Privacy Policy
Last updated July 12, 2026
This Privacy Policy explains how Mesh CRM, a product operated by Meshever ("we", "us"), collects, uses, and protects information when a business uses Mesh CRM to run an AI messaging agent across WhatsApp, Messenger, and Instagram. Questions: info@meshever.com.
Who we are
Mesh CRM is operated by Meshever. Our principal office is 560/C, Road-5, Shantibag R/A, Agrabad, Chittagong, Bangladesh, with a secondary office at 138 Sheridan Ave, Brooklyn, NY, United States.
For any privacy or data request, contact info@meshever.com.
Data we process and why
We process two broad categories of data. Business (vendor) account data — the details a business provides to create and run its workspace: name, email, login credentials, plan and billing status, connected-channel identifiers, and knowledge-base content the business uploads.
End-customer messaging data — when a customer messages a business through a connected channel, we process the message content, the customer's channel identifier (e.g. a Messenger/Instagram-scoped id or WhatsApp phone number), display name where provided, and conversation metadata.
We process this data solely to provide the service: routing messages to the correct business, generating grounded AI replies from that business's own knowledge base, enforcing plan limits, and handing conversations to a human agent when needed.
Meta Platform data
When a business connects a WhatsApp, Messenger, or Instagram channel, that connection and the resulting message flow are handled through Meta's APIs and our messaging infrastructure. We access only the Page, Instagram account, or WhatsApp Business identifiers and the message events needed to operate the agent for that business.
We do not sell Meta Platform data, we do not use it for advertising, and we do not share it with third parties except the subprocessors listed below that are strictly necessary to deliver the service. Use of Meta data complies with the Meta Platform Terms and Developer Policies.
Service providers (subprocessors)
The inbox where your team reads, replies to, and takes over conversations runs on our own self-hosted infrastructure — conversation content is not handed to a separate inbox vendor.
We rely on a small set of processors to run the service, each bound to protect the data they handle:
- Our large-language-model provider — generates AI replies from the business's knowledge-base context; prompts are scoped per business.
- Cloud hosting and database providers that store the data described above.
Tenant isolation
Each business is a separate tenant. Knowledge base, tools, conversations, and audit trail are isolated at the database level, and the agent only ever loads context scoped to that business. Content is never merged across businesses.
Data retention
We retain data for as long as the business account is active and as needed to provide the service. When an account is closed or terminated, business data is deleted after a short purge window, while a minimal, anonymized record may be retained where required for audit, security, or legal compliance.
Your rights and choices
You may request access to, correction of, or deletion of your data by emailing info@meshever.com. End users can also have their data deleted automatically — see our Data Deletion policy at /legal/data-deletion.
International data transfers
Meshever operates in both Bangladesh and the United States. Data may be processed in either location; we apply consistent safeguards regardless of where processing occurs.
Children
The service is intended for businesses and is not directed to children. We do not knowingly collect data from children.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the effective date at the top of this page.
Contact
Meshever, 560/C, Road-5, Shantibag R/A, Agrabad, Chittagong, Bangladesh. Email info@meshever.com · +88 01742 494424 (BD) · +1 516-298-4870 (US).