ARARBOT Privacy Policy
Last updated: September 4, 2026
ARARBOT is a customer conversation management dashboard. We use Meta Platform data only to connect authorized Facebook Pages, manage Page conversations, and provide the business workflows selected by the Page or business administrator.
1. Who We Are
This Privacy Policy explains how ARARBOT collects, uses, stores, and deletes information when you use ARARBOT. You can contact us at admin@arar.vn.
2. Information We Collect
Depending on the features you enable, ARARBOT may process the following information:
- Account information used to sign in to ARARBOT, such as username and role.
- Facebook Login identifiers and basic profile information provided by Meta, such as user ID and name.
- Facebook Page information, such as Page ID, Page name, Page avatar, granted permissions, and connection status.
- Meta access tokens required to maintain authorized Page connections and send messages on behalf of connected Pages.
- Messenger conversation data for connected Pages, including message text, attachments, sender identifiers, timestamps, delivery metadata, and webhook events.
- Business asset identifiers required to let an authorized user select and manage Pages or business assets that they administer.
- If catalog features are enabled, product catalog information such as catalog IDs, item names, SKUs, prices, availability, images, and item update results.
- If utility messaging features are enabled, Page utility message templates and delivery metadata needed to send transactional or service-related messages.
We do not collect Facebook passwords. Facebook Login is handled by Meta.
3. How We Use Information
We use collected information to:
- Connect a Facebook Page or business asset after an authorized user grants permission.
- Display, sync, and manage Page conversations in the ARARBOT dashboard.
- Send replies or approved utility messages from connected Pages when a user or authorized workflow requests it.
- Manage Page metadata, webhooks, access token status, and connection health.
- Support sales and customer service workflows, including customer records, lead tracking, and conversation history.
- Operate, secure, debug, and improve the service.
4. Sharing Information
We do not sell personal information. We may share limited information with infrastructure, database, messaging, analytics, or AI service providers only as needed to operate ARARBOT. We may also disclose information when required by law or to protect the security and integrity of the service.
5. Data Retention
We retain connected Page data, conversation history, and related customer service records while the account or Page connection remains active, unless a shorter retention period is required by law or requested by an authorized administrator. Access tokens are deleted or disabled when a Page is disconnected, permission is revoked, or deletion is requested and verified.
6. Data Deletion
You can request deletion of data associated with your account or Facebook connection by contacting admin@arar.vn. You can also remove ARARBOT from your Facebook settings. When Meta sends us a valid data deletion callback, we delete the matching Facebook data stored in ARARBOT and return a confirmation status.
Data deletion instructions are available at https://asa.arar.vn/data-deletion/. The Meta data deletion callback URL for this app is https://asa.arar.vn/facebook/data-deletion/.
7. Security
We use access controls, token protection, HTTPS in production, request validation, and operational logging to protect data. No method of transmission or storage is completely secure, but we take reasonable measures to reduce unauthorized access, misuse, and loss.
8. International Processing
Information may be processed in countries where we or our service providers operate. We take reasonable steps to protect information according to this policy and applicable law.
9. Children's Privacy
ARARBOT is intended for business use and is not directed to children. We do not knowingly collect personal information from children.
10. Website Visitors and Enquiry Forms
This section covers our public marketing pages only — the home page, the industry solution pages, and these legal pages. It does not apply to the operator console, where conversation data lives.
Enquiry form. When you submit the consultation form, we collect the name and phone number you provide, plus any optional business name, industry, message volume, email and note. We also record the page you submitted from, the referring page, campaign parameters in the link you followed (UTM), and your browser user-agent string, so we can tell which channels bring genuine enquiries. Your IP address is not stored: we keep only a salted one-way hash of it, which lets us detect abuse of the form without retaining an identifier. We use this information to contact you about your enquiry, and we keep it until the enquiry is closed or you ask us to delete it.
Analytics. Our public marketing pages use Google Analytics 4 to count visits and understand which pages lead to enquiries. It sets first-party cookies in your browser and sends usage data to Google, which acts as our processor; we enable IP anonymisation. You can prevent this by blocking cookies in your browser or by installing the Google Analytics opt-out browser add-on. No analytics code runs inside the operator console.
11. Changes to This Policy
We may update this Privacy Policy when our service, legal obligations, or Meta Platform use changes. The latest version will remain available at this URL.