Privacy Policy
Last updated: 27 July 2026
This Privacy Policy explains how PHIBIT LTD ("we", "us", "our") handles personal data under the UK GDPR and the Data Protection Act 2018. It covers two things: the phi-bit.com website and our software development services, and Labeeb, the chat automation platform we operate for businesses on Instagram and Messenger (and later WhatsApp).
1. Who we are, and in which role
PHIBIT LTD is a company registered in England and Wales under company number 17261109, with registered office at 63 Gabriel Crescent, Lincoln, LN2 4ZD, United Kingdom.
We act in two distinct roles, and the difference matters because it decides whom you address a request to:
- Data Controller for subscriber account data, billing, audit logs, and enquiries sent through the website. Here we decide the purposes and means of processing.
- Data Processor for everything to do with our customers' own audiences inside Labeeb: the business you messaged is the controller, and we act only on its instructions.
Meta is an independent controller for its own platform data and has its own privacy policy governing your use of Instagram, Facebook and WhatsApp.
2. Data we collect as controller
- Contact data: name, email, phone number, company, country.
- Project details: description, indicative budget, timeline.
- Account data: email, name, a scrypt-hashed password if you set one, session tokens, single-use magic-link tokens, and your workspace membership and role (owner, admin, agent).
- Billing data: your Stripe customer and subscription identifiers, plan and renewal date, and the billing address you enter with Stripe. We never see or store your card details.
- An audit trail: which account was connected or disconnected and when, who ran an export, who changed a plan — together with the IP address of the user who did it. The trail holds no message text.
- Technical data for the marketing site: IP address, browser type, pages visited (via website analytics).
3. Data we process on behalf of our business customers (Platform Data)
If you message or comment on a business account that uses Labeeb, we store and process the following on that business's behalf:
- The contact record: the identifier Meta issues for you on that account (IGSID / PSID / WhatsApp number), display name, username, avatar URL, locale, and channel.
- The text of every inbound and outbound message in that conversation, the text of your comment, Meta's post, comment and message identifiers, and the send outcome (which rule produced it, or why it was refused).
- A raw copy of the inbound Meta event exactly as received — stored before any processing to prevent duplicate replies and to explain later why a reply happened. It contains the same text.
- The timestamps of your last inbound and last outbound message (used by the 24-hour window guard), your opt-out state, and whether a human agent has paused automation on your conversation.
- Tags and custom fields the business applies to you. Their contents are chosen by the business, not by us, and our Terms forbid putting special-category data in them.
- A phone field exists in the database and nothing writes to it in the current phase; it will be used when the WhatsApp channel launches.
- The connected account's access token, granted to us by the business through Meta. It is stored encrypted (AES-256-GCM), is never returned by any API, and never appears in a log.
Contact and message records are stored as plain text in a database protected by the access controls in section 12 — field-level encryption is applied to access tokens only. Conversations are readable by every member of the business's workspace with the agent role or above.
4. Where Platform Data comes from
- Directly from Meta: Meta sends us a signed webhook for every message, comment or story reply on the connected account. We verify the signature and refuse any unsigned request.
- From Meta on first contact only: we read your display name and profile picture (plus username on Instagram) once, so the business's inbox can show who is writing.
- From the business itself: tags and custom fields added by its staff or by its automation rules.
5. Lawful bases for processing
- Performance of a contract: running your account and subscription and delivering the services we agreed.
- Legitimate interests: platform security, abuse prevention, the audit trail, and improving the service using aggregate numbers.
- Consent: when you submit a contact form, and for non-essential cookies.
- Legal obligation: UK accounting and tax record-keeping.
- For Platform Data, the lawful basis is chosen by the business that acts as controller — usually its legitimate interest in replying to people who contact it, or your consent. We do not choose that basis and do not process outside its instructions.
6. What we never do with Platform Data
- We do not sell, rent or trade it, and we do not share it with data brokers or advertisers.
- We do not use it to train AI models — ours or anyone else's. No conversation content is sent to any AI provider in the current phase (the AI step exists in the data model but the runner skips it without executing). If that changes, the provider will be added to the sub-processor list below and customers notified in advance.
- We do not use it for our own marketing, and we never message our customers' audiences on our own behalf.
- We do not combine one workspace's data with another's. Workspace isolation is enforced at a single fail-closed point in the code, and a database constraint prevents two workspaces from holding the same Meta account.
7. The Meta permissions we request, and why
This is the full set of permissions the app requests across the Instagram and Messenger channels; Meta's consent dialog shows the ones relevant to the account you are connecting. We never ask for an Instagram or Facebook password, and we do not use any permission for a purpose other than the one stated:
| pages_show_list | To list the Pages you manage so you can pick the one to connect. |
| pages_messaging | To receive your Page's messages and send automated replies and your team's replies. |
| pages_manage_metadata | To subscribe your Page to Meta's webhooks — without it no message or comment ever reaches us. |
| instagram_basic | To identify the professional Instagram account linked to your Page, its name and picture. |
| instagram_manage_messages | To receive direct messages and story replies, and to send replies to them. |
| instagram_manage_comments | To read Instagram comments and reply publicly or with a single private message. |
The WhatsApp channel has not launched and we do not request its permissions from customers today; it will be added to this table when it does. An account holder can disconnect at any time from the dashboard — we then unsubscribe the Page at Meta and wipe the stored access token in the same moment.
8. Who we share data with (sub-processors)
We do not sell data. We rely only on the providers below, each bound by contract and limited to the stated purpose:
| Meta Platforms | The channels themselves: receiving messages and comments, sending replies, reading the sender's name and picture. | Ireland and the United States |
| Stripe | Account holders' subscriptions and invoices. Card details never touch our servers. | United States and Ireland |
| Database and application hosting | Storing and running the platform. The current provider and region are stated on request at the email below, and customers are notified before any change. | Confirmed before launch |
| Vercel | Hosting this marketing site (phi-bit.com). No customer conversations are stored on it. | United States and Europe |
| Zoho Mail | The [email protected] support mailbox and our correspondence with you. | European Union |
| Google Analytics | Measuring traffic on this marketing site only. It does not run inside the dashboard and no conversation content reaches it. | United States |
| Google Ads | Measuring advertising results on the marketing site only: a booking request, a contact message, a WhatsApp click. It does not run inside the dashboard, and it is not enabled before you accept cookies. | United States |
We also use accounting and legal advisers bound by confidentiality. We notify customers before adding any new sub-processor that touches Platform Data, and they may object as set out in the Terms.
In addition: if a business configures a webhook step inside an automation rule, we send the contact's identifier, name, username and custom fields to the address that business chose. That destination is chosen by the business and is outside our control, and the business is responsible for it as controller.
9. International transfers
We are a UK company and most of our customers' audiences are in Iraq and the Gulf. Data is therefore processed in the UK, the EU and the United States. For transfers out of the UK we rely on UK adequacy regulations where they exist, or on the Standard Contractual Clauses with the UK International Data Transfer Addendum, or on the UK Extension to the EU-US Data Privacy Framework where the recipient is certified under it.
10. Retention
- Contacts, messages and raw Meta events: for the life of the business's subscription, then erased on its request or within 30 days of termination.
- The audit trail (including IP addresses): 24 months.
- Account data: 12 months after the account is closed.
- Accounting records and invoices: six years, as UK company law requires.
- Website enquiry data: 24 months after our last interaction. Development project records: six years after contract end.
Plainly, on the current state: deletion today is carried out manually on request, and automatically through Meta's deletion callback and when an account is disconnected. The scheduled purge job that enforces the periods above without human involvement is being built and is not yet running. Until it is, any deletion request is actioned by hand within 30 days at the latest.
11. Cookies
- phibit_session — strictly necessary: keeps you signed in to the dashboard.
- automation_connect_state and automation_connect_token — strictly necessary during a Meta connection only: they carry the connect state and a short-lived encrypted token, and expire within ten minutes.
- Google Analytics and Google Ads cookies on the marketing site only, when measurement is enabled on this deployment and after you accept. They do not exist inside the dashboard.
Plainly, on the current state: the cookie banner is now actually wired to Google's tools. Choosing Decline sends a denial signal that stops analytics and advertising cookies from being stored and stops any advertising identifier being passed, and your choice is re-applied on every later visit before any measurement tag runs. UK and EEA visitors start denied by default until they explicitly accept. The measurement tag runs on the marketing site only and is not loaded inside the dashboard, and no analytics or advertising cookie is used to track our customers' end-customer conversations. You can still block it through your browser settings or an ad blocker.
12. Security
These are the controls in place today, not intentions:
- Meta access tokens are encrypted with AES-256-GCM under an application key, are never returned by any API response, are never logged, and are wiped on disconnect, on app removal, and on a deletion request.
- Every inbound Meta webhook has its signature verified against the raw body with a constant-time comparison; unsigned requests are refused.
- Passwords are hashed with scrypt; magic-link tokens are stored hashed and expire.
- Workspace isolation is enforced in a single fail-closed function, plus a database constraint that stops the same Meta account being connected in two workspaces.
- No message text is written to operational logs, and every sensitive action (connect, disconnect, export, deletion) is recorded in the audit trail.
- The automation refuses non-compliant sends by default: outside the 24-hour window, to anyone who opted out, or a second private reply to the same comment — and the refusal is recorded with its reason.
We do not currently offer two-factor authentication on dashboard accounts; it is planned and not yet built. We recommend using an email account that is itself protected by two-factor authentication.
13. Your rights
Under the UK GDPR you have the right to access, rectification, erasure, restriction, objection, portability, and withdrawal of consent at any time. Email [email protected] and we respond within one month.
If your request concerns a conversation you had with a business that uses the platform, that business is the controller and it is best to ask it first, since it may hold its own copy outside our systems. Even so, if you contact us directly we will erase what we hold and inform the business of the request.
The three routes to deletion, and exactly what is erased, are set out on our data deletion page. Account holders can export contacts, tags, rules and conversations from the dashboard; the file itself states whether any section hit an export cap, in which case support provides the remainder.
To stop the messages without deleting anything: reply STOP — or «إيقاف» — in the conversation. The opt-out is recorded immediately and permanently, and no rule or broadcast can override it.
14. Children's data
The platform is sold to businesses for talking to their own audience. We do not ask for a sender's age and Meta does not supply it. We do not target children or knowingly process their data; if you are a parent or guardian and believe we hold a child's data, contact us and we will erase it through the same routes.
15. Automated replies
Replies you receive from a business using the platform may be entirely automated, triggered by a keyword or by a comment you wrote. We make no automated decision producing legal or similarly significant effects, and a member of the business's team can pause the automation and answer personally at any moment.
16. Changes to this policy
We update this page whenever the processing actually changes — a new channel, a new sub-processor, a new permission — and change the last-updated date above. Material changes affecting Platform Data are emailed to customers before they take effect.
17. Complaints
If you are unhappy with how we handle your data, contact us first at [email protected]. You always have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
18. Contact us
PHIBIT LTD
63 Gabriel Crescent, Lincoln, LN2 4ZD, United Kingdom
Email: [email protected]
Company No: 17261109
See also: Terms of Service · Data deletion