AutoMashi is committed to protecting subscriber and customer data. We do not sell or rent your data to advertisers or data brokers. We process data to provide platform services, run automations, deliver technical support, and protect the service, as described in this policy.
1. Introduction & Scope of Policy
This Privacy Policy outlines how AutoMashi (automashi.com), its software, cloud APIs, hosted storefronts, and affiliated services collect, process, store, and safeguard personal and conversational data. This policy applies to all registered subscribers, merchants, creators, and agencies, as well as end-users who interact with automated Instagram, WhatsApp, TikTok, and YouTube workflows, or hosted storefronts.
2. Categories of Data Collected
We process strictly the minimum necessary data to power your automation workflows and hosted stores:
- Account Credentials: Full name, verified email, store name, encrypted authentication credentials.
- Channel Integration Data: Instagram Professional Account ID, WhatsApp Business Account ID, TikTok Open ID, YouTube Channel ID, scoped OAuth access tokens issued directly by external platforms.
- Conversational & Engagement Logs: Comment text, DM payloads, incoming/outgoing timestamps, interaction IDs needed for trigger execution and dashboard reporting.
- Information you add to messages: Product links or prices you enter manually in the flows you create.
3. Purpose of Data Processing
Data is processed strictly for the following operational purposes:
- Sending the replies you configure to comments and direct messages, subject to connected channel permissions.
- Running customer message reply flows through the official WhatsApp connection.
- Scheduling and publishing short-form video content (YouTube Shorts and TikTok) per user direction.
- Aggregating real-time conversion, ROI, and engagement analytics within your private dashboard.
- Ensuring system resilience, uptime monitoring, and anti-abuse safeguards.
- Technical Support & Diagnostics: An authorized administrator may access channel, automation, post, and analytics data needed to investigate a documented support request or operational incident through a read-only support session lasting at most 30 minutes. Edits, sending, exports, conversations, contacts, and sensitive sections are unavailable in this mode. All support sessions are logged.
4. Data Security & Encryption Standards
We maintain industry-leading technical and organizational safeguards:
- In-Transit Encryption: HTTPS and TLS 1.3 protect all network traffic to and from the service.
- At-Rest Encryption: Integration access tokens across all platforms are encrypted using AES-256-GCM before storage, with encryption keys isolated in secure server environments.
- Multi-Tenant Isolation: Logical database segregation and Row Level Security (RLS) prevent cross-tenant data exposure across merchant workspaces.
- Fail-Closed Role Privileges: Strict least-privilege role boundaries governing background worker processes and admin support access.
5. Meta Data Deletion Callback & User Erasure Rights
In compliance with Meta Platform Terms and global privacy frameworks:
- Users may disconnect their Meta accounts or submit a comprehensive data deletion request at any time.
- Data Deletion Instructions: A dedicated portal to check deletion status and submit requests is publicly available at automashi.com/data-deletion.
- Data Erasure Request: You can submit a formal data deletion request by emailing our team at privacy@automashi.com with the subject "Data Erasure Request". Full erasure is executed within 24 hours.
- Automated Meta Deletion Callback: AutoMashi exposes an automated callback endpoint at
https://automashi.com/api/auth/data-deletionproviding immediate JSON verification and tracking codes. - All tokens, conversation logs, and cached records are permanently erased within 24 hours of request submission.
6. International Regulatory Compliance (KVKK, GDPR, PDPL)
AutoMashi operates in full alignment with premier global and regional data protection regimes:
6.1 Turkish Personal Data Protection Law (KVKK Law No. 6698):
We strictly enforce data processing principles pursuant to KVKK, specifically Articles 10 and 11:
- Article 10 (Obligation to Inform / Aydınlatma Yükümlülüğü): We transparently notify data subjects regarding the identity of the data controller, legal purposes of processing, transfer recipients, and collection methods.
- Article 11 (Rights of the Data Subject / İlgili Kişinin Hakları): Data subjects have the right to learn whether data is processed, request information, rectify inaccuracies, request erasure/destruction, object to automated profiling decisions, and lodge complaints before the Turkish Personal Data Protection Board (KVKK Kurumu).
6.2 European Union General Data Protection Regulation (GDPR - EU 2016/679):
- Lawful Bases for Processing (Article 6): Data processing is founded upon contractual necessity (Art. 6(1)(b)) to deliver platform features, legitimate business interests (Art. 6(1)(f)) for fraud prevention and security, legal obligations (Art. 6(1)(c)), or explicit user consent (Art. 6(1)(a)).
- Data Controller vs. Data Processor Distinction (Article 28): AutoMashi acts strictly as a Data Processor on behalf of subscribers (who act as Data Controllers) with respect to end-consumer chat logs, orders, and interaction data; AutoMashi acts as a Data Controller solely regarding direct subscriber account, billing, and credential information.
- Cross-Border Transfers & Standard Contractual Clauses (SCCs): Any transfer of European personal data outside the EEA is protected by European Commission-approved Standard Contractual Clauses (SCCs) ensuring an equivalent level of security.
6.3 Saudi Personal Data Protection Law (PDPL):
We comply with Royal Decree No. (M/19) and its executive regulations in the Kingdom of Saudi Arabia:
- Article 4 Compliance: Processing is governed by legality, purpose limitation, transparency, and data minimization.
- Statutory Roles: AutoMashi acts as a Data Processor for Saudi merchants regarding customer conversational workflows, and as a Data Controller for merchant subscriptions.
- Data Subject Rights & Regulatory Recourse: Users enjoy rights of notification, access, rectification, and destruction. Users may submit inquiries or file regulatory complaints directly with the Saudi Data & AI Authority (SDAIA) via its official portal (sdaia.gov.sa).
7. Google API & YouTube API Services User Data Policy & Limited Use
AutoMashi is committed to complete transparency, user privacy, and data security when integrating with Google and YouTube API services (including Google Sheets, Google Drive, and YouTube Shorts). Our access, usage, storage, and transfer of Google user data strictly comply with Google developer policies and the following rigorous safeguards:
AutoMashi utilizes YouTube API Services to enable subscribers and creators to connect their channels, schedule, upload, and manage short-form video clips (YouTube Shorts). By using these integrated features, you expressly agree and acknowledge that:
- You are agreeing to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms).
- Your data is processed in accordance with the Google Privacy Policy (https://policies.google.com/privacy).
- Revocation and Permissions Management: In addition to disconnecting via the AutoMashi dashboard, users can review and revoke AutoMashi's access to their Google and YouTube data at any time via the Google Security Settings page (https://security.google.com/settings/security/permissions).
7.1 Google User Data Access:
We strictly access the minimum relevant Google user data necessary to provide user-facing platform features:
- Identity and Profile Information: User email address, display name, and avatar URL via
openid,userinfo.email, anduserinfo.profilescopes to authenticate the user and display the connected Google account identity in the dashboard. - Google Drive Metadata: Spreadsheet file names and IDs via
drive.readonlyscope to allow users to search and select an existing destination spreadsheet from a dropdown inside their dashboard. - Google Sheets Structure and Content: Spreadsheet sheet names, column headers, and cell values via
spreadsheetsscope to append captured customer leads, order transactions, and form submissions. - YouTube Channel & Shorts Data: Channel identification details (Channel ID, title, and thumbnail URL) via
youtube.uploadandyoutube.force-sslscopes to allow creators and merchants to connect their YouTube channel, schedule, upload, and manage short-form video content (YouTube Shorts).
7.2 Google User Data Use:
Google user data is utilized exclusively to provide the following user-directed operational features:
- Authenticating user sessions securely via Google Single Sign-On (SSO).
- Automatically formatting and appending captured customer leads and inquiries generated from connected social automation channels and landing pages into the user's designated Google Sheet.
- Formatting spreadsheet header rows to ensure structured and readable lead records.
- Enabling creators and merchants to schedule, upload, and publish short-form video clips (YouTube Shorts) directly to their connected YouTube channel at their scheduled publish times according to their selected privacy settings.
7.3 Sharing, Transfer, and Disclosure of Google User Data:
AutoMashi explicitly discloses with whom Google user data is shared, transferred, or disclosed:
- Parties With Whom We DO NOT Share Data: We do not share, transfer, or disclose Google user data to any third parties, advertisers, data brokers, or marketing platforms. We do not sell, rent, lease, or monetize Google user data under any circumstances.
- Service Providers & APIs: Data and requests are securely transmitted between our servers and Google's official API endpoints, and hosted on secure cloud databases (Supabase and Vercel) under strict data protection agreements and enterprise-grade encryption (AES-256-GCM at rest, TLS 1.3 in transit), with zero authorization to use data for independent purposes.
- Legal Compliance: We may disclose the minimum necessary Google user data strictly if required to comply with applicable laws, subpoenas, or enforceable court orders, in accordance with the recognized limited exceptions under Google's User Data Policy.
7.4 Data Protection, Storage & Encryption:
All Google OAuth access tokens and refresh tokens are encrypted at rest using industry-standard authenticated AES-256-GCM encryption before database persistence. All communications are secured via HTTPS / TLS 1.3, with strict multi-tenant Row Level Security (RLS) ensuring that no user can access another user's integration.
7.5 Data Retention, Disconnection & Deletion:
- Immediate Disconnection: Users can disconnect their Google account at any time via Dashboard > Settings > Integrations > Disconnect, which immediately and permanently purges all stored OAuth tokens from our database.
- Comprehensive Deletion: Users may request complete deletion of their account and all associated data by emailing privacy@automashi.com or submitting a request via automashi.com/data-deletion. All requests are processed within 24 hours.
7.6 Limited Use Compliance & AI/ML Model Training Prohibition:
AutoMashi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Prohibited AI/ML Model Training:
AutoMashi explicitly affirms that raw, derived, or aggregated user data received from Google Workspace APIs (including Google Sheets and Google Drive) or YouTube is NOT used to develop, improve, or train generalized Artificial Intelligence (AI) or Machine Learning (ML) models. Furthermore, no Google user data is transferred to third-party AI/ML services for model training purposes.
7.7 Prohibited Use Cases Compliance:
- No sending of unsolicited commercial emails or communications (cold emailing or spam).
- No email warming services or simulated email engagement to circumvent anti-spam filters.
- Full compliance with YouTube Developer Policies and Terms of Service: no artificial engagement manipulation, no buying/selling views or subscriptions, and no rewarding users for channel interactions.
7.8 TikTok API User Data & Developer Policy Compliance:
When utilizing TikTok integration features within AutoMashi:
- Data Accessed: We access strictly the minimum user data via official TikTok OAuth endpoints (Open ID, display name, avatar) and video upload endpoints to schedule and publish user-directed short-form videos.
- Encryption at Rest & Transit: TikTok OAuth access tokens are encrypted at rest using AES-256-GCM authenticated encryption, and all network transmissions are protected via TLS 1.3.
- Zero AI Model Training: User data received through TikTok APIs is never used to develop, train, or improve AI/ML models, and is never transferred to third parties for model training purposes.
- Revocation & Deletion: Users can revoke access anytime via their TikTok App (Settings & Privacy > Security > Manage App Permissions) or via AutoMashi dashboard settings, and may request comprehensive data deletion via privacy@automashi.com or our Data Deletion Portal.
8. Data Retention & Erasure Schedule
AutoMashi retains personal data strictly for the period necessary to deliver services and comply with statutory obligations:
| Data Category | Retention Period | Purpose & Action Upon Expiry |
|---|---|---|
| Primary Account Data | Active subscription + up to 30 days post-closure | Account administration and service continuity; permanently purged after 30 days or upon formal erasure request. |
| Conversation & Interaction Logs | Rolling 30 to 90 days | Workflow triggers and analytics reporting; systematically erased or anonymized on a rolling schedule. |
| OAuth Integration Credentials | Immediate deletion upon disconnection | Purged instantly from active database tables when channel is unlinked or account deleted. |
| Financial & Billing Invoices | 5 to 10 years | Mandatory compliance with corporate tax, commercial accounting, and anti-fraud regulations. |
9. Children's Privacy Protection
AutoMashi is strictly a business-to-business and creator SaaS platform intended solely for individuals aged 18 years and older. Our services and hosted storefronts are not directed to minors under 18, and we do not knowingly solicit, collect, or maintain personal information from children or minors under the age of 18.
In compliance with the Children's Online Privacy Protection Act (COPPA), GDPR Article 8, and the Saudi PDPL: if we become aware that personal data of an individual under 18 has been collected without verified parental consent, we will take immediate steps to permanently delete that information from our servers and terminate the associated account. Parents or guardians may contact us immediately at: privacy@automashi.com.
10. Essential Session Cookies
We deploy only strictly necessary, encrypted session cookies required for authentication and security. We do not utilize third-party advertising tracking cookies.
11. Data Protection Officer (DPO) Contact & Complaints
For privacy inquiries, audit requests, or to exercise your statutory data subject rights, contact our Data Protection Officer at: privacy@automashi.com