Legal Documents
Privacy Policy
Last updated July 1st 2026
1. Introduction
Welcome to Alps ("Service," "Platform," "we," "us," or "our"). We are committed to protecting your privacy and ensuring transparency about how we collect, use, and process your personal data. This Privacy Policy explains our practices regarding data collection and your rights under applicable privacy laws, particularly the Nigeria Data Protection Regulation (NDPR) and other applicable Nigerian and international data protection frameworks.
This Privacy Policy applies to:
- Users who create and manage support desks on our platform
- Customers/visitors who interact with public support widgets
- Team members invited to workspaces
- Any individual whose data is processed by Alps
By accessing or using Alps, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service.
2. Data Controller & Contact Information
Compliance Officer (Data Protection)
Email: info@tryalps.com
For privacy inquiries, data subject requests, or to exercise your rights under the NDPR, contact us at info@tryalps.com. We aim to respond to all inquiries within 14 days.
3. What Personal Data We Collect
- Account Creation & User Profile Data
- First name, last name, email address
- Password (stored securely via Firebase Auth)
- Display name, profile picture, company name
- Phone number, city, state, country
- Workspace & Team Data
- Email addresses, names, roles (owner/admin/member), permissions, join date
- Branding (logo, colors, fonts), help center customization
- Email addresses of invited users
- Customer Conversation Data
- Name, email address, phone number
- Conversation metadata
- Messages
- Notes
- Contact Data
- Full name, email address, phone number, company name
- Job title, job role, department
- Street address, city, state/province, country, postal code, website
- Flexible custom fields defined by you
- Billing & Payment Data
- Email address, workspace owner name
- Plan tier, number of seats, subscription status, trial end date
- Transaction amounts, currency, payment status, invoice PDFs
- Meta Platform Data (Facebook & WhatsApp)
When you connect a WhatsApp Business Account or Facebook Page, Meta shares the following with us:
- WhatsApp Business Account (WABA) ID, business phone number, phone number ID, and business profile details
- The content of WhatsApp and Messenger messages sent and received between your business and your customers, including media attachments and delivery/read status
- WhatsApp message template names, content, and approval status
- Facebook Page ID, Page name, and Page access tokens
- Your customer's WhatsApp or Messenger display name and profile picture, where made available by Meta
We use this data solely to power your unified inbox - displaying and sending/receiving these messages on your behalf. We do not use Platform Data from Meta for advertising or ad targeting, and we do not sell or rent it to any third party. You can disconnect a WhatsApp or Facebook channel at any time from Settings → Channels, which stops further data sharing from Meta.
5. How We Use Your Personal Data
5.1 Service Delivery
- Create and manage your account
- Route and deliver customer support messages
- Process payments and manage subscriptions
- Provision and customize your workspace/help center
5.2 Communication
- Send account verification emails
- Send workspace invitations
- Send billing notifications
- Send service updates and announcements
5.3 Analytics & Improvement
- Analyze usage patterns to improve the platform
- Monitor system performance and uptime
- Identify technical issues and bugs
6. Who We Share Your Data With
6.1 Third-Party Service Providers
We share data with trusted service providers under Data Processing Agreements:
- Database, authentication, cloud storage
- Email delivery
- Payment processing
- File upload & CDN storage
- Real-time message delivery
6.2 User-Initiated Integrations
When you connect integrations, we share data as necessary:
- Meta (WhatsApp & Facebook): Send/receive WhatsApp and Messenger messages on your behalf - see Section 3 for the full list of Platform Data involved
- Google Calendar: Check your availability and create calendar events for meetings you schedule - see Section 13 for full details on how Google user data is handled
- Create tasks from conversations
- Create cards from conversations
- Sync inbound emails
7. Data Retention
7.1 Retention Periods
| Data Type | Retention Period |
|---|---|
| Account/User Profile | Until account deletion |
| Conversations & Messages | Until manually deleted |
| Payment/Invoice Records | 7 years (legal requirement) |
| Email Logs | 90 days |
| Deleted Account Data | 30 days (backup retention) |
7.2 Account Deletion
When you delete your workspace or account:
- All workspace data is marked for deletion
- Payment records are retained for 7 years (legal requirement)
- Backup copies may persist for up to 30 days
- All OAuth integrations are disconnected
8. Your Rights Under the NDPR
Right to Access
You can request a copy of the personal data we hold about you.
Email info@tryalps.com with subject "Access Request (NDPR)" • Response: 14 days
Right to Rectification
You can correct inaccurate, incomplete, or misleading data.
Log into Alps and update your profile, or email info@tryalps.com • Response: 14 days
Right to Erasure (Right to Be Forgotten)
Under certain conditions, you can request deletion of your data.
Email info@tryalps.com with subject "Erasure Request (NDPR)" • Response: 14 days
Right to Data Portability
You can request your data in a portable, commonly-used format (CSV/JSON).
Email info@tryalps.com with subject "Data Export Request (NDPR)" • Response: 14 days
Right to Object
You can object to processing for marketing, profiling, or legitimate interest purposes.
Unsubscribe links in emails, or email info@tryalps.com to opt out
9. Data Location & Cross-Border Transfers
9.1 Where Your Data Is Stored
- Primary Infrastructure: Globally distributed
- Email Service: USA (us-east-2 region)
- Payment Processing: Lagos, Nigeria
- File Storage: Global CDN
9.2 Data Transfers Outside Nigeria
When your data is transferred outside Nigeria:
- We ensure transfers are lawful under the NDPR
- We implement appropriate safeguards (encryption, agreements)
- We prioritize keeping sensitive data within Nigeria where possible
10. Security Measures
10.1 Technical Security
- Encryption in Transit: HTTPS/TLS 1.2+ for all connections
- Encryption at Rest: Firebase Firestore provides Google-managed encryption
- Authentication: Firebase Auth with email/password and Google OAuth
- Authorization: Role-based access control (Owner/Admin/Member)
- Rate Limiting: Protection against brute-force attacks
- Security Headers: CSP, HSTS, X-Frame-Options via Helmet.js
10.2 Limitations
No security measure is 100% secure. While we work to protect your data, we cannot guarantee absolute security against all possible attacks.
11. Children's Privacy
Alps is not intended for children under 13 years old. We do not knowingly collect personal data from children under 13. If we learn we have collected data from a child under 13, we will delete it promptly.
Parents/guardians who believe their child's data was collected should contact info@tryalps.com immediately.
12. Privacy Updates & Changes
12.1 Updates to This Policy
We may update this Privacy Policy to reflect:
- Changes to our data practices
- New features or integrations
- Legal or regulatory requirements
- Other operational changes
Notice of Changes
We will provide 30 days' notice of material changes by:
- Updating the "Last Updated" date at the top
- Sending email notification to your registered email
- Posting a notice on the Alps website
Your Acceptance: Continuing to use Alps after changes are effective means you accept the updated policy.
13. Google User Data
Alps lets each team member optionally connect their own Google Calendar so meetings can be scheduled with customers from inside Alps. This section explains exactly what Google user data we access through that connection, and how we use, store, share and delete it.
Alps' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
13.1 What Google data we access
Only when you choose to connect Google Calendar, we request these permissions (scopes):
- See and download your calendars (calendar.readonly): your free/busy times, the details of events on your primary calendar (title, time, guests, meeting link), and the name of the connected calendar account
- View and edit events (calendar.events): to create, update and delete events that you schedule through Alps
We only access your own primary calendar. We do not access your contacts, email, files, or any other Google data.
13.2 How we use it
- Check when you are free, so customers are only offered times you can actually meet
- Create a calendar event (with a Google Meet link and the customer as a guest) when a customer picks a time
- Update or delete that event if the meeting is rescheduled or cancelled in Alps
- Show your calendar events on the Alps Calendar page
We use Google user data only to provide these user-facing scheduling features. We do not use it for advertising, and we do not use it to develop, improve or train generalized AI or machine-learning models.
13.3 Sharing
We do not sell Google user data, and we do not share it with third parties, except as needed to provide the scheduling feature you asked for (for example, the customer you invite receives the calendar invitation), to comply with applicable law, or as part of a merger or sale of our business with notice to you. We do not allow humans to read your Google user data unless you give us explicit permission, it is necessary for security purposes or to comply with law, or it is aggregated and anonymized for internal operations.
13.4 Storage and protection
- Your Google access and refresh tokens are stored encrypted (AES-256-GCM) in our database, and are only decrypted in memory when needed to make a request on your behalf
- Your other calendar events are read live when needed and are not copied into our database. Meetings booked through Alps are saved as meeting records in your workspace (time, title, guests and meeting link)
13.5 Retention and deletion
- You can disconnect Google Calendar at any time in Settings > Apps & Integrations. Disconnecting immediately deletes the stored tokens we use to access your calendar
- You can also revoke Alps' access at any time from your Google Account at myaccount.google.com/permissions
- Deleting your account or workspace disconnects all integrations, as described in Section 7.2
- To ask us to delete meeting records created through Alps, contact us at info@tryalps.com
14. Contact Information
Alps
Lagos, Nigeria
For General Inquiries:
Email: info@tryalps.com
For Privacy Concerns:
Email: info@tryalps.com
Regulatory Contacts
Nigeria - National Data Protection Bureau (NDPB):
Federal Ministry of Communications and Digital Economy, Abuja, Nigeria
If you're unsatisfied with our response, you have the right to lodge a complaint with the National Data Protection Bureau or pursue legal remedies through Nigerian courts.
Table of Contents: