Privacy Policy

Your conversations deserve clear boundaries. This policy explains the information handled by mohamedelashram.com, IGCDM and WAAPI, why it is used, and how to request access, correction or deletion.

العربية · Contact about privacy · Request data deletion

1. Who this policy covers

The website and tools are operated by Mohamed Salah Elashram, based in Jeddah, Saudi Arabia. Privacy enquiries can be sent to Hello@mohamedElashram.com. IGCDM is the conversation and automation tool at igcdm.mohamedelashram.com; WAAPI is the WhatsApp operations tool at waapi.mohamedelashram.com.

This notice applies to website visitors, tool account holders, and people whose comments, messages or contact details are processed through a connected business channel. A business using a tool determines the purposes of its customer communications and is responsible for its own privacy notice, permissions and marketing consent. We process those communications on its instructions and manage service-account, security and support information for our own operational purposes. Connecting an account does not give us access to every asset in your business portfolio.

2. Information we handle

Website: information you submit in contact or resource-request forms, such as name, email, phone, company and enquiry; browser and device information, visited pages, referral source and interaction events; and hosting/security logs, which may include IP addresses.

Tool accounts: signup email, workspace name, password hash where password login is used, approval status, usage counters, session information and support correspondence. Please do not send us passwords or access tokens in an email or support message.

IGCDM: connected Instagram or Facebook Page identifiers, account names, authorization tokens and permission/connection status; selected post identifiers and media available through the authorized API; comments, usernames or provider-scoped participant identifiers; message text, replies, conversation state, automation rules, delivery outcomes and event identifiers used to prevent duplicate processing. When enabled, website chat and a connected Telegram bot also process conversation text, participant/session identifiers and delivery state.

WAAPI: authorized business/account/phone identifiers and names, connection credentials, templates and campaign parameters; imported contact names, phone numbers and language; consent source and date, opt-out/suppression records; incoming message text, outgoing campaign records, provider message identifiers and delivery/read/failure events.

A channel is processed only when its integration is enabled and the relevant business or account holder has provided access. A planned channel or an unapproved permission is not treated as an active connection. We do not request a customer's Facebook, Instagram or WhatsApp password; authorization takes place with the provider.

3. Why we use this information

We use information to respond to enquiries, operate accounts and approval controls, connect selected channels, run configured comment and message automations, provide conversation history, send eligible replies or consent-based WhatsApp campaigns, track outcomes, honor opt-outs, troubleshoot failures and protect the service against abuse.

Where applicable, processing relies on consent, steps requested by you or performance of a service agreement, legal obligations, or legitimate interests in secure service operation subject to applicable safeguards. The business sending a marketing message must establish the required permission; installing an app or connecting a channel is not consent for every future marketing campaign. Personal information is not sold.

4. Meta authorization and your choices

When official sign-in is available, Meta asks you to authorize the relevant app and choose the assets to connect. Depending on the product and approved permissions, access supports profile/media lookup, comment management, eligible Instagram or Facebook Messenger replies, or WhatsApp account management, templates and messaging. The tool uses the access granted for its selected functions, not as unrestricted access to your personal Facebook account.

You can disconnect supported channels in the tool or remove the app in Meta's Apps and Websites or Business Integrations settings. Revoking permission prevents further authorized access but does not automatically erase records already stored by the tool or messages already sent. Use the deletion instructions below for those records. Meta independently handles information under its own policies.

5. Who receives information

The connected business and people authorized for its account can view its customer-conversation and delivery records. Service operators may access information for approvals, support, security and maintenance. WAAPI currently operates as an owner-managed pilot; this policy does not claim that a shared multi-client WAAPI workspace is available.

IGCDM and WAAPI use Cloudflare infrastructure for hosting, databases and background processing. The main website uses Lovable hosting, Supabase-backed forms/content and Google Analytics. Meta processes information required by its Instagram, Facebook Messenger and WhatsApp APIs. Telegram processes messages when a business enables that channel. Providers receive information needed for the relevant function and apply their own terms and privacy policies.

Information may also be disclosed when necessary to comply with a lawful request, protect users or investigate abuse. Infrastructure and connected providers may process data outside your country, including outside Saudi Arabia. We do not represent that all information remains in Saudi Arabia; applicable transfer requirements must be considered for the service and business concerned.

6. Security and browser storage

The tools encrypt stored channel credentials and do not return saved access tokens in dashboard responses. Password-based IGCDM accounts use password hashes, and authenticated sessions limit account access. These measures reduce risk but cannot guarantee that every transmission or system is completely secure.

Essential session cookies or browser storage support sign-in and security. IGCDM website chat stores a random session token and an unsent draft in the visitor's browser so the conversation can continue after a reload. The main website uses Google Analytics to measure page views and interactions, which may involve analytics cookies or identifiers. This notice does not itself provide a cookie-consent control; browser settings can restrict cookies and storage, and Google provides an Analytics opt-out tool. Disabling storage can affect login or chat continuity.

7. Retention

Account, workspace, conversation, contact, consent and delivery records are kept while needed to operate the account, maintain message deduplication, honor opt-outs, investigate problems or meet applicable obligations. Current message and campaign records are not subject to a universal automatic 90-day deletion rule; do not assume they disappear when a campaign ends.

IGCDM schedules webhook diagnostic records for removal after 30 days and periodically removes expired sessions and recovery links. Other service records remain until deleted through supported account controls or an approved request, subject to justified legal/security retention. Backup copies may remain during the infrastructure provider's recovery-retention period and are not necessarily removed immediately from every backup. You can ask us about the records and retention relevant to your account.

8. Request deletion or disconnect a tool

Email Hello@mohamedElashram.com with the subject “IGCDM data deletion”, “WAAPI data deletion” or “Website privacy request”. Include the account email, workspace, connected account username or WhatsApp business number needed to locate your records. If you are a message recipient, identify the business and channel involved; you may also contact that business directly. Never include your password, authorization token or sensitive message history unnecessarily.

We may verify control of the account or your identity before acting. We review the request, remove the relevant stored data where required, and confirm completion or explain any lawful exception or remaining backup retention. Removing tool records cannot delete messages already delivered to another person's account or erase information independently held by Meta, Telegram or the connected business.

IGCDM customer workspace owners can use “Delete my workspace and account” in the dashboard, confirm with their current password and type DELETE. This removes the live customer account and associated workspace records. WAAPI pilot deletion requests are handled through the privacy email above. To stop future access, also disconnect the channel and revoke the app with the provider. For WhatsApp campaign opt-out, reply STOP to the connected business or contact it directly.

9. Your privacy rights

Depending on the law that applies, you may request information about processing, access or a copy of your data, correction, deletion, restriction or objection, and withdrawal of consent where processing relies on consent. Withdrawal does not affect processing already lawfully carried out. We handle requests within applicable legal timeframes and may need information to verify the request.

Contact Hello@mohamedElashram.com to exercise these rights or raise a concern. You may also complain to the relevant data-protection authority, including the Saudi Data & AI Authority (SDAIA) where Saudi personal-data law applies. This policy is not a certification of GDPR, CCPA or Saudi PDPL compliance.

10. Changes and contact

We update this policy when service practices or relevant requirements change and display the new effective date here. Where required, material changes will be communicated through an appropriate account or contact channel. Questions about this policy or the use of IGCDM and WAAPI can be sent to Hello@mohamedElashram.com.

Hello@mohamedElashram.com