Policy
Privacy
What MiniManager stores, why it stores it, and how one business's data is kept apart from another's.
Last updated: 16 August 2026
What this covers
MiniManager is a business platform. Two different groups of people are involved: the businesses who use MiniManager, and the customers who message those businesses on WhatsApp, Instagram or Facebook.
This page describes what MiniManager does with both kinds of data.
Data about your business
When you register we store the account and business details you provide, and the configuration you create while using the platform.
- Account details: email address, password (stored hashed, never in readable form), and role.
- Business profile: business name, workspace address, industry, address, timezone and contact number.
- Agent configuration: your knowledge base, catalog, FAQs, tone settings and handoff rules.
- Billing records: credit purchases, usage history and invoices.
Data about your customers
Conversations that reach your agent are stored so you can read them, hand them to a person, and keep a record of the orders and appointments they produced.
This data belongs to your business. MiniManager processes it in order to run the service for you.
- Conversation threads and messages across connected channels.
- Customer contact details supplied through those conversations.
- Orders and appointments created from a conversation, and their status history.
Separation between businesses
Every business operates in its own tenant with its own workspace address. Isolation is enforced at the database query layer rather than only in the interface, and no query is permitted to cross from one tenant into another.
Connector credentials
When you connect an external system such as Shopify or ERPNext, the credentials you supply are stored encrypted and are never exposed to the AI layer or returned to the browser.
Credentials can be rotated without rebuilding the connector, and every use of a credential is written to an audit log that account owners can review.
Third parties involved
Running the service means data passes through providers we depend on. These include Meta, for the messaging channels themselves, and the AI provider that generates agent responses.
Where you configure a connector, data also passes to the external system you have pointed it at — that system is under your control, not ours.
- Meta Platforms — WhatsApp Business Platform, Instagram and Messenger message delivery.
- AI providers — Anthropic, Google or DeepSeek, depending on the model configured for the platform, used to generate agent replies.
- Cloud hosting and database providers used to run and store the service.
- Payment providers, for credit purchases and invoices.
WhatsApp, Instagram and Messenger data
When you connect a channel, Meta issues us an access token scoped to your business. We store that token encrypted and use it only to send and receive messages on your behalf, to subscribe to the webhooks your account needs, and to read the display name and number of the account you connected.
We do not use your Meta access token for advertising, we do not share it with other businesses on the platform, and we do not use the content of your customer conversations to train AI models.
Our use of the WhatsApp Business Platform is subject to Meta's own terms and policies, which apply to you as the business owner of the connected account.
How long we keep data
We keep data for as long as your account is active, and afterwards only where we are required to.
- Account and business records: for the life of the account, then deleted within 90 days of closure.
- Conversations, orders and appointments: for the life of the account, unless you delete them earlier from within the platform.
- Channel and connector credentials: deleted immediately when you disconnect the channel or connector.
- Billing and invoice records: retained for the period required by Indian tax law, even after account closure.
How we protect data
Access tokens and connector credentials are encrypted at rest using AES-256-GCM, and are never returned to the browser or exposed to the AI layer — the interface only ever shows a masked hint.
Passwords are stored using a one-way hash and cannot be read back by us or by anyone else. Traffic between your browser and the platform is encrypted in transit.
No system is perfectly secure. If a breach affects your data we will notify you and the relevant authority as required by law.
Deleting your data
You can disconnect any channel or connector at any time from within the platform, which deletes the stored credential immediately.
To delete your account and the data associated with it, follow the instructions on our data deletion page, or write to us from the email address on the account. We will confirm once the deletion is complete.
Cookies and similar technologies
We use cookies and browser storage only to keep you signed in and to remember interface preferences such as your theme. We do not use advertising or cross-site tracking cookies.
Children
MiniManager is a tool for businesses and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us through a conversation, contact us and we will remove it.
Your rights
You can access, correct, export or delete your business data. Where the data concerns your own customers, you are the party responsible for answering their requests, and we will assist you in doing so.
If you are unhappy with how a request was handled, you may escalate it to the contact below, and you retain the right to complain to the relevant data protection authority.
Changes to this policy
If we change how data is handled we will update this page and change the date at the top. Where a change is significant we will tell account owners by email before it takes effect.
Contacting us about privacy
Privacy questions, data requests and complaints can be sent to [email protected], and we will respond within 30 days.
MiniManager is operated by Nano Cloud Technology, India.