Privacy Policy

Last updated: January 15, 2026

Alab & Alon Innovations Inc. ("AlonChat", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI agent platform and services (the "Service").

By using AlonChat, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.

1. Information We Collect

1.1 Information You Provide

We collect information that you voluntarily provide when using our Service:

  • Account Information: Name, email address, and profile details when you create an account
  • AI Agent Data: Configurations, system prompts, and knowledge base content you provide to build your AI agents
  • Communication Data: Information from your interactions with our support team
  • Payment Information: Billing details processed securely through our payment processor

1.2 Automatically Collected Information

  • Usage Data: Information about how you interact with our Service, including features used, pages visited, and time spent
  • Device Information: IP address, browser type, operating system, and device identifiers
  • Cookies and Tracking: We use cookies and similar technologies to track activity and improve user experience

1.3 Third-Party Service Data

When you connect third-party services to AlonChat, we may collect:

  • Facebook Messenger: Conversation history, contact information, and metadata from your Facebook page
  • Google Services: See "Google Services Integration" section below for detailed information

1.4 Merchant and Payment Processing Data

When you use AlonChat's payment processing features (integrated with PayMongo and other payment processors), we collect additional information necessary for merchant onboarding, KYC (Know Your Customer) verification, and financial compliance:

  • Business Information: Business name, trade name, business type (sole proprietor, corporation, etc.), industry, business address
  • Identification Documents: Government-issued IDs (passport, driver's license, national ID), TIN (Tax Identification Number), business registration documents (DTI, SEC, CDA, Mayor's Permit)
  • Bank and Payout Information: Bank account details, e-wallet accounts (GCash, Maya, etc.) for receiving payouts from customer transactions
  • Authorized Representative Information: Name, contact details, ID documents, and proof of authority for business representatives
  • Transaction Data: Payment amounts, transaction IDs, payment methods used by your end-customers, timestamps, and transaction status
  • Financial Compliance Data: Source of funds, estimated monthly transaction volume, nature of business, and other information required for Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) compliance

This data is collected and stored in accordance with Bangko Sentral ng Pilipinas (BSP) regulations and payment processor requirements.

2. Google Services Integration

AlonChat integrates with Google services to enable your AI agents to perform tasks on your behalf. We only access Google user data when you explicitly authorize us through OAuth 2.0 authentication.

2.1 Gmail Integration

Data We Access:

  • Read your emails (gmail.readonly scope)
  • Send emails on your behalf (gmail.send scope)
  • Compose draft emails (gmail.compose scope)
  • Your email address and profile information

How We Use It: Your AI agent can read incoming emails and respond automatically based on your training data and instructions. Email content is processed in real-time to generate responses and is NOT permanently stored in our systems beyond OAuth access tokens.

2.2 Google Calendar Integration

Data We Access:

  • Read calendar events (calendar.readonly scope)
  • Create, edit, and delete calendar events (calendar.events scope)
  • Check your availability and free/busy times
  • Your email address and profile information

How We Use It: Your AI agent can schedule appointments, check your availability, and manage calendar events based on customer requests. Calendar data is queried in real-time when needed and is not permanently stored.

2.3 Google Drive Integration

Data We Access:

  • Read files from your Google Drive (drive.readonly scope)
  • Access file metadata (names, types, modification dates)
  • Your email address and profile information

How We Use It: Your AI agent can access Google Drive files to enrich its knowledge base. Files are processed and chunked for AI training purposes. Original files remain in your Google Drive and are not modified or deleted.

2.4 Security and Control

  • OAuth 2.0 Authentication: We use industry-standard OAuth 2.0 for secure authorization. We never see or store your Google password.
  • Minimum Scopes: We only request the minimum permissions necessary for the features you choose to use.
  • Encrypted Storage: OAuth access and refresh tokens are encrypted and stored securely in our database.
  • No Permanent Storage: Email and calendar content is processed in real-time for AI responses. We do not permanently store email bodies or calendar event details.
  • Revoke Access Anytime: You can disconnect Google services and revoke our access at any time from your AlonChat dashboard or Google Account settings.
  • Automatic Token Refresh: Tokens are refreshed securely to maintain uninterrupted service without requiring you to re-authenticate.

Google API Services User Data Policy Compliance: AlonChat's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. Facebook & Instagram Integration

AlonChat integrates with Facebook Messenger and Instagram Direct Messages to enable your AI agents to provide automated customer support on your social media channels. We only access your business data when you explicitly authorize us through Facebook OAuth authentication.

3.1 Facebook Messenger Integration

Data We Access:

  • Your Facebook Page's conversation history with customers
  • Message content, timestamps, and sender information
  • Attachments shared in conversations (images, files)
  • Page name, profile picture, and category

How We Use It: Your conversation history is indexed to enable your AI agent to retrieve relevant past answers when responding to new customer inquiries. This is retrieval-based assistance—your data improves responses for YOUR business only and is completely isolated from other customers.

3.2 Instagram Direct Messages Integration

Data We Access:

  • Your Instagram Business/Professional Account's DM history
  • Message content, timestamps, and sender information
  • Your Instagram username, profile picture, and follower count

How We Use It: Similar to Facebook, your Instagram conversation history is processed to enable context-aware automated replies. The AI agent searches your past answers to provide consistent, brand-aligned responses.

3.3 Data Isolation & Security

đź”’ Your Data is Completely Isolated:

  • Per-Business Silos: Your conversation data and embeddings are stored separately and can ONLY be accessed by your AI agents. Other AlonChat customers cannot access your data.
  • No Cross-Customer Learning: Your business data is never used to improve AI responses for other businesses. Each business's knowledge base is completely independent.
  • Encrypted Storage: Access tokens, conversation data, and embeddings are encrypted at rest using industry-standard encryption.
  • Token Security: Facebook/Instagram access tokens are stored securely in our database and are never exposed in logs, URLs, or client-side code.

3.4 What We Do NOT Do

  • No AI models are modified: We index past conversations to retrieve relevant examples for reply generation. Your data is used for retrieval only—no AI model weights are ever changed.
  • We do NOT share your data with other AlonChat customers or third parties (except AI providers for response generation).
  • We do NOT access personal messages from your personal Facebook/Instagram accounts—only business Page/Professional Account conversations.
  • We do NOT sell your data for advertising or marketing purposes.

3.5 Data Retention & Deletion

  • Conversation Data: Stored as long as your connection is active. Typically limited to the last 3 months of history for processing efficiency.
  • Embeddings: Retained until you disconnect the integration or delete the AI agent.
  • Access Tokens: Long-lived tokens (60 days) are refreshed automatically and deleted when you disconnect.
  • Disconnection: When you disconnect Facebook/Instagram from AlonChat, we unsubscribe from webhooks and delete your access tokens. You can request full data deletion by contacting privacy@alonchat.com.

3.6 Permissions We Request

PermissionPurpose
pages_messagingRead and send messages on your Facebook Page
instagram_manage_messagesRead and send Instagram Direct Messages
pages_show_listDisplay your Pages for selection
pages_read_engagementAccess Page metadata and statistics

Meta Platform Terms Compliance: AlonChat's use and handling of data received from Facebook and Instagram APIs adheres to the Meta Platform Terms and Messenger Platform Policy. You can revoke AlonChat's access to your Facebook/Instagram data at any time through your Facebook Business Settings or the AlonChat dashboard.

4. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, maintain, and improve our AI agent platform and features
  • AI Training: To train and optimize your custom AI agents based on the data you provide
  • Communication: To send important service updates, security alerts, and notifications
  • Customer Support: To respond to your questions, requests, and provide technical assistance
  • Analytics: To understand how users interact with our Service and improve user experience
  • Security: To detect, prevent, and address technical issues, fraud, and security vulnerabilities
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes
  • Third-Party Integrations: To enable features like Gmail automation, calendar scheduling, and file access as authorized by you
  • Payment Processing: To facilitate payment transactions between you (the merchant) and your end-customers through integrated payment processors
  • Fraud Prevention: To monitor transactions, detect suspicious activity, and prevent fraudulent use of the Service
  • Financial Compliance: To comply with Bangko Sentral ng Pilipinas (BSP) regulations, Anti-Money Laundering (AML) laws, and Counter-Terrorism Financing (CTF) requirements

5. How We Share Your Information

5.1 AI Service Providers

We share data with AI providers (OpenAI, Anthropic, Google, and others) to process your requests and generate AI responses. These providers process data according to their own privacy policies and data processing agreements.

5.2 Service Providers

We may share information with third-party service providers who perform services on our behalf, including:

  • Cloud infrastructure providers (Supabase, Vercel, Railway)
  • Payment processors (PayMongo): To facilitate merchant onboarding, KYC verification, transaction processing, and payouts. PayMongo processes data in accordance with BSP regulations and their own privacy policy.
  • Analytics providers
  • Customer support tools

5.3 Legal Requirements

We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5.5 Law Enforcement and Fraud Investigations

IMPORTANT: AlonChat reserves the right to cooperate with law enforcement agencies, government authorities, and regulatory bodies (including but not limited to the National Bureau of Investigation, Philippine National Police, Department of Trade and Industry, Bangko Sentral ng Pilipinas, Securities and Exchange Commission, and DICT Cybercrime Division) in the investigation of suspected fraud, scams, illegal activities, or violations of our Terms of Service.

We may disclose merchant information, including but not limited to:

  • Account details, business information, and contact information
  • KYC documents (government-issued IDs, business registration, bank account details)
  • Transaction history, payment records, and financial data
  • Chat logs, AI agent configurations, and customer interaction records
  • IP addresses, device information, access logs, and activity timestamps
  • Reports filed by end-customers or third parties regarding suspected fraud
  • Any other information required by court order, subpoena, search warrant, or lawful legal request

By using the Service, you explicitly consent to such disclosures and acknowledge that AlonChat has a legal and regulatory obligation to cooperate with authorities. You waive any claims, demands, or causes of action against AlonChat arising from the disclosure of information to law enforcement or regulatory agencies in good faith compliance with legal obligations or in response to suspected illegal activity.

We will not provide advance notice of such disclosures where prohibited by law or where doing so would compromise an ongoing investigation.

We never sell your personal data to third parties for marketing purposes.

6. Data Storage and Retention

6.1 Storage Location

Your data is stored on secure cloud infrastructure provided by Supabase (PostgreSQL database) with servers located in the United States and other regions depending on your account settings.

6.2 Retention Period

  • Active Accounts: We retain your data as long as your account is active
  • Inactive Data: Unused data is automatically deleted after 90 days of inactivity
  • OAuth Tokens: Google OAuth tokens are retained encrypted until you disconnect the integration
  • Backups: Database backups are retained for 30 days for recovery purposes
  • Transaction Records: Payment transaction data is retained for 7 years to comply with Philippine tax laws and BSP regulations
  • KYC Documents: Merchant identification and business registration documents are retained for 5 years after account closure as required by AML/CTF regulations
  • Legal Requirements: Some data may be retained longer if required by law, court order, or ongoing legal proceedings

6.3 Data Deletion

You can request deletion of your data at any time by contacting us at privacy@alonchat.com. We will delete your data within 30 days unless retention is required by law, regulatory obligations, or ongoing legal proceedings.

Note: Financial records, transaction history, and KYC documents may be retained beyond 30 days to comply with BSP regulations, tax laws, and AML/CTF requirements.

7. Security

We implement industry-standard security measures to protect your data:

  • Encryption: Data is encrypted in transit (TLS/SSL) and at rest
  • Access Controls: Strict authentication and role-based access controls
  • Monitoring: Continuous monitoring for security threats and vulnerabilities
  • Audits: Regular security audits and penetration testing
  • Compliance: Adherence to industry best practices and security standards, including BSP Circular No. 1074 (Guidelines on Information Security Management)

However, no method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

8. Your Rights

8.1 General Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal retention requirements)
  • Portability: Request transfer of your data in a machine-readable format
  • Objection: Object to certain processing activities
  • Restriction: Request restriction of processing in certain circumstances

8.2 GDPR Rights (EU/EEA Residents)

If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to be informed about data collection and processing
  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Rights related to automated decision-making and profiling

8.3 CCPA Rights (California Residents)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information
  • Right to opt-out of the sale of personal information (we do not sell personal data)
  • Right to non-discrimination for exercising your CCPA rights
  • Right to correct inaccurate personal information
  • Right to limit use and disclosure of sensitive personal information

8.4 Philippine Data Privacy Act Rights

Under the Data Privacy Act of 2012 (Republic Act No. 10173), Philippine residents have the right to:

  • Be informed of the nature, purpose, and extent of data processing
  • Access personal data and request copies
  • Dispute inaccurate or incomplete data and request corrections
  • Suspend, withdraw, or order the blocking, removal, or destruction of personal data
  • Lodge complaints with the National Privacy Commission (NPC)
  • Obtain damages for inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal data

To exercise any of these rights, please contact us at privacy@alonchat.com.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to improve your experience:

9.1 Essential Cookies

Required for the website to function properly, including authentication, session management, and security features.

9.2 Analytics Cookies

Help us understand how visitors interact with our website using tools like Google Analytics and Facebook Pixel.

9.3 Managing Cookies

You can control cookies through your browser settings. However, disabling cookies may affect website functionality.

10. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal data, please contact us immediately.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We take appropriate measures to ensure your data is protected in accordance with this Privacy Policy and applicable laws.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Alab & Alon Innovations Inc.

Email: privacy@alonchat.com

Support: support@alonchat.com

Data Protection Officer: dpo@alonchat.com

National Privacy Commission (Philippines):
If you have unresolved privacy concerns, you may contact the National Privacy Commission at www.privacy.gov.ph