Back to PropX

Privacy Policy

Last updated: 30 June 2026

PropX is a multi-tenant real-estate CRM that helps businesses capture leads and communicate with them, including over the WhatsApp Business Platform. This policy explains what data we process, why, and the choices and rights you have.

1. Who we are

PropX (“PropX”, “we”, “us”) provides a software-as-a-service customer-relationship platform for real-estate businesses. Throughout this policy we distinguish two roles:

  • Customers (Controllers) — the organisations that subscribe to PropX and load their own leads, contacts and WhatsApp Business accounts. They decide what data to process and are the controllers of that data.
  • End Users / Data Subjects — the leads, contacts and WhatsApp recipients whose information a Customer stores in, or messages through, PropX. For that data PropX acts as a processoron the Customer’s behalf.

For privacy questions, or to reach our Grievance Officer, email info@business-compose.com.

2. Data we collect

Account & organisation data. When a Customer signs up we collect names, email addresses, hashed authentication credentials, organisation details and role assignments (owner, admin, manager, agent).

Lead & contact data. Customers store information about their prospects, which may include: full name, phone and alternate phone numbers, email, WhatsApp number, budget range, preferred location and project, unit preference, purchase timeline, lead source, tags, notes, activity history and any custom fields the Customer defines.

WhatsApp Business Platform data. When a Customer connects a WhatsApp Business Account through Meta, we process — strictly to operate the messaging features the Customer enables:

  • WhatsApp Business phone numbers and their phone number IDs, and the WhatsApp Business Account (WABA) ID
  • Approved message templates and their content
  • Inbound and outbound message content, and message metadata such as delivery, sent, read and failure status
  • The phone numbers and display names of the contacts a Customer messages

Meta credentials.To call the WhatsApp Cloud API and Graph API on a Customer’s behalf we store access tokens and related identifiers (e.g. App ID, phone number ID). Tokens are held server-side only, are never exposed to the browser, and are used solely to provide the service.

Technical & usage data. Session cookies for authentication, IP address, browser/device information, and application logs used for security, debugging and abuse prevention.

3. How we use data

  • Provide the CRM: capturing, organising, assigning and tracking leads across the pipeline
  • Send and receive WhatsApp messages, run campaigns and automated workflows that a Customer configures
  • Track message deliverability (delivered / read / failed) and prevent duplicate or failed sends
  • Authenticate users, enforce per-organisation access, and keep the service secure
  • Provide support, and notify Customers about service-related changes
  • Comply with legal obligations and enforce our Terms

We do not sell personal data, and we do not use data obtained through the WhatsApp Business Platform or other Meta Technologies for advertising or for any purpose other than providing and improving the features the Customer has enabled.

4. WhatsApp & Meta Platform compliance

Our use and transfer of information received from Meta APIs adheres to the Meta Platform Terms and the Meta Developer Policies, and Customers’ messaging is subject to the WhatsApp Business Messaging Policy. PropX is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc.; “WhatsApp” is a trademark of Meta. Each Customer is responsible for obtaining the opt-in and consent required to message its contacts.

6. Sharing & sub-processors

We share data only with infrastructure providers that help us run PropX, under contractual confidentiality and data-protection obligations:

  • Supabase — managed PostgreSQL database and authentication. Customer data is isolated per organisation using row-level security.
  • Vercel — application hosting and content delivery.
  • Trigger.dev — background job execution for campaigns and workflows.
  • Meta Platforms — the WhatsApp Cloud API and Graph API, used to deliver the messaging features a Customer enables.

We may also disclose data where required by law, or to protect the rights, safety and security of PropX, our Customers and the public. We do not sell or rent personal data.

7. Data retention & deletion

We retain personal data for as long as a Customer’s account is active and as needed to provide the service. When data or an account is deleted, we remove it from our production systems and it is purged from encrypted backups within 30 days, except where retention is required by law. For full instructions on deleting data — including data processed through WhatsApp — see our Data Deletion page.

8. Security

We protect data with measures including strict per-organisation isolation via row-level security, encryption in transit (TLS), server-side-only handling of access tokens and secrets, HMAC-signed outbound webhooks with replay protection, and SSRF protections that block requests to private or internal network addresses. No method of transmission or storage is completely secure, but we work to protect your data and to notify affected parties of incidents as required by law.

9. Your rights

Subject to applicable law you may request access to, correction of, or deletion of your personal data, and you may withdraw consent or raise a grievance. Because PropX usually processes End-User data on a Customer’s behalf, please direct requests to the Customer (the business you interacted with). If you contact us directly, we will forward your request to the relevant Customer and assist them in responding. To exercise a right or raise a grievance, email info@business-compose.com.

10. Cookies

We use strictly necessary cookies to keep you signed in and to secure the application. We do not use third-party advertising or cross-site tracking cookies.

11. Children's data

PropX is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child’s data has been provided to us, contact us and we will delete it.

12. International transfers

Our service providers may process data in regions outside your own. Where data is transferred across borders, we rely on the providers’ contractual safeguards and process the data consistent with this policy and applicable law.

13. Changes & contact

We may update this policy from time to time; material changes will be reflected by the “Last updated” date above. For any question about this policy or our data practices, contact info@business-compose.com (registered office: [Registered office address], India).