Privacy Policy

Hellopixels Central Integration Service provider onboarding, OAuth connection, and webhook relay service

Last updated: July 13, 2026

This Privacy Policy explains how Hellopixels LLC, the operator of Hellopixels Central Integration Service ("we", "us", or "our"), collects, uses, stores, and protects information when businesses use our provider onboarding, OAuth connection, webhook relay, and related CRM integration services. This includes WhatsApp, Google, and Microsoft provider connections where enabled by the connected CRM.

1. Service Overview

Hellopixels Central Integration Service is a central provider integration service for client-hosted CRM deployments. It helps business customers connect their own provider accounts to an authorized CRM and routes the resulting connection or webhook data to the correct CRM instance.

Depending on the CRM features enabled, Hellopixels Central Integration Service may support WhatsApp Embedded Signup and webhook relay, Gmail mailbox connections, Google Calendar and Google Meet scheduling, Microsoft mailbox connections, and Microsoft Teams meeting connections.

For OAuth connections, Hellopixels Central Integration Service creates a short-lived authorization session, exchanges the provider authorization code, and returns the resulting connection details to the authorized CRM. The CRM then uses the granted provider permissions for the user-requested feature. Hellopixels Central Integration Service may also exchange a refresh token supplied by the authorized CRM for a new provider access token when the CRM calls the token-broker refresh endpoint.

This service is not operated by Meta, Google, Microsoft, Facebook, Instagram, WhatsApp, or Teams. Those providers are governed by their own terms, policies, and privacy notices.

2. Information We Collect

Depending on how the integration is used, we may process the following information:

3. How We Use Information

We use information only for legitimate service, security, and support purposes, including to:

We do not sell Google user data, use it for advertising, or use it for unrelated profiling. We do not use provider data for purposes beyond the connected CRM feature and the service, security, support, and compliance purposes described in this policy.

For Google connections, the requested permissions may include https://www.googleapis.com/auth/gmail.modify to synchronize messages and read state, https://www.googleapis.com/auth/gmail.send to send or reply to messages, https://www.googleapis.com/auth/calendar.events to create, update, or cancel calendar events and associated Google Meet conference details, and https://www.googleapis.com/auth/calendar.calendars.readonly to verify the selected calendar's metadata and access. We request only the permissions required by the selected CRM feature and handle Google user data in accordance with the Google API Services User Data Policy and its Limited Use requirements.

4. Sharing and Disclosure

We do not sell personal information. We may share or disclose information only as follows:

5. Data Retention

We retain information only for as long as needed to provide the service, maintain security, troubleshoot issues, satisfy audit requirements, and comply with legal obligations. OAuth sessions are short-lived. Redacted connection metadata, provider identifiers, webhook delivery records, route records, and audit logs may be retained while the CRM integration remains active and for a reasonable period afterward for security, support, and compliance purposes. Raw Google and Microsoft email or meeting access and refresh tokens are not retained in the corresponding Hellopixels Central Integration Service connection metadata. Other provider connection records may retain provider tokens where required for their enabled workflow. Mailbox, calendar, and meeting data stored directly in the CRM is subject to the CRM's own retention policy.

6. Data Deletion and Access Requests

A business customer may request access, correction, export, or deletion of information related to its Hellopixels Central Integration Service provider connections by contacting us at ameen@hellopixels.com.

If a request relates to a specific client CRM account, we may need to verify the request with the CRM owner or administrator before taking action. Deleting connection data may disconnect a provider from the CRM or limit service functionality. To delete mailbox, calendar, meeting, or message data already stored in the CRM, the request may also need to be submitted to the CRM owner. Users can additionally revoke Google or Microsoft access from the relevant provider account security settings.

7. Security

We use technical and organizational safeguards designed to protect information, including HTTPS transport, signed callbacks, webhook signature verification, token redaction for Google and Microsoft email/meeting connection metadata, access controls, environment-based secret management, database-backed audit records, and operational monitoring. No system is completely secure, but we work to protect information against unauthorized access, alteration, disclosure, or destruction.

8. International Processing

Information may be processed in the countries where we, our infrastructure providers, Meta, or the relevant client CRM systems operate. Where required, we use appropriate safeguards for such processing and transfers.

9. Children's Privacy

The service is intended for business use and is not directed to children. We do not knowingly collect information from children through this service.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and make the revised policy available at this URL.

11. Contact Us

For privacy questions or data requests, contact Hellopixels LLC at ameen@hellopixels.com.