Security & Legal
Privacy Policy
Last updated:
1. Introduction
Blaze Technologies Inc ("Xelp", "we", "us", or "our") operates Xelp, an omnichannel customer support and commerce platform. When you use our services, you trust us with your information. We take that responsibility seriously and work hard to protect your information and put you in control.
This Privacy Policy explains what information we collect, why we collect it, how we use and share it, and the choices and rights you have.
This Policy applies to:
- Our websites at xelp.io and xelp.shop (the "Websites");
- The Xelp web application and platform (the "Platform");
- The Xelp mobile application for agents (the "Mobile App");
- All related services, features, and integrations (together with the Websites, Platform, and Mobile App, the "Service").
Key terms used in this Policy:
- "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject").
- "Customer" or "Business" means a legal business entity that has an agreement with Xelp to use the Service.
- "End User" means an individual (such as a Customer's customer or contact) who communicates with a Customer through the Service via WhatsApp, Instagram, Facebook Messenger, SMS, Email, Telegram, TikTok, or other supported channels.
- "Agent" means an individual authorized by a Customer to use the Service (including the Mobile App) to respond to End User communications.
- "Service Data" means messages, contacts, orders, and other content processed on behalf of our Customers in the course of providing the Service.
2. What is Xelp
Xelp is an omnichannel customer support and commerce SaaS platform operated by Blaze Technologies Inc. The Service allows Businesses to receive, manage, respond to, and analyze customer conversations across multiple messaging channels — including WhatsApp (via the WhatsApp Business Platform / Cloud API), Instagram, Facebook Messenger, SMS, Email, Telegram, and TikTok — and, where the Business uses our Commerce Module, to manage product catalogs, carts, orders, shipping, and order tracking.
Xelp is a technology provider and business solution built on the WhatsApp Business Platform and Meta developer platforms. Our use of information received from Meta APIs adheres to the applicable Meta Platform Terms and Developer Policies, including the WhatsApp Business Terms.
3. Our Roles: Data Controller and Data Processor
We process Personal Data in two distinct capacities:
(a) As a Data Controller. For information about our Customers, their Agents and representatives, Website visitors, and prospective customers — such as account registration details, billing information, support communications, and Website usage data — Xelp determines the purposes and means of processing and acts as the data controller.
(b) As a Data Processor. For Service Data — including End User contact details, messages, conversation history, and commerce data that our Customers collect and manage through the Service — our Customers act as the data controller, and Xelp processes such data solely on the Customer's behalf and instructions, as documented in our Data Processing Addendum ("DPA").
End Users interact with our Customers, not directly with Xelp. Our Customers determine what End User data is collected through the Service, how it is used and disclosed, and how long it is retained. If you are an End User and have questions about how your Personal Data is handled, or wish to exercise your privacy rights, please contact the Business you communicated with directly. We will assist our Customers wherever possible in responding to End User requests.
4. Personal Data We Collect
4.1 Account and Business Information (as Controller)
When a Business registers for or uses the Service, we collect:
- Contact details of the account owner and Agents: name, email address, phone / WhatsApp number;
- Full business information, including business name, business category, and business location / address;
- Login credentials, including OAuth credentials if you sign in or connect accounts via Facebook Login or other supported identity providers (we never receive your password for those services);
- Connected channel identifiers, such as your WhatsApp Business Account (WABA) details, Facebook Page, Instagram professional account, Telegram bot/handle, TikTok business account, and email/SMS sender identities;
- User profile and role information for Agents.
4.2 Billing and Tax Information (as Controller)
When you subscribe to a paid plan, we collect commercial and billing details, which may include company name, billing address, and tax identification numbers where applicable. Payments are processed by our payment processor, Stripe. Xelp does not store full payment card numbers; Stripe collects and processes your payment card details in accordance with its own privacy policy (https://stripe.com/privacy). We use billing information solely to process payments, generate accurate invoices, calculate applicable taxes, and comply with tax and accounting requirements.
4.3 Service Data — End User Information (as Processor, on behalf of Customers)
In providing the Service, we receive, store, and process on behalf of our Customers:
- End User identifiers and contact details: name, phone / WhatsApp number, email address, Telegram handle, Instagram username, TikTok username, Messenger ID, and similar channel identifiers;
- The content of messages and conversations between End Users and the Business, including attachments and media;
- Commerce data (where the Business uses our Commerce Module): product catalogs, cart contents, orders, payment status, shipping addresses, and order tracking information;
- Labels, notes, and attributes the Business associates with its contacts.
We process Service Data only to provide the Service to the Customer and as instructed by the Customer. We do not sell Service Data, use it for advertising, or use it for any purpose other than providing and securing the Service, as further described in our DPA.
4.4 Service Usage and Technical Data
When you access the Service or Websites, we automatically collect usage information, including IP address, browser type and settings, device type and operating system, pages or features accessed, referring pages, timestamps, time spent, links clicked, and log and diagnostic data. We use this information to operate, secure, and improve the Service and to investigate and prevent security issues, abuse, and fraud.
4.5 Information You Provide to Us Directly
- Demo requests and inquiries: when you request a demo or contact us, we may collect your name, job title, WhatsApp number, business email address, company information, and the content of your communication.
- Support requests: when you contact support, we collect the information you provide and may retain it to assist you in the future and improve our Service.
4.6 Mobile App Data
The Xelp Mobile App allows Agents to respond to inbound queries. In addition to the data described above, the Mobile App may access, with your permission:
- Camera, media, and documents: only to allow you to attach media files or documents to your chats;
- Push notification tokens: to deliver notifications of new inbound messages;
- Mobile analytics data: app usage frequency, in-app events, performance data, device type, operating system version, and app store source, used to understand and improve app performance.
You can withdraw device permissions at any time through your device settings.
4.7 Cookies
Our Websites use cookies and similar technologies. See Section 13 (Cookie Policy) below.
We ask that you not send or disclose to us any sensitive Personal Data (such as government identification numbers, racial or ethnic origin, political opinions, religious beliefs, health data, biometric or genetic data, or criminal background information) on or through the Service.
5. How We Use Personal Data
We use Personal Data for the following purposes:
- Providing and managing the Service — creating and administering accounts; routing, storing, and displaying conversations across connected channels; operating the Commerce Module; providing the Mobile App; providing customer support.
- Processing Service Data on behalf of Customers — strictly under Customer instructions and our DPA.
- Billing and payments — processing subscription payments via Stripe, invoicing, and tax compliance.
- Communicating with you — responding to inquiries, demo requests, and support tickets; sending service announcements, technical notices, security alerts, and administrative messages.
- Marketing — informing you about products, services, features, and offers, where permitted by law. You can opt out of marketing communications at any time via the unsubscribe link in our emails or by contacting privacy@xelp.io. We do not sell or rent your Personal Data.
- Improving the Service — understanding how the Service and Websites are used; developing new features; monitoring performance.
- AI-assisted features — see Section 6 below.
- Security, fraud prevention, and compliance — investigating and preventing abuse, fraud, and security incidents; enforcing our Terms of Service; complying with legal obligations and lawful requests.
We may aggregate and/or de-identify data so that it no longer relates to an identifiable individual or Customer; this Policy does not limit our use of such aggregated or de-identified data.
6. AI Features
Certain Service features use artificial intelligence to assist with tasks such as reply suggestions, message drafting, conversation summarization, and automation. These features are powered by Cloudflare Workers AI and Cloudflare AI Gateway, which process the relevant conversation content on our behalf as a sub-processor under contractual safeguards.
- AI features process only the data necessary to perform the requested function.
- We do not permit our AI infrastructure providers to use Customer or End User data to train their general-purpose models.
- Businesses are responsible for informing their End Users about the use of automated or AI-assisted responses where required by applicable law.
7. WhatsApp Business Platform (Cloud API) and Meta Products
Xelp integrates with Meta platforms to provide the Service:
- WhatsApp Cloud API. Messages sent and received via WhatsApp are transmitted through Meta's WhatsApp Cloud API. Meta temporarily stores messages for delivery purposes and automatically deletes them from Cloud API servers after delivery or after a limited retention window (per Meta's documentation, messages are deleted automatically, typically within 30 days). Meta processes this data in accordance with the WhatsApp Business Terms and Meta's privacy policies.
- Facebook Login. If you sign in or connect assets using Facebook Login, we receive basic profile information (such as name and email) and the permissions you grant. We never receive your Facebook password.
- Instagram and Messenger. If you connect an Instagram professional account or Facebook Page, we receive and process messages, comments/DMs, and related identifiers via Meta's APIs to display and manage them in your inbox.
Our access to and use of data received from Meta APIs complies with the Meta Platform Terms, Developer Policies, and WhatsApp Business Terms, including applicable Limited Use requirements. For more information about Meta's data practices, see https://www.facebook.com/privacy/policy and https://www.whatsapp.com/legal/business-terms.
8. How We Share Personal Data
We do not sell, trade, or rent Personal Data. We share Personal Data only as described below:
-
Sub-processors and service providers. We engage third parties to process data on our behalf and under our instructions, including:
- Cloudflare, Inc. (USA) — application frontend hosting, content delivery, security, and AI infrastructure (Workers AI / AI Gateway);
- Railway Corp. (USA) — backend application hosting and data storage;
- Stripe, Inc. (USA) — payment processing;
- Meta Platforms, Inc. / Meta Platforms Ireland Ltd — WhatsApp Cloud API, Instagram, Messenger, and Facebook Login, as described in Section 7;
- Other providers of infrastructure, analytics, email delivery, and customer support tooling.
These providers may access Personal Data only to perform services for us and are bound by data processing agreements. A current list of sub-processors is available on request at privacy@xelp.io.
-
Channel providers you connect. When a Business connects a channel (e.g., Telegram, TikTok, SMS/email providers), relevant data is exchanged with that platform to send and receive messages. Each platform's own privacy policy governs its processing.
-
Business transfers. If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of some or all of our assets, Personal Data may be transferred as part of that transaction, subject to this Policy.
-
Legal compliance and protection. We may disclose Personal Data to comply with applicable laws, regulations, legal processes, or lawful governmental requests, and to protect the rights, property, or safety of Xelp, our Customers, or others, including to enforce our agreements and investigate or prevent fraud.
9. International Data Transfers
Xelp primarily serves Customers in Azerbaijan, Seychelles, and India, and our Service is available globally. Our hosting and infrastructure providers (including Cloudflare, Railway, Stripe, and Meta) are headquartered in the United States and may process and store data in the United States and other countries. This means your Personal Data may be transferred to, stored, and processed in countries other than your own, which may have data protection laws different from those of your country.
Where we transfer Personal Data internationally, we take steps to ensure it receives an adequate level of protection, including:
- entering into data processing agreements with our sub-processors;
- using recognized transfer mechanisms, such as Standard Contractual Clauses (SCCs), where required by applicable law (including for any Personal Data of EEA/UK data subjects);
- complying with applicable cross-border transfer requirements under India's Digital Personal Data Protection Act, 2023 (DPDP Act), Azerbaijani data protection law, and the Seychelles Data Protection Act.
10. Data Retention
- Service Data remains available for as long as the Business maintains it in its account. The Business controls retention of its contacts, conversations, and commerce data.
- Inactive accounts: if an account shows no usage, we will notify the account owner, and data associated with the account may be deleted after 90 days of continued inactivity following that warning.
- Account termination or deletion: upon termination or deletion of an account, all associated data (contacts, conversations, commerce data, etc.) is permanently deleted from our production systems, unless the Customer requests otherwise or a longer retention period is required by law (e.g., invoicing and tax records) or necessary to establish, exercise, or defend legal claims.
- Account and billing records are retained for as long as needed to fulfil the purposes described in this Policy and to comply with legal, tax, and accounting obligations.
- Log data is retained for a limited period for security, diagnostics, and abuse prevention.
11. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your Personal Data:
- Access — request confirmation of whether we process your Personal Data and obtain a copy;
- Rectification / Correction — request correction of inaccurate or incomplete data;
- Erasure / Deletion — request deletion of your Personal Data;
- Restriction — request that we restrict processing in certain circumstances;
- Portability — receive your Personal Data in a structured, commonly used, machine-readable format, where technically feasible;
- Objection — object to processing based on legitimate interests or for direct marketing;
- Withdraw consent — where processing is based on consent, withdraw it at any time (without affecting prior lawful processing);
- Grievance redressal and nomination (for individuals in India, under the DPDP Act) — raise grievances with us and nominate another individual to exercise your rights in the event of death or incapacity;
- Complain — lodge a complaint with your local data protection authority (for example, the Data Protection Board of India, the Seychelles Information Commission, or the relevant authority in Azerbaijan).
How to exercise your rights. You (or your authorized representative) can exercise these rights:
- In-app, through your account settings;
- Via the customer portal; or
- By email to privacy@xelp.io.
We may need to verify your identity before fulfilling a request. We will respond within the timeframe required by applicable law. Some rights may be subject to limitations or exceptions permitted by law.
If you are an End User, please direct your request to the Business you communicated with, since they control your data. If you contact us directly, we will refer your request to the relevant Business and assist them in responding.
12. How We Protect Personal Data
We implement technical and organizational measures appropriate to the risk to protect Personal Data against loss, misuse, and unauthorized access, disclosure, alteration, or destruction. These measures include encryption of data in transit (TLS), access controls and role-based permissions, network security controls provided through our infrastructure providers, logging and monitoring, and personnel confidentiality obligations.
No method of transmission or storage is 100% secure. If we become aware of a security breach affecting your Personal Data that is likely to result in a risk to your rights, we will notify you and/or the relevant authority as required by applicable law (including breach notification obligations under the India DPDP Act and other applicable regimes).
13. Cookie Policy
Our Websites use cookies and similar technologies (session-based and persistent) to:
- keep you logged in and remember your preferences (strictly necessary cookies);
- understand Website traffic and usage so we can improve it (analytics cookies);
- where applicable, measure the effectiveness of our marketing (marketing cookies).
Session cookies are deleted when you close your browser; persistent cookies remain until they expire or you delete them. You can manage or disable cookies through your browser settings, though disabling some cookies may affect the functioning of the Service. Where required by law, we will request your consent for non-essential cookies via a cookie banner, which you can change at any time.
We do not currently respond to browser Do Not Track signals, as no consistent industry standard exists.
14. Children
The Service is not directed to children under 16, and we do not knowingly collect Personal Data from anyone under 16. Individuals under 16 may not register for the Service. If you believe a child under 16 has provided us Personal Data, please contact us at privacy@xelp.io and we will delete it promptly. Businesses using the Service are responsible for ensuring their own communications comply with laws protecting minors, including obtaining verifiable parental consent where required (e.g., under India's DPDP Act for users under 18 in India).
15. Legal Bases for Processing (Where Applicable)
Where laws such as the GDPR/UK GDPR or similar frameworks apply, we rely on the following legal bases:
- Performance of a contract — to provide the Service, manage accounts, and process payments;
- Legitimate interests — to secure and improve the Service, prevent fraud and abuse, communicate with business contacts, and market our services to businesses, where these interests are not overridden by your rights;
- Consent — for optional cookies, certain marketing communications, and other cases where we request it; you may withdraw consent at any time;
- Legal obligation — to comply with tax, accounting, and other legal requirements.
Under India's DPDP Act, we process digital personal data on the basis of consent and for certain legitimate uses recognized by that Act.
16. Third-Party Links
The Websites and Service may contain links to third-party websites and services that we do not operate. Their privacy practices are governed by their own policies, and we are not responsible for them. We encourage you to review the privacy policy of every site you visit.
17. Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes to our practices, technologies, or legal requirements. We will post the revised Policy on the Websites and update the "Last Updated" date above. For material changes, we will provide notice through the Service or by email, and obtain consent where required by applicable law. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
18. Contact Us
Please contact us if you have questions or complaints about this Privacy Policy, wish to exercise your rights, or want to know more about our data practices:
Blaze Technologies Inc 651 N Broad St., Ste 024 Middletown, DE 19709, United States Email: privacy@xelp.io
Data Protection Officer Renuka Vivek Email: renuka@xelp.io
If you are not satisfied with our response, you may lodge a complaint with the data protection authority in your jurisdiction.