Skip to content
Nextorn

Legal

Privacy

We collect only the information you send us through the contact form (name, email, company, message). We use it to respond — nothing else.

We don't sell, trade, or share your information with third parties for marketing.

We use Vercel for hosting, Resend for transactional email, and Cloudflare Turnstile to prevent spam — all of which may temporarily process your request data.

When you connect your workspace

Customers who sign up at /dashboard share more data: long-lived OAuth tokens for their Facebook Pages, the lead form submissions Meta delivers to our webhooks, and the message history of Messenger / Instagram conversations they route through our platform. We store this data inside the customer's private MongoDB workspace and our self-hosted Chatwoot instance — never co-mingled with other customers'.

OAuth tokens are encrypted at rest with AES-256-GCM. We use them only to read the data the customer asked us to pull (Lead Ads forms, Page messages) and to send replies on their behalf when their agent clicks send. We never proactively message Page followers or post on the customer's behalf.

Auto-generated AI replies (for new leads / suggested chat responses) are produced by OpenAI on our infrastructure. The lead's name, email, phone, and message text are sent to OpenAI; OpenAI's data-handling policy applies. We don't train any model on customer data.

Data deletion

You can delete your data at any time. The fastest paths:

Inside the dashboard — Settings → Account → Delete workspace. This wipes the customer record, all leads, all OAuth tokens, all chat history, and the linked Chatwoot account within 24 hours.

Per-channel — Settings → Inboxes → Disconnect on any connected Facebook Page / Instagram / Email inbox. This revokes our OAuth access to that channel and stops new webhooks. Historical messages from that channel stay in your workspace; if you want them deleted too, use the workspace-delete option above.

Manual — email support@nextorn.com from the address tied to your workspace (or any address you've contacted us from), and we'll wipe everything within 7 days and reply with a confirmation.

Meta-specific — if you only want to revoke Facebook / Instagram access without deleting your Nextorn workspace, you can also remove Nextorn at facebook.com → Settings → Apps and Websites → Nextorn Marketing. Doing so terminates our token within 24 hours; we'll mark the integration as expired and stop trying to use it.