Privacy Policy
Lets Crooz (SMC-Private) Limited · Incorporated in Pakistan (CUIN 0346167)
Last updated 18 July 2026 · Version 2026-07-18
This Privacy Policy explains how Lets Crooz (SMC-Private) Limited ("Lets Crooz", "we", "us", or "our") collects, uses, shares, and protects information when you use our platform (the "Service"). Lets Crooz is a business-automation platform: businesses across retail, food, services, and healthcare sign up for a private workspace that runs their records, bookings, stock, and billing, and that sends and receives messages with their customers over WhatsApp and email. This policy is written for the business owners and staff who hold accounts with us, and it explains our role in respect of the customer and records data your business stores in, and sends through, the Service. It should be read together with our Terms of Service, which governs your contractual relationship with us, including liability.
1. The two roles of data in the Service
The Service involves two categories of data with two different roles.
First, account and billing information, which we control in order to create and run your account. For this data, Lets Crooz is the controller.
Second, the business, customer, and records data your business enters or sends through the Service — including your customers' contact details and WhatsApp phone numbers, the messages exchanged with them, and (for healthcare businesses) patient and clinical records. Your business is the controller of this data; Lets Crooz acts as a processor, handling it only to provide the Service and only on your documented instructions.
2. Information we collect
- Account details you give us, such as your name, email address, mobile number, business name, chosen web address, and password.
- Billing information needed to manage your plan, meter your usage, and process payments.
- Verification data, such as the one-time codes we send to your email and mobile to confirm they belong to you.
- Usage and device data, such as log records, IP address, browser type, and the pages you use, collected automatically to keep the Service secure and to improve it.
- Support messages you send to us.
- Business and customer data that you and your staff enter into your workspace to run your business, and the WhatsApp and messaging data described in Section 3.
3. WhatsApp Business Platform data
The Service connects to the WhatsApp Business Platform, provided by Meta, so your business can message its customers. This may run through a shared Lets Crooz WhatsApp number or, if you enable it, through your own WhatsApp number that you connect to your workspace.
To deliver this, we process, on your instructions and on your behalf, your customers' WhatsApp phone numbers, WhatsApp profile names, and the content of the messages sent and received (for example order confirmations, appointment reminders, delivery updates, and replies). We use this data solely to send, receive, meter, and log the messages that power your automations, and to provide support.
We do not sell this data, and we do not use it for any purpose unrelated to providing the Service. Any information we obtain through WhatsApp or the Meta platforms is used only to operate the Service and is handled in accordance with the Meta Platform Terms, the WhatsApp Business Terms, and applicable law. Where messages are delivered through Meta's WhatsApp Business Platform, Meta processes that message data as a service provider on your and our behalf under its own terms, and message content is also subject to WhatsApp's own privacy terms. We keep each business's messaging data logically separated from that of every other business.
4. AI features (optional)
The Service may offer optional AI features that a business can choose to enable — for example, an AI assistant that helps answer customer messages. These features are off by default and operate only for a business that opts in.
When enabled, the AI processes the content of incoming customer messages together with relevant information from your workspace (such as your hours, services, prices, and availability) in order to generate a reply, or a suggested reply, on your behalf. To do this, the necessary message content and context are sent to a third-party AI provider solely to generate that response. We send only the data needed for the response, and we require our AI providers to use it only to provide the response to us — not for their own purposes and not to train their models — in line with their terms. We do not use this data to train our own models.
The AI is designed to hand anything sensitive or uncertain to you rather than answering on its own, and you remain responsible for reviewing AI output and for the messages sent to your customers. AI features are metered and capped in the same way as messaging, and you can disable them at any time.
5. How we use account information
We use account and usage information to create and run your workspace, to verify your email and mobile at sign-up, to provide support, to send you service and billing messages, to meter usage for billing, to keep the Service secure and prevent abuse, and to understand and improve how the Service works. We do not sell your personal information.
6. Customer and records data — our role as processor
Your business is the controller of the customer and records data it enters or sends, and we act as a processor. We use this data only to provide the Service and only on your instructions. We do not sell it. Each business workspace is kept separate from every other business.
7. Your responsibilities as the controller
Because your business is the controller of the customer and records data, you are responsible for:
- having a lawful basis, and any customer or patient consent or opt-in that is needed, for the data you enter and for any reminders, follow-ups, marketing, or feedback messages you choose to send through the Service;
- complying with the WhatsApp Business Messaging Policy, the Meta Platform Terms, and all messaging, consumer-protection, and data-protection laws that apply to you and your customers; and
- keeping the data you enter accurate and lawfully obtained.
You agree not to use the Service to send unlawful, deceptive, or unsolicited messages. We may suspend or limit sending, or take other reasonable action, where we believe the Service is being used in breach of these responsibilities or of the WhatsApp policies, in order to protect your customers, other users, and the Service.
8. Sharing and third parties
We share information only as needed to run the Service — for example with hosting and infrastructure providers, the messaging providers and platforms that deliver WhatsApp and email (including Meta), the AI providers that power optional AI features, payment processors, and analytics tools. We require these providers to protect the information and to use it only for the services they provide to us. We may also disclose information where the law requires it, in response to lawful requests by public authorities, or where necessary to protect the rights, property, or safety of our users, the public, or the Service. We do not sell your data or your customers' data.
9. Security
We protect data using measures such as encryption of data in transit, access controls, logical separation of each business workspace, and keeping secrets and credentials out of the application code. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security; however, we work to protect your data, and if we become aware of a security incident affecting your data we will act promptly and notify you and any authorities as required by applicable law.
10. How long we keep data
We keep account and billing data while your account is active and for a limited period after it closes, so that we can meet legal, accounting, and security needs. We keep customer, messaging, and records data according to your instructions as the controller. Messages sent through the WhatsApp Business Platform are also subject to Meta's own platform retention limits. You can export your data before your account closes, and we delete or anonymise data when it is no longer needed for the purposes described in this policy.
11. Your rights and how to request deletion
Subject to the law that applies to you, you can ask to access, correct, export, or delete the account data we hold about you. To make a request, email us at hello@letscrooz.com. We will verify your request and respond within a reasonable time, and in any event within the period required by applicable law.
Deleting business, customer, and WhatsApp data. You can delete records within your workspace at any time. When you ask us to delete your account, or send a deletion request to hello@letscrooz.com, we delete or anonymise your account data and the customer, messaging, and records data associated with your workspace — including WhatsApp phone numbers and message content processed on your behalf — except where we are required to retain limited data to meet legal, accounting, or security obligations. Where a customer of a business asks about their data held inside that business's workspace, the customer should contact the business directly, since the business is the controller of that record; we will support the business in responding.
12. International processing
Your data may be processed in countries other than your own, for example where our providers (including Meta and our AI providers) operate. Where this happens, we take steps to protect the data in line with this policy and with the law that applies.
13. Cookies
We use necessary cookies to keep you signed in and to keep the Service secure, and we use a limited amount of analytics to understand usage. You can control cookies through your browser settings, though some features may not work without the necessary ones.
14. Children
The Service is intended for businesses and their staff, and it is not intended for direct use by children. Businesses may store the records of minors (for example patients) as part of providing their service, and those records are handled as controller data under this policy.
15. Governing law
This policy and any matter relating to it are governed by the laws of the Islamic Republic of Pakistan, without prejudice to any mandatory data-protection rights you may have under the laws of the country in which you are located. Your overall relationship with us, including contractual terms and liability, is governed by our Terms of Service.
16. Changes to this policy
We may update this policy from time to time. When we do, we will post the updated version with a new date, and for material changes we will take reasonable steps to notify you before they take effect.
17. Contact
Questions about this policy or about your data can be sent to hello@letscrooz.com.