← Back to FreshStack

// legal

Privacy Policy

Last updated: 21 July 2026

FreshStack ("we", "us", "our") builds and operates AI-powered messaging assistants ("receptionist" bots) that businesses use to respond to their customers on WhatsApp, Instagram, and Facebook Messenger. This policy explains what we collect, how we use and share it, and your choices. For any questions, contact us at hello@freshstack.ai.

1. Who this applies to

This policy applies to end customers who message a business using a FreshStack assistant (for example, a patient messaging a clinic's WhatsApp number), business clients who deploy an assistant, and visitors to freshstack.ai. When you message a business that uses FreshStack, that business is the controller of your personal data and FreshStack acts as a processor on its behalf, handling data only to provide the messaging service.

2. Information we collect

We do not ask for, and you should not send, sensitive information such as payment card numbers, passwords, or government ID numbers through the assistant.

3. How we use information

We use this information to deliver the assistant on the business's behalf (understanding your message and generating a helpful reply), book, change, or remind you about appointments where offered, route your conversation to a human team member when needed, maintain, secure, debug, and improve the service, and comply with legal obligations.

4. Automated processing

Replies are generated with the help of automated systems, including third-party AI models, based on your message and the recent conversation history. A human member of the business's team can review conversations and take over at any time.

5. Sharing and sub-processors

We share information only as needed to run the service, with the following key sub-processors: Meta Platforms (WhatsApp Business Platform, Messenger, Instagram) for messaging transport; Anthropic for the AI model used to generate replies; n8n for workflow automation; Google (Calendar) for appointment scheduling where enabled; and cloud hosting and infrastructure providers used to run the service. We require our sub-processors to protect your data and use it only to provide services to us. We do not sell your personal information.

6. Data retention

We retain conversation data only as long as needed to provide the service, comply with legal obligations, and resolve disputes. Retention periods are set together with each business client; you can ask the business you contacted, or us, about deletion.

7. Your rights

Depending on your location (including under the GDPR and UAE data protection law), you may have the right to access, correct, delete, or restrict the use of your personal data, and to object to certain processing. To exercise these rights, email hello@freshstack.ai or contact the business you messaged. We will respond in line with applicable law.

8. Data deletion

To request deletion of your data, email hello@freshstack.ai with the phone number or profile you used. We will delete or de-identify your data unless we are required to retain it by law.

9. Security

We use appropriate technical and organisational measures — including encryption in transit, access controls, and secrets management — to protect your data. No method of transmission or storage is completely secure, but we work to protect your information and continuously improve our safeguards.

10. Children

Our services are not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

11. International transfers

Your data may be processed in countries other than your own, including where our sub-processors operate. Where required, we put appropriate safeguards in place for such transfers.

12. Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the "Last updated" date above.

13. Contact us

FreshStack — email hello@freshstack.ai.