← Mishora CRM
Privacy Policy
Last updated: September 24, 2026
This Privacy Policy explains how Mishora CRM ("we", "us", "our") collects, uses, and protects
information when you use our CRM platform, including features that connect to your
Instagram and WhatsApp Business accounts via the Meta Platform.
1. Information We Collect
We collect the following categories of information:
- Account information — name, email, phone number, and business details provided when you sign up.
- CRM data — leads, contacts, deals, quotations, invoices, tasks, and other records you or your team create in the platform.
- Meta Platform Data — when you connect your Instagram or WhatsApp Business account, we receive and store:
- Access tokens issued by Meta to authorize API calls on your behalf.
- Your Instagram Business Account ID, connected Facebook Page ID, and WhatsApp Business Account (WABA)/Phone Number ID.
- Incoming Instagram comments and direct messages, and incoming WhatsApp messages, so we can match them against your automation rules and reply on your behalf.
- Basic account/profile info (name, username, phone number) of the customers who message or comment, strictly to display and respond to them inside your CRM.
- Usage data — log-in activity and feature usage within the CRM, used only to operate and improve the product.
2. How We Use Meta Platform Data
Data obtained through the Instagram and WhatsApp APIs is used solely to power the automation features you configure — for example, auto-replying to a comment, sending a keyword-triggered DM, or logging a conversation against a CRM contact. We do not sell this data, and we do not use it for advertising or share it with data brokers.
Specifically:
- Access tokens are stored securely and used only to make API calls (send DM, reply to comment, send WhatsApp message) on your explicit configuration.
- Message/comment content is matched against the automation rules and chatbot flows you create, and logged in your account's activity log for your own reference.
- Only your organization ("tenant") and its authorized staff can view data connected to your Instagram/WhatsApp accounts — other tenants on the platform cannot see it.
3. How We Use Information (General)
- To provide and operate the CRM, including lead management, messaging automation, invoicing, and reporting.
- To authenticate you and secure your account.
- To send you service-related notifications (e.g. task reminders, follow-up alerts).
- To improve and troubleshoot the platform.
4. Data Sharing
We do not sell your data. We share information only:
- With Meta (Facebook/Instagram/WhatsApp), strictly as required to make the API calls you've configured.
- With infrastructure providers (hosting, database, email/SMS delivery) who process data only on our instructions.
- When required by law, or to protect the rights and safety of our users.
5. Data Security
Access tokens and credentials are stored server-side and are never exposed to other tenants or the public. We use industry-standard practices (encrypted connections, access control, tenant data isolation) to protect your data.
6. Data Retention & Deletion
We retain data for as long as your account is active. If you disconnect your Instagram or WhatsApp account, stored access tokens are no longer used for new API calls. You may request permanent deletion of your account and associated data at any time by contacting us below.
7. Your Rights
- Access, correct, or export the data stored in your CRM account.
- Disconnect your Instagram/WhatsApp integration at any time from your account settings.
- Request deletion of your account and data.
8. Children's Privacy
Mishora CRM is a business tool and is not directed at, or knowingly used by, children under 16.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
10. Contact Us
For privacy questions, data access, or deletion requests, contact us at
octacoretechnologies0@gmail.com.