Privacy Policy
Last updated: August 2026
What is Hilo?
Hilo is a CRM (customer relationship management software) that lets a business connect its own WhatsApp and Instagram channels, centralize conversations with its customers in one inbox, and use AI to reply to and organize those conversations.
Who is responsible for what
When a business (the "Customer") uses Hilo to serve its own end customers, the Customer decides what data to collect and why — it is the controller of its contacts' data. Hilo acts as a processor: we process that data on the Customer's behalf, following its instructions, to operate the service.
This policy describes how we handle personal data of: (1) people who use Hilo directly (agent and admin accounts), and (2) a Customer's contacts whose conversations pass through the platform, to the extent Hilo is involved in that processing.
What data we collect
From people who sign up or use Hilo as agents/admins: name, email, password (stored as a hash, never in plain text), role within the organization, and basic usage activity (last seen, assignments).
From a Customer's contacts, via the connected channels (WhatsApp Cloud API and Instagram, through Meta's Graph API): WhatsApp/Instagram identifier, profile name, the content of exchanged messages, attachments (images, audio, documents), and conversation metadata (date, channel, delivery status, tags assigned by the Customer's team).
From people who visit this site: basic technical browsing data collected by our hosting provider (Vercel) to operate the site, and by analytics tools if enabled.
What we use this data for
To operate the service: send and receive messages over connected channels, display conversations in the inbox, run automatic assignment between agents, generate AI replies when the Customer enables that feature, and store conversation history.
To provide support, prevent fraud or abuse of the platform, and comply with legal obligations where applicable.
We do not sell personal data to third parties or use it for advertising unrelated to Hilo.
Who we share it with
Meta / WhatsApp Cloud API and Instagram Graph API: messages are sent and received through Meta's infrastructure, subject to its own terms and data policies.
Xano: our database and backend provider, where the platform's data lives.
Vercel: our hosting provider for the web application.
Language model providers (e.g. OpenAI): when the Customer enables the AI agent, the relevant message content is sent to that provider to generate a reply.
We do not share this data with third parties for marketing purposes unrelated to running the service.
Where data is stored
Data is stored on our hosting/database providers' infrastructure (Xano and Vercel), which may operate data centers outside the Customer's or its contacts' country. By using Hilo, you accept this transfer, which is necessary to provide the service.
How long we keep it
We retain account and conversation data while the Customer keeps the service active, plus a reasonable additional period for backups and legal obligations. A Customer may request deletion of specific data by contacting support.
Your rights
You may request access, correction, deletion of, or objection to the processing of your personal data. If you're an agent/admin on a Hilo account, you can do this directly from your account or by contacting us. If you're a contact of a business using Hilo, the request should first go to that business, since it controls its relationship with you; Hilo will assist with that request.
Cookies
This marketing site may use technical cookies necessary for it to function. If analytics or advertising cookies are enabled in the future, this section will be updated.
Changes to this policy
We may update this policy as the product evolves. We'll post the last-updated date on this page.
Contact
For any question or request about this policy, book a call or email us at adrian5digo@gmail.com.