Privacy Policy
How CtrlLane handles business, contact, and platform data
CtrlLane helps businesses manage contacts and customer conversations across WhatsApp, Instagram, voice calling, data sources, APIs, and webhooks. This policy explains what data we process, why we process it, how we protect it, and how users can request access, correction, export, or deletion.
Information we process
We may process account details, login identifiers, business profile details, verified phone numbers, contact details, campaign names and source metadata, message content, media attachments, call recordings or transcripts when enabled, uploaded knowledge files, product or invoice data, structured data fields, delivery reports, wallet and billing activity, support requests, audit logs, and technical logs needed to run and secure the service.
Meta, WhatsApp, Instagram, and Google data
If a user connects Meta, Facebook, Instagram, WhatsApp Business, or Google services, we process the account, page, business, phone number, messaging, template, contact, webhook, and permission data required to provide the connected feature. We use this platform data only to operate the requested integration, display connection status, send or receive permitted business communications, maintain delivery and audit records, troubleshoot failures, and comply with provider policies.
How we use information
We use information to authenticate users, route conversations, send messages or calls requested by a business, power AI-assisted replies and summaries, maintain delivery reports, manage wallet usage, provide support, prevent abuse, secure the platform, investigate errors, and improve reliability.
AI processing
AI features may use configured business knowledge, structured contact fields, conversation history, call transcripts, source data, and workflow rules to draft replies, summarize conversations, classify interest, suggest next actions, or run approved voice and messaging flows. Businesses remain responsible for configuring agents, knowledge sources, consent, and message content for their use case.
Sharing and providers
We share data only with service providers needed to operate requested channels, such as Meta and WhatsApp Business Platform services, telecom and messaging providers, AI model providers, cloud infrastructure, storage providers, business software integrations, analytics, security, and support tools. We do not sell contact, customer, message, or platform data.
Consent and customer communications
Businesses using CtrlLane are responsible for ensuring they have the required consent, opt-in, permission, or lawful basis before contacting contacts or customers through WhatsApp, Instagram, SMS, voice calling, or any other channel. Businesses must follow applicable laws and provider rules for templates, service windows, opt-outs, calling, and promotional or transactional communication.
Security
We use access controls, encrypted credential storage, HTTPS, audit records, and tenant separation controls to protect business data. Production provider secrets and OAuth credentials are stored server-side and are not exposed in browser code. Users should keep their login credentials confidential and restrict access to accounts, connected businesses, and communication channels.
Retention and deletion
We keep data for as long as needed to provide the service, comply with legal, billing, security, dispute, audit, and abuse-prevention requirements, or as configured by the business. Users and connected businesses can request export or deletion of their data. Deletion instructions are available at /data-deletion.
Contact
For privacy questions, data access, correction, export, or deletion requests, contact info@ctrllane.com.
Last updated: August 27, 2026