Skip to main content
Effective date: 7 February 2026 | Last updated: 3 October 2026

Welcome to TFlow. We value your privacy and are committed to protecting your personal data in accordance with international best practices and the requirements of Meta/WhatsApp Business Platform.

1. Who we are

TFlow is a customer relationship management (CRM) platform using WhatsApp Business API, owned and operated by:

  • Legal name: Tarabot Tech for Communications and Information Technology
  • Address: Bouzheir Street, Al-Mashtal Road, Tripoli, Libya
  • Email: [email protected]
  • Phone: +218 91 456 7777

We act as the controller for account, billing and support data. Customer and conversation data entered by an organization or received through connected channels is processed on the organization's behalf and according to its instructions. The organization remains responsible for the lawfulness of collecting that data and informing the individuals concerned.

2. Information we collect

2.1 Information you provide directly

  • Account and profile information: Full name, username, email, phone number, company name, profile picture, role and permissions. Passwords are stored as secure hashes and are not displayed as readable text.
  • Customer relationship management (CRM) data: Customer, contact, lead, task, ticket, appointment, note, tag and activity history data, which may include date of birth, identity number and nationality when entered.
  • Addresses and business data: The address, country, city, street and location entered by the user or shared by the customer, as well as company information, commercial registration and tax number when entered.
  • Financial and banking data: Deal values, currencies, invoices, credit limits, bank name, account number and IBAN when entered in the workspace.
  • Conversations and files: Messages, internal notes, images, video, audio, documents and attachments, and call data and recordings when recording is enabled.
  • Integration data: Account and channel identifiers for WhatsApp, Facebook, Instagram and TikTok, phone numbers and conversation identifiers, together with the access tokens needed only for integrations enabled by the workspace administrator.
  • Account deletion request data: Workspace domain, username, email, WhatsApp number, request scope, reason, reference number, status and processing dates.

2.2 Information collected automatically

  • Device and app data: A server-issued installation or session identifier, a Firebase installation identifier and a push notification token (FCM) when notifications are enabled, together with the operating system, device type and app or browser version.
  • Usage and operational data: Login times, actions, API request logs and operational and security errors that reach our servers and are necessary to operate and support the service.
  • IP address: For security and fraud prevention
  • Website measurement: Cloudflare Web Analytics processes aggregated technical performance and visit metrics on the pages of tflow.ly. Meta processes technical data through Meta Pixel on the product pages and the trial creation page, as explained in section 11 together with the ways to stop it. Neither tool is present in the mobile app.

2.3 Device data the mobile app does not collect

  • Address book: The mobile app does not access the iPhone address book or copy contacts stored on the device. CRM contacts come from the workspace, connected channels or information the user enters in the service.
  • Device location: The mobile app does not request device location permission or collect GPS location in the background. CRM records may contain an address or location entered by a user or sent by a customer in a conversation; this is not tracking your device's location.
  • Advertising tracking: The mobile app does not use an advertising identifier, track users across other companies' apps or websites, or request App Tracking Transparency permission.

2.4 Optional mobile permissions

  • Microphone: Requested when recording a voice message or starting a call; the audio is used to carry out the action you initiated.
  • Photo library: Used only when you choose a profile picture or conversation attachment yourself. The current version does not use the iPhone camera or collect video from it.
  • Documents: The app opens a file picker when you choose a document to send or view; it does not scan device files in the background.
  • Notifications: The app requests notification permission so you can receive the message, task, ticket and call alerts you choose to enable.

3. How we use your information

  • Providing the service: Connecting your WhatsApp Business account and managing conversations
  • Improving the service: Analyzing usage patterns to develop the platform
  • Notifications: Linking your device to your account and delivering message, task, ticket and call notifications
  • Artificial intelligence: Processing content needed for features enabled by the workspace administrator, such as reply assistance, transcription or analysis, through the selected provider
  • Website measurement: Measuring page performance and aggregate visits, and measuring trial requests and campaign attribution through Meta Pixel, as described in section 11
  • Technical support: Helping you resolve technical issues
  • Security: Protecting your account and preventing fraud
Important note: We do not sell your personal data to any third party. The mobile app also does not use your data for advertising tracking across apps and websites. Section 11 explains website measurement, which is separate from the mobile app.

4. Legal basis for processing

  • Performance of a contract: To provide the services you requested
  • Consent: When you explicitly consent to specific processing
  • Legitimate interests: To improve our services and protect the platform's security
  • Legal obligation: To comply with laws and regulations

5. Sharing information

We do not sell or rent your personal information. We share only the minimum information needed to operate the feature you use. This may include:

  • Google Firebase Cloud Messaging: The notification token, account and workspace routing identifiers, destination-opening data, and the notification title and body. A message notification may include a message summary and CRM identifiers; a call notification may include the caller's or customer's name and phone number when available.
  • Cloudflare: Website delivery, protection and performance measurement through Web Analytics. This includes network requests passing through Cloudflare and the technical page-load metrics described in section 11; results are presented to us as aggregate statistics.
  • Meta and TikTok: Channel and recipient identifiers and the message or media content needed to send and receive conversations when those channels are connected. Meta may separately process the website measurement data described in section 11.
  • Telecommunications and voice infrastructure providers: Call numbers, identifiers, signaling and audio needed to make, record or analyze calls when the workspace administrator enables these features. ICE/STUN services may process IP addresses and network data to establish the connection.
  • OpenAI, Google Gemini or Moonshot Kimi: The request, context and text, visual or audio content needed to carry out the selected feature, depending on the feature and provider's capabilities, only when it is enabled and used. The workspace administrator determines the available provider.
  • Hosting and security providers: Technical data and copies needed to operate, protect and restore the infrastructure.
  • Legal requirements: Where required by law

These providers may process data in other countries under their terms and applicable processing agreements. We do not send them your account password, and we limit data to what the requested operation needs.

6. WhatsApp Business API integration

Important — regarding WhatsApp:

By using our platform, you also agree to WhatsApp Business Policy and Meta Privacy Policy.

7. Data security

  • Transport and credential protection: Using TLS/SSL in transit and storing passwords as hashes that cannot be displayed
  • Access control: Limited access for authorized staff only
  • Security and operational logs: Logging operational and security events needed to investigate faults and abuse attempts
  • Recovery copies: The hosting environment may create backups to support recovery and service continuity. Their duration and controls depend on the environment's configuration and operating contract.

8. Data retention

We retain account and CRM data while the account is active or the data is needed to provide the service. The following periods apply:

  • Verified deletion request: After matching the request details to the account and completing the required verification, we begin deletion or anonymization in active systems without undue delay and aim to complete processing within 30 days after verification is complete. We may request additional evidence or retain what the law requires. The reference number's status remains the primary means of tracking the request.
  • Account closure without a verified deletion request: Closure alone is not treated as a comprehensive deletion request. Data not requested for deletion is subject to the operational schedule, contract and applicable law; use the verified deletion form to initiate a specific, trackable request.
  • Call recordings: Audio files stored locally in the tenant environment are deleted after a default period of 90 days from the recording's creation. The environment operator may configure a different period, which must be reflected in the service agreement and legal requirements. Call metadata may remain for the CRM account's retention period after the audio file is deleted.
  • Device and notification tokens: We unlink the token from the account after successful logout or session revocation, and delete tokens confirmed to be invalid. An FCM token may remain locally on the device until Firebase replaces it or the app deletes it. Authentication sessions may expire automatically according to their validity period.
  • Deletion request record: We retain the request's identifying data during review. When deletion is complete, we immediately remove the domain, username, email, phone number, reason and WhatsApp verification evidence from the request record. For cancelled or rejected requests, this data is removed after 90 days. A minimal operational record without customer-identifying data is retained for up to two years, then automatically deleted by the system.

We may retain the minimum necessary billing, accounting, security, fraud prevention and request evidence records when required by law or in the event of a dispute or legal claim. We restrict their use to that purpose, then delete or anonymize them when the required period ends.

9. Your rights

  • Right of access: Request a copy of your personal data
  • Right to rectification: Correct inaccurate data
  • Right to erasure: Request deletion of your data
  • Right to portability: Obtain your data in a portable format

10. Data deletion

You can initiate deletion of your account and associated personal data, subject to the exceptions in section 8, through the account deletion form, verify your WhatsApp number, and immediately receive a reference number for tracking. Use [email protected] for questions and help with tracking a registered request.

The processing target of 30 days starts after verification and request matching are complete. The reference number shows the processing status and final outcome. We may contact you through the email or WhatsApp number recorded in the request if we need additional evidence or to confirm the outcome. Disabling the account alone is not a substitute for carrying out the deletion request.

11. Cookies and website measurement

We use an essential session cookie to operate the website, protect requests and maintain the session. The website also uses Cloudflare Web Analytics to measure performance and aggregate visits, and uses the Meta Pixel/Dataset source named Website - Active Pixel on the product pages and the trial creation page.

11.1 Cloudflare Web Analytics

The Cloudflare Web Analytics beacon is automatically injected into website pages at Cloudflare's edge. The beacon collects page-load timings and Core Web Vitals, the domain and page path without the query string, referrer, country, device type, browser, operating system and navigation type. We use aggregate results to detect slow pages and improve performance and reliability, based on our legitimate interest in operating and improving the website.

Basic technical data such as IP address and browser data reaches Cloudflare with network requests. According to Cloudflare's description of the service, Web Analytics does not use cookies or localStorage, does not fingerprint visitors using IP address or user agent, and does not track individuals across Cloudflare customers' websites. Beacon metrics are sent to /cdn-cgi/rum and processed by Cloudflare under its privacy policy. This processing is separate from Meta Pixel.

11.2 Meta Pixel and its purpose

Meta Pixel measures visits to TFlow pages and successful stages of trial requests, and helps us understand campaign attribution and effectiveness. We load the library fbevents.js automatically when these pages open, based on our legitimate interest in measuring and improving our marketing campaigns, and we send Meta only the events listed below. Stopping measurement does not affect using the website or creating a trial.

  • PageView: A page visit; our custom parameters are limited to two fixed values: product=tflow and site=tflow.ly.
  • Lead: Completion of the trial request verification stage.
  • CompleteRegistration: Completion of trial creation, with the fixed value content_name=tflow_trial.

11.3 Technical data Meta may process

When the pixel loads, Meta may receive the event name and time, page address and path, referrer, browser and device type, IP address, and Meta identifiers or cookies such as _fbp and _fbc if present. Some of this data may constitute personal data or online identifiers and may be processed by or transferred to Meta outside Libya. Its processing is also subject to the Meta Privacy Policy.

Our integration does not place names, phone numbers, email addresses, business names, domains, appId or passwords in Meta Pixel event parameters. Because the trial creation page contains these fields, the features Automatic website matching and Track events automatically without code must be disabled in Events Manager before enabling the pixel in any environment that uses real data. We do not rely solely on removing data from event parameters to prevent automatic matching, and we do not allow inferred events that could duplicate our defined events.

11.4 Controlling and disabling Meta measurement

We do not show a consent notice for Meta measurement. If you enable the Global Privacy Control (GPC) signal in your browser, we will not load the tool or send new events, and we also respect any refusal previously saved in your browser by an earlier version of the site. You can also block third-party cookies in your browser settings or adjust your ad preferences in your Meta account settings. Stopping measurement does not undo data processed before it.

12. Contact us

For any questions about this privacy policy:

  • Tarabot Tech for Communications and Information Technology
  • Bouzheir Street, Al-Mashtal Road, Tripoli, Libya
  • [email protected]