Privacy Policy
Effective date: August 20, 2026
1. Introduction
This Privacy Policy explains how Meerlume LLC, a limited liability company registered in the Republic of Armenia (operator of the Meerlume service, “Meerlume,” “we,” “us”) collects, uses, shares, and protects personal data when you use our bot-building platform for WhatsApp, Telegram, the chat widget you can embed on your own website, and related channels. Depending on where you are and which laws apply to the processing, you may have rights over your personal data — section 9 describes the rights we honour and how to use them. Some of those we grant to everyone as a matter of policy rather than because a particular statute requires it, and section 9 says which.
Two roles are relevant to this policy:
- For your account information and your use of Meerlume, we are the data controller.
- For data collected by your bots from your end customers (their messages, phone numbers, names, booking details), you are the controller and we act as your processor. Our Data Processing Addendum contains the Article 28 processor terms and the transfer terms for EEA, UK and Swiss customers. Those form part of the Terms of Service automatically, as section 11 of the DPA explains.
2. Information We Collect
Account data. When you sign up we collect your email, name, and password (stored hashed). If you choose Google sign-in, Google authenticates your Google account and returns the basic profile information and tokens we need to create or open your Meerlume account. An email address and a password or linked Google account are necessary to create and run a Meerlume account; without them we cannot provide the Service.
Bot configuration data. Bot names, descriptions, flow definitions, prompts, instructions, channel settings, and any drafts you save while using the builder, including the chat transcript of your conversation with the AI builder.
Channel credentials. If you connect a WhatsApp Business or Telegram bot, we store the relevant identifiers and tokens: your WhatsApp Business Account (WABA) ID, phone-number ID, display phone number, and access token; and, for Telegram, the bot token. These credentials are encrypted at rest.
Notification settings. If you enable owner notifications, we store your notification preferences and the delivery details needed to reach you — for example, the Telegram chat identifier created when you link our notification bot, or a per-bot notification address. Notifications themselves contain submission details (such as the booking summary your template includes).
Support requests. If you contact support, we receive the email address, subject, category, and message you submit, and we retain that correspondence to resolve your request.
End-customer data your bots collect. When your end customers interact with your bots on WhatsApp, Telegram, or the chat widget on your website, we receive and store their messages, the phone numbers or usernames the messaging platform exposes where it exposes any, the structured answers they provide to your bot’s questions, conversation transcripts (including messages you exchange with a customer when you take over a conversation), and any booking details they submit (including name, contact details, time slot, and notes). We process this data on your behalf to deliver the Service.
Website chat. If you embed our chat widget on your own site, we also receive a random session identifier the visitor’s browser creates and discards when the tab closes, the address of the site the widget is loaded on, and the IP address and request metadata involved in serving the chat itself. Website chat does not require a visitor to give a name or an email address, and exposes no phone number or platform username. It is not anonymous, though: a session identifier, an IP address, request metadata, the site address and the message content may all be personal data on their own. What is true is that once the session identifier is gone we may be unable to tie a transcript to the person asking about it without more information from them or from you. The widget does not read your site’s cookies and does not follow visitors between sites.
Payment data. Subscription payments are processed by Paddle as Merchant of Record. We do not receive or store full payment-card details; we receive only transaction-level data such as plan, status, last four digits, and billing country needed to provision your subscription.
Technical data. Our backend automatically logs IP addresses and request metadata for security, debugging, and abuse-prevention purposes. We also use a small number of cookies and local-storage entries described in section 10.
3. How We Use Information
- To provide, operate, and maintain the Service.
- To authenticate you, secure your account, and prevent abuse.
- To deliver your bot’s messages to and from end customers via the chosen messaging platform.
- To send you the notifications you have configured about activity in your bots — in the dashboard, by Telegram, or by email — such as new submissions awaiting your review.
- To diagnose issues, and to improve the Service and develop new features — for that last purpose using the account and usage information we hold as controller, and information aggregated or deidentified so that it cannot reasonably be used to identify a person or a customer.
- To communicate with you about service updates, security notices, and (with your consent where required) marketing.
- To comply with legal obligations and respond to lawful requests.
4. Legal Bases for Processing (GDPR / UK GDPR)
- Contract — to provide the Service you have signed up for.
- Legitimate interests — to keep the Service secure, prevent fraud, and improve our product.
- Consent — for any optional marketing communications and any non-essential cookies (we do not currently use any).
- Legal obligation — to comply with applicable law and respond to lawful requests from authorities.
5. Provider List
This is our Provider List, referred to by the Data Processing Addendum. A small number of providers are involved in running the Service, and what we owe you for each depends on the role it actually plays, so they are grouped by role rather than listed flat.
Sub-processors we appoint. These process your data and your end customers’ data on our instructions, on our contracts, as our sub-processors. We give notice before this group changes — see below.
- Neon (database hosting, EU — AWS eu-central-1, Frankfurt). Receives account data, bot configuration, and end-customer data your bots store.
- Railway (application hosting, EU region). Runs our backend API, the services that send and receive WhatsApp and Telegram messages, and the chat page that loads inside the website widget, so it processes everything those services handle, including message content and phone numbers.
- Cloudflare (static site hosting, DNS, CDN, and TLS termination for meerlume.com). Serves the dashboard, the marketing site, and the widget script your own site loads, and processes connection metadata such as IP addresses in that role. Your bots’ conversations are not stored by Cloudflare.
- Google (Gemini API) for AI-assisted bot building. Receives the bot content you create in the builder. Live conversations with your end customers are executed by our own flow engine and are not sent to the Gemini API. Subject to Google’s API terms.
- Brevo for email delivery. For transactional email (support correspondence and notifications you configure) it receives the recipient address and message content. If you opt in to product and marketing emails, we also sync your email address, first name, and consent state to Brevo’s contact list. If you later opt out, Brevo keeps your address on a suppression list so we cannot email you again by mistake.
Services you connect. These receive data because you switched them on. A provider in this group may act as your own processor, as an independent controller, or as our sub-processor — which one depends on the service and the contractual arrangement, not on who clicked connect. The rule we apply is functional: where we engage a provider to process your data on our behalf, it is treated as a sub-processor under the DPA and belongs in the first group, with the notice rules attached; where you contract with or instruct a provider directly, that relationship is yours. New integrations appear here as they ship.
- Meta Platforms (WhatsApp Business / Cloud API) for message routing on WhatsApp. Receives the messages, phone numbers, and metadata necessary to send and receive WhatsApp conversations.
- Telegram FZ-LLC for message routing on Telegram. Receives the messages and user identifiers necessary to operate your Telegram bot and, if you enable Telegram notifications, the owner notifications we deliver to you through our notification bot.
Our own business operations. These process your account and billing details, where we are the controller. Neither receives your end customers’ data.
- Paddle as our Merchant of Record for billing, invoicing, and tax compliance. Receives transaction and billing-country data.
- Google (Sign in with Google), if you choose it to sign in. Google authenticates your Google account and returns the profile information and tokens we need to create or open your Meerlume account. This is separate from the Gemini API above, which is a different service and receives different data.
When this list changes. Before we appoint a new sub-processor in the first group, we update this section and give at least 15 calendar days’ written notice to the account administrator before the provider receives personal data, except for an urgent security or service-continuity change — you do not have to subscribe to anything to be told. You may object during the notice period on reasonable, documented data-protection grounds, and we will work with you in good faith to find a commercially reasonable alternative; if none is reasonably available, either of us may terminate the affected part of the Service, with any refund governed by the Terms. Providers in the second group arrive when you connect them, so there is nothing for us to announce in advance. Section 5 of the Data Processing Addendum is the contractual version of this.
We do not sell, rent, lease, or trade your personal data or your end customers’ data, we do not share it for advertising, ad targeting, ad measurement, or cross-context behavioural advertising. We do not use it to train any model of our own, and we do not send it to a third-party AI provider to train theirs: your end customers’ conversations are run by our own flow engine, and only the builder text you type reaches the Gemini API, under Google’s own terms for what it does with it.
6. WhatsApp Business Platform Data
Where you connect a WhatsApp channel, Meerlume receives and processes data from Meta’s WhatsApp Business Platform (the WhatsApp Business / Cloud API) on your behalf, as your processor. This section states in one place how we handle that Platform Data.
What we receive and store. Inbound and outbound message content; the end customer’s WhatsApp phone number and profile name; message and conversation identifiers and delivery status; the structured submission payloads your bot collects (form answers, booking details, names, contact details, notes); and your channel identifiers and credentials — WABA ID, phone-number ID, display phone number, and access token.
Why we process it. Solely to run the conversational flow you configured — receiving each inbound message, evaluating it against your flow, and sending the reply — and to deliver the resulting submissions to you in your dashboard and through the notification channels you enable. We do not process Platform Data for our own independent purposes.
How long we keep it. Conversations and submissions remain available while your account is active, because they are the record of your customer relationships and you decide when they go; you can delete any conversation, contact, or bot at any time. Deleting your account in the dashboard removes the account and the records attached to it immediately; a request you send us by email is handled on the timetable in section 9. Two things outlive deletion: delivery records in our notification outbox, which can contain submission details such as a customer name and a booking time and are pruned after a short retention period; and isolated copies in our database provider’s recovery window, until it rolls forward over them. Neither is used for ordinary product purposes. Server access and security logs are kept for a limited period.
What we never do with it. We do not sell, rent, lease, or trade Platform Data. We do not use it for advertising, ad targeting, or ad measurement. We do not use it to train machine-learning or AI models. Live conversations with your end customers are executed by our own flow engine and are never sent to a third-party AI provider — the Gemini API sees only the text you type into the builder while designing a bot, never your customers’ messages.
Who else sees it. Only the sub-processors in section 5 that are needed to operate the channel: Neon (storage), Railway (the services that run the flow), and, where you turn them on, Brevo or Telegram to deliver notifications to you. We do not share Platform Data with any other third party except where required by law.
Where it lives. Primary application and database hosting is currently configured in the European Union. Authorised access from Armenia, and processing by the providers listed in section 5, may occur elsewhere — see section 7.
How to have it deleted. Account owners can delete in-app from Settings, and anyone — including an end customer who messaged one of your bots — can write to privacy@meerlume.com. Our Data Deletion page sets out both routes, what is removed, and the timelines above.
7. Where Your Data Is Stored and Processed
Your account data, bot configuration, conversations, and the data your bots collect are held in hosting currently configured in the European Union. Authorised remote access from Armenia, and processing by the providers in section 5, may occur elsewhere subject to applicable safeguards. Our database runs on Neon in AWS eu-central-1 (Frankfurt, Germany) and our application services run on Railway in an EU region. We currently operate no other storage or compute region.
Our own access from Armenia. Meerlume is operated from Yerevan, and our personnel reach the systems above remotely to run, support, and debug the Service. Armenia is not covered by a European Commission adequacy decision, so that access is a transfer out of the EU even though the data itself never leaves Frankfurt. Section 11 of our Data Processing Addendum automatically incorporates and completes the 2021 EU Standard Contractual Clauses for EEA-established customers, together with the UK and Swiss provisions described there. It also records the Armenia transfer assessment and supplementary measures. Access is limited to the people who need it, and access and security events are logged.
Some processing also happens outside the EU because the service connects to platforms and providers that operate globally: Meta routes WhatsApp messages, Telegram routes Telegram messages, Cloudflare terminates connections at the edge location nearest the visitor, Brevo delivers email, Paddle processes payments, and the Gemini API answers builder prompts. For a provider we appoint as a sub-processor, its applicable data-processing terms must cover the processing before we give it customer data. Where a provider or onward recipient processes data in a country without adequacy, we rely on the transfer mechanism applicable to that recipient and service — for example a qualifying Data Privacy Framework certification for a US recipient, or Standard Contractual Clauses in the provider’s DPA. Services you connect directly remain governed by your agreement and transfer arrangements with that service.
8. Data Retention
We retain personal data only for as long as needed for the purposes described in this policy.
- Account data is retained while your account is active. When you delete your account in the dashboard we delete it immediately, along with your bots, conversations, and end-customer data. Two categories outlive the account: delivery records in our notification outbox, which can still contain a customer name or booking time and are pruned after a short retention period, and isolated copies in our database provider’s recovery window, until it rolls forward over them. Neither is used for ordinary product purposes.
- Bot configuration and end-customer data is retained until you delete it, close your account, or give us a valid documented instruction to delete it. After that, active records are removed on the timetable described here, subject to the notification-outbox and backup lifecycle above.
- Server access and security logs are retained for a limited period, and delivery records for no longer than needed to complete and troubleshoot delivery.
- We may retain limited information for longer where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
Our Data Deletion page sets out how to request deletion, what is removed, and the billing records we must keep.
9. Your Rights
Subject to applicable law, you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data;
- request restriction of, or object to, certain processing;
- request a portable copy of your data;
- withdraw any consent you previously gave (without affecting the lawfulness of prior processing);
- lodge a complaint with your local data-protection authority.
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
California residents have additional rights under the CCPA/CPRA, including the right to know what personal information we collect, the right to delete it, and the right to opt out of “sale” or “sharing” — note that we do not sell or share personal information as those terms are defined under the CCPA.
To exercise any of these rights, email us at privacy@meerlume.com. We will respond within one month, extended where applicable law permits it — for a complex request, or a high volume of them, by a further two months, and we will tell you why. If your request concerns data your bot collected from one of your end customers, that customer should contact you (the controller) directly; we will support you in fulfilling such requests under the DPA.
10. Cookies & Local Storage
We use only strictly necessary and functional storage:
- A session cookie we set to keep you signed in.
- A small
sidebar_statecookie that remembers whether you collapsed the dashboard sidebar. meerlume-teaser-dismissed:<code>— onesessionStorageentry per bot, keyed by that bot’s share code, written on the site hosting the widget. It remembers that a visitor closed the greeting so it is not shown again in that tab. This is a display preference, not something the chat needs in order to work: if storage is unavailable the widget still runs, and the greeting may simply reappear.meerlume-session— onesessionStorageentry written on the chat frame’s own origin, which is ours rather than the host site’s. It holds the identifier that ties a visitor’s messages to their conversation, so a chat the visitor asked for cannot continue without it. Cleared when the tab closes.- Browser
localStorageentries that hold your theme preference, calendar view choice, panel-collapsed state, a flag recording whether you are signed in (used only to avoid a flash of the wrong layout), and the drafts and AI chat history you create in the bot builder before you sign up.
We do not use analytics, advertising, session replay, or cross-site tracking cookies.
If you embed the chat widget, note that the two entries above sit on different origins — the teaser flag on your own site, the session identifier on ours — and serve different purposes. Describe them in your own site’s notices as your obligations require.
11. Children's Privacy
Meerlume accounts require the minimum age stated in section 3 of the Terms. The data your bots collect is yours as controller, and you must not configure a bot to target children.
12. Security
We use appropriate technical and organisational measures including TLS in transit, encryption at rest for sensitive credentials (such as your WhatsApp access tokens and Telegram bot tokens), access controls, and least-privilege production access. No system can be guaranteed perfectly secure; if we become aware of a breach that affects you, we will notify you as required by applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The “Effective date” at the top of this page reflects the latest revision. If a change is material we will provide reasonable notice (for example, by email or through the Service) before it takes effect.
14. Contact
Questions, requests, or complaints about this Policy can be sent to privacy@meerlume.com. See also our Terms of Service, Refund Policy, and contact page.
The data controller is Meerlume LLC, a limited liability company registered in the Republic of Armenia.