Privacy Policy

Last updated July 1st 2026

1. Introduction

Welcome to Alps ("Service," "Platform," "we," "us," or "our"). We are committed to protecting your privacy and ensuring transparency about how we collect, use, and process your personal data. This Privacy Policy explains our practices regarding data collection and your rights under applicable privacy laws, particularly the Nigeria Data Protection Regulation (NDPR) and other applicable Nigerian and international data protection frameworks.

This Privacy Policy applies to:

  • Users who create and manage support desks on our platform
  • Customers/visitors who interact with public support widgets
  • Team members invited to workspaces
  • Any individual whose data is processed by Alps

By accessing or using Alps, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service.

2. Data Controller & Contact Information

Data Controller & Company

Lagos, Nigeria

Email: info@tryalps.com

Compliance Officer (Data Protection)

Email: info@tryalps.com

For privacy inquiries, data subject requests, or to exercise your rights under the NDPR, contact us at info@tryalps.com. We aim to respond to all inquiries within 14 days.

3. What Personal Data We Collect

  • Account Creation & User Profile Data
    • First name, last name, email address
    • Password (stored securely via Firebase Auth)
    • Display name, profile picture, company name
    • Phone number, city, state, country
  • Workspace & Team Data
    • Email addresses, names, roles (owner/admin/member), permissions, join date
    • Branding (logo, colors, fonts), help center customization
    • Email addresses of invited users
  • Customer Conversation Data
    • Name, email address, phone number
    • Conversation metadata
    • Messages
    • Notes
  • Contact Data
    • Full name, email address, phone number, company name
    • Job title, job role, department
    • Street address, city, state/province, country, postal code, website
    • Flexible custom fields defined by you
  • Billing & Payment Data
    • Email address, workspace owner name
    • Plan tier, number of seats, subscription status, trial end date
    • Transaction amounts, currency, payment status, invoice PDFs
  • Meta Platform Data (Facebook & WhatsApp)

    When you connect a WhatsApp Business Account or Facebook Page, Meta shares the following with us:

    • WhatsApp Business Account (WABA) ID, business phone number, phone number ID, and business profile details
    • The content of WhatsApp and Messenger messages sent and received between your business and your customers, including media attachments and delivery/read status
    • WhatsApp message template names, content, and approval status
    • Facebook Page ID, Page name, and Page access tokens
    • Your customer's WhatsApp or Messenger display name and profile picture, where made available by Meta

    We use this data solely to power your unified inbox - displaying and sending/receiving these messages on your behalf. We do not use Platform Data from Meta for advertising or ad targeting, and we do not sell or rent it to any third party. You can disconnect a WhatsApp or Facebook channel at any time from Settings → Channels, which stops further data sharing from Meta.

4. Cookies & Browser Storage

4.1 How We Use Cookies & Storage

Alps uses browser storage to enhance your experience:

Local Storage (Persistent):

  • Authentication tokens for session management
  • Cached user profile data
  • Workspace and account preferences

Session Storage (Tab-Specific):

  • Session identifiers for active browsing sessions

4.2 Your Cookie Choices

Most browsers allow you to refuse cookies. Please note:

  • Refusing essential cookies may prevent the Service from functioning
  • We recommend keeping cookies enabled for optimal experience
  • Disabling localStorage will limit widget persistence features

5. How We Use Your Personal Data

5.1 Service Delivery

  • Create and manage your account
  • Route and deliver customer support messages
  • Process payments and manage subscriptions
  • Provision and customize your workspace/help center

5.2 Communication

  • Send account verification emails
  • Send workspace invitations
  • Send billing notifications
  • Send service updates and announcements

5.3 Analytics & Improvement

  • Analyze usage patterns to improve the platform
  • Monitor system performance and uptime
  • Identify technical issues and bugs

6. Who We Share Your Data With

6.1 Third-Party Service Providers

We share data with trusted service providers under Data Processing Agreements:

  • Database, authentication, cloud storage
  • Email delivery
  • Payment processing
  • File upload & CDN storage
  • Real-time message delivery

6.2 User-Initiated Integrations

When you connect integrations, we share data as necessary:

  • Meta (WhatsApp & Facebook): Send/receive WhatsApp and Messenger messages on your behalf - see Section 3 for the full list of Platform Data involved
  • Google Calendar: Check your availability and create calendar events for meetings you schedule - see Section 13 for full details on how Google user data is handled
  • Create tasks from conversations
  • Create cards from conversations
  • Sync inbound emails

7. Data Retention

7.1 Retention Periods

Data TypeRetention Period
Account/User ProfileUntil account deletion
Conversations & MessagesUntil manually deleted
Payment/Invoice Records7 years (legal requirement)
Email Logs90 days
Deleted Account Data30 days (backup retention)

7.2 Account Deletion

When you delete your workspace or account:

  • All workspace data is marked for deletion
  • Payment records are retained for 7 years (legal requirement)
  • Backup copies may persist for up to 30 days
  • All OAuth integrations are disconnected

8. Your Rights Under the NDPR

Right to Access

You can request a copy of the personal data we hold about you.

Email info@tryalps.com with subject "Access Request (NDPR)" • Response: 14 days

Right to Rectification

You can correct inaccurate, incomplete, or misleading data.

Log into Alps and update your profile, or email info@tryalps.com • Response: 14 days

Right to Erasure (Right to Be Forgotten)

Under certain conditions, you can request deletion of your data.

Email info@tryalps.com with subject "Erasure Request (NDPR)" • Response: 14 days

Right to Data Portability

You can request your data in a portable, commonly-used format (CSV/JSON).

Email info@tryalps.com with subject "Data Export Request (NDPR)" • Response: 14 days

Right to Object

You can object to processing for marketing, profiling, or legitimate interest purposes.

Unsubscribe links in emails, or email info@tryalps.com to opt out

9. Data Location & Cross-Border Transfers

9.1 Where Your Data Is Stored

  • Primary Infrastructure: Globally distributed
  • Email Service: USA (us-east-2 region)
  • Payment Processing: Lagos, Nigeria
  • File Storage: Global CDN

9.2 Data Transfers Outside Nigeria

When your data is transferred outside Nigeria:

  • We ensure transfers are lawful under the NDPR
  • We implement appropriate safeguards (encryption, agreements)
  • We prioritize keeping sensitive data within Nigeria where possible

10. Security Measures

10.1 Technical Security

  • Encryption in Transit: HTTPS/TLS 1.2+ for all connections
  • Encryption at Rest: Firebase Firestore provides Google-managed encryption
  • Authentication: Firebase Auth with email/password and Google OAuth
  • Authorization: Role-based access control (Owner/Admin/Member)
  • Rate Limiting: Protection against brute-force attacks
  • Security Headers: CSP, HSTS, X-Frame-Options via Helmet.js

10.2 Limitations

No security measure is 100% secure. While we work to protect your data, we cannot guarantee absolute security against all possible attacks.

11. Children's Privacy

Alps is not intended for children under 13 years old. We do not knowingly collect personal data from children under 13. If we learn we have collected data from a child under 13, we will delete it promptly.

Parents/guardians who believe their child's data was collected should contact info@tryalps.com immediately.

12. Privacy Updates & Changes

12.1 Updates to This Policy

We may update this Privacy Policy to reflect:

  • Changes to our data practices
  • New features or integrations
  • Legal or regulatory requirements
  • Other operational changes

Notice of Changes

We will provide 30 days' notice of material changes by:

  • Updating the "Last Updated" date at the top
  • Sending email notification to your registered email
  • Posting a notice on the Alps website

Your Acceptance: Continuing to use Alps after changes are effective means you accept the updated policy.

13. Google User Data

Alps lets each team member optionally connect their own Google Calendar so meetings can be scheduled with customers from inside Alps. This section explains exactly what Google user data we access through that connection, and how we use, store, share and delete it.

Alps' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

13.1 What Google data we access

Only when you choose to connect Google Calendar, we request these permissions (scopes):

  • See and download your calendars (calendar.readonly): your free/busy times, the details of events on your primary calendar (title, time, guests, meeting link), and the name of the connected calendar account
  • View and edit events (calendar.events): to create, update and delete events that you schedule through Alps

We only access your own primary calendar. We do not access your contacts, email, files, or any other Google data.

13.2 How we use it

  • Check when you are free, so customers are only offered times you can actually meet
  • Create a calendar event (with a Google Meet link and the customer as a guest) when a customer picks a time
  • Update or delete that event if the meeting is rescheduled or cancelled in Alps
  • Show your calendar events on the Alps Calendar page

We use Google user data only to provide these user-facing scheduling features. We do not use it for advertising, and we do not use it to develop, improve or train generalized AI or machine-learning models.

13.3 Sharing

We do not sell Google user data, and we do not share it with third parties, except as needed to provide the scheduling feature you asked for (for example, the customer you invite receives the calendar invitation), to comply with applicable law, or as part of a merger or sale of our business with notice to you. We do not allow humans to read your Google user data unless you give us explicit permission, it is necessary for security purposes or to comply with law, or it is aggregated and anonymized for internal operations.

13.4 Storage and protection

  • Your Google access and refresh tokens are stored encrypted (AES-256-GCM) in our database, and are only decrypted in memory when needed to make a request on your behalf
  • Your other calendar events are read live when needed and are not copied into our database. Meetings booked through Alps are saved as meeting records in your workspace (time, title, guests and meeting link)

13.5 Retention and deletion

  • You can disconnect Google Calendar at any time in Settings > Apps & Integrations. Disconnecting immediately deletes the stored tokens we use to access your calendar
  • You can also revoke Alps' access at any time from your Google Account at myaccount.google.com/permissions
  • Deleting your account or workspace disconnects all integrations, as described in Section 7.2
  • To ask us to delete meeting records created through Alps, contact us at info@tryalps.com

14. Contact Information

Alps

Lagos, Nigeria

For General Inquiries:

Email: info@tryalps.com

For Privacy Concerns:

Email: info@tryalps.com

Regulatory Contacts

Nigeria - National Data Protection Bureau (NDPB):

Federal Ministry of Communications and Digital Economy, Abuja, Nigeria

If you're unsatisfied with our response, you have the right to lodge a complaint with the National Data Protection Bureau or pursue legal remedies through Nigerian courts.