Privacy Policy & Data Deletion

Privacy Policy

This policy explains how Rasael AI collects, uses, shares, and stores personal data, including data received through the official APIs of the WhatsApp Business Platform, Instagram, Facebook, and Google Calendar. It also describes how to delete your data.

Effective date: July 23, 2026Last updated: July 23, 2026
This policy covers how Rasael AI handles data received through the official APIs of the WhatsApp Business Platform, Instagram, Facebook, and Google Calendar.

1. Who We Are

2. Scope & Channels Covered

This policy explains how we collect, use, share, and store personal data when you use Rasael AI, including data received from Meta via official APIs for WhatsApp Business Platform, Instagram, and Facebook (Pages/Catalog/Graph/Marketing APIs), and data received from Google via the official Google Calendar API.

3. Data We Process

3.1 Facebook & Instagram permissions (only if actually enabled)

Permission / FeatureData from MetaPurpose (why we need it)
catalog_managementCatalog item data (product/item IDs, title, description, price/currency, image URLs, availability, inventory, categories/variants)Sync/add/update/delete items and product sets in Rasael AI for FB/IG Commerce. No off-app advertising use.
pages_read_engagementPage posts, comments, reach/engagement insightsIn-app analytics and dashboards.
pages_manage_postsCreate/edit/schedule Page postsEnable publishing from Rasael AI.
pages_manage_metadataPage settings and connectionsLink Page and verify ownership.
pages_read_user_content (optional)UGC on your PageModeration/support if enabled.
instagram_basicAccount ID, name, basic mediaDisplay/connect content in-app.
instagram_manage_comments (optional)Comments on your mediaModeration and replies.
instagram_manage_messages (optional)Instagram Direct for business accountsCustomer service/private replies.
instagram_manage_insightsEngagement/reach metricsPerformance reporting.
instagram_content_publish (optional)Publish Instagram contentScheduling/publishing from Rasael AI.
public_profile (optional with social login)Name, profile photo, user IDAccount creation/verification and in-app display.
email (optional with social login)Email addressVerification, security and support communications.

3.2 WhatsApp (WhatsApp Business Platform)

When you connect a business number, we process (depending on your use):

  • Messaging data: customer phone numbers, displayed profile name, conversation/message IDs, message content and media you send/receive via Rasael AI, delivery/read statuses, conversation categories (service/marketing/authentication per Meta), message templates and approval status, webhook notifications.
  • Account/settings data: WABA ID and Phone Number ID, messaging tier/quality rating, opt-in/opt-out status.
  • Purpose: to enable customer support, notifications and transactions, manage templates, reporting and compliance.
  • Restrictions: We do not use WhatsApp message content or channel data to build advertising profiles or for off-app targeting, and we do not onward-transfer Meta Platform Data to third parties other than our processors without your consent or a clear legal basis.

3.3 Google Calendar (Google Calendar API)

Appointment Scheduling Integration

When you choose to connect your Google Calendar to Rasael AI, we request the following Google OAuth scopes and process the corresponding data. We access your Google user data only after you explicitly grant permission, and only to provide this feature.

ScopeData from GooglePurpose (why we need it)
calendar / calendar.eventsYour calendars and calendar events (event titles, times, attendees, availability/free-busy information)Read your availability and create, update, or cancel booking/appointment events on your calendar when your customers schedule appointments with your business through Rasael AI chat channels.
openid, emailYour Google account identifier and email addressIdentify which Google account is connected to your workspace and display it in your settings.
  • OAuth tokens: the access and refresh tokens Google issues for your connection are stored encrypted at rest and are used solely to call the Google Calendar API on your behalf.
  • Change notifications: we receive Google Calendar push notifications so your availability stays in sync; these notifications contain no event content, only a signal that something changed.
  • What we do NOT do: we do not use Google Calendar data for advertising, we do not sell it, and we do not transfer it to third parties except as necessary to provide the feature (our hosting processors) or as required by law. Humans do not read your calendar data except with your explicit permission (e.g., a support request), for security/abuse investigation, or where required by law.
Google API Services — Limited Use Disclosure

Rasael AI’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained from Google APIs is:

  • Used only to provide and improve the Appointment Scheduling feature you requested.
  • Not transferred or sold to third parties for advertising, marketing, or other unrelated purposes.
  • Not used to serve advertisements.
  • Not used to train generalized or non-personalized AI/ML models. Google user data is never used to train our AI models.
  • Accessed by humans only in the limited cases permitted by Google — with your explicit consent, for security or legal compliance, or when the data has been aggregated and anonymized.

3.4 Other data we may collect

  • In-app usage logs (diagnostics), limited to what is necessary.
  • Device/browser info (device type, OS, public IP).
  • Content you provide (e.g., product data, media, captions) when using publishing tools, catalog management, or messaging features.

4. How We Use Data

  • Provide the service: enable channels (WhatsApp/Instagram/Facebook/Google Calendar) and the features you choose (e.g., catalog sync, messaging, publishing, appointment scheduling).
  • Analytics & performance: understand feature usage and improve experience (typically aggregated/de-identified).
  • Security & fraud prevention: protect accounts, investigate abuse.
  • Service communications: important changes or incidents. We do not use Meta or Google data for marketing without your explicit consent.
  • AI features (if enabled): some functions may use AI models hosted by us or our processors. We do not use your customer content to train general-purpose models without your consent, and we never use Google Calendar data to train AI models.

5. Sharing & Disclosure

  • Service providers (hosting, databases, analytics, media caching, customer-support tooling) under data-protection agreements.
  • Legal compliance where required.
  • Corporate transactions (merger/acquisition) with continued protections.

We do not sell personal data, we do not share Meta Platform Data or Google user data for off-app ad targeting, and we do not combine Meta or Google data with external sources to build marketing profiles without explicit consent.

Processing is based on: (a) contract performance, (b) legitimate interests (security/performance), and (c) consent where required (for optional features).

7. Retention

  • Catalog-related sync and diagnostic logs: up to 90 days.
  • Working copies needed to operate your commerce integration (e.g., mappings between your product IDs and Meta Item IDs): retained while your account/integration is active, then deleted within 30 days of disconnect or deletion request.
  • Message content/attachments processed via WhatsApp or Instagram messaging features: retained only as needed to operate the feature (e.g., deliver, display, or troubleshoot), then deleted per your workspace settings; if no setting applies, up to 30 days.
  • Google Calendar OAuth tokens and connection records: retained while your Google Calendar connection is active, then deleted within 30 days of disconnection, revocation, or deletion request. Booking events we created remain on your Google Calendar under your control.

8. International Transfers

Your data may be processed on servers outside your country. We use appropriate safeguards (e.g., Standard Contractual Clauses where applicable) to ensure an equivalent level of protection.

9. Security

We apply technical and organizational measures (TLS in transit, encryption at rest for access tokens and credentials, restricted access controls, environment isolation, encrypted backups) and conduct periodic reviews of permissions and logs.

10. Your Rights & Choices

You may request access, correction, deletion, portability, and restriction/objection, and withdraw consent where applicable. You can:

  • Disconnect channels (e.g., WhatsApp/FB/IG/Google Calendar) from Rasael AI at any time.
  • Revoke Rasael AI’s access to your Google account at any time from your Google Account security settings.
  • Stop WhatsApp marketing by replying STOP or via channel settings.
  • Submit a deletion request using the section below.

Contact support@ahlamkom.com to exercise your rights.

11. Children

Rasael AI is not directed to children under 13, and we do not knowingly process their data.

12. Changes

We will post any changes on this page and update the “Last updated” date.

13. Contact

Ahlamkom Solutions LLC

Dubai, UAE

WhatsApp: +971 60 056 1636

Data Deletion

Data Deletion Instructions

Applies to Meta (Facebook/Instagram), WhatsApp Business Platform, and Google Calendar integrations.

A) Self-service: disconnect integrations

  1. Rasael AI → Settings → Channels: disconnect the WhatsApp number, Facebook Page, Instagram account, or Google Calendar.
  2. Facebook/Instagram: you may also remove Rasael AI in Facebook Business Integrations and revoke the Instagram connection.
  3. Google Calendar: you may also revoke Rasael AI’s access from your Google Account → Security → Third-party access. Revoking invalidates our stored tokens immediately.
Disconnecting stops further data flow. It does not by itself delete data we already store; submit a deletion request as described below.

B) Request deletion from us

Use our form: https://ahlamkom.com/facebook-data-deletion (or /data-deletion).

Include:

  • Your account email and company name.
  • IDs relevant to the integration you want deleted (any that apply): Page ID, Instagram Business/Professional Account ID, WABA ID and/or Phone Number ID, or the Google account email connected for Google Calendar.
  • What to delete: account data, channel connections/tokens, catalog sync data, message content/attachments, logs.

What we delete

  • Account profile, channel connections and access tokens (including Google OAuth access and refresh tokens).
  • Catalog mappings and sync artifacts (e.g., product-ID ↔ Meta item-ID tables).
  • Message content and media stored by us for WhatsApp/Instagram messaging features.
  • Google Calendar connection records and sync state stored by us. (Events on your Google Calendar itself remain under your control in Google Calendar.)
  • Diagnostic/sync logs (subject to the timeline below).

What we may retain

  • Minimal audit logs, security records, and billing/invoices as required by law and for fraud prevention. These are kept separately and not used for marketing.

Timeline

  • We acknowledge your request within 7 days and complete deletion within 30 days (unless a longer period is legally required).
  • Backups are overwritten on a rolling cycle (up to 35 days). Once expired, deleted data becomes unrecoverable.
  • Deleting data in Rasael AI does not delete your content from Meta or Google themselves (e.g., items in your Meta Catalog or events on your Google Calendar); manage those in Facebook/Instagram/Google Calendar directly or ask support for help.

Automated callbacks

If you remove our app from Facebook/Instagram, disconnect a WhatsApp number, or revoke Rasael AI’s Google access, our Data Deletion Callback runs to delete associated tokens/mappings per the rules above.

Contact

If you cannot access the form, email support@ahlamkom.com with the subject “Data Deletion Request – Rasael AI” and include the details listed above.