Privacy Policy

Last updated 23 August 2026

1. Two kinds of data

Account data is about you as our customer: your name, email, business details and how you use the portal. We are the controller of that data. Business data is what your own customers send you — enquiries, orders, messages, contact details. You control that; we process it on your behalf and only to run the service for you.

2. What we collect

  • Account: full name, work email, business name, industry, country, business phone and optional website.
  • Security: a hash of your password (never the password itself), session records, and a hash of your IP address for rate limiting and abuse detection.
  • Business data: customer names and contact details, enquiries, bookings, orders, quotations, payments and WhatsApp message history for your account.
  • Operational: request logs, audit records of significant actions, and usage counters used to apply plan limits.

3. What we do not collect

  • We do not store your password in a readable form.
  • We do not store card numbers. Payments are handled by the payment provider you connect.
  • We do not put access tokens, API secrets or verification tokens into audit logs.
  • We do not sell your data or your customers' data, and we do not use it to train models.

4. Why we process it

  • To provide the service you signed up for (performance of a contract).
  • To keep the service secure and prevent abuse (legitimate interests).
  • To bill you and keep accounting records (legal obligation).
  • To send service messages such as email verification and account notices.

5. Who else is involved

  • Meta Platforms — WhatsApp message delivery, if you connect a number.
  • Our hosting and database providers — to run the service and store your data.
  • Our email provider — to deliver verification and notification emails.
  • Your payment provider — if you enable payments.

We share only what each provider needs, and we do not give any of them the right to use your data for their own purposes.

6. Isolation between customers

Every record in the system carries the account it belongs to, and every query is scoped to the account of the authenticated caller. An API key can only ever read and write its own account's data. This is enforced in the service itself, not by convention.

7. How long we keep it

  • Business data: for as long as your account is open, and then only as long as the law requires.
  • Sessions: 30 days, or until you sign out.
  • Email verification and reset tokens: hours, and they are single-use.
  • Audit logs: retained as a security record.

8. Your rights

You can access, correct, export or delete your account data — email support@makutano.co.tz and we will respond within 30 days. If one of your own customers asks you to delete their data, you can do that yourself in the portal or through the API.

9. Your customers' consent

You are responsible for having permission to message the people you contact through the service, and for telling them how you use their data. The service records opt-outs and enforces them on every send.

10. Changes

We will notify you by email or in the portal before any material change to this policy takes effect.

Questions about this page? Email support@makutano.co.tz.