Privacy Policy
Your privacy is important to us. Learn how we handle your data.
1. Introduction
At BeeCastly, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the platform.
2. Information We Collect
We collect information that you provide directly to us, including:
- Account information (name, email, password)
- Contact information (phone number, address)
- Payment information (processed securely by our payment providers)
- Communication preferences
- Customer support inquiries
3. WhatsApp Data Collection
When you use our WhatsApp Business Platform integration, we collect and process the following data:
- Phone Numbers: Your WhatsApp Business phone number and the phone numbers of your contacts/recipients stored in your contact lists
- Message Content: The content of messages sent and received through the platform, including text, media, templates, and delivery status
- Contact Lists: Names, phone numbers, and any additional information you upload or sync to your contact database
- Conversation Metadata: Timestamps, read receipts, message IDs, and conversation thread information
- WhatsApp Business Account Information: WABA ID, phone number ID, and business verification status
4. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Send WhatsApp messages, broadcasts, and campaigns to your contacts
- Process transactions and send related information
- Generate campaign analytics, delivery reports, and engagement metrics
- Send technical notices, updates, and support messages
- Respond to your comments and questions
- Personalize your experience
- Monitor and analyze trends and usage
5. Data Sharing with Meta
We share certain data with Meta Platforms, Inc. to facilitate the WhatsApp Business Platform services:
- Message Content: Messages are transmitted through Meta's WhatsApp Business API infrastructure
- Phone Numbers: Recipient phone numbers are shared with Meta to deliver messages
- Template Messages: Message templates must be submitted to Meta for approval before use
- Analytics Data: Delivery status, read receipts, and engagement metrics are processed by Meta
Meta's use of this data is governed by their Business Data Processing Terms and Privacy Policy. We do not sell your data to Meta or any third parties.
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet is 100% secure.
7. Your Rights
Depending on your location (including GDPR for EU residents and CCPA for California residents), you have the following rights:
- Access: Request a copy of your personal information we hold
- Correction: Correct inaccurate or incomplete information
- Deletion: Request deletion of your personal data (subject to legal obligations)
- Portability: Export your contact lists and campaign data in a structured format (CSV/JSON)
- Objection: Object to certain processing of your data
- Restriction: Request limitation of processing in certain circumstances
To exercise these rights, please contact us using the information in Section 9 below.
8. Data Retention
We retain your data for the following periods:
- Account Data: Retained while your account is active; deleted 30 days after account closure
- Contact Lists: Retained until you delete them or close your account
- Message Content & History: Retained for 12 months from the date of sending
- Campaign Analytics: Retained for 24 months for reporting purposes
- Payment Records: Retained for 7 years as required by tax regulations
- Support Tickets: Retained for 3 years after resolution
You may request earlier deletion of specific data by contacting us.
9. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us:
- Email: [email protected]
- Data Protection Requests: [email protected]
- Response Time: We respond to data requests within 30 days
10. Google User Data (Gmail Integration)
This section applies only if you choose to connect a Gmail or Google Workspace mailbox to BeeCastly. Connecting a mailbox is optional, and you can disconnect it at any time.
What we access. We use Google sign-in to request the https://mail.google.com/ permission and your email address. We request this permission because we connect to your mailbox using the standard IMAP and SMTP protocols, and it is the only permission Google offers for that access. We never ask for or store your Google password.
Why we access it:
- To read incoming mail: so that you and your team can see and answer customer emails inside BeeCastly
- To send mail: so that your replies come from your own address and stay in the same conversation thread for the customer
- Your email address: to show you which mailbox is connected
What we store from a connected mailbox:
- The subject line and full message body of emails received in that mailbox
- The sender's name and email address, which we use to create or update a contact record
- The message identifier and the time it was sent, so that replies are threaded correctly
We do not download or store email attachments, and when syncing we only look at mail from the last few days.
AI-assisted replies. If you switch on AI-assisted email replies, the content of an incoming email is sent to a third-party artificial intelligence provider (for example OpenAI or OpenRouter) for the single purpose of drafting a suggested reply for you to review. This feature is switched off by default and requires your explicit consent, which you can withdraw at any time. We do not use your email content to train artificial intelligence models. If you do not give consent, no email content is sent to any artificial intelligence provider.
Limited Use. BeeCastly's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular:
- We use Google user data only to provide and improve the features described above, which are visible to you in the product
- We do not transfer Google user data to other parties, except as necessary to provide these features, for security purposes, or to comply with applicable law
- We do not use Google user data for advertising purposes, and we never sell it
- We do not allow people to read your Google user data, unless you have given us your specific consent, it is necessary for security purposes such as investigating abuse, or the law requires it
Keeping and deleting this data:
- When you disconnect: we withdraw our access with Google and delete the mail we synced from that mailbox
- When you delete your account: we withdraw our access with Google and all synced mail is removed
- Automatically: synced message content is deleted 12 months after we receive it, as described in Section 8
- Directly with Google: you can remove our access at any time from your Google Account permissions page
11. Browser Extension (BeeCastly Client Finder)
Our Chrome extension helps you capture business contact details from public directory pages into your BeeCastly account. It is optional, and installing it is entirely your choice.
What the extension collects. Only the business listing details you choose to capture — such as a business name, phone number, email address, postal address, website, category and public rating — from the page you are viewing. These are business listings, not information about you.
- Stored on your device first: captured leads are held in your browser's local storage until you choose to sync them to your BeeCastly account.
- Why it needs access to websites: to read the listing on the page you are actively capturing from, and to show the capture button.
- Why it needs tab access: to know which page you are capturing from.
What the extension does not do. It does not record your browsing history, does not read pages you are not capturing from, does not capture your screen, and does not collect passwords, payment details or the contents of your email or messages.
12. Worker Time Tracking and Screen Captures
We publish a separate extension, BeeCastly Worker Time Tracking, used only by people who have been enrolled by an administrator of their organisation. It is a distinct extension from the Client Finder described above, and neither one performs the other's function. If you have not been enrolled, it records nothing.
What is recorded when it is enabled for you:
- Active working time: how many seconds you were actively working, measured in short windows. The timer stops automatically when your computer is idle or your screen is locked, and resumes when you return.
- The BeeCastly page you were on: the address and title of the BeeCastly tab you were working in.
- Periodic screen captures: if, and only if, screen capture has been separately enabled for your account, the extension takes an occasional image of the BeeCastly tab you are viewing.
What is never recorded. Screen captures are limited to the BeeCastly tab you are actively viewing. Your other browser tabs, other applications and your desktop are never captured. If you switch away from BeeCastly while a capture is being taken, the image is discarded and never leaves your device. The addresses and contents of websites other than BeeCastly are never recorded or transmitted, and time spent outside BeeCastly is not counted.
Your visibility and control. While tracking is active, the extension displays this at all times, including whether screen capture is on and how much time has been recorded today. Time tracking and screen capture are two separate settings, and both are off by default; enabling time tracking does not enable screen capture. Your administrator can switch either off at any time, and uninstalling the extension stops all recording immediately.
Who can see it, and for how long. Recorded time and screen captures are visible only to platform administrators of your organisation. Screen captures are stored privately, are never publicly accessible, are served only through short-lived links that expire, and are permanently deleted after 30 days. You may ask us to delete your recorded time or captures at any time using the contact details in Section 9.
We do not sell this information, do not use it for advertising, and do not transfer it to third parties other than the infrastructure providers described in Section 6.
Last updated: September 5, 2026