Privacy Policy

Effective date: 10 April 2026
Last updated: 12 August 2026

Parrotron (“Parrotron”, “we”, “us”, or “our”) is the legal entity responsible for operating the Parrotron Chat Android application, the Parrotron web application, the website at https://parrotron.com, and related messaging, automation, customer-management, advertising-optimisation, and support services collectively referred to as the “Services”.

This Privacy Policy explains what information we collect, how we use and disclose it, how long we retain it, and the choices available to users.

Legal entity: Parrotron
Email: contact@parrotron.com
Website: https://parrotron.com
Android application ID: com.parrotron.chat

1. Scope of This Policy

This policy applies to:

  • The Parrotron Chat Android application.
  • The Parrotron web application and administrative dashboard.
  • Parrotron websites, forms, support services, and account-management pages.
  • Messaging services connected to WhatsApp, Instagram, Messenger, and other supported channels.
  • Automation, scheduling, AI assistance, customer-management, notification, and advertising-optimisation features.

This policy does not govern the independent privacy practices of Meta, Google, individual businesses using Parrotron, or other third-party services.

2. Our Role

Parrotron may process information in two different capacities:

  1. As a data controller: When we process information relating to Parrotron users, account owners, administrators, agents, subscribers, and website visitors for account administration, security, billing, support, and service improvement.

  2. As a service provider or data processor: When a business uses Parrotron to manage conversations, contacts, leads, customers, schedules, advertising events, and other business data. In this situation, the business using Parrotron determines why and how its customer data is processed.

If you are a customer who communicated with a business using Parrotron, you may also contact that business directly regarding your information.

3. Information We Collect

3.1 Account and identity information

We may collect:

  • Name and display name.
  • Email address.
  • Phone number.
  • User ID and account identifiers.
  • Business name, category, website, and business profile information.
  • Tenant, workspace, role, administrator, and agent assignments.
  • Profile image, where provided.
  • Google Sign-In identifiers and basic profile information authorised by the user.

3.2 Authentication and security information

We may process:

  • Passwords stored using secure hashing rather than plain text.
  • One-time passwords and OTP verification status.
  • Two-factor authentication preferences.
  • Authentication provider identifiers.
  • Login sessions, access tokens, refresh tokens, and session expiry information.
  • Failed-login attempts and security records.
  • Account-recovery and account-deletion verification information.

We do not intentionally store Google account passwords.

3.3 Messaging and customer information

When users connect supported messaging channels, we may process:

  • Messages sent and received through connected channels.
  • Message timestamps, delivery status, read status, and message IDs.
  • Contact names, phone numbers, usernames, and platform-scoped identifiers.
  • WhatsApp Business Account identifiers.
  • Facebook Page and page-scoped user identifiers.
  • Instagram account and Instagram-scoped user identifiers.
  • Connected channel and business account information.
  • Photos, videos, audio, voice recordings, documents, and other attachments.
  • Message replies, saved replies, AI-assisted replies, notes, labels, and tags.
  • Contact status, customer status, sales-stage information, and assignments.
  • Call records entered by users, call reminders, follow-up reminders, and scheduled activities.

Parrotron does not read a user’s device address book unless a feature explicitly requests access and the user grants the corresponding permission.

3.4 Automation and scheduling information

We may process:

  • Automation rules, triggers, conditions, and actions.
  • Scheduled messages and follow-up schedules.
  • Appointment, booking, availability, and pricing information configured by a business.
  • Reminder dates and times.
  • Agent assignments and workflow history.
  • Automation execution logs and delivery outcomes.

3.5 Advertising and attribution information

If a business enables advertising optimisation, Parrotron may process and transmit permitted messaging conversion events to Meta or another configured advertising platform.

This may include:

  • Events such as LeadSubmitted and Purchase.
  • Event name, time, source, and event ID.
  • Messaging channel.
  • Relevant Page, Instagram, or WhatsApp Business Account identifiers.
  • Dataset or advertising account identifiers.
  • Currency and transaction value when supplied.
  • Campaign, advertisement, referral, and click attribution information.
  • Permitted user or platform-scoped identifiers required to associate an event with a messaging interaction.

These events are used for conversion measurement, attribution, campaign reporting, and advertising optimisation. Advertising-event transmission is only performed when the relevant business enables and configures this functionality.

Parrotron does not independently use a business’s customer conversations to advertise unrelated Parrotron products to those customers.

3.6 Device and technical information

We may collect:

  • Device type and model.
  • Operating system and version.
  • Application version.
  • Browser type and version.
  • IP address.
  • Language, time zone, and general regional settings.
  • Device or installation identifiers.
  • Expo, Firebase Cloud Messaging, and browser push-notification tokens.
  • Notification permission, delivery status, and notification preferences.
  • Crash, diagnostic, performance, and error information.
  • API, webhook, security, and activity logs.

We do not intentionally collect precise GPS location unless a future feature clearly requests it and the user grants permission.

3.7 Usage information

We may collect information about how the Services are used, including:

  • Screens and features accessed.
  • Search queries performed within the application.
  • Buttons and actions selected.
  • Account and tenant switching activity.
  • Setup and onboarding progress.
  • Messages, reminders, automations, reports, and tools used.
  • Dates, times, duration, and outcomes of application actions.

3.8 Support and communications

When users contact us, we may collect:

  • Contact details.
  • Support requests.
  • Screenshots and attachments.
  • Diagnostic information.
  • Correspondence and feedback.
  • Information required to investigate and resolve a problem.

4. How We Use Information

We use information to:

  • Create, authenticate, secure, and manage accounts.
  • Provide unified messaging and inbox functionality.
  • Connect and operate supported messaging channels.
  • Deliver messages, attachments, notifications, and reminders.
  • Manage contacts, customers, labels, tags, notes, agents, and schedules.
  • Run user-configured automations and AI-assisted features.
  • Provide booking, availability, scheduling, and follow-up tools.
  • Send configured advertising conversion events.
  • Measure advertising performance when enabled.
  • Maintain message delivery, read, and failure statuses.
  • Provide customer support.
  • Detect fraud, abuse, unauthorised access, and security incidents.
  • Troubleshoot technical problems and improve reliability.
  • Comply with applicable legal obligations.
  • Enforce our agreements and protect our users, Services, and legal rights.

5. Legal Bases for Processing

Depending on the user’s location and the circumstances, we process information based on:

  • Performance of a contract or provision of requested Services.
  • User consent.
  • Legitimate interests in operating, securing, supporting, and improving the Services.
  • Compliance with legal and regulatory obligations.
  • Instructions from a business acting as the controller of its customer data.

Where processing relies on consent, consent may be withdrawn, subject to legal and contractual restrictions.

6. AI-Assisted Features

Parrotron may provide AI-assisted replies, classification, summarisation, automation, scheduling, data extraction, and related features.

When an AI feature is used:

  • Relevant message content and instructions may be sent to a configured AI service provider.
  • Only information reasonably required to perform the requested function should be transmitted.
  • AI-generated output may be inaccurate and should be reviewed before being relied upon or sent.
  • Businesses are responsible for configuring and using AI features appropriately.
  • We use service providers subject to contractual, security, and confidentiality obligations where applicable.

Parrotron does not claim ownership of customer message content merely because it is processed by an AI feature.

7. How We Share Information

We may disclose information to the following categories of recipients:

7.1 Service providers

We may use service providers for:

  • Cloud hosting and storage.
  • Database and infrastructure services.
  • Authentication.
  • Email and OTP delivery.
  • Push notifications.
  • Crash reporting and diagnostics.
  • AI processing.
  • Customer support.
  • Security and fraud prevention.

These may include Google, Firebase, Expo, hosting providers, email providers, AI providers, and other infrastructure vendors used to operate the Services.

7.2 Messaging and advertising platforms

When a user connects or enables an integration, we may exchange information with:

  • Meta Platforms and its services, including WhatsApp, Facebook, Instagram, Messenger, Meta Business tools, and Meta Conversions API.
  • Google services used for authentication, notifications, application distribution, and related functionality.
  • Other platforms expressly connected by the user.

Their processing is also governed by their respective terms and privacy policies.

7.3 Businesses and authorised users

Information within a business workspace may be available to:

  • The workspace owner.
  • Administrators.
  • Assigned agents.
  • Other authorised team members.
  • Service providers authorised by that business.

7.4 Legal and safety disclosures

We may disclose information when reasonably necessary to:

  • Comply with a law, regulation, court order, or lawful government request.
  • Protect users, customers, Parrotron, or the public.
  • Investigate fraud, abuse, or security incidents.
  • Establish, exercise, or defend legal claims.
  • Enforce our agreements and policies.

7.5 Business transactions

If Parrotron undergoes a merger, acquisition, financing, restructuring, or sale of assets, relevant information may be transferred as part of that transaction, subject to applicable law and appropriate safeguards.

8. Sale of Personal Information

Parrotron does not sell personal information for monetary consideration.

Parrotron does not share personal information for unrelated third-party advertising. Information may be transmitted to advertising platforms only when an authorised business enables advertising measurement or optimisation functionality.

9. Push Notifications

The Android application and web application may use push notifications for:

  • New messages.
  • Assigned conversations.
  • Follow-up reminders.
  • Scheduled calls and activities.
  • Account and security alerts.
  • Operational notices.

Push delivery may require a device or browser push token. Users can manage notification permissions through their device, browser, and Parrotron notification settings.

Disabling notifications does not delete the user’s account or other information.

10. Device Permissions

Depending on the features used, the application may request access to:

  • Notifications.
  • Photos and videos selected by the user.
  • Camera, when the user chooses to capture media.
  • Microphone, when recording audio or voice messages.
  • Files and documents selected by the user.

Parrotron only uses these permissions for the feature requested by the user. Permissions can be withdrawn through Android settings, although doing so may prevent the related feature from working.

11. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this policy.

Generally:

  • Account information is retained while an account remains active.
  • Workspace and customer information is retained while required to provide Services to the relevant business.
  • Message and attachment retention may depend on the connected platform, the business’s configuration, contractual requirements, and operational needs.
  • Push tokens are retained while required to deliver notifications and may be removed when invalid, replaced, or associated with a deleted account.
  • Security, API, webhook, and diagnostic logs may be retained for a limited period needed for troubleshooting, security, audit, and fraud prevention.
  • Account-deletion requests are normally processed within seven business days after successful identity verification.
  • Deleted data may remain in restricted backups for up to 30 days before being overwritten.
  • Certain records may be retained longer where required for taxation, legal compliance, security, fraud prevention, dispute resolution, or enforcement.

Where Parrotron acts as a processor, retention may also be determined by the relevant business’s instructions.

12. Account and Data Deletion

Users may request deletion of their Parrotron account and associated personal data through the Account Deletion page:

https://parrotron.com/account-deletion/

In the Android or web application

Use the Delete Account option available in account settings. Parrotron will require identity verification using an OTP sent to the account’s registered contact method before accepting the deletion request.

Through the website

Visit:

https://parrotron.com/account-deletion/

Users who cannot access the application may submit a deletion request through the public deletion page or contact:

contact@parrotron.com

For other privacy or data removal requests that do not require deleting the full account, users may visit:

https://parrotron.com/data-removal/

A request must contain enough information to locate and verify the account. We may request additional verification to prevent unauthorised deletion.

Deletion generally includes:

  • The Parrotron user account.
  • Authentication and profile information.
  • Personal preferences.
  • Stored push-notification tokens.
  • Personal information directly associated with the account.
  • Other account-associated data that Parrotron is legally and operationally permitted to delete.

Some information may be retained where required for legal compliance, security, fraud prevention, billing, dispute resolution, or enforcement.

Information belonging to a business workspace may remain under the control of that business where the user acted as an agent or team member. Requests concerning customer conversations or business records may need to be directed to the relevant workspace owner.

13. User Rights

Subject to applicable law, users may request:

  • Access to personal information.
  • Correction of inaccurate information.
  • Deletion of personal information.
  • Restriction of processing.
  • Objection to certain processing.
  • Withdrawal of consent.
  • A portable copy of eligible information.
  • Information about how personal data is used.

Requests may be sent to contact@parrotron.com. We may verify identity before fulfilling a request.

Users may also complain to the applicable data-protection authority.

14. Security

We use reasonable technical and organisational safeguards designed to protect information, including:

  • Encryption in transit using HTTPS/TLS.
  • Access controls and role-based permissions.
  • Secure credential handling.
  • Password hashing.
  • OTP and authentication controls.
  • Token and session management.
  • Logging and monitoring.
  • Restricted administrative access.
  • Security updates and operational controls.

No system is completely secure. Users should protect their credentials, use secure devices, and notify us promptly of suspected unauthorised access.

15. International Data Transfers

Parrotron and its service providers may process information in countries other than the user’s country.

Where required, we use appropriate contractual, technical, and organisational safeguards for international transfers. By using connected third-party platforms, information may also be processed in locations specified by those platforms.

16. Children’s Privacy

The Services are intended for business users aged 18 or older.

Parrotron does not knowingly permit children under 18 to create accounts or intentionally collect their personal information. If we learn that information has been collected from a child without appropriate authorisation, we will take reasonable steps to delete it.

17. Third-Party Services and Links

The Services may contain links to or integrations with third-party services. Parrotron does not control those services’ independent privacy practices.

Users should review the privacy policies of relevant providers, including:

18. Business Responsibilities

Businesses using Parrotron are responsible for:

  • Having an appropriate legal basis to process customer information.
  • Providing required notices to their customers.
  • Obtaining consent where required.
  • Configuring integrations and automations lawfully.
  • Limiting access to authorised personnel.
  • Responding to customer privacy requests where the business is the data controller.
  • Avoiding the transmission of prohibited, unnecessary, or highly sensitive information.

Parrotron may suspend access where the Services are used unlawfully or in violation of applicable policies.

19. Changes to This Policy

We may update this Privacy Policy to reflect changes in:

  • The Services.
  • Legal requirements.
  • Security practices.
  • Third-party integrations.
  • Data-processing activities.

The updated policy will be posted on this page with a revised “Last updated” date. Material changes may also be communicated through the application, website, or email.

20. Contact Us

For privacy questions, requests, or complaints, contact:

Parrotron
Email: contact@parrotron.com
Website: https://parrotron.com
Account deletion: https://parrotron.com/account-deletion/