Privacy Policy
Last updated: September 11, 2026
Badala is a multi-workspace customer communications service operated by Bricks Marketing LLC, registered in Wyoming, United States. Organizations use Badala to connect Instagram professional accounts and WhatsApp business numbers they own or are authorized to manage, and to communicate with people who contact those accounts. This policy explains how Badala processes information about workspace users, connected accounts, and those contacts.
Who we are
Each organization chooses which channels to connect, which teammates may access its workspace, and which optional integrations to enable. Badala processes connected-channel data to provide the service for that organization. Privacy questions and deletion requests may be sent to [email protected].
What data Badala stores
- Workspace account data: name, email address, password hash, workspace role, IP address, last activity, audit records, and short-lived presence information such as the current Badala page and device category while signed in.
- Connected-account data: identifiers such as an Instagram professional account ID and username, Facebook Page IDs and names, OAuth access tokens and granted permissions, connection status, and last webhook activity. For optional Facebook authorization, this includes the authorizing account's app-scoped ID, name, and email address when provided with permission.
- Contact records: for WhatsApp, a phone number and profile name when shared; for Instagram, an Instagram-scoped user ID, username, public profile name, and profile image when Meta returns them. Records may also contain workspace-added tags, notes, company information, and marketing-consent status.
- Conversation content: WhatsApp and Instagram Direct messages, Instagram comments delivered to Badala, text, attachments and media, timestamps, reactions, read and delivery state, and related conversation status.
- Integration and operational data: webhook payloads from Meta, internal audit records, delivery and error logs, and data a workspace deliberately sends to a configured CRM or outbound webhook.
How we use the data
Badala uses this data to authenticate and maintain connected channels, route incoming messages and comments to the correct private workspace, display contact identity and conversation history, let authorized teammates respond, protect the service, and troubleshoot delivery. When a workspace enables an integration, Badala also uses the data needed to perform the action that workspace requested, such as creating a CRM record or delivering an outbound webhook.
For Instagram, Badala uses instagram_business_basic to identify the connected professional account and display its account ID and username. It uses instagram_business_manage_messages to receive, display, manage, and respond to user-initiated Direct Messages. It uses instagram_business_manage_comments to receive and display comments on the connected account's media, post public replies, hide or unhide visitor comments, and delete comments when Meta permits those actions. Badala does not sell Meta data, use it for its own advertising, or send unsolicited Instagram Direct Messages.
Optional Social workspace
Where enabled, workspace owners can separately authorize an Instagram professional account through Instagram Login or Facebook Login and choose the requested capabilities. Authorized workspace owners and administrators can view account insights, posts, comments, and recent Direct Messages returned by Meta. Facebook-connected accounts can also support likes and partnership-ad permission requests when those capabilities are selected and Meta grants the required access.
Badala retrieves insights and social content to display them to authorized workspace users. It stores the connected account identity, encrypted authorization tokens, and an action history containing the initiating user, reviewed text and destination, timestamps, and outcome. Replies, comment moderation, likes, and creator permission requests require a preview and confirmation before Badala sends the action to Meta. Public replies and likes are visible on Instagram. A creator permission request may notify that creator through Meta. This workspace does not create advertising campaigns or spend advertising budgets.
Disconnecting in Settings > Social workspace stops access through that connection. It does not disconnect an independently authorized inbox channel or delete existing action history. Revoking authorization at Meta also makes that grant unusable. Requests to delete retained account data or action history use the deletion process below.
Optional Google Calendar connection
When you connect Google Calendar, Badala uses your verified Google account email, read-only access to your calendar list, and event access to show personal and shared meetings you can read. Your connection belongs to your Badala user account. Other workspace users cannot browse it through Badala. Calendar authorization tokens are encrypted on the server.
Only meetings you explicitly save become part of a workspace conversation. Saved details include the title, start and end times, time zone, location and meeting links. Badala does not automatically copy event descriptions or attendee lists into chats. If you approve a WhatsApp message plan, the reviewed template and meeting details are processed by Meta and sent to the exact recipient shown in the review. Badala rechecks the event before delivery and pauses reminders when relevant details change.
When you choose Create meeting in a chat, Badala sends the exact title, times, time zone, location and description you confirm to your selected Google calendar. You can optionally generate a unique Google Meet link for a new event. Existing calendar sharing controls who can see it. Badala requests event-write access for creation on calendars you can edit, but does not offer editing or deleting existing Google events, inviting attendees, or changing sharing permissions. No attendees or default Google reminders are added to events created by Badala. Calendar data is not used for advertising. Disconnecting in Settings removes the stored authorization tokens and pauses pending reminders. Saved meeting and message history remains with the workspace. You can also revoke Google access in your Google Account permissions. Contact [email protected] for a calendar-data deletion request.
Workspace isolation and data sharing
Each organization's data is logically separated from other workspaces. It is available to authorized users of that workspace and to limited Badala platform administrators when needed to operate, secure, or support the service.
- Meta Platforms: WhatsApp and Instagram messages, comments, and account authorization are processed through Meta's official business APIs, subject to Meta's own terms and policies.
- AWS: the primary application, database and media storage are in Mumbai, India (
ap-south-1). Recovery backups and replicated media are also stored in Frankfurt, Germany (eu-central-1). CloudFront delivers media through its content-delivery network, so delivery processing can occur outside those storage regions. - Cloudflare: provides network delivery, edge proxying, and security for Badala domains. This network processing is not restricted to the primary database's country.
- Notification delivery: when notifications are enabled, Badala sends device tokens and notification content to the applicable delivery service. Mobile notifications use Expo's push service and Apple or Google delivery services. Browser notifications use the browser's push service. Notifications may include a contact or channel name, a message or note preview, and a link back to the workspace. Workspace and device notification preferences control which alerts are delivered.
- LiveKit Cloud: where WhatsApp calling is enabled, LiveKit provides the real-time connection between the business workspace and the call. This processes call audio, participant identity, connection metadata, and the Meta authorization needed to bridge the call. If call recording is enabled by Badala's operator, the recording service writes the recording to Badala's configured storage. Calling uses a distributed network and is not limited to the primary database's country.
- AI features: when a workspace enables AI assistance, relevant conversation text, workspace-provided knowledge and context are sent to the configured AI service to produce a response or suggestion. Meeting commands send the command text and calendar time context for interpretation. The current integration uses Anthropic's API, or an operator-configured compatible endpoint.
- Workspace-configured integrations: Badala exchanges only the data needed for a CRM or outbound webhook feature, and only after an authorized workspace user configures that destination or performs the related action.
Marketing consent
Contacts can opt out of marketing messages at any time. Once a contact is flagged marketingConsent=false, Badala excludes them from every broadcast, regardless of audience filter. This is enforced server-side and cannot be overridden by a teammate at send time.
Retention
Badala retains workspace, contact, and conversation data while it is needed to provide the workspace, maintain security and audit records, comply with legal obligations, or resolve disputes. Disconnecting a channel does not delete its existing conversation history. A workspace user, connected-account owner, or contact may use the deletion paths below. Meta separately processes and retains Instagram and WhatsApp activity under Meta's terms. Badala can request supported platform actions, such as deleting an eligible Instagram comment, but it cannot control or guarantee deletion of Meta's independent records.
Your rights and data deletion
Depending on your relationship with Badala, you may:
- Delete your Badala workspace login from Settings > Account. If you are the only owner of a workspace, transfer ownership first.
- Disconnect a connected Instagram or WhatsApp channel as a workspace owner from Settings > Channels. Existing conversation history is retained until it is separately deleted.
- Request a copy or correction of personal data held about you.
- Request deletion of connected-account, contact, or conversation data.
- Request removal from marketing audiences.
Email [email protected] with the workspace name and the Instagram username or WhatsApp number involved. Badala may ask for information needed to verify your identity or authority before acting on the request.
Changes to this policy
Material changes will be reflected in the "Last updated" date above. The live version of this document is at docs.badala.app/privacy.