Legal

Privacy policy

This policy explains what personal data Frictionless handles, why, and the choices you have. Frictionless is operated by Geteazra LTD, a company registered in Nigeria.

Last updated 14 September 2026

1. Who this policy covers

Frictionless is a customer-support tool. Businesses (“our customers”) use it to receive and reply to messages from their own customers (“end users”) on WhatsApp and through a chat widget on their website.

  • Account data belongs to the people who sign up and use the Frictionless dashboard. For this data, Geteazra LTD is the data controller.
  • Conversation data means the messages and details of end users. For this data, the business using Frictionless is the data controller, and Geteazra LTD processes it on the business’s behalf and on its instructions.

2. Data we collect

Account data

  • Your name, work email address and password (stored only as a one-way hash).
  • Your business name, industry, and your role in the workspace.
  • Invitations you send to teammates, including their email addresses.

Conversation data (processed for our customers)

  • Messages exchanged between a business and its end users, including text and descriptions of media.
  • End users’ WhatsApp phone numbers and WhatsApp profile names.
  • An anonymous visitor identifier for people who chat through the website widget.
  • Context a business chooses to send about an interaction, such as an order reference, an amount or the page the visitor was on. For people who arrive from a Click-to-WhatsApp ad, we also receive details of that ad.
  • Details a business chooses to send about its own users through our Context API, such as their user ID in the business’s system, name, email address, phone number, account attributes (for example a plan or verification status) and events (for example a failed payment).
  • Message delivery status (sent, delivered, read, failed).

WhatsApp connection data

When a business connects WhatsApp through Meta, we store its WhatsApp Business Account ID, phone number ID, display number and verified name, and an access token issued by Meta. Access tokens are encrypted before they are stored.

Technical data

A sign-in token stored in your browser to keep you logged in, and server logs (such as request times and errors) that we use to keep the service running and secure.

We also count visits to our public website so we know which pages people find useful. This measurement is anonymous: it sets no advertising cookies, does not follow you to other websites, and cannot be used to identify you.

3. How we use data

  • To provide the service: delivering messages, showing conversations to the right team, and sending replies.
  • To create and secure accounts, and to let owners invite and manage teammates.
  • To diagnose problems, prevent abuse, and keep the service reliable.
  • To contact you about your account or important changes to the service.

We do not sell personal data, and we do not use conversation data or data received from Meta’s WhatsApp Business Platform for advertising or to build profiles for third parties. Data received through WhatsApp is used only to provide the service to the business that connected it.

4. Legal basis

We process account data to perform our contract with you and for our legitimate interest in running a secure service. Conversation data is processed on the instructions of the business that controls it, which is responsible for having a lawful basis to communicate with its end users. We comply with the Nigeria Data Protection Act 2023 and, where it applies, the EU and UK GDPR.

5. Who we share data with

We share data only with service providers that help us run Frictionless:

  • Meta Platforms, to send and receive WhatsApp messages for businesses that connect the WhatsApp Business Platform. Meta’s handling of that data is governed by WhatsApp’s own terms and policies.
  • Neon, our database provider. Data is stored in its London (United Kingdom) region.
  • Render, our cloud hosting provider, which runs the application servers.
  • Vercel, which serves our website and provides the anonymous visit counts described above.

We may also disclose data if required by law, or to protect the rights and safety of our users or the public. Because our providers operate outside Nigeria, data may be transferred internationally; we rely on providers that offer appropriate safeguards for such transfers.

6. Requests from public authorities

Governments, regulators and law enforcement agencies sometimes ask service providers for personal data. We handle any such request for personal data, including data received from Meta, as follows:

  • Legal review. Every request is reviewed to confirm it is valid, comes from an authority with the power to make it, and is backed by an applicable law or court order. We do not respond to informal or unverified requests.
  • Challenging unlawful requests. If a request is unclear, too broad, or appears unlawful, we ask for clarification, seek to narrow it, or challenge it through the available legal channels before disclosing anything.
  • Data minimization. When we are legally required to disclose data, we provide only the minimum information necessary to satisfy the request.
  • Documentation. We keep a record of each request, the authority that made it, the legal basis given, our response, and the reasoning and people involved in the decision.
  • Notice. Where the law allows, we notify the affected business before disclosing its conversation data, so it can respond or object.

7. How long we keep data

We keep account and conversation data for as long as the workspace is active. When a business disconnects WhatsApp, we delete its stored access token immediately. When a workspace is deleted, or we receive a valid deletion request, we delete the associated personal data within 30 days, except where the law requires us to keep it longer.

8. Security

  • Data is encrypted in transit (HTTPS).
  • Passwords are stored as salted one-way hashes; WhatsApp access tokens are encrypted at rest (AES-256).
  • Each business’s data is isolated to its own workspace, and only its members can access it.
  • Messages from Meta are verified by signature before we accept them.

9. Your rights

Depending on where you live, you can ask to access, correct, delete or receive a copy of your personal data, object to or restrict how it is processed, and withdraw consent. If you are an end user who messaged a business, please contact that business first, because it controls your conversation data. We will help it respond. You can also contact us directly, and you may complain to the Nigeria Data Protection Commission.

To have data deleted, follow the steps on our data deletion page.

10. Children

Frictionless is a business tool and is not intended for anyone under 18.

11. Changes to this policy

We will update this page when our practices change and revise the date at the top. For significant changes we will notify account owners by email.

12. Contact

Questions or requests about privacy: appfrictionless@gmail.com. Geteazra LTD, Nigeria.