Who we are
NextPilot Chat (“NextPilot”, “we”, “us”) provides a WhatsApp-first customer relationship management (CRM) platform at nextpilot.chat and app.nextpilot.chat. We help teams manage conversations, leads, automations, broadcasts, and AI-assisted replies in a shared workspace.
For privacy questions or requests, contact us at hello@nextpilot.chat.
What this policy covers
This policy applies to visitors of our marketing site, account holders, workspace members invited to your organization, and end customers whose messages flow through channels you connect to NextPilot.
When you connect Meta (Facebook, Instagram, Messenger) or WhatsApp Business, their platforms also process data under Meta’s terms and policies. You are responsible for informing your customers as required by applicable law.
Information we collect
We collect information in these categories:
- Account & profile — name, email address, password hash, workspace name, role, and organization membership.
- Workspace & CRM data — contacts, leads, pipeline stages, conversation threads, message content (inbound and outbound), notes, labels, segments, custom fields, automations, flows, sequences, broadcasts, templates, reports, usage metrics, and store-related settings you create or import.
- Channel connection data — when you connect WhatsApp, Messenger, or Instagram we store channel identifiers (such as phone number ID, WABA ID, Page ID, Instagram account ID), connection status, and non-secret configuration. Access tokens and app secrets are stored separately with restricted server-side access.
- AI & automation processing — message text and context needed to generate AI replies, run automations, sequences, and flows; model usage and cost events logged in our usage records.
- Billing — plan selection, trial status, and payment references from processors such as SSLCommerz or bKash (we do not store full card numbers on our servers).
- Website & support — newsletter sign-ups, contact form submissions, and basic technical logs (IP address, browser type, timestamps) for security and reliability.
- Integrations — when you use developer keys or connect an online store or live data source, we process payloads according to your configuration.
How we use information
We use collected information to:
- Provide and operate the CRM — inbox, leads, automations, flows, sequences, broadcasts, reports, usage tracking, team permissions, and mobile access.
- Deliver messages you send and receive through connected channels on your instructions.
- Run AI auto-reply and live data answers when you enable those features.
- Power online store automations (order updates, catalog sync) when you connect a store.
- Process subscriptions, trials, and local payment methods where offered.
- Improve reliability, prevent abuse, and secure multi-tenant workspaces (each organization’s data is scoped by organization ID and access controls).
- Send product updates or respond to support requests when you contact us.
Legal bases (where applicable)
Depending on your location, we rely on performance of a contract (providing the service you signed up for), legitimate interests (security, product improvement), and consent where required (for example marketing emails or certain channel connections you initiate through Meta OAuth).
How we share information
We do not sell your personal information. We share data only as needed to operate the service:
- Messaging platforms — Meta (WhatsApp Cloud API, Messenger, and Instagram) when you connect those channels and send or receive messages.
- Infrastructure — Supabase, Inc. (database, authentication, storage, realtime) and DigitalOcean, LLC (application and WhatsApp gateway hosting on secured cloud servers).
- AI providers — OpenRouter and the underlying model providers you select in Settings (for example OpenAI when using openai/gpt-4o-mini), limited to message text and context required to generate a response.
- Payment processors — SSLCommerz, bKash, or other gateways you choose for billing.
- Service providers — email delivery, monitoring, or support tools under confidentiality obligations.
- Legal requirements — when required by law, court order, or to protect rights, safety, and security.
Data processors and subprocessors
We use the following categories of service providers that process personal information and Meta Platform Data (such as WhatsApp user identifiers, message content, profile information, and channel access tokens) on our behalf to deliver NextPilot Chat:
- Supabase, Inc. — cloud database, authentication, storage, and realtime services; stores workspace data, conversation threads, channel identifiers, and channel access tokens.
- DigitalOcean, LLC — cloud infrastructure hosting the NextPilot web application and WhatsApp message gateway that processes inbound and outbound messages through connected Meta channels.
- OpenRouter — routes AI requests to the model you configure; processes message text and conversation context when AI auto-reply or AI assist features are enabled.
- Underlying AI model providers (for example OpenAI when you select openai/gpt-4o-mini) — generate AI responses from the content sent via OpenRouter.
- Meta Platforms, Inc. — WhatsApp Cloud API, Messenger, and Instagram APIs used to deliver messages you send and receive through channels you connect.
- Payment processors — SSLCommerz, bKash, or other gateways for subscription billing (they do not receive WhatsApp message content).
Data retention
We retain workspace data while your account is active and for a reasonable period afterward so you can export or recover information, unless you request deletion sooner.
Message and CRM records may be retained according to your workspace settings and legal obligations. Usage and audit logs may be kept longer for billing and security.
Your choices and rights
Depending on applicable law, you may have the right to access, correct, export, or delete personal data, or object to certain processing. Workspace owners can:
- Disconnect WhatsApp, Messenger, or Instagram channels from Settings → Channels.
- Manage team access and roles from the Team area.
- Exclude opted-out contacts from broadcasts and respect WhatsApp marketing rules.
- Contact hello@nextpilot.chat to request account or workspace deletion.
Security
We use encryption in transit (HTTPS), organization-scoped access controls, row-level security in our database, and server-side storage for channel secrets. See our Security page for more detail.
Children
NextPilot Chat is a business service not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. We will post the revised version on this page and update the “Last updated” date. Continued use of the service after changes constitutes acceptance of the updated policy.