Privacy Policy

This Privacy Policy explains how Reeberio ("Hobbytronics" "we," "us") collects, uses, discloses, and protects information when you use our business messaging platform (the "Service").

Reeberio is a B2B platform: our direct customers ("you," the "Customer") are businesses that use the Service to communicate with their own end customers ("Contacts") over WhatsApp, webchat, SMS, and other supported channels. This policy covers both:

• information we collect about you and your team as our Customer, and
• our role in processing information about your Contacts on your behalf.

1. Who this applies to

• If you are a Customer (you signed up for an account): this policy describes what we collect about you directly and how the Service handles data you upload or generate through it.
• If you are a Contact (someone messaging a business that uses Reeberio): the business you're messaging is responsible for its own privacy practices and is the data controller for your information. We process your data as a processor, on that business's instructions. Contact the business directly for privacy requests; see Section 8 for how we support such requests.

2. Information we collect

Account information. When you sign up, we collect your name, email address, and password (stored as a salted hash, never in plain text). If you use single sign-on, we receive the profile information your identity provider shares with us.

Business and channel information. To connect a messaging channel, we store the credentials needed to operate it on your behalf — for example, WhatsApp Business API access tokens, phone number IDs, and webhook verification tokens. These are encrypted at rest.

Conversation content. Messages, media (images, video, voice notes, documents), interactive message metadata, reactions, and delivery/read status that flow through channels you connect — both from your team and from your Contacts.

Contact records. Names, phone numbers, custom fields, tags, and consent status for the people your team communicates with.

Team and usage data. Team member roles, assignments, internal notes, workflow configurations, message templates, campaign definitions, and audit logs of account activity.

Payment information. We do not store full payment card numbers ourselves. Billing is handled by our payment processors — currently Lemon Squeezy — who collect and process payment details under their own privacy policies.

Device and diagnostic information. For SMS and GSM gateway channels, the Service communicates with an Android device or GSM hardware that you or your Contact's carrier controls; call and SMS metadata from that device is synced to your account so messages can be sent and received.

We do not use third-party advertising or analytics trackers. We have not integrated tools like Google Analytics or similar cross-site trackers into the Service as of this policy's last update.

3. How we use information

We use the information above to:

• operate the shared inbox, route and deliver messages, and keep conversation history in sync across your team;
• power optional AI features — automated replies, intent detection, and knowledge-base-grounded answers — by sending relevant conversation content to our AI model provider (see Section 4);
• send transactional email (e.g., account, billing, and security notifications) via our email delivery infrastructure;
• send push notifications about new messages or assignments via Firebase Cloud Messaging (Google);
• process subscription billing and enforce plan limits;
• detect abuse, secure the Service, and comply with legal obligations;
• provide support and respond to your requests.

We do not sell your information or your Contacts' information to third parties.

4. Who we share information with

We share information only as needed to run the Service:

• Meta / WhatsApp Business Platform — messages you send and receive over WhatsApp are transmitted through Meta's WhatsApp Business Platform (Cloud API), which has its own data handling terms as the underlying network operator.
• AI model provider — if you enable AI auto-reply or knowledge-base features, relevant message content and any documents you upload are sent to our AI routing provider (OpenRouter) and the underlying model it calls, solely to generate a response.
• Payment processors — as listed in Section 2, to process your subscription.
• Google (Firebase) — to deliver push notifications to your team's devices.
• Infrastructure providers — the servers that host the Service and store uploaded files.
• Legal requirements — if required by law, regulation, legal process, or governmental request.
• Business transfers — if we're involved in a merger, acquisition, or asset sale, in which case we'll notify you.

We do not currently use a third-party SMS API provider for SMS/GSM channels — those messages are routed through hardware you or your Contact's carrier control, as described in Section 2.

5. Data retention

Message and conversation retention is tied to your subscription plan and is configurable:

Nom du forfeit
Free
Pro
Business
Data retention
Message retention
30 days
90 days
180 days

After the retention window, historical messages are automatically purged. Account and billing records are retained as needed for legitimate business, accounting, and legal purposes even after your subscription ends. You may request earlier deletion under Section 8.

6. Security

We encrypt sensitive credentials (such as channel access tokens) at rest and use encrypted connections (TLS/HTTPS) in transit. Access to customer data within our team is limited to what's needed to operate and support the Service. No system is perfectly secure, and we cannot guarantee absolute security.

7. International data transfers

[Describe where your servers/sub-processors are located and, if you or your Contacts are in the EEA/UK/Switzerland, the transfer mechanism you rely on — e.g., Standard Contractual Clauses.]

8. Your rights and choices

Depending on your location and role, you may have rights to access, correct, export, or delete personal information, and to withdraw consent to messaging.

• Customers: manage most of this directly in your account (contact records, exports, team data). For anything you can't self-serve, contact us at support [a] reeberio.com].
• Contacts: we support data-subject requests routed to us by our Customers. Our platform includes built-in tools for a Customer to anonymize or erase a Contact's records, and to record consent/opt-out status (including automatic opt-out handling for STOP/UNSUBSCRIBE-style keywords). If you are a Contact and want your data removed, please contact the business you were messaging directly; if you're unable to reach them, contact us at support [a] reeberio.com] and we will assist.

If you are in the EEA, UK, or another jurisdiction with a data protection authority, you may also have the right to lodge a complaint with that authority.

9. Children's privacy

The Service is intended for business use and is not directed to children. We do not knowingly collect personal information from children under 16 through our own account-signup flow. If you believe a child has provided us information directly, contact us at support [a] reeberio.com].

10. White-labeled deployments

If you access a business's messaging support through a white-labeled instance of the Service, that business — not Reeberio — is presented as the customer-facing brand, but Reeberio Technologies remains the underlying data processor as described in this policy.

11. Changes to this policy

We may update this policy from time to time. We'll update the "Last updated" date above and, for material changes, notify account holders by email or in-app notice.

12. Contact us

Questions about this policy or your data:

Hobbytronics XX Graveyard Road Mochiwali, Kahror Pakka 59340, Lodhran Punjab, PK support [a] reeberio.com

Last updated: 25 JUN, 2026