Growth OS · Last updated 17 September 2026
This Privacy Policy explains how SIGMAINTENT TECHNOLOGIES LLP (“we”, “us”), operator of the Growth OS platform (“Service”), collects, uses, stores, and protects information when you and your end-customers use the Service. Growth OS helps businesses manage customer conversations over the WhatsApp Business Platform and other channels.
Account data: name, email, password (hashed), workspace and role.
Business/customer data you add: your contacts’ and leads’ names, phone numbers, email, notes, tags, and deal information.
WhatsApp & messaging data: messages sent to and from your connected WhatsApp Business number, message status, and template usage — processed solely to deliver the Service.
Integration credentials: tokens for connected services (e.g. Meta/WhatsApp access tokens, AI keys), stored encrypted at rest.
Usage & technical data: log data, device/browser info, and diagnostics used for security and reliability.
To provide, operate, secure, and improve the Service; to send and receive messages on your behalf; to generate AI-assisted replies and insights; to process billing; and to comply with legal obligations. We do not sell your data.
When you connect a WhatsApp Business Account, we access and process WhatsApp message data only to provide the Service to you, in accordance with Meta’s Platform Terms, the WhatsApp Business Messaging Policy, and applicable Developer Policies. We do not use WhatsApp data for advertising and do not share it except with the sub-processors listed below.
If you connect WhatsApp using “Connect with Meta” (Facebook Login for Business), Meta shares with us: your WhatsApp Business Account ID, the phone number ID and display number you select, the verified business name, an access token limited to the WhatsApp permissions you approve (whatsapp_business_management and whatsapp_business_messaging), and an app-scoped Facebook user ID. We use these only to send and receive WhatsApp messages and manage message templates for your workspace. We do not access your personal Facebook profile, friends, or posts.
If you connect a Facebook Page (Integrations → Facebook Page & Instagram), we receive the Page ID and name, a Page access token, and the ID and username of the Instagram professional account linked to that Page. With them we: receive the answers people submit in your Lead Ads forms and add them to your CRM; receive and send Instagram Direct messages for that account (including the sender's Instagram name and username, message text and attachments) so your team and AI agent can reply in the Inbox; and read your ad campaigns and their results when you sync them. Permissions used for this include pages_show_list, pages_manage_metadata, pages_read_engagement, leads_retrieval, instagram_basic, instagram_manage_messages, ads_read and ads_management.
Access tokens are encrypted at rest and are never shown back in the product. You can disconnect at any time from Settings → Meta or Integrations, or remove Growth OS from your Facebook “Business Integrations” settings — any of these deletes the stored tokens and account IDs.
To draft replies, summarize conversations, and qualify leads, message content and relevant context may be processed by third-party AI providers under contractual confidentiality. This content is used only to perform the requested task and is not used to train third-party models where opt-out is available.
We share data only with infrastructure providers needed to run the Service, including: Meta Platforms (WhatsApp delivery), our database/hosting provider (Supabase), our application hosting providers, AI model providers, and payment processors. Each is bound by data-protection obligations.
We retain data for as long as your account is active or as needed to provide the Service. You may request export or permanent deletion of your workspace data at any time by emailing info@sigmaintent.com; we will action verified deletion requests within 30 days, subject to legal retention requirements.
To delete the data we received from Meta, follow the steps on our Data Deletion Instructions page. Deletion requests sent through Facebook are processed automatically and come with a confirmation code you can check on that page.
We apply technical and organizational safeguards including encryption in transit and at rest for sensitive credentials, tenant data isolation, and access controls. No method of transmission is 100% secure, but we work to protect your data.
Depending on your jurisdiction (e.g. GDPR, India’s DPDP Act), you may have rights to access, correct, export, or delete your personal data, and to withdraw consent. Contact us to exercise these rights.
SIGMAINTENT TECHNOLOGIES LLP. Governing law: the laws of India. Questions or requests: info@sigmaintent.com.