Privacy Policy | LocalBIX

Loading LocalBIX...

Skip to content

Privacy Policy

Last updated: August 16, 2026 · Effective immediately

LocalBIX ("we", "us", "our") operates a SaaS platform that helps local businesses manage customer engagement across Google Business Profile, WhatsApp Business, Facebook, Instagram, and other channels. This Privacy Policy explains what data we collect when you use localbix.com or any of our mobile applications (the "Service"), how we use it, who we share it with, and the choices you have.

1. Information We Collect

1.1 Account & Profile Data

  • Name, email address, mobile number, password (hashed)
  • Business name, business address, business category, working hours
  • Email verification status and OTP records

1.2 OAuth & Integration Tokens

When you connect a third-party platform, we receive and store:

  • Meta (Facebook, Instagram, WhatsApp Business): OAuth access tokens (encrypted), refresh tokens, your Meta user ID, granted page/IG/WABA IDs, business portfolio ID.
  • Google Business Profile: OAuth access tokens, refresh tokens, Google user ID, list of business locations you manage, business metadata (name, address, phone, hours, photos).
  • Twitter/X, LinkedIn: OAuth tokens and the social profile IDs you authorize.

1.3 WhatsApp Business Data

When you connect a WhatsApp Business number through Meta's Embedded Signup flow, we receive and store:

  • WhatsApp Business Account ID (WABA), phone number ID, verified business name, display phone number, quality rating, messaging limit tier
  • Inbound messages from your customers (text, sender phone, sender name, timestamp, message type)
  • Outbound messages sent by you or by our AI agent on your behalf
  • Message delivery status, read receipts, conversation metadata

1.4 Google Business Profile Data

  • Customer reviews (text, star rating, author name, author avatar, review date)
  • Your replies to those reviews (and the timestamp Meta posts them publicly)
  • Business location metadata (hours, attributes, photos, lat/lng)

1.5 Knowledge Base Content (optional)

If you choose to upload a business catalog (products, services, FAQs, policies, sample responses) for our AI agent, we store that text in our database and forward it to our AI provider (OpenAI) to generate contextual replies. You can delete these at any time from your dashboard.

1.6 Usage & Device Data

  • IP address, browser type, OS, device identifiers, referring URL
  • Pages viewed, features used, actions taken, timestamps
  • Mobile app crash logs and performance metrics

1.7 Cookies

We use first-party cookies for session management, CSRF protection, and preference storage. We do not use third-party advertising cookies. See our Cookie Policy.

2. How We Use Your Information

We use the data above to:

  • Authenticate you and keep your account secure
  • Connect your account to third-party platforms (Meta, Google, etc.) and exchange data with them on your behalf
  • Display your Google reviews, post your replies, and sync your business information to the panel
  • Deliver and log WhatsApp messages between you and your customers, including AI-generated replies when enabled
  • Improve our AI reply quality (your business catalog is sent to OpenAI only when a customer message requires it; OpenAI's API data usage policy applies)
  • Send you service notifications, security alerts, billing emails
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations and respond to lawful requests

3. Who We Share Data With

We never sell your data. We share it only with:

3.1 Meta (Facebook / Instagram / WhatsApp)

To deliver WhatsApp Business messaging, we exchange data with Meta Graph API and WhatsApp Cloud API. Meta's own Data Policy applies to data Meta receives. When you disconnect an account, we delete stored tokens immediately and request Meta to revoke access.

3.2 Google

To read your Google reviews and post replies, we use the Google Business Profile API. Google's Privacy Policy governs data Google collects.

3.3 OpenAI (for AI replies)

If you use the AI reply feature, the customer's message and your business knowledge-base excerpts are sent to OpenAI to generate a reply. OpenAI retains API data for 30 days for abuse monitoring, then deletes it. We do not send personal customer data to OpenAI beyond what is needed for the reply.

3.4 Service Providers

  • Hosting: Hostinger (data center: USA/EU)
  • Email delivery: Hostinger SMTP (transactional email only)
  • Error monitoring: Sentry (crash reports only, no PII)
  • Payments: Razorpay (billing data only)

3.5 Legal & Safety

We may disclose information if required by law, court order, or valid request from a government authority, or to protect the safety, rights, or property of LocalBIX, our users, or others.

4. Data Retention

  • Account data: kept while your account is active, deleted within 30 days of account closure (except where retention is legally required, e.g. tax records)
  • OAuth tokens: deleted within 24 hours of disconnecting the integration
  • WhatsApp messages: kept while your account is active, deleted within 90 days of account closure
  • Google reviews and replies: kept while your account is active; if you delete a review locally we remove our copy, but the public review on Google remains until you remove it via Google Business Profile directly
  • Backups: retained for 30 days, then permanently deleted

5. International Data Transfers

LocalBIX is operated from India. By using the Service you understand that your data may be transferred to and processed in India, the United States, and the European Union (where our hosting and AI providers are located). We rely on Standard Contractual Clauses and equivalent safeguards for cross-border transfers.

6. Your Rights

You have the right to:

  • Access a copy of the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your account and all associated data
  • Export your data in a portable format (JSON)
  • Withdraw consent at any time (e.g. revoke OAuth for Meta or Google)
  • Object to processing for direct marketing or legitimate-interest purposes
  • Lodge a complaint with your local data-protection authority

To exercise any of these rights, email privacy@localbix.com. We respond within 30 days.

7. Security

We protect your data with:

  • TLS 1.2+ encryption for all data in transit
  • Encrypted storage of OAuth tokens (Laravel encryption with APP_KEY)
  • Bcrypt-hashed passwords (never stored in plaintext)
  • CSRF protection on all forms, rate limiting on auth endpoints
  • Database access restricted to application servers only (no direct external access)
  • Quarterly access-log review and incident response drills

No system is 100% secure. If we discover a breach affecting your data, we will notify you and the relevant authorities within 72 hours.

8. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.

9. Changes to This Policy

We may update this Privacy Policy as the Service evolves. The "Last updated" date at the top will always reflect the current version. For material changes we will notify you by email and/or in-app banner at least 14 days before they take effect.

10. Contact Us

LocalBIX
Email: privacy@localbix.com
Support: support@localbix.com
Data Protection Officer: dpo@localbix.com

See also: Terms of Service · Cookie Policy · GDPR · Refund Policy