Privacy Policy
Last Updated: September 6, 2026 | Effective Date: September 6, 2026
Table of Contents
Navigation1 Introduction & Scope
TechFlow Software Company ("TechFlow", "we", "our", or "us"), headquartered at #5B, Pallikudathan Street, Kanchipuram – 631501, Tamil Nadu, India, respects your privacy and is committed to protecting business and personal information entrusted to us.
This Privacy Policy explains how TechFlow collects, uses, stores, processes, and protects information when you use our websites, software applications, APIs, and business management services, including:
- AcPro Cloud ERP: Textile, weaving, apparel, and manufacturing ERP with GST billing and accounting.
- BookEzy: Cloud appointment scheduling, multi-staff booking calendars, and customer notifications.
- Bill.cafe (BillFeast): Restaurant point of sale (POS), table billing, and Kitchen Order Ticketing (KOT).
- HotelDesk PMS: Hotel property management, room inventory, guest check-in/checkout, and front office.
- FieldForce CRM: Field sales tracking, live GPS visit verification, and order capture.
- SchoolDesk ERP: Campus administration, student attendance, parent alerts, and fee management.
- WhatsApp Business Platform Integrations: WhatsApp Cloud API and Meta Embedded Signup integrations configured by customers.
Website: https://techflow.co.in/
2 Information We Collect
We collect business and technical data strictly necessary to provide, maintain, and support our cloud software services:
- Account & Registration Information: Name, business name, email address, mobile/telephone number, login credentials, business address, and subscription details.
- Operational Business Data: Invoices, inventory catalogs, bookings, customer ledgers, purchase records, employee details, and transactions entered by your authorized users. Such data generally remains under customer ownership and control.
- System & Diagnostic Logs: Device IP address, browser type, operating system, and access timestamps for diagnostic, performance, and security auditing.
3 Tenant-Level Access Controls & Architectural Isolation
TechFlow implements architectural tenant isolation designed to logically separate customer data. Each client organization operates within a scoped tenant context governed by application-level authorization and database row-level scoping to prevent unauthorized cross-tenant data access. Your proprietary transaction data, GST records, customer accounts, and communication logs are logically partitioned to safeguard customer confidentiality.
WhatsApp Business Platform & Meta Integration Policy
4. Meta / WhatsApp Business Platform Integration
TechFlow integrates with the WhatsApp Business Platform / WhatsApp Cloud API provided by Meta Platforms, Inc. ("Meta") as an Independent Tech Provider.
Connecting a WhatsApp Business Account to TechFlow is completely optional. Customers choose whether to connect their WhatsApp Business Account to TechFlow software (for example, to enable BookEzy appointment reminders or automated AcPro/Bill.cafe GST invoice delivery).
- No Ownership Claim: TechFlow does not claim ownership of customer WhatsApp accounts, phone numbers, messages, media, or business information.
- Customer Compliance: Customers remain responsible for their WhatsApp communications and for compliance with applicable WhatsApp and Meta policies (including the WhatsApp Business Messaging Policy) and applicable privacy or consent laws.
- No Sale of Data: TechFlow does not sell WhatsApp data, customer contact lists, or customer business data to third parties.
5. WhatsApp Business Account Information
When a customer connects their WhatsApp Business Account to TechFlow, we process account-level identifiers, including the WhatsApp Business Account ID (WABA ID), business account name, currency, timezone, and linked Meta Business Manager identifiers necessary to establish, configure, and maintain the integration.
6. WhatsApp Phone Numbers and Business Profile Information
TechFlow processes the verified WhatsApp phone number, phone number ID, business display name, certificate status, quality rating, and messaging tier status associated with the connected number. This information is used to authenticate outbound Cloud API requests and route incoming notifications to the appropriate customer tenant.
7. WhatsApp Messages, Media, and Message Metadata
When an authorized integration is active, TechFlow processes:
- Outbound Messages: Transactional alerts, GST invoice PDFs, booking confirmations, appointment reminders, OTP alerts, and service notifications sent upon your instruction.
- Incoming Messages: Customer responses, confirmation replies (e.g., Yes/No appointment confirmations), and incoming text messages sent to your connected WhatsApp number.
- Media Attachments: Invoices, receipts, PDF documents, and images transmitted through the integration.
- Message Metadata: Message delivery timestamps, sent status, delivered status, read receipts, and delivery error codes.
8. WhatsApp Message Templates
TechFlow facilitates the creation, management, and synchronization of WhatsApp message templates with Meta. We process template names, categories (Utility, Authentication, Marketing), language codes, body text, parameter placeholders, and approval statuses as returned by Meta's WhatsApp Cloud API.
9. WhatsApp Cloud API and Webhook Data
TechFlow receives and processes real-time webhook events dispatched by Meta's WhatsApp Business Platform, including message delivery status updates, incoming customer messages, template status changes, and phone number quality updates. Webhook event payloads are verified using cryptographic signatures (SHA-256 HMAC) against configured App Secrets before processing, and are used strictly to update status logs and trigger customer-configured workflows.
10. Meta Embedded Signup
Customers authorize the WhatsApp connection through Meta's official Embedded Signup onboarding flow:
- The customer initiates the connection from their TechFlow administrative settings.
- The customer logs in to Meta and grants explicit permissions (such as
whatsapp_business_managementandwhatsapp_business_messaging) through Meta's secure authorization modal. - The customer chooses the Meta Business Account, WhatsApp Business Account, and phone number they want to connect.
- Meta securely transmits authorization credentials to TechFlow via OAuth server-to-server exchange.
TechFlow never receives, collects, or stores customer Meta or Facebook account passwords.
11. WhatsApp Access Tokens and Authentication Information
TechFlow processes authentication credentials, access tokens, identifiers, and webhook secrets required to operate authorized WhatsApp integrations.
We take reasonable measures to protect authentication credentials: access tokens are stored securely in restricted database environments, excluded from client-side code, scrubbed from diagnostic logs, and accessible strictly to authorized background integration services.
12. Purpose of Processing WhatsApp Data
TechFlow uses WhatsApp data solely for providing the functionality requested by the customer, including:
- Dispatching transactional notifications (such as GST invoices, appointment confirmations, and payment receipts) requested by the customer.
- Receiving and routing incoming customer replies to the appropriate staff or software module.
- Tracking message delivery and read statuses and troubleshooting API errors.
- Managing and synchronizing pre-approved WhatsApp message templates.
- Maintaining operational logs, security auditing, and service continuity.
14. WhatsApp Data Retention
TechFlow retains WhatsApp-related data and message delivery logs only for as long as reasonably necessary to fulfill the requested business services, maintain transaction records, resolve customer support inquiries, meet accounting obligations, and ensure system security.
WhatsApp-related information may be deleted or disconnected when the customer removes the WhatsApp integration or requests data deletion, subject to applicable legal, security, and statutory retention requirements.
15. Disconnecting a WhatsApp Business Account
Customers can disconnect their WhatsApp Business Account from TechFlow at any time through application settings or by contacting TechFlow support.
When a WhatsApp integration is disconnected, TechFlow stops using the connection for future WhatsApp API operations, except where continued temporary processing or retention is necessary for legitimate legal, security, audit, or backup purposes.
16. WhatsApp Data Deletion Requests
Customer Data RightsCustomers can request deletion of their applicable WhatsApp-related data by contacting TechFlow:
Please provide your registered business name, registered email address, connected WhatsApp phone number, and the specific scope of deletion requested.
After identity verification, TechFlow will process the request within a reasonable period, subject to legitimate legal, regulatory, security, and accounting retention requirements.
17. Meta / WhatsApp Privacy Requests
Meta Platform ComplianceIf you have connected a Meta or WhatsApp account to TechFlow and want to submit a data deletion request in accordance with Meta Platform policies, contact us at:
We will verify the request, execute data deletion on applicable records, and provide confirmation in compliance with Meta's developer data deletion requirements.
18 Security Safeguards
We use reasonable technical and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction. Security measures include:
- Data is protected in transit using HTTPS/TLS encryption.
- User authentication and authorization controls, including hashed passwords and session management.
- Database security measures and parameterized queries to protect data integrity.
- Restricted administrative access and server-level access controls.
- Auditing and monitoring of administrative events with automated scrubbing of sensitive credentials.
- Protection and server-side isolation of API tokens and webhook secrets.
No internet-based system can be guaranteed to be completely secure.
19 Third-Party Services
Our applications may integrate with third-party platforms and services based on customer requirements:
- Meta / WhatsApp Business Platform: For messaging and notification services.
- Payment Providers: For UPI, card processing, and billing settlement.
- Government Tax APIs: For GSTN e-Invoice and e-Way Bill generation.
- Infrastructure & Email Providers: For cloud hosting and transactional email dispatch.
Third-party services operate under their own independent terms and privacy policies. TechFlow is not responsible for the privacy practices of external services outside our direct control.
20 User Privacy Rights & DPDP Act 2023
TechFlow handles personal information in accordance with applicable Indian laws, including the Digital Personal Data Protection Act, 2023 (DPDP Act).
Depending on applicable law, users and organizations have rights regarding their personal data, including:
- The right to access a summary of personal data processed by TechFlow.
- The right to correct inaccurate or misleading personal data.
- The right to request deletion of personal data, subject to legal and accounting retention requirements.
- The right to grievance redressal regarding personal data processing.
To exercise applicable data rights, please contact our Data Governance desk using the information below.
21 Contact Information
If you have questions regarding this Privacy Policy, wish to exercise privacy rights, or need assistance with data deletion, please contact our headquarters:
Registered Headquarters
TechFlow Software Company
#5B, Pallikudathan Street, Kanchipuram – 631501, Tamil Nadu, India.
Website: https://techflow.co.in/
Communications & Support
Landline: 044-46370003
Mobile / WhatsApp: 9380808400 / 8015208400
Official Privacy & Support Email: support@techflow.co.in
(General Inquiries: info@bookezy.in)