Merbix Privacy Policy

Last updated: July 22, 2026

Merbix respects your privacy. This policy explains what we collect, why we use it, who we share it with, and how you can control or request deletion of your information.

1. Introduction

Merbix is an Egyptian SaaS platform that helps merchants and service providers manage Facebook and Instagram comments and messages, organize orders and customers, and run suggested or automated AI-assisted replies according to each workspace’s settings.

The platform is operated by Merbix, operated from the Arab Republic of Egypt (Arab Republic of Egypt). For questions: support@merbix.cloud.

For general service terms, see Terms of Service.

2. Scope of this policy

This policy covers:

  • Merchant accounts registered on Merbix.
  • Public storefronts hosted through Merbix.
  • Connected Facebook Pages and linked Instagram professional accounts.
  • Meta-originated comments and messages processed inside Merbix.

For end-customer data received from Meta, Merbix acts as a data processor on behalf of the merchant, who remains responsible to their customers.

3. Information collected directly from you

  • Name, email, and phone when you register or update your profile.
  • Password and authentication records (stored securely, never displayed).
  • Workspace information: brand name, business description, AI and autopilot settings.
  • Product/service catalog, orders, customers, leads, and complaints.
  • Uploaded logos and media.
  • Subscription payment confirmation: InstaPay or Vodafone Cash transaction reference and invoice records.
  • Support messages and public contact form submissions.
  • In-app activity logs for audit and security.

There is no active credit-card payment gateway for Merbix subscriptions in the current interface.

4. Information received through Meta platforms

When you connect a Facebook Page or Instagram professional account, we may receive and process — depending on permissions you approve in OAuth:

  • Connected Facebook Page or Instagram professional account information.
  • Post or media context when available.
  • Comments, message text, platform identifiers, and display names.
  • Customer-initiated Messenger or Instagram conversations.
  • Meta webhook events.
  • Encrypted Page/account access tokens.
  • Business asset selection information during connection.

5. Meta permissions

We request only permissions used in our codebase. We do not use them for unrelated purposes:

PermissionHow Merbix uses itWhen it is used
pages_show_listLets a business owner view and select a Facebook Page they manage during connection.Settings → Integrations → Connect Facebook.
pages_read_engagementReceives and displays comments and engagement on the connected Page inside Merbix.A customer comments on a connected Page post; Merbix ingests the webhook.
pages_read_user_contentReads comment text and related user content needed to display and reply.Incoming Facebook comment or private-reply context.
pages_manage_engagementPublishes replies to customer comments and a public acknowledgment when configured.You approve or send a comment reply from Merbix.
pages_manage_metadataSubscribes the connected Page to supported webhook events for new comments and messages.Successful Page connection or webhook resync.
pages_messagingReceives and sends replies in customer-initiated Messenger conversations.A customer messages the connected Page; you reply from Merbix Messages.
instagram_basicShows the linked Instagram professional account name and profile details on the integration card.Instagram account linked to the connected Facebook Page.
instagram_manage_commentsReceives Instagram comments and lets the Page owner reply from Merbix.A customer comments on a linked Instagram post.
instagram_manage_messagesReceives and replies to supported customer-initiated Instagram conversations. Merbix does not send unsolicited or cold Instagram messages.A customer sends an Instagram DM to the connected account.

6. How Merbix uses information

  • Operating accounts and workspaces.
  • Displaying comments and messages and drafting or sending approved replies.
  • Matching products, creating leads and orders, and providing reports.
  • Securing accounts and preventing abuse.
  • Processing subscriptions, support, and legal compliance.

We do not sell your personal information.

7. AI processing

Merbix may use Groq and/or Google Gemini to classify intent, match products, draft replies, extract structured order information, or generate business insights. Only data needed for the requested feature is processed.

Merbix does not use customer conversations to train a public general-purpose model operated by Merbix. When third-party AI APIs are used, information is processed under the applicable provider terms, privacy commitments, and Merbix’s configured service settings.

8. Human review and automated actions

  • Safe Mode and the Review Center let you review sensitive outputs before they are sent.
  • Some replies may be sent automatically according to your settings; merchants remain responsible for approved replies.
  • We do not guarantee that AI output is always correct.

9. Payments

Subscription payments may be completed using the payment options displayed in the Merbix billing interface, which may include manual InstaPay or Vodafone Cash transfers. Merbix may store a transaction reference or payment confirmation information for verification. Merbix is not a licensed payment institution.

10. Information sharing and service providers

ProviderRole
Meta PlatformsWebhooks, Graph API, OAuth for connected Pages and Instagram accounts
GroqAI API for classification and reply drafting when configured
Google GeminiAI API for classification and reply drafting when configured
PostgreSQL hostingApplication database
Zoho SMTPTransactional email (OTP and account messages)
Merbix file storageUploaded logos and workspace media

11. Data security

  • HTTPS for connections.
  • Meta tokens and AI keys encrypted with AES-256-GCM.
  • JWT authentication and session cookies.
  • Workspace-level data isolation.
  • HMAC signature verification for Meta webhooks.

12. Data retention

Merbix stores account and business data in PostgreSQL until you request deletion or your account is removed. Some records may be soft-deleted or disconnected while remaining in the database. Merbix does not run automated purge jobs for all data categories. Backup copies, if any, may persist for a period determined by the hosting provider’s backup lifecycle — confirm with your Merbix operator.

Settings such as AI processing windows or historical import limits control what Merbix processes or imports — they are not automatic deletion periods.

13. Disconnecting Meta accounts

  • Inside Merbix: Settings → Integrations → Disconnect.
  • Inside Facebook: Settings → Business Integrations → Merbix → Remove.
  • Disconnecting stops new collection and revokes or removes tokens where technically supported.
  • Historical business records may remain unless you request deletion.

14. Your rights

  • Access, correction, deletion, and objection where applicable.
  • Withdraw connected-platform access.
  • Contact us to submit a request.

15. Account and data deletion

See Data Deletion Instructions at /data-deletion. Email support@merbix.cloud from your account email with your workspace name to identify your account.

There is no self-service Delete Account button in the current interface.

16. Children

Merbix is directed to adults (18+) and does not target children.

17. International processing

Data may be processed through hosting or AI providers outside Egypt under their applicable terms.

18. Changes to this policy

Last updated: July 22, 2026. We may update this policy and publish it at https://merbix.cloud/privacy.

19. Contact

Contact

Operator: Merbix, operated from the Arab Republic of Egypt

Country: Arab Republic of Egypt

Email: support@merbix.cloud

Data deletion: /data-deletion