Privacy Policy

Last updated: July 24, 2026

1. Who We Are

Cresa is operated by Crest Sync (Private) Limited (“Cresa,” “we,” “us,” or “our”), a company registered in Pakistan. Cresa is a multi-tenant business-communication platform that helps authorized businesses (“Business Customers”) manage conversations, automate workflows, and send AI-assisted responses across connected channels including WhatsApp, Facebook Messenger, Instagram, website chat, and email.

For most data processed through connected channels, the Business Customer is the data controller and Cresa acts as their processor, handling data on their behalf and under their instructions. For our own account, billing, and service-operations data, Cresa acts as the controller. Questions about this policy can be sent to hello@crestsync.com.

2. Information We Process

We process the following categories of information:

  • Account & business data: name, email, password (hashed), role, organization details, and settings for Business Customers and their team members.
  • Connected platform data (Meta): when a Business Customer connects a channel, we process page and account identifiers, WhatsApp Business Account and phone-number identifiers, message content, comments, mentions, media attachments, sender profile names and identifiers, timestamps, and message-status events — strictly to deliver inbox, automation, analytics, and reply features.
  • End-customer data: information about the people who message a Business Customer (e.g., phone number, display name, and the content they send), processed so the Business Customer can respond and manage the relationship.
  • Billing data: subscription, plan, and payment status. Card payments are handled by our payment processor (Paddle); we do not store full card numbers.
  • Technical & usage data: log data, device/browser information, IP address, and session cookies necessary to authenticate users and secure the service.

3. How We Use Information

We use information to:

  • display conversations and route messages to human agents;
  • generate AI-assisted replies and voice responses at a Business Customer’s direction;
  • send messages, templates, and interactive flows on behalf of authorized businesses;
  • provide analytics, monitor channel health, and maintain service security and auditability;
  • process subscriptions and prevent fraud or abuse;
  • comply with legal obligations and platform requirements.

4. AI Processing

Where a Business Customer enables AI features, message content and related context may be sent to third-party AI providers to generate suggested or automated replies, summaries, transcriptions, or voice output. These providers currently include OpenAI, Google (Gemini), and ElevenLabs. We send only the data needed to perform the requested task. We do not use message content to train our own models, and we instruct AI providers to process data solely to return a result to the service. AI-generated responses can be inaccurate; Business Customers are responsible for reviewing them before enabling automated replies in production.

This includes media a customer sends: voice notes are transcribed and images are analysed so their content can be read in the inbox and answered. These AI providers are located outside Pakistan, so enabling AI features involves an international transfer of the message content concerned. Business Customers can disable AI features at any time, after which no message content is sent to these providers.

5. How We Share Information

We do not sell personal data and we do not use Meta platform data for advertising or cross-context profiling. We share information only as needed to operate the service, with the following categories of sub-processors:

  • Cloud hosting & infrastructure (Railway) — to run the application.
  • Database & storage (MongoDB and object/file storage) — to store service data.
  • AI providers (OpenAI, Google, ElevenLabs) — to generate AI-assisted output as described above.
  • Error monitoring (Sentry) — to detect and diagnose faults in the service. Diagnostic reports can incidentally include message content present at the moment of an error.
  • Payment processing (Paddle) — to manage subscriptions and payments. Paddle does not receive message content or Meta platform data.
  • Messaging platforms (Meta / WhatsApp) — to deliver and receive messages you authorize.

We may also disclose information where required by law, to protect our rights or the safety of others, or in connection with a corporate transaction, subject to appropriate safeguards.

6. Meta Platform Data

Our use of information obtained through Meta APIs (WhatsApp Business Platform, Messenger, and Instagram) complies with the Meta Platform Terms and Developer Policies. We access this data only with the Business Customer’s authorization, use it solely to provide the features they enable, and do not sell it or use it for unrelated purposes. When a Business Customer disconnects a channel or removes our app from their business, we stop processing the associated platform data and delete or anonymize it in accordance with Section 8.

7. International Transfers

We operate globally and our service providers may process data in countries other than your own, including outside Pakistan. Where we transfer personal data internationally, we rely on appropriate safeguards and require our providers to protect the data consistent with this policy.

8. Data Retention

We retain data only for as long as needed to provide the service, satisfy legal or contractual obligations, resolve disputes, and enforce our agreements. Connected platform data is retained while a channel remains connected and is deleted or anonymized following disconnection or a valid deletion request, typically within 30 days, subject to legal retention requirements.

9. Security

We use reasonable administrative, technical, and organizational controls to protect account credentials, conversation data, and configuration — including encryption in transit, access controls, and hashed passwords. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

10. Your Rights & Choices

Business Customers can disconnect channels, disable AI automation, export or delete records, and close their account at any time from the dashboard or by contacting us. End-customers who messaged a business through Cresa should contact that business directly to exercise rights over their data, since the business controls it; you may also contact us and we will route the request to the relevant business. Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data.

11. Data Deletion

To request deletion of data processed by Cresa, see our Data Deletion page or email hello@crestsync.com.

12. Cookies

We use strictly necessary cookies to authenticate users and keep sessions secure. We do not use advertising cookies. You can control cookies through your browser, though disabling essential cookies may prevent you from signing in.

13. Children’s Privacy

Cresa is a business tool not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us data, contact us and we will delete it.

14. Changes to This Policy

We may update this policy from time to time. We will revise the “Last updated” date above and, where appropriate, provide additional notice. Continued use of the service after changes take effect constitutes acceptance.

15. Contact

Crest Sync (Private) Limited — Pakistan.
Privacy inquiries: hello@crestsync.com.