Privacy Policy & Data Protection
Learn how Softymize collects, protects, encrypts, and handles user data, Google Workspace APIs, and Meta WhatsApp Business integrations.
Commitment to Data Privacy & Security
At Softymize("we", "our", "us"), protecting the privacy, confidentiality, and security of your personal and business data is our highest priority. This Privacy Policy details how Softymize collects, uses, processes, stores, and protects data when you use our multi-tenant WhatsApp Automation CRM, integrations (including Google Workspace APIs and Meta WhatsApp Business API), and related services.
Information We Collect
We collect information strictly necessary to provide, manage, and optimize our enterprise automation and CRM services:
- Account & Profile Information: Name, business email address, organization name, billing details, and contact phone number provided during account registration and onboarding.
- Integration & API Credentials: User-authorized OAuth tokens, webhook URLs, and API keys necessary to connect third-party platforms (e.g., Google Workspace, Meta WhatsApp Business Cloud API, Shopify, WooCommerce, CRM systems).
- Operational & Transactional Data: Customer contact details, messaging logs, workflow triggers, and event payload data processed on your behalf through your configured automation flows.
- Log & Technical Data: IP addresses, browser types, device identifiers, session timestamps, and system performance telemetry collected to ensure platform stability, security, and fraud prevention.
Google API Services & Workspace User Data Policy (Limited Use Compliance)
Softymize allows users to connect their Google accounts (via OAuth 2.0) to enable features such as appointment scheduling via Google Calendar and lead/data syncing via Google Sheets.
Affirmative Statement on Limited Use & AI/ML Restrictions
Softymize's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
No AI/ML Model Training: Under the Google Workspace API User Data and Developer Policy, the use of raw, aggregated, or derived user data received from Google Workspace APIs (including Google Calendar, Google Sheets, and user profile data) will strictly adhere to the Google User Data Policy, including the Limited Use requirements. Specifically, Softymize does NOT use, transfer, or sell Google user data—including raw, aggregated, or derived data—to create, train, fine-tune, or improve generalized or foundational machine learning (ML) and artificial intelligence (AI) models.
Specific Google Scopes & Usage:
.../auth/calendar.events: Used solely to create, view, or update calendar events and appointments requested by users or their customers via automated conversation flows..../auth/spreadsheets: Used solely to read and append rows (e.g., contact records, form submissions, and order records) to user-selected Google Sheets as configured in user workflows.openid,.../auth/userinfo.email,.../auth/userinfo.profile: Used solely to authenticate user identity and display account owner email on the connection dashboard.
We never transfer Google user data to third parties, except as strictly necessary to provide or improve the specific user-facing features of the application, comply with applicable laws, or as part of a merger/acquisition with explicit user notice.
Data Protection & Security Mechanisms for Sensitive Data
Softymize employs rigorous technical, physical, and administrative safeguards to protect sensitive and personal data against unauthorized access, destruction, loss, alteration, or disclosure:
Encryption in Transit
All communications between user browsers, our backend servers, and external third-party endpoints (Google, Meta, Shopify) are encrypted using industry-standard Transport Layer Security (TLS 1.2 / TLS 1.3) and HTTPS.
Encryption at Rest
All sensitive customer records, stored OAuth tokens, refresh tokens, and secret API credentials are encrypted at rest in our databases using industry-grade AES-256 encryption.
Multi-Tenant Data Isolation
Strict tenant-level scoping and role-based access control (RBAC) ensure that every workspace's data is logically segregated, preventing cross-tenant leakage or unauthorized access.
Principle of Least Privilege
Our integrations request only the minimum necessary OAuth scopes required for user functionality. Internal access to production infrastructure is restricted to authorized personnel under multi-factor authentication (MFA).
Meta WhatsApp Business API & Messaging Processing
As a WhatsApp automation and customer communications platform, Softymize processes messaging content strictly on behalf of the customer:
- All message payloads and media transmitted via the Meta WhatsApp Cloud API are processed strictly according to Meta's Business Policies.
- We do not sell, rent, or monetize end-user conversation contents or phone numbers.
- Message logs and media are processed solely to facilitate customer communication flows, template messaging, live chat routing, and analytics.
How We Use Collected Information
We use information solely for legitimate operational purposes:
- To provide, maintain, and execute customer automation workflows and bot responses.
- To synchronize events, leads, and orders across authorized third-party accounts (e.g., Google Sheets, Google Calendar, Shopify).
- To send critical system notifications, security alerts, and account billing statements.
- To detect, investigate, and prevent fraudulent activity, unauthorized access, or policy violations.
Data Retention, User Rights & Deletion Protocols
We retain personal data and integration logs only for as long as your workspace account is active or as necessary to fulfill the operational purposes described in this policy.
Revocation and Deletion Controls
- Disconnect Integrations: You may revoke or disconnect your Google or Meta connections at any time directly from the Softymize Integration Settings panel.
- Google Account Permissions: You can also revoke Softymize's access to your Google account at any time through the Google Security Permissions Console.
- Complete Account & Data Deletion: You can request full deletion of your workspace, conversation history, and synced records by contacting us at info@softymize.com. Data deletion requests are processed within 30 days.
Third-Party Data Disclosures
We do not sell, trade, or share your personal data with third parties for marketing or advertising purposes. Data is shared exclusively with:
- Infrastructure and cloud service providers (such as hosting and database providers) operating under strict confidentiality and data protection agreements.
- Third-party platforms explicitly connected and authorized by you (e.g., Google, Meta, payment gateways) solely to carry out your specified automation workflows.
- Law enforcement or regulatory authorities only when strictly required by applicable legal obligations.
Updates to This Policy
We may update this Privacy Policy periodically to reflect enhancements in our platform, new integrations, or changes in legal regulations. When material changes are made, we will update the "Effective Date" at the top of this page and notify active workspace administrators via email or in-app notifications.
Contact Our Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or our compliance with Google API / Meta policies, please reach out to our Data Protection Officer:
Softymize Technologies
Email / Inquiries: info@softymize.com
© 2026 Softymize. All rights reserved.