Legal

Privacy Policy

Last updated: 2026-08-15

BotNira ("we", "our", "us", operated by The Digi Sparrow) provides an AI-powered receptionist platform that lets businesses ("Vendors") answer customer inquiries and book appointments across multiple channels including web chat, WhatsApp, SMS and email, and integrates with third-party tools such as Google Calendar. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

1.Who is covered by this policy

  • Vendors — businesses who sign up for a BotNira workspace.
  • End users — individuals who chat, call, message or email a Vendor whose front desk runs on BotNira.

Vendors are the Data Controllers of their End users' conversations. BotNira acts as the Data Processor on their behalf.

2.Information we collect

From Vendors at signup and while using the service

  • Full name, business name, work email, hashed password
  • Business description, FAQs and tone settings you paste into Bot Studio
  • Channel credentials you connect (WhatsApp Business Account IDs, phone number IDs, access tokens issued by Meta)
  • Billing information processed by our payment provider (we never store card numbers)

From End users (customers who contact your business)

  • Their name and phone number / email when provided (including WhatsApp profile name)
  • The text of each message they exchange with BotNira
  • Basic metadata: channel, timestamps, message delivery status

Automatically

  • Standard server logs (IP address, user agent, API endpoints called)
  • A single cookie / localStorage key in the embeddable web widget to remember a conversation

3.How we use the information

  • Deliver the service — route messages to/from the Vendor's trained bot, show conversations in the Inbox, schedule appointments.
  • Train the Vendor's bot in real time — we send the Vendor's business description + FAQs (never End-user data from other Vendors) to our LLM provider as grounding context.
  • Billing & usage metering — count messages, minutes, and appointments for the Vendor's plan.
  • Security & abuse prevention — rate-limit, detect fraud, and audit access.

We do not sell End-user data. We do not use End-user data to train general-purpose AI models.

4.Third-party processors

To run BotNira we share the minimum necessary data with:

  • Meta Platforms Inc. — for WhatsApp Business Cloud API (receiving + sending messages).
  • BotNira's AI engine — to generate the AI replies (we send the Vendor's business info + the current conversation, never a customer's private data outside of what they themselves typed).
  • MongoDB Atlas — as our primary database.
  • Stripe — payment processing (we never see full card numbers).

Each processor is contractually bound to handle data only on our instructions and in line with applicable data-protection laws.

5.WhatsApp data specifically (required disclosure)

When a Vendor connects their WhatsApp number to BotNira through Meta's Embedded Signup, we receive the WhatsApp Business Account ID, Phone Number ID and an access token scoped to that Vendor's account.

  • We use these tokens only to send and receive messages on behalf of the Vendor.
  • Message content is stored in our database for the Vendor to view in their Inbox.
  • We do not share WhatsApp message content with any third party other than the AI providers listed above, and only to generate an immediate reply.
  • A Vendor can disconnect WhatsApp at any time from Channels → WhatsApp → Disconnect; tokens are revoked and no further messages flow through BotNira.

6.Google user data (Google Calendar integration)

If a Vendor chooses to connect their Google Calendar, BotNira requests access to that Vendor's Google Account through Google's OAuth 2.0 consent screen. This section discloses exactly how BotNira accesses, uses, stores and shares Google user data, in accordance with the Google API Services User Data Policy.

Scopes we request and why

  • .../auth/calendar — to read the Vendor's calendar busy/free times and existing events (so the AI receptionist never double-books a slot) and to create, update and delete the appointment events that BotNira books on the Vendor's behalf.
  • .../auth/userinfo.email and openid — to identify which Google Account was connected and display that email address in the Vendor's dashboard.

How we access it — Access occurs only after the Vendor explicitly grants consent on Google's screen, and only for that Vendor's own Google Account. End users who book appointments never connect their Google accounts.

How we use it

  • Read upcoming events and busy periods to calculate real-time availability and prevent double-booking across BotNira and Google Calendar.
  • Create and manage calendar events for appointments booked through BotNira (via voice, chat, WhatsApp, or the public booking page).
  • Display the connected account's email so the Vendor knows which calendar is linked.

How we store it — We store the OAuth access token and refresh token for the connected account in our secured backend database (encrypted in transit and at rest). These tokens are never exposed to client-side code and are never accessible to any other Vendor. Calendar busy/free data is read on demand to compute availability; it is not repurposed or resold.

How we share it — We do not sell, rent, or transfer Google user data to third parties. We do not use Google user data to develop, improve, or train generalized or non-personalized AI/ML models. Google user data is used solely to provide and improve the user-facing calendar-sync feature the Vendor has explicitly enabled.

Limited Use. BotNira's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access & deletion — A Vendor can disconnect Google Calendar at any time from Appointments → Calendars → Disconnect, which deletes the stored tokens from our systems. Vendors may also revoke BotNira's access directly at myaccount.google.com/permissions. On disconnection or workspace deletion, all stored Google tokens and cached calendar data are permanently deleted within 30 days.

7.How long we retain data

  • Conversations & transcripts: retained for as long as the Vendor's workspace is active. Vendors can delete individual conversations at any time.
  • Billing records: 7 years (legal requirement).
  • When a Vendor deletes their workspace, all associated conversations, messages, appointments and integration tokens are permanently deleted within 30 days.

8.Your rights

Depending on your jurisdiction (GDPR, PIPEDA, CCPA), you have the right to:

  • Access a copy of your data
  • Correct inaccurate data
  • Request deletion ("right to be forgotten")
  • Object to processing and/or withdraw consent
  • Port your data to another provider

End users should direct requests to the Vendor they interacted with (the Data Controller). Vendors can email us directly — see contact below — and we respond within 30 days.

9.Security

We encrypt data in transit (TLS 1.2+) and at rest. Access tokens are stored only in our backend database, never in client-side code. Production access is restricted to a small number of authorised engineers and logged.

10.International transfers

BotNira is operated from Canada. Data may be transferred to and processed in the United States and the European Union by our sub-processors listed above, each under Standard Contractual Clauses.

11.Children

BotNira is not directed at children under 16 and we do not knowingly collect their data.

12.Changes to this policy

If we materially change this policy we'll notify active Vendors by email 30 days before the change takes effect.

13.Contact us

Data protection queries: privacy@thedigisparrow.com
Mailing: The Digi Sparrow, Toronto, Canada

This Privacy Policy is specifically written to comply with Meta Platforms' WhatsApp Business API Terms (see WhatsApp Business Policy) and applicable data-protection regulations including GDPR and PIPEDA.