Last updated: July 2026
Welcome to Careflow. Careflow is a customer conversation management platform that helps businesses connect authorized messaging and social channels, manage customer conversations, support customer service teams, and operate chatbot-assisted workflows. This Privacy Policy explains how Careflow collects, uses, stores, protects, and shares information when users access our website, platform, applications, dashboards, APIs, integrations, and related services.
By accessing, registering, using, or interacting with Careflow, you acknowledge that you have read, understood, and agreed to this Privacy Policy. If you do not agree with this Privacy Policy, you should not access or use Careflow or any related services.
“Personally Identifiable Information” refers to information that can be used to identify, contact, or locate an individual, customer, business user, or authorized representative. This may include names, email addresses, phone numbers, profile information, user IDs, business information, login credentials, customer communication records, message content, IP addresses, browser information, device information, and other information provided through Careflow or connected services.
Personally Identifiable Information does not include anonymous, aggregated, or de-identified information that cannot reasonably be used to identify a specific individual.
We may collect information from visitors, registered users, customers, organizations, and authorized representatives who access or use Careflow. This information may include account registration details, business contact information, user roles and permissions, connected channel information, customer conversation records, chatbot interaction records, support activity data, website interaction data, device information, browser information, and data generated through the use of our services.
Information may be collected directly when users submit forms, register accounts, configure integrations, manage customer conversations, create chatbot workflows, or use platform features. Information may also be collected through APIs, cookies, analytics tools, third-party integrations, and connected services, including Meta/Facebook, Instagram, Zalo, TikTok, X, Google/YouTube, LinkedIn, and other supported platforms where applicable.
Careflow may integrate with third-party platforms, APIs, webhooks, business tools, messaging systems, and social channels. When users connect a third-party platform to Careflow, we may access or process information that is necessary to provide customer conversation management functionality. This may include Page, Official Account, channel, or business account information, customer user IDs, display names, profile pictures, message content, attachments, timestamps, conversation status, message events, tags, notes, assignment data, and related metadata.
Careflow only accesses connected platform data after authorization is granted by the business owner, administrator, or authorized user through the official authorization flow or approved API configuration. The type of data received depends on the permissions granted, the relevant platform API, platform approval requirements, and customer configuration.
We use collected information to provide, operate, maintain, secure, and improve Careflow and related services. This includes connecting authorized business channels, receiving and displaying customer messages, enabling authorized team members to reply to customer conversations, supporting chatbot-assisted workflows, organizing inbox conversations, managing tags, notes, statuses, and assignments, providing reporting, administering user accounts, monitoring system performance, and improving user experience.
We may also use information to respond to support requests, send service-related notifications, verify account access, prevent fraud, protect system security, troubleshoot technical issues, and comply with applicable legal, regulatory, or platform requirements.
Careflow uses data from connected platforms only for the purposes required to provide the services authorized by the business user. These purposes may include customer conversation management, inbox synchronization, message handling, chatbot assistance, customer support workflows, reporting, integration maintenance, and technical support.
We do not sell Meta/Facebook, Instagram, Zalo, TikTok, X, Google/YouTube, LinkedIn, or other connected platform data. We do not use connected platform data for unrelated purposes, unauthorized advertising, unauthorized profiling, or resale. Users are responsible for ensuring that their use of Careflow and connected platform integrations complies with applicable platform terms, developer policies, and laws.
Careflow does not sell personal data. Careflow does not share customer conversation data with unrelated third parties for independent marketing or resale. Careflow does not access any Page, Official Account, channel, or business account without authorization. Careflow does not use connected platform data for unauthorized advertising or unrelated profiling. Careflow does not use connected platform data to train public AI models unless explicitly permitted by the customer and allowed by applicable platform policies.
Careflow may use cookies, session identifiers, analytics technologies, and similar tracking tools to support platform functionality, maintain secure sessions, remember user preferences, analyze usage patterns, monitor platform performance, and protect against unauthorized access. Users may choose to disable cookies through their browser settings. However, some platform features may not function properly if cookies are disabled, especially features related to login sessions, security, and personalized user experience.
We do not sell Personally Identifiable Information to third parties. We may share information only when necessary to provide our services, operate the platform, support integrations requested by users, comply with legal obligations, protect the security of the platform, or work with trusted service providers who assist us in hosting, infrastructure, analytics, communication, security, or technical operations.
Access to information is limited to authorized employees, administrators, vendors, or service providers who need such access for legitimate business or operational purposes. These parties are expected to handle information securely and only for the purposes for which access is provided.
We implement commercially reasonable security measures designed to protect information from unauthorized access, disclosure, alteration, misuse, or destruction. These measures may include HTTPS connections, access controls, authentication procedures, secure token handling, monitoring systems, internal security practices, and infrastructure protection mechanisms.
Although we take reasonable steps to protect information, no method of electronic transmission or storage is completely secure. Users acknowledge that online systems may be subject to errors, unauthorized access, technical failures, or other security risks, and we cannot guarantee absolute security.
Careflow retains information only for as long as necessary to provide services, maintain business records, comply with legal obligations, resolve disputes, support security operations, and meet platform or operational requirements. When a third-party integration is disconnected, Careflow will stop using the related access tokens or refresh tokens for that integration.
Users or business customers may request deletion or deactivation of certain personal data or account data by contacting us. In some cases, certain information may remain in backup systems, logs, archived records, or records required for legal, security, compliance, or operational purposes. Where deletion is requested, we will make reasonable efforts to ensure that the information is no longer actively used for ordinary business purposes unless retention is required or permitted by law.
Users may contact us to request access to their information, correct inaccurate information, update account details, disconnect a platform integration, or request deletion or deactivation of certain personal data. We will review and respond to such requests in accordance with applicable laws, platform requirements, and operational limitations.
Careflow may contain links to third-party websites, applications, tools, or services. When users access third-party services, they are subject to the privacy policies and practices of those external providers. We are not responsible for the content, privacy practices, security practices, or data handling procedures of third-party websites or services.
We reserve the right to modify or update this Privacy Policy at any time. Updated versions will be posted on this page with the revised effective date. Continued use of Careflow after any changes are published constitutes acceptance of the updated Privacy Policy.
If you have any questions regarding this Privacy Policy or wish to submit a request related to your information, please contact us at: