We are committed to protecting your personal data and being transparent about how we collect and use it.
EasyManage ("we", "our", "us") operates a business management platform that integrates AI assistance, WhatsApp Business API messaging, email communication, and a REST API for mobile and third-party integrations.
This Privacy Policy explains what personal data we collect, why we collect it, how it is stored and protected, and your rights as a user or end-customer interacting with businesses that use our platform.
| Category | Examples | Purpose |
|---|---|---|
| Identity | Full name, profile photo, national ID (optional) | Account creation, employee cards |
| Contact | Email address, phone number | Login, WhatsApp verification, notifications |
| Usage Data | Login timestamps, IP address, device info, session tokens | Security, audit trails, 2FA |
| Messaging | Chat messages, file attachments, conversation history | Internal messaging, AI chat, WhatsApp routing |
| Phone number, messages sent/received, session tokens | WhatsApp Business integration | |
| AI Interactions | Chat prompts, uploaded files, AI responses, audio | AI assistant functionality |
| Business Data | Company name, subscription, invoices, production records | Platform service delivery |
| API Tokens | Sanctum tokens, API keys | Mobile app & third-party access |
Our platform integrates with the WhatsApp Business API (via Meta/Facebook) to allow businesses to communicate with their customers and employees through WhatsApp.
Each company configures its own WhatsApp Phone Number, Access Token, and Webhook on Meta's Developer Console. Incoming messages are routed to our webhook endpoint (/api/v1/whatsapp/webhook?company=...) using signature verification (App Secret). Messages may be processed by our AI assistant if the user is routed to the AI agent node.
WhatsApp messages are retained for as long as the company account is active or until explicitly deleted by a company administrator. Debug webhook logs are temporary and can be cleared from the admin panel at any time.
Our platform includes an AI-powered assistant (powered by Google Gemini models and optionally OpenAI TTS) available via the web dashboard, mobile API, and WhatsApp channel.
Your prompts may be transmitted to Google's Gemini API or OpenAI's API for processing. These providers have their own privacy policies that govern data handling:
AI interaction logs are available to company administrators for debugging. These logs can be viewed and cleared from the AI Settings panel at any time.
We use email for the following purposes within the platform:
Our platform exposes a REST API (/api/v1/...) secured via Laravel Sanctum tokens for mobile applications and authorized third-party integrations.
A small number of endpoints are publicly accessible without authentication (e.g., scanner device configuration by token, WhatsApp webhook). These are designed with minimal data exposure and are protected by other security mechanisms (signed tokens, HMAC signatures).
We implement industry-standard security measures to protect your personal data:
We use the following cookies and browser storage mechanisms:
| Cookie | Type | Purpose |
|---|---|---|
laravel_session | Essential | Maintains your authenticated session |
XSRF-TOKEN | Essential | CSRF protection for all form submissions |
locale | Preference | Stores your chosen language (En/Fr/Ar) |
darkmode | Preference | Stores your UI theme preference |
remember_* | Functional | "Remember me" login persistence |
We do not use advertising or tracking cookies.
Our platform integrates with the following third-party services. Each is subject to its own privacy policy:
| Service | Purpose | Data Shared |
|---|---|---|
| Meta / WhatsApp Business API | WhatsApp messaging | Phone numbers, messages, webhook payloads |
| Google Gemini API | AI text generation | User prompts, uploaded files |
| OpenAI API | Text-to-speech (TTS) | AI-generated text for voice conversion |
| PayPal / Stripe | Payment processing | Transaction amounts, billing info (handled by provider) |
| Google Fonts / CDN | UI assets | Browser IP (standard CDN request) |
Depending on your jurisdiction, you may have the following rights regarding your personal data:
We retain personal data for as long as necessary to provide the service and comply with legal obligations:
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
We will respond to all legitimate requests within 30 days. For complex requests, we may need up to 90 days, in which case we will notify you of the extension.