Privacy Policy
Last updated: July 11, 2026
1. Introduction
Anito Connect ("we", "our", or "us"), operated by Daloy Tech Solutions, provides an AI-powered customer engagement, booking, and e-commerce platform that works across multiple channels including Facebook Messenger and website chat. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our service.
2. Information We Collect
When you connect a channel (Facebook Page, website widget, etc.) to Anito Connect, we collect:
- Your Facebook Page ID and Page name
- A Page Access Token (used to send automated replies on your behalf)
- Page-Scoped User IDs (PSID) of your customers (to maintain conversation history and identify returning users)
- Messages and comments sent to your connected channels by end-users, including voice messages (which are transcribed to text by a speech-to-text service in order to generate a reply)
- Your account email address (via Supabase Auth)
- Business configuration data (e.g. business hours, knowledge base documents, AI personality settings) that you upload, including any historical Facebook conversation exports you choose to import into your knowledge base
- Booking and appointment data including customer names, contact info, and scheduled times
- Product catalog data including product names, descriptions, prices, and images
- Order and transaction data including order details and customer shipping/billing information
- Payment proof screenshots or receipts customers upload to verify a booking or order payment
- Payment account details you provide (e.g. GCash, Maya, or bank account information) so we can tell your customers where to send payment
- Support ticket details submitted by your customers through the AI
- A consolidated customer profile (a "contact") that links the identities one customer uses across your connected channels, holding their name, email address, phone number, and their answers to the intake questions you configure (for example address, company, or preferred branch) — collected when they share those details in chat, or when they provide them while booking or ordering
- Mobile phone numbers — yours (if you enable SMS alerts) and your customers' (when they provide one while booking or ordering) — used to send transactional SMS such as booking confirmations, reminders, and payment follow-ups; each SMS attempt is logged for audit and cost-tracking purposes
- If you sign in with Google or Facebook, the basic profile information those providers share with us (your name, email address, and profile picture) — used only to create and secure your account, never to access your personal social media content
- If you invite team members, their email address and the module permissions you assign them
3. How We Use Your Information
- To generate and send AI-powered replies to messages and comments on your connected channels
- To store your business knowledge base for context-aware responses
- To manage bookings, appointments, and scheduling on your behalf
- To display and manage your product catalog and process customer orders
- To provide analytics, lead tracking, and conversation insights
- To power the marketing features you choose to enable — grouping your contacts into segments and sending broadcast or automated follow-up campaigns by Messenger, SMS, or email, subject to the marketing consent recorded for each contact and to their right to unsubscribe at any time
- To manage your account and provide customer support
- To improve and develop our services
4. Facebook Data and Required Permissions
To provide our AI engagement services, we access your Facebook Page data strictly through the Meta Graph API. During the OAuth flow, we request specific permissions. Here is exactly what they are used for:
- pages_show_list: Used to show the list of Facebook Pages you manage during onboarding and connection setup.
- pages_manage_metadata: Used to subscribe the selected Page to webhook events for receiving customer messages and comments.
- pages_messaging: Used to send support replies to customer-initiated Messenger messages within the standard 24-hour response window (or up to 7 days for human agent interventions).
- pages_read_engagement: Used to detect comments and engagement events on connected Page posts via webhooks.
- pages_read_user_content: Used to read customer comment text so our AI support assistant can understand the question and generate a relevant reply.
- pages_manage_engagement: Used to post Page replies under customer comments on connected Page posts.
5. Google Calendar Data and Limited Use
If you choose to connect your Google Calendar, we access it strictly through the Google Calendar API using a single OAuth permission — https://www.googleapis.com/auth/calendar.events — which is the narrowest scope that supports the feature (we do not request access to your calendar settings, sharing/permissions, or your other calendars). We use it only to keep your Anito Connect appointment bookings in sync with your calendar: we create a calendar event when a customer books an appointment, update it when a booking is rescheduled, delete it when a booking is cancelled, and read your existing events (with change notifications) so times you are already busy are automatically blocked and not double-booked. You can disconnect Google Calendar at any time from your dashboard settings, which revokes our access and removes the events we created.
Limited Use: Anito Connect's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Although Anito Connect uses AI language models to operate the Service, we do NOT use, transfer, or sell Google Workspace (Google Calendar) user data — whether raw, aggregated, or derived — to create, train, or improve any generalized or foundational artificial intelligence or machine learning models. Google Calendar data is used solely to provide the calendar-sync feature described above.
6. Data Sharing and Protection
We do NOT sell, share, or transfer Facebook user data to third parties, except as required to operate the core service (e.g., Supabase for encrypted database storage; Google Gemini and OpenAI for AI-generated replies, knowledge base search, and voice message transcription; PayMongo for payment processing; Semaphore for SMS delivery; Sentry for error monitoring). We strictly adhere to the Meta Platform Terms and Developer Policies. Data is never used for targeted advertising. Team Members: if you invite staff to your workspace, they can access the customer conversations, bookings, orders, and support tickets of YOUR business according to the module permissions you grant them. You are responsible for who you invite; you can revoke a team member's access at any time from Settings → Team, which takes effect immediately. Admin Access for Debugging: Authorized Anito Connect administrators have the technical ability to temporarily access and impersonate your account. This capability is strictly limited to debugging software issues, resolving complex customer support inquiries, and providing hands-on technical assistance at your request. All such administrative access events are securely audited and logged for security and compliance purposes.
7. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Booking and order data is retained for business record-keeping purposes. If you delete your account, we immediately pause your AI and disconnect all your channels, then permanently delete your data within 30 days. You may request deletion of your data at any time via our Data Deletion page. Some third-party processors (e.g. our error-monitoring and AI providers) may retain limited technical logs for a shorter period under their own retention policies, independent of our systems.
8. Third-Party Services
We use the following third-party services to operate Anito Connect:
- Supabase – Database, file storage, and authentication (including Google and Facebook sign-in)
- Google Gemini and OpenAI – AI language models for generating replies, searching your knowledge base, and (OpenAI) transcribing customer voice messages to text
- PayMongo – Payment processing for subscriptions, add-ons, and (where enabled) customer bookings/orders
- Semaphore – SMS delivery within the Philippines (booking confirmations, reminders, payment follow-ups, and owner alerts)
- Sentry – Error monitoring, used to diagnose issues; error reports may incidentally include recent message content or business context needed to reproduce the issue
- Resend – Transactional email delivery
- Upstash – Rate-limiting infrastructure (processes IP addresses and account emails solely to prevent abuse)
- Netlify – Application hosting; service traffic transits its infrastructure
- Meta (Facebook) Graph API – Page messaging integration and (optionally) Facebook sign-in
- Google Calendar API – Optional two-way calendar sync for your appointment bookings, active only if you connect your Google account (see Section 5)
9. Security
We implement industry-standard security measures including encrypted storage of access tokens, HTTPS-only communication, row-level security policies on all database tables, and server-side validation of all user actions. However, no method of electronic transmission or storage is 100% secure.
10. Cookies and Local Storage
We use essential cookies to maintain your session and store your active page selection. We do not use tracking cookies or third-party advertising cookies.
11. Your Rights
You have the right to access, correct, or delete your personal data. You may disconnect your channels at any time through the dashboard. To exercise data deletion rights, visit our Data Deletion page or contact us at support@daloytechsolutions.com. For users in the Philippines, we process personal data in accordance with the Data Privacy Act of 2012 (RA 10173) and its IRR; you also have the right to lodge a complaint with the National Privacy Commission (privacy.gov.ph). Data may be processed and stored on servers located outside the Philippines by the providers listed in Section 7, each bound by their own data-protection commitments.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page with an updated date.
13. Contact Us
Daloy Tech Solutions
Email: support@daloytechsolutions.com
Website: anitoconnect.com