Homa Meta Platform
Privacy Policy
How Homa Meta Platform processes data received through Meta authorization, why it is processed, how long it is retained, how it is secured and how you can revoke access or request deletion.
- Effective date:
- 2026-01-01
- Last updated:
- 2026-01-01
1. Introduction
This Privacy Policy explains how Homa Meta Platform processes information when a customer connects authorized Meta business assets to Homa CRM.
It describes the categories of data involved, the purposes for processing, the retention approach, the security measures intended to protect it, and the rights available to you. It applies to the connection and management of Meta business assets through this service.
2. Identity of the service
- Operating company
- Fanavaran Negin Shahre Novin
- Product
- Homa CRM
- Service
- Homa Meta Platform
- Service domain
- https://meta.homacrm.com
- Privacy contact
- privacy@homacrm.com
Homa Meta Platform is an independent integration service. It is not endorsed by, affiliated with, certified by or partnered with Meta Platforms, Inc.
3. Scope of this policy
This policy covers the integration layer that connects authorized Meta business assets to Homa CRM: the authorization flow, the data received as a result of that authorization, webhook events, and the technical logs produced while operating the service.
- It does not govern Meta’s own processing of your data. Meta acts under its own terms and privacy policy.
- It does not replace the privacy terms that apply to your wider use of Homa CRM.
- It does not cover third-party sites reached through links on this website.
4. Categories of data processed
The specific data available to the service depends entirely on which permissions you grant and which of those permissions Meta has approved for the application. The categories below describe what may be processed, not what is always processed.
- Identifiers for connected accounts and business assets.
- Profile and Page information for authorized assets.
- Instagram professional account information.
- Messages and conversation metadata for authorized conversations.
- Comments and engagement data on authorized content.
- WhatsApp Business account, phone number and template information.
- Webhook event payloads delivered by Meta.
- Technical and operational logs.
5. Data received from Meta
Data is received from Meta only after you complete an authorization flow and only within the scopes you approve. The service does not receive, request or store your Meta password.
6. Account and business asset identifiers
The service stores identifiers for the assets you connect so it can associate them with the correct tenant and make subsequent API calls on your behalf.
- Identifiers for connected Pages, Instagram professional accounts and WhatsApp Business assets.
- The internal tenant identifier that owns the connection.
- Timestamps recording when a connection was created, reauthorized or revoked.
7. Profile and Page information
Where you grant the relevant permission, the service may process descriptive information about authorized Pages and accounts, such as names, categories and usernames, so connected channels can be presented meaningfully inside Homa CRM.
8. Instagram professional account data
Instagram integration requires a professional account (business or creator). Personal Instagram accounts are not supported, because the Meta APIs the service depends on are not available for them.
- Professional account profile information for authorized accounts.
- Eligible media and, where permitted, insights associated with authorized accounts.
- Only accounts you explicitly authorize are processed.
9. Messages and conversation metadata
Where messaging permissions are granted and approved, the service may process message content and conversation metadata for authorized conversations so that they can be displayed and answered inside Homa CRM.
- Message content for authorized conversations.
- Conversation metadata such as participants, timestamps and delivery state.
- Messages are processed to operate the inbox, not to build advertising profiles.
11. WhatsApp Business data
Where WhatsApp Business assets are authorized, the service may process information required to send and receive approved business messages.
- WhatsApp Business account and phone number information.
- Message template information and approval state.
- Message content and delivery state for approved business messaging.
12. Webhook events
Meta may deliver webhook events to the service for subscribed and authorized assets, for example a new message or a new comment. Event payloads are verified before processing and are used to keep Homa CRM current.
13. Technical logs
The service records operational logs needed to run, secure and debug the integration.
- Request and error records, including correlation identifiers.
- Authorization lifecycle events such as connection, reauthorization and revocation.
- Security-relevant events such as rejected webhook deliveries.
- Access tokens, authorization codes and secrets are excluded from logs by design.
14. Purpose of processing
Data is processed to provide the integration you requested and to keep it secure and reliable.
- To establish and maintain connections to authorized Meta business assets.
- To display and manage authorized messages, comments and content inside Homa CRM.
- To synchronize contacts and activity history where permitted.
- To operate, monitor, debug and secure the service.
- To respond to support requests and to satisfy legal obligations.
15. Legal or contractual basis where applicable
Where a legal basis is required by applicable law, processing generally rests on the performance of the agreement under which Homa CRM is provided, on your explicit authorization granted through Meta, and on legitimate operational interests such as security and fraud prevention. Applicable law varies by jurisdiction; this section does not assert compliance with any specific regulation.
16. Data minimization
The service is designed to request the narrowest set of permissions that will support the features you have enabled, and to process only the data those features require.
- Permissions are requested for enabled features rather than pre-emptively.
- Declining a permission disables the dependent feature rather than blocking the whole integration.
- Removing a feature is a reason to reduce the permissions requested at the next authorization.
17. Data retention
Data is retained only as long as necessary to provide the service, or for longer where a legitimate requirement applies.
- Operational data is retained while the connection is active and the service is provided.
- Tokens are deleted when a connection is revoked or removed.
- Records may be retained where necessary for security, legal compliance, accounting, fraud prevention or dispute resolution.
- Logs are retained for a limited operational period appropriate to their purpose.
18. Data security
The service is designed with layered technical measures intended to protect the data it processes. No method of transmission or storage is completely secure, and no absolute guarantee is offered.
- Transport encryption for data in transit.
- Encryption of stored access tokens.
- Least-privilege permission requests.
- Tenant-level isolation enforced at the query layer.
- Webhook signature verification.
- Audit logging of authorization lifecycle events.
19. Token storage
Access tokens are treated as high-sensitivity credentials. They are held server-side, encrypted at rest, and are never transmitted to a browser, embedded in a URL or written to logs.
20. Encryption
Data in transit is protected using HTTPS. Stored access tokens are encrypted before they are written, using a key managed outside the application database, so that a database extract does not yield usable credentials.
21. Access controls
Administrative access to production systems is restricted to personnel who require it to operate the service, and such access is intended to be logged.
22. Tenant separation
Each customer’s connections, tokens and synchronized data belong to a single tenant. Queries that read connection data are scoped to the tenant of the authenticated session, so that data cannot be read across tenant boundaries.
23. Service providers and subprocessors
The service relies on infrastructure and operational providers, for example hosting and email delivery, to function. Such providers process data only as needed to supply their service.
To request the current list of providers used in connection with this service, contact privacy@homacrm.com.
24. International processing
Infrastructure and third-party providers, including Meta, may process data in countries other than your own. Where data is transferred internationally, it remains subject to this policy and to the terms of the providers involved.
25. Your rights
Subject to applicable law, you may request access to the information stored about your integration, correction of inaccurate information, deletion of stored integration data, or withdrawal of the authorization you granted.
To exercise any of these, contact privacy@homacrm.com or use the user data deletion page. Identity verification may be required before a request is actioned.
26. Revoking Meta permissions
You remain in control of the authorization you granted and can withdraw it at any time.
- Disconnect the integration from inside Homa CRM.
- Remove the application from your Meta account settings, which invalidates the token.
- Contact support if you cannot complete either step yourself.
27. Requesting deletion
Deletion can be requested through the user data deletion page on this website, or by email to privacy@homacrm.com. A request should identify the account or connection concerned so it can be located.
28. Data deletion procedure
A deletion request follows a defined sequence so that its progress is auditable.
- The request is received and a reference is generated.
- The request is acknowledged.
- Identity and authority over the account may be verified.
- Authorized data is deleted or anonymized where applicable.
- Associated tokens are revoked and removed.
- Confirmation is sent once the request has been completed.
Requests are acknowledged and processed within a reasonable period, subject to legitimate legal retention requirements. Some records may be retained where required for legal, accounting, fraud-prevention, security or dispute-resolution purposes.
29. Children’s privacy
The service is intended for business use by adults and is not directed at children. It is not knowingly used to collect information from children. If you believe such information has been provided, contact the privacy address so that it can be removed.
30. Changes to this policy
This policy may be updated as the service changes or as legal requirements evolve. The revised version will be published at this URL with an updated revision date. Material changes will be communicated where reasonably practicable.
31. Contact information
- Privacy enquiries
- privacy@homacrm.com
- Support
- support@homacrm.com
- Security reports
- security@homacrm.com
- Operating company
- Fanavaran Negin Shahre Novin
32. Effective date
This policy is effective from 2026-01-01.
33. Last updated
This policy was last updated on 2026-01-01.
10.10. Comments and engagement data
Where the relevant permissions are granted, the service may process comments and engagement data on authorized content so that they can be reviewed, replied to or moderated from Homa CRM.