Skip to content
MK LABS

MK LABS

Privacy Policy

Last updated:

MK LABS ("we", "us") builds and runs software for restaurants and other businesses ("our clients"): AI assistants that answer customers on WhatsApp, Facebook Messenger and Instagram, ordering websites, operations dashboards, and point-of-sale (POS) apps. Our Meta developer app appears on Facebook as "MK projects".

This policy explains what personal data passes through those systems, why, who else receives it, how long we keep it, and how to have it deleted. It applies to all of our services and to this website.

1. Who is responsible for your data

If you are a customer of one of our clients (for example, you messaged a restaurant or ordered from its website), that business decides why your data is collected, and we process it on the business's behalf and under its instructions. You can direct any request either to the business or to us, and we will handle it together.

For our own business clients and their staff, for people who connect their Meta accounts to our app, for visitors to this website, and for anyone who contacts us, MK LABS is responsible for the data.

2. What we collect

From people who message a business we serve on WhatsApp, Messenger or Instagram:

  • Your name or profile name and the identifier the platform gives us (your WhatsApp phone number or username, or your Messenger / Instagram user ID).
  • The content of your messages: text, voice notes, photos (for example a screenshot of a payment transfer, or a photo of an order), locations you share, and the time each message was sent and delivered.
  • Order details: items, sizes and add-ons, prices, delivery address and area, phone number, payment method, and any notes.
  • Ratings, complaints and anything attached to them.

From people who order on an ordering website we built for a business:

  • Your name, phone number, delivery address, order and notes.
  • Anonymous usage data, described in section 8.

From businesses that connect their accounts to our app through Facebook Login for Business or WhatsApp Embedded Signup:

  • The name and Meta ID of the person who logs in.
  • The IDs and names of the assets the business chooses to share with us: business portfolio, WhatsApp Business account, business phone number and its display name, Facebook Page, and Instagram professional account.
  • The access tokens Meta issues for those assets, limited to the permissions the business approves in Meta's own dialog.
  • Messages, message templates and account notifications (webhooks) for those assets.

From our clients' staff who use our dashboards and POS apps:

  • Login details, and a record of actions taken such as order status changes and replies sent to customers.

From visitors to this website, and from people who contact us:

  • Anonymous usage data (section 8), plus technical logs our hosting provider keeps, such as IP address and browser type.
  • Whatever you send us when you get in touch.
  • Business contact details that businesses publish themselves (for example on their Instagram profile, website or map listing), which we use to introduce our services to them.

3. How we use it

  • To answer customers' questions and take their orders on the business's behalf, and to pass each order to the business's staff and delivery team.
  • To send updates about an order the customer placed: confirmation, preparation, dispatch, a request to rate it afterwards, and replies to any complaint.
  • To understand voice notes and photos: voice notes are converted to text, and photos are checked for what they show (for example whether a picture is a payment receipt).
  • To let the business's staff see conversations, step in and reply themselves, and see order history, so returning customers are recognised.
  • To produce statistics for the business, such as order counts and returning-customer rates.
  • To detect and block spam and abuse.
  • To keep our systems running and to fix mistakes, which includes reviewing conversations when something went wrong.
  • To operate the Meta assets a business connected to our app, only to deliver the service that business asked for.
  • To understand, in aggregate, how this website is used, and to reply to people who contact us.
  • To meet legal obligations.

We only message people inside conversations they started with the business, within the time windows and rules Meta sets. We do not send unsolicited messages. If a business sends promotional messages through our systems, it may only do so with Meta-approved templates, and only to people who agreed to receive them.

4. AI and automated replies

Replies from a business's assistant are generated by AI language models. Prices, order totals and delivery fees are calculated by our software from the business's own menu and price list, not made up by the AI. You can ask to speak to a person at any time, and the business's staff can take over any conversation.

AI is not used to make decisions about you that have legal or similarly significant effects. We do not use your messages or orders to train AI models.

5. Who we share it with

We do not sell personal data, and we do not share it with data brokers or with anyone for their own advertising. It is shared only with:

  • The business you contacted, and its staff and delivery drivers. Drivers receive only what they need to deliver: name, phone number, address and the order.
  • Meta Platforms (WhatsApp, Messenger and Instagram), which carries the messages.
  • AI providers that generate replies and understand voice notes and photos: OpenRouter, which routes each request to a model provider such as OpenAI or Google; and Groq, for converting voice notes to text. We send only what is needed to produce the reply.
  • Supabase, which hosts our databases and stored files, and Railway, which hosts our servers.
  • Meta, through the Meta Pixel, on some businesses' ordering websites where the business has chosen to use it for advertising measurement (see section 8).
  • Authorities, when the law requires it, or when needed to protect people's safety or our rights.
  • A successor organisation if MK LABS is merged or sold, under this same policy.

Some of these providers store or process data outside Egypt, including in the United States and the European Union. We only use providers that commit to protecting the data they handle for us.

Requests from public authorities: we review every request for its legal basis before acting on it, challenge requests we consider unlawful or too broad, disclose only the minimum data the request lawfully requires, and keep a record of each request, our response, the legal reasoning and the people involved. Where the law allows, we tell the affected business first.

6. Data we receive from Meta

Data we receive through Meta's platforms (WhatsApp, Messenger, Instagram and Facebook Login) is used only to provide the service the business or the customer asked for, in line with Meta's Platform Terms and Developer Policies. We do not sell it, use it to target ads, or combine it with other data to build profiles of people.

A business can remove our access at any time: in Meta Business Suite under Settings → Integrations → Connected apps, in Facebook under Settings → Business integrations, or from WhatsApp Manager. The access tokens stop working as soon as access is removed. The data-deletion page explains how to have the information we already hold erased.

7. How long we keep it

  • Conversations, orders and customer records: for as long as the business uses our services, so it can see its order history and recognise returning customers. After a business stops using our services, we delete its customers' data within 90 days, unless the business asks us first to hand it over, or the law requires us to keep it.
  • Meta access tokens: until the business disconnects or stops using our services, then deleted.
  • Anonymous website usage data: up to 24 months.
  • Messages from people who contacted MK LABS, and business contact details used to introduce our services: until the conversation is no longer needed, or sooner if you ask.
  • Deleted data can remain in encrypted backups for a short period until those backups are overwritten.

8. Cookies and analytics

This website and the ordering websites we build use our own first-party analytics. A random ID is stored in your browser to count visits, together with the page you viewed, the site you came from, and whether you use a phone, tablet or computer. It does not identify you by name, and nothing is sent to third-party analytics companies. This website sets no cookies.

Ordering websites also remember the name, phone number and address you typed, on your own device (in browser storage, and on some sites in a first-party cookie that lasts up to a year), so you do not have to type them again. They stay in your browser and only reach the business when you place an order.

Some businesses choose to add the Meta Pixel to their ordering website. On those sites, Meta receives events such as page views, items added to the cart and completed orders, and uses cookies to measure the business's ads. You can control this through your browser's cookie settings and your Facebook ad preferences.

The dashboards and POS apps use storage in your browser or device only to keep you signed in.

9. How we protect it

All traffic is encrypted over HTTPS. Dashboards require a login. Access tokens and other secrets are kept on our servers and never sent to browsers. Our database provider encrypts data at rest. Only the MK LABS team members who need access to run and support a service have it.

No system is completely secure. If a breach affects your data, we will inform the affected business without delay, and the people affected where the law requires it.

10. Your rights

Subject to the law that applies to you, including Egypt's Personal Data Protection Law (No. 151 of 2020), you can ask to see the personal data held about you, correct it, have it deleted, object to or restrict how it is used, withdraw consent you gave, and receive a copy of it. You can also ask not to be messaged again.

Contact us or the business you dealt with. We answer within 30 days. To confirm the request comes from you, we may ask you to send it from the same WhatsApp number or account you used with the business.

11. Deleting your data

Step-by-step instructions, for both customers and businesses, are on our data-deletion page:

12. Children

Our services are not directed at children under 13, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

13. Changes to this policy

We will update the date at the top of this page whenever this policy changes. If the change is significant, we will also inform our business clients directly before it takes effect.

14. Contact us

MK LABS, Egypt. For questions, requests or complaints about privacy: