Privacy policy
Last updated: August 30, 2026
1. Our role and the customer’s role
lippem LLC is the controller for data needed to administer accounts, security, support, and billing. When a business connects channels and communicates with its own contacts, that business determines the purposes of the communication and Lippem processes the data under its instructions, unless law requires otherwise.
2. Data we process
Depending on enabled features, Lippem processes:
- Account and operational data: name, email, company, users, roles, sessions, settings, and security logs.
- Connected asset data: WABA identifiers, WhatsApp Business numbers, Facebook Pages, professional Instagram accounts, usernames, granted permissions, and access tokens.
- Contact and conversation data: name, phone number or platform identifier, username, profile image when supplied by the provider, text, audio, images, video, attachments, reactions, timestamps, delivery status, and webhook metadata.
- Content uploaded by the customer for AI agents, including documents, answers, and business information.
3. How we use this data
- Authorize, connect, and maintain channels requested by the customer.
- Receive, display, send, and synchronize messages, files, and status updates in the shared inbox.
- Run assignments, workflows, and customer-configured AI responses when enabled.
- Secure the platform, prevent abuse, troubleshoot incidents, provide support, and administer accounts.
4. Providers and international transfers
We share only the data needed with Meta Platforms to operate WhatsApp Business, Instagram Direct, and Messenger; with infrastructure, storage, transactional email, monitoring, and payment providers; and with the AI provider enabled by the customer. These services may currently include Vultr, Cloudflare R2, and Brevo. Some providers process data in other countries, including the United States, subject to their contracts and safeguards. We do not sell contact or conversation data.
5. How we protect data
Provider tokens are stored encrypted, customer data is isolated by tenant, and access is protected by authentication, authorization, and session controls. When a Meta channel is disconnected, Lippem requests removal of its webhook subscription and deletes the stored reusable token from active systems.
6. Retention and deletion
We retain account, contact, and conversation data while the service is active or for as long as needed to provide the requested functions. We acknowledge a verified request within 7 business days and complete it in active systems within 30 days, unless legal obligations, disputes, or fraud prevention require retention. Backups are overwritten on their normal cycle and may retain data for up to 90 days without returning it to operational use. See our data deletion instructions.
7. Rights and choices
You may request access, correction, or deletion. If you are a contact of a business using Lippem, contact that business first so it can identify your conversation, or email support@lippem.com. Administrators can also disconnect channels in Lippem and revoke access from Meta.
8. Children
Lippem is a business service and is not directed to children under 13.
9. Changes to this policy
We may update this policy as the platform evolves. The latest update date appears at the beginning of this document.
10. Contact
The controller responsible for this policy is lippem LLC, a Wyoming limited liability company located at 30 N Gould St Ste N, Sheridan, WY 82801, United States.
For questions about how your data is handled, email support@lippem.com or call +1 (307) 218-8166.