: Messages and template sends are transmitted through the official WhatsApp Business API under Meta's terms.
- Infrastructure providers: Supabase for database, authentication, storage, and realtime; Hostinger for application hosting; Cashfree for payments.
- AI providers: Only when you configure your own provider keys for draft or auto-reply features.
- Legal requests: When required by applicable law or to protect users and the Service.
7. Security
We use TLS in transit, AES-256-GCM encryption for WhatsApp tokens at rest, row-level security in our database, webhook signature verification, and role-based access inside each account. No internet transmission method is completely secure, but we apply commercially reasonable safeguards.
8. Data retention and deletion
We retain data only as long as needed to provide the Service or meet legal obligations. When you request deletion or remove our app from Meta, we purge cached profile data and access tokens within 30 days. Backup copies naturally expire and are overwritten within 90 days.
You can request deletion by email at support@aiagentcorner.in or by following the steps on our Data Deletion Instructions page.
9. Your rights
Depending on your jurisdiction, you may request access, correction, export, restriction, or deletion of your personal data. Contact us at:
10. Cookies
We use essential cookies for login sessions and optional functional preferences such as theme selection. You can disable cookies in your browser, but some features may stop working.
11. Changes
We may update this policy from time to time. Material changes will be posted on this page with a new effective date. Continued use of the Service after changes constitutes acceptance.