ClarityERP is a business management platform (quotations, invoicing, stock, payroll, CRM and a customer messaging inbox) used by businesses ("customers") to run their operations. This policy explains what we collect, why, where it is stored and how it is deleted. It applies to the ClarityERP web application, the ClarityERP online catalog pages, and messages that reach our customers through WhatsApp, Facebook Messenger and Instagram.
ClarityERP is operated by Brand's Talk Marketing Agency (Malaysia). For anything in this policy, contact us at brandtalk.marketingfirm@gmail.com or through the enquiry form on this website.
| Data | Where it comes from | Why |
|---|---|---|
| Account details: name, email, password (hashed), company name, logo, address, phone, tax and bank details | Entered by the customer at sign-up and in Settings | To run the customer's account and print their documents |
| Business records: clients, suppliers, products, quotations, invoices, payments, stock, payroll, claims, projects | Entered or uploaded by the customer | The core service |
| Messages: message text, attachments (photos, documents, voice notes), sender name and platform ID, phone number (WhatsApp), delivery and read status | Received from Meta's WhatsApp Business Platform, Messenger Platform and Instagram Messaging API, and sent by the customer from the inbox | So the customer can read and reply to their own customers in one inbox |
| Facebook Page, WhatsApp Business Account and Instagram account identifiers and access tokens | Granted by the customer when they connect a channel with Facebook Login or WhatsApp Embedded Signup | To receive and send messages on the customer's behalf |
| Catalog enquiries: name, phone number, company, message | Submitted by an end user on a customer's online catalog page | Passed to that customer as a lead |
| Technical logs: request time, IP address, browser type | Automatic | Security and troubleshooting; kept for a short period by our hosting providers |
When a customer connects WhatsApp, a Facebook Page or Instagram, we act as the customer's technology provider. Messages, sender identifiers and attachments received from Meta are stored in the customer's ClarityERP account so the customer can reply. Access tokens are stored encrypted at rest and are never shown in the browser. We use Meta data only to deliver the messaging inbox to that customer and for no other purpose, in line with Meta's Platform Terms and Developer Policies. Message costs charged by Meta are billed by Meta to the customer's own business account.
These providers process data under their own security commitments and only as needed to run the service.
All traffic is encrypted (HTTPS). Data in the database is isolated per customer with row-level security, so one customer can never read another customer's records. Channel access tokens are only handled by server-side functions. Staff accounts are limited by the module permissions the customer sets.
The application uses only the session storage needed to keep you signed in and remember interface preferences. The marketing website does not use tracking cookies.
If this policy changes materially we will notify customers in the application and update the date at the top of this page.