Privacy Policy
Last updated:
This Privacy Policy explains how Makers Innovations for Digital Manufacturing ("UniPulse", "we", "us") handles personal data when you visit unipulse.tech, create a UniPulse account, or interact with a business that uses UniPulse.
In short: we use the data you and your connected accounts give us only to provide UniPulse to you. We do not sell personal data, we do not use data from Meta platforms for advertising or profiling, and you can disconnect accounts or delete your data at any time — see Data Deletion.
1. Who we are and who this policy covers
UniPulse is operated by MAKERS INNOVATIONS FOR DIGITAL MANUFACTURING, a limited liability company registered in Egypt (Commercial Registration No. 282508), at 28 El Wasat Street, Helwan, Cairo, Egypt. Full details are on our Company Information page. Contact us about privacy at privacy@unipulse.tech.
This policy covers three groups of people:
- Customers and users — businesses that subscribe to UniPulse and the people who log in to their workspaces. For your account, workspace and billing data, UniPulse decides how and why the data is processed.
- Customers' contacts — people who message, comment on or buy from a business that uses UniPulse. That business decides why it collects your data; UniPulse processes it on the business's behalf and according to its instructions. Questions about how a business uses your data should go to that business first (see section 11).
- Website visitors — people browsing unipulse.tech.
2. Data we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Name, email address, phone number (if you sign up with one), password (stored only as a bcrypt hash), profile picture, time zone, interface preferences, and the onboarding answers you give (industry, role, team size, how you heard about us). | You, or Google/Microsoft if you sign in with them (name and email, and for Google your profile picture). |
| Workspace | Workspace name and settings, members and their roles, teams, invitations (invitee email). | You and your teammates. |
| Connected accounts | For each Facebook Page, Instagram professional account, WhatsApp Business number or TikTok account you connect: its platform ID, name, username and picture, the access tokens the platform issues (encrypted), and the ID of the Facebook user who authorised the connection. | The platform, after you authorise the connection. |
| Content | Posts, captions, hashtags, images and videos you create, upload or schedule; publishing results. | You. |
| Messages and comments | Messages and comments your connected accounts receive and send: text, attachments (copied to our storage so your inbox can display them), the sender's platform-specific ID, name and profile picture, and for WhatsApp the sender's phone number. Notes, tags and assignments your team adds. | Meta platforms, via webhooks and APIs, for accounts you connected. |
| Analytics | Engagement metrics for your own posts and accounts (reach, likes, comments, shares, saves) as reported by the platform. | The platforms' insights APIs. |
| Website visitor events | If your workspace installs the UniPulse tracking SDK on its own website: page and conversion events, a browser identifier, ad click identifiers (fbclid, gclid, ttclid), IP address and user agent, and email, phone and name only in SHA-256-hashed form. | Your website visitors' browsers, via the SDK your workspace installs. |
| Contacts and commerce | Contact profiles your workspace builds (name, email, phone, social handles, tags, interaction history); customers, orders and products from stores you connect (Shopify, WooCommerce, EasyOrders, Odoo, OpenCart); storefront visitors and orders if you use UniPulse storefronts. | Your conversations, your connected stores, and your storefront. |
| AI | The prompts sent to AI providers and the generated output, AI chat history, AI-suggested replies and message classifications (intent, sentiment). | Generated when you or your workspace's automations use AI features. |
| Billing | Plan, subscription status and payment history. For saved cards we keep only the brand, the last four digits (encrypted) and the expiry date. Full card numbers are entered directly with our payment processors and never reach our servers. | You and our payment processors. |
| Technical | IP address, browser user agent, request logs, and security audit records (for example: who connected or disconnected an account, and when). | Your browser and our servers. |
3. How we use data
| Purpose | Data used | Basis |
|---|---|---|
| Provide the service: log you in, run your workspace, publish your posts, show your inbox and analytics | Account, workspace, connected accounts, content, messages, analytics, contacts and commerce | Our contract with you |
| AI features you or your workspace turn on: drafting content, suggesting or sending replies, classifying messages, summarising conversations | Content and messages, as described in section 5 | Our contract with you; your workspace's configuration |
| Billing | Account, workspace, billing | Our contract with you; legal obligations |
| Security and abuse prevention: rate limiting and audit records | Technical, account | Our legitimate interest in keeping UniPulse and its users safe |
| Service messages: verification codes, security alerts, notifications you configure | Account | Our contract with you |
| Support | Whatever you share with us and what we need to look into the issue | Our contract with you |
| Legal compliance | As required | Legal obligations |
We do not sell personal data. We do not use the data in your workspace — including anything received from Meta platforms — to advertise to you or anyone else, to build profiles for third parties, or to make eligibility decisions (credit, housing, employment, insurance) about anyone. The one advertising-related flow is one your workspace sets up itself: if it connects its own Meta, Google or TikTok ad account under Tracking, UniPulse sends that account conversion events (for example a purchase from its store) so the workspace can measure its own campaigns — see section 6.
4. Data from Facebook, Instagram, Messenger and WhatsApp
UniPulse connects to Meta platforms only when a workspace Owner or Admin chooses to connect an account and approves the requested permissions in Meta's own authorization dialog (or, for WhatsApp, provides credentials from their own WhatsApp Business Account). We use Meta Platform Data only to provide the features below to that workspace, only on its behalf, and we keep each workspace's data separate from every other workspace.
APIs and permissions we use
| Permission | Why UniPulse needs it |
|---|---|
| pages_show_list, business_management | List the Facebook Pages (including Pages managed through a business portfolio) you can connect, so you can choose which one UniPulse manages. |
| pages_manage_posts | Publish the posts you create or schedule in UniPulse to your Page. |
| pages_read_engagement, pages_read_user_content | Read your Page's posts, comments and engagement so they appear in your inbox and analytics. |
| pages_manage_engagement | Reply to and like comments on your Page from the UniPulse inbox. |
| pages_messaging | Receive and answer Messenger conversations with your Page in the UniPulse inbox. |
| pages_manage_metadata | Subscribe your Page to webhooks so new messages and comments reach your inbox in real time. |
| instagram_basic | Identify the Instagram professional account linked to your Page and show its profile and media. |
| instagram_content_publish | Publish posts you create in UniPulse to your Instagram account. |
| instagram_manage_comments | Show and reply to comments on your Instagram posts. |
| instagram_manage_messages | Receive and answer Instagram Direct messages in the UniPulse inbox. |
| instagram_manage_insights | Show performance metrics for your Instagram posts. |
| WhatsApp Business Platform (Cloud API) | Send and receive messages for the WhatsApp Business number you connect, and manage its message templates. |
What we retrieve and store
- The connected Page, Instagram account or WhatsApp number: ID, name, username, picture.
- Access tokens Meta issues to UniPulse for that connection — encrypted at rest with AES-256-GCM and used only by our servers. They are never shown in the app or sent to your browser.
- Messages, comments and their attachments, plus the sender's platform-scoped ID, name and picture (and phone number for WhatsApp), so your team can read and answer them.
- Posts and their engagement metrics for your own accounts.
How we use it
To display your inbox and analytics, publish what you schedule, send the replies you or your configured automations write, and run the AI features your workspace enables (see section 5). We do not use Meta Platform Data for advertising, for profiling people across businesses, or for any purpose other than providing UniPulse to the workspace that connected the account. We share it only with the service providers in section 6 that help us run UniPulse.
When you disconnect
Disconnecting an account in UniPulse (Settings → Connected Accounts → Manage Accounts, then Disconnect) stops webhook delivery for that Page or WhatsApp Business Account where no other connection still uses it, withdraws UniPulse's authorization with Meta where possible, and deletes the stored access tokens immediately. Messages, comments and post history already in the workspace stay available to your team until the workspace deletes them or the workspace itself is deleted.
When Meta tells us you removed UniPulse
If you remove UniPulse in your Facebook settings, Meta notifies us and we disconnect every Page and Instagram connection you authorised, deleting their tokens. If you also send a data deletion request from Facebook, we additionally remove the remaining identifying details of those connections and give you a confirmation code and a status page. See Data Deletion.
5. AI processing
UniPulse's AI features send data to third-party AI providers to generate a result, and only when a feature that needs it is used:
| Feature | What is sent |
|---|---|
| Content generation, captions, hashtags, repurposing, AI chat | Your prompt and the workspace context it needs (for example your brand voice settings and sample posts). |
| Inbox AI — reply suggestions, automatic replies, intent and sentiment classification, conversation summaries, follow-up messages | The incoming message, recent messages in that conversation, and relevant contact details such as the contact's name and order history with the business. Images, voice messages and videos sent in a conversation may be sent for analysis (for example to recognise a payment receipt or understand a voice note). |
| Competitor and trend insights | Public information about the accounts or topics you ask about. |
Providers. UniPulse uses Google (Gemini) and OpenAI by default. A workspace Owner or Admin can instead connect the workspace's own account with another supported AI provider; that provider then receives the workspace's AI requests under the workspace's own agreement with it.
We do not use your content, your contacts' messages or any Meta Platform Data to train AI models, and we do not ask AI providers to do so. Providers process requests under their API terms, which govern how long they keep request data. Inbox automation is controlled by each workspace: a business decides whether AI may reply to its customers automatically.
We keep a log of AI requests and responses for 90 days to measure usage against plan limits and to investigate problems, then delete it automatically.
7. Where data is processed
UniPulse's servers, database and stored media are hosted in France. The company that operates UniPulse is in Egypt, and our team may access data from Egypt to provide support and run the service. AI providers, payment processors and the platforms you connect may process data in the United States and other countries under their own terms and safeguards.
8. How long we keep data
| Data | Retention |
|---|---|
| Account | Until you delete your account. Deletion removes your name, email, phone, password and profile details; see Data Deletion. |
| Workspace data (content, messages, contacts, analytics, commerce data) | Until the workspace deletes it or the workspace is deleted. |
| Uploaded and received media files (post images and videos, inbox attachments, profile pictures) | Deleting a file in the media library removes it. Files are not yet removed automatically when a workspace or account is deleted; they stay at unguessable addresses until we purge them — ask privacy@unipulse.tech and we will. |
| Access tokens for connected accounts | Until you disconnect the account, Meta notifies us that you removed UniPulse, or the workspace or your account is deleted — then deleted immediately. |
| AI request log | 90 days. |
| Raw payloads of payment and store webhooks | 30 days (the processed record stays with the workspace). |
| Search usage statistics (no search text) | 90 days. |
| Server request logs | Rotated automatically on the server; older entries are overwritten as new ones are written. |
| Database backups | Encrypted backups are kept on our hosting server for 30 days and then deleted. Data you delete disappears from backups as they expire. |
| Security audit records | Kept to investigate security incidents and disputes. They may include the email address of the person who performed an action. |
9. Security
We protect data with encryption in transit (HTTPS), encryption of platform access tokens and app secrets at rest, hashed passwords, workspace isolation and role-based access. (Webhook secrets for connected stores are an exception and are not yet encrypted.) Our Security & Trust page describes these measures and how to report a vulnerability. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authorities as the law requires.
10. Your choices and rights
- Access and correction — view and edit your profile in Settings → Profile. Ask us for a copy of your personal data at privacy@unipulse.tech.
- Deletion — delete your account yourself in Settings → Profile → Delete account, delete a workspace in Settings → Workspace, or disconnect any connected account at any time. See Data Deletion.
- Withdraw platform permissions — disconnect in UniPulse, or remove UniPulse from your Facebook, Instagram or TikTok settings.
- Objection and restriction — write to privacy@unipulse.tech.
Depending on where you live, data protection law may give you further rights, including the right to complain to a supervisory authority. We verify requests by asking you to write from your account email address or to confirm your identity in another way, and we aim to respond within 30 days.
11. If you contacted a business that uses UniPulse
If you messaged or commented on a business's Facebook Page, Instagram account or WhatsApp number, and that business uses UniPulse, your messages, name, profile picture and (for WhatsApp) phone number are stored in that business's UniPulse workspace so it can reply to you. The business may use AI features to help answer you. The business controls this data: ask it to access, correct or delete it. If you cannot reach the business, write to privacy@unipulse.tech and we will help.
12. Children
UniPulse is a business tool and is not directed to children. You must be at least 18 years old to create an account. If you believe a child has given us personal data, contact us and we will delete it.
14. Changes to this policy
We will update this page when our practices change and show the date at the top. If a change materially affects how we use your data, we will tell account holders by email or in the app before it takes effect.
15. Contact
MAKERS INNOVATIONS FOR DIGITAL MANUFACTURING, 28 El Wasat Street, Helwan, Cairo, Egypt. Email privacy@unipulse.tech.