Privacy Policy
Last updated: August 2026
01
Information We Collect
We collect the information needed to run conversations on your behalf:
- Business account data — name, email, and business details provided when the account is set up.
- Customer data — the name and profile information the messaging platform provides, plus any contact details a customer shares in conversation.
- Conversation messages — message content exchanged between customers and Hapsay on Facebook Messenger and Instagram.
- Approved business knowledge — the rates, schedules, and policies a business publishes for Hapsay to answer from.
- Usage data — aggregated service metrics used to operate and improve the platform.
02
How We Use Your Information
Your information is used to:
- Answer routine customer questions from information the business approved.
- Hand a conversation to a person, with its context attached, when judgment is needed.
- Notify the business team about conversations that are waiting on them.
- Operate, secure, and improve the service.
We do not sell personal data, and we do not use customer conversations to train machine-learning models.
03
Automated Processing
Hapsay uses automated systems to read customer messages and draft replies. When a customer messages a business through a connected channel:
- The message is sent to a third-party language-model provider to generate a reply, and is transmitted solely for that purpose.
- Replies are grounded in the business knowledge the business has approved and published. Hapsay does not invent rates, schedules, or commitments.
- Our providers are contractually barred from training their models on this content.
- When Hapsay cannot answer safely, it stops and asks a person rather than guessing. Businesses remain responsible for what their team confirms.
04
Third-Party Services
Hapsay is operated by DorellWorks Software Development Services (Philippines), the data controller for personal data processed through the service. We rely on the following sub-processors:
- Messaging platforms — Meta Platforms, Inc. (United States) delivers Facebook Messenger and Instagram conversations.
- Hosting and infrastructure — Cloudflare, Inc. (United States) runs the application, serves this site, protects sign-in, and routes every language-model request through its AI Gateway.
- Database — Hetzner Online GmbH (Germany) hosts the managed PostgreSQL database holding conversations and business knowledge.
- Language-model providers — OpenAI, L.L.C. and Groq, Inc. (both United States) generate automated replies from conversation content. We do not permit either to train on this data.
- Staff notifications — browser push services operated by Apple, Google, and Mozilla deliver alerts to signed-in staff devices. These carry a notification envelope, never conversation content.
Each sub-processor operates under its own privacy policy (Cloudflare, Hetzner, OpenAI, Groq). We share only the minimum data each service needs. All integrations comply with Meta Platform Policies.
05
Meta Platform Data
Hapsay accesses Facebook and Instagram data through Meta’s platform APIs and handles it in accordance with Meta Platform Policies:
- We access only what the service needs — receiving messages, sending replies, and identifying the conversation they belong to.
- We do not sell, license, or transfer Meta platform data to any third party.
- We do not use Meta platform data for advertising, ad targeting, or analytics.
- Access tokens are stored encrypted and are used only to act on behalf of the business that granted them.
- Businesses may request deletion of all Meta platform data at any time.
06
Data Retention
- Conversations and customer records are retained while the business account remains active.
- Staff sign-in sessions end after 30 days without use, and always within 90 days.
- Account data is retained until the business requests deletion or ends the service.
07
Data Security
- All data is encrypted in transit using TLS.
- Platform access tokens are encrypted at rest with AES-256-GCM and are readable only by the component that sends messages.
- Every business’s data is isolated at the database level. Row-level security is enforced by PostgreSQL itself, not only by application code, so a business can reach only its own records.
- The components that talk to customers hold read-only access to published business knowledge and cannot alter it.
08
Your Rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data, subject to legal retention requirements — see Data Deletion.
- Export your data in a portable format.
To exercise these rights, contact us at hello@hapsay.com.
09
Cookies
We use only the cookies the service needs to function, such as keeping a staff member signed in. We do not use advertising or third-party tracking cookies.
10
Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes we will notify affected users by email or through a notice in the platform. Continued use of the service after a change constitutes acceptance of the updated policy.
11
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at hello@hapsay.com.