This Privacy Policy explains how Hellopixels LLC, the operator of Hellopixels Central Integration Service ("we", "us", or "our"), collects, uses, stores, and protects information when businesses use our provider onboarding, OAuth connection, webhook relay, and related CRM integration services. This includes WhatsApp, Google, and Microsoft provider connections where enabled by the connected CRM.
1. Service Overview
Hellopixels Central Integration Service is a central provider integration service for client-hosted CRM deployments. It helps business customers connect their own provider accounts to an authorized CRM and routes the resulting connection or webhook data to the correct CRM instance.
Depending on the CRM features enabled, Hellopixels Central Integration Service may support WhatsApp Embedded Signup and webhook relay, Gmail mailbox connections, Google Calendar and Google Meet scheduling, Microsoft mailbox connections, and Microsoft Teams meeting connections.
For OAuth connections, Hellopixels Central Integration Service creates a short-lived authorization session, exchanges the provider authorization code, and returns the resulting connection details to the authorized CRM. The CRM then uses the granted provider permissions for the user-requested feature. Hellopixels Central Integration Service may also exchange a refresh token supplied by the authorized CRM for a new provider access token when the CRM calls the token-broker refresh endpoint.
This service is not operated by Meta, Google, Microsoft, Facebook, Instagram, WhatsApp, or Teams. Those providers are governed by their own terms, policies, and privacy notices.
2. Information We Collect
Depending on how the integration is used, we may process the following information:
- Provider account and profile information, such as an account email address, display name, provider user ID, and account status.
- OAuth session and authorization information, including redirect state, requested scopes, authorization-code exchange data, token expiry metadata, and provider response metadata.
- Raw access and refresh tokens transiently during an OAuth exchange or refresh operation. For Google and Microsoft email or meeting connections, Hellopixels Central Integration Service redacts token values before storing the related connection metadata; the authorized CRM may retain credentials according to its own privacy and security practices. Other provider connectors may have separate token-storage behavior described by their provider-specific workflow.
- Google Gmail data when the connected CRM requests Gmail features, which may include message identifiers, headers, snippets, bodies, attachments, labels, read state, and send-related information.
- Google Calendar and Google Meet data when the connected CRM requests meeting features, which may include event titles, descriptions, times, attendees, calendar identifiers, conference details, and event update or cancellation status.
- Microsoft mailbox and calendar data when the connected CRM requests Microsoft email or Teams features.
- Business account identifiers, including WhatsApp Business Account ID, phone number ID, and business portfolio ID.
- CRM connection information, including CRM origin, callback URL, webhook relay URL, and connection status.
- WhatsApp Embedded Signup results, including authorization codes, access tokens, token metadata, and setup metadata returned by Meta.
- Webhook event data sent by Meta, including message metadata, sender identifiers, recipient identifiers, timestamps, delivery statuses, and message payloads required to operate the CRM messaging workflow.
- Administrative and audit data, including signup session identifiers, route identifiers, delivery attempts, error messages, and timestamps.
- Technical data such as IP address, request headers, logs, and security signatures needed to operate, secure, debug, and audit the service.
3. How We Use Information
We use information only for legitimate service, security, and support purposes, including to:
- Create OAuth sessions, display the appropriate provider consent screen, exchange authorization codes, and return connection details to the authorized CRM.
- Refresh provider access tokens only when requested by the authorized CRM and only for the provider scope associated with that connection.
- Enable the authorized CRM to synchronize Gmail messages, send email, update Gmail read state, schedule or update Google Calendar/Meet events, and perform the corresponding enabled Microsoft features.
- Create and complete WhatsApp Embedded Signup sessions.
- Connect a business's WhatsApp Business Account to its CRM instance.
- Verify webhook signatures and route WhatsApp webhook events to the correct CRM.
- Enable the CRM to send, receive, and manage WhatsApp communications requested by the business.
- Maintain delivery retries, audit logs, diagnostics, and operational reliability.
- Prevent fraud, abuse, unauthorized access, and security incidents.
- Comply with applicable legal, regulatory, contractual, and platform obligations.
We do not sell Google user data, use it for advertising, or use it for unrelated profiling. We do not use provider data for purposes beyond the connected CRM feature and the service, security, support, and compliance purposes described in this policy.
For Google connections, the requested permissions may include
https://www.googleapis.com/auth/gmail.modify to synchronize messages and read
state, https://www.googleapis.com/auth/gmail.send to send or reply to messages,
https://www.googleapis.com/auth/calendar.events to create, update, or cancel
calendar events and associated Google Meet conference details, and
https://www.googleapis.com/auth/calendar.calendars.readonly to verify the selected
calendar's metadata and access. We request only the permissions required by the selected CRM
feature and handle Google user data in accordance with the Google
API Services User Data Policy and its Limited Use requirements.
4. Sharing and Disclosure
We do not sell personal information. We may share or disclose information only as follows:
- With the client CRM instance that the business has authorized us to connect.
- With Meta, Google, Microsoft, WhatsApp, Google Calendar/Meet, or Microsoft Graph APIs as necessary to complete authorization, refresh a token requested by the CRM, operate the connected provider feature, or deliver webhook events.
- With infrastructure, hosting, database, monitoring, or security providers that help us operate the service under appropriate confidentiality and security obligations.
- When required by law, legal process, regulatory request, or to protect rights, safety, and security.
5. Data Retention
We retain information only for as long as needed to provide the service, maintain security, troubleshoot issues, satisfy audit requirements, and comply with legal obligations. OAuth sessions are short-lived. Redacted connection metadata, provider identifiers, webhook delivery records, route records, and audit logs may be retained while the CRM integration remains active and for a reasonable period afterward for security, support, and compliance purposes. Raw Google and Microsoft email or meeting access and refresh tokens are not retained in the corresponding Hellopixels Central Integration Service connection metadata. Other provider connection records may retain provider tokens where required for their enabled workflow. Mailbox, calendar, and meeting data stored directly in the CRM is subject to the CRM's own retention policy.
6. Data Deletion and Access Requests
A business customer may request access, correction, export, or deletion of information related to its Hellopixels Central Integration Service provider connections by contacting us at ameen@hellopixels.com.
If a request relates to a specific client CRM account, we may need to verify the request with the CRM owner or administrator before taking action. Deleting connection data may disconnect a provider from the CRM or limit service functionality. To delete mailbox, calendar, meeting, or message data already stored in the CRM, the request may also need to be submitted to the CRM owner. Users can additionally revoke Google or Microsoft access from the relevant provider account security settings.
7. Security
We use technical and organizational safeguards designed to protect information, including HTTPS transport, signed callbacks, webhook signature verification, token redaction for Google and Microsoft email/meeting connection metadata, access controls, environment-based secret management, database-backed audit records, and operational monitoring. No system is completely secure, but we work to protect information against unauthorized access, alteration, disclosure, or destruction.
8. International Processing
Information may be processed in the countries where we, our infrastructure providers, Meta, or the relevant client CRM systems operate. Where required, we use appropriate safeguards for such processing and transfers.
9. Children's Privacy
The service is intended for business use and is not directed to children. We do not knowingly collect information from children through this service.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and make the revised policy available at this URL.
11. Contact Us
For privacy questions or data requests, contact Hellopixels LLC at ameen@hellopixels.com.