1. Scope and who we are
The Tech Pad is a business messaging platform operated by Glam Labs (“The Tech Pad”, “we”, “us” or “our”). This Policy applies to thetechpad.com, our application, APIs, support channels and related services (the “Service”). It does not replace the privacy notices of businesses that communicate with their customers using the Service.
For account and operational data, Glam Labs generally acts as the data controller. For contacts, messages and other content processed on behalf of a customer business, that customer normally determines the purpose of processing and Glam Labs acts as its service provider or processor.
2. Information we collect
Account and workspace data
- Name, work email, company name, authentication records and workspace role.
- Subscription, support and service correspondence.
WhatsApp and Meta connection data
- WhatsApp Business Account identifiers, business display names, phone-number identifiers, phone numbers, quality status and connection state.
- Authorization credentials supplied by Meta. Access tokens are stored server-side in encrypted form and are not exposed through the browser.
Customer communication data
- Contact names, phone numbers, email addresses and customer-provided attributes.
- Message content, media references, templates, direction, timestamps and sent, delivered, read or failed statuses.
- Webhook endpoints, API-key metadata and technical event records.
Usage and device data
We may collect IP address, browser type, timestamps, error logs, pages used and security events. Our public website uses Crisp for support chat, which may process chat content and browser information under its own privacy terms.
3. How we use information
- Provide authentication, tenant isolation, contact management, messaging, inboxes, APIs and webhooks.
- Connect authorized WhatsApp Business assets and exchange messages through Meta’s Cloud API.
- Secure, troubleshoot, monitor and improve the Service.
- Provide support, service notices and billing administration.
- Prevent abuse, enforce our Terms and comply with legal obligations.
We do not sell personal information or use customer message content for third-party advertising.
4. Legal bases
Where required by law, we process information to perform our contract, pursue legitimate interests in operating and securing the Service, comply with law, or based on consent. Customer businesses are responsible for establishing a lawful basis and providing required notices for contacts whose information they process through the Service.
5. How information is shared
We share information only as needed with service providers and integrations, including Meta and WhatsApp for business messaging; Supabase for authentication, database, realtime and Edge Functions; Cloudflare and website hosting providers for delivery and security; and Crisp when a visitor uses support chat. We may also disclose information to advisers, authorities or a successor business where legally required or as part of a legitimate transaction.
Providers may process information in countries other than your own. We use contractual and technical safeguards appropriate to the service and applicable law.
6. Retention
We retain account and workspace information while an account is active and for a reasonable period afterward for security, dispute resolution and legal compliance. Customer-controlled contacts and messages are retained according to customer instructions and service configuration. Backup copies and security logs may remain for limited periods before deletion or anonymisation.
7. Choices and privacy rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, objection or portability. Account owners can contact us directly. A person who received a message from one of our customers should generally contact that business first because it controls the communication and contact data.
Deletion instructions are available at thetechpad.com/data-deletion. Removing The Tech Pad from Meta Business Integrations stops future authorized access but may not automatically delete information already retained under a lawful basis.
8. Security
We use access controls, row-level tenant isolation, encrypted transport, server-side secrets, encrypted WhatsApp credentials, webhook signature validation and operational logging. No system can guarantee absolute security. Customers must protect credentials, assign appropriate roles and notify us promptly of suspected compromise.
9. Children
The Service is intended for businesses and authorized adult users, not children. We do not knowingly offer accounts directly to children.
10. Changes
We may update this Policy as the Service or law changes. We will publish the new effective date and provide additional notice when a material change requires it.