1. Who we are
Nexus is a customer-communication, CRM and social-publishing platform operated by Startip L.L.C, a limited liability company organized in the State of Delaware, United States (“Startip”, “we”, “us”). This policy covers the Nexus website (nexus.startip.net), the Nexus web console (app.nexus.startip.net), the Nexus API (api.nexus.startip.net) and the Nexus mobile apps (together, the “Service”).
Businesses that sign up for Nexus (“Customers”) use it to talk to their own customers and leads (“Contacts”). For account and billing data of Customers and their team members, Startip is the controller. For data that Customers put into or receive through Nexus about their Contacts (“Customer Data”), Startip acts as a processor / service provider on the Customer’s instructions; the Customer is the controller of that data.
2. Data we collect
2.1 Account data
- Name, email address, password (stored only as a salted Argon2 hash), role and workspace membership.
- If you sign in with Google: your Google account email, name and profile ID.
- Workspace details (name, plan, settings) and billing contact details. Card payments are handled by our payment processor; we never store full card numbers.
2.2 Customer Data (contacts and CRM)
- Contacts, companies, deals, tasks, notes, tags, custom fields and files that a Customer creates, imports (e.g. CSV upload) or syncs into Nexus.
- This can include Contacts’ names, phone numbers, email addresses, social profile names/IDs and any other information the Customer chooses to store.
2.3 Messages
- Messages and attachments exchanged between a Customer and its Contacts over the channels the Customer connects: WhatsApp (WhatsApp Business Platform), Facebook Messenger, Instagram Direct, email and the Nexus web-chat widget.
- Message metadata such as sender/recipient identifiers (phone number, page-scoped or Instagram-scoped ID, email address), timestamps, delivery/read status and conversation assignment.
2.4 Connected social accounts
- When a Customer connects a Facebook Page, Instagram professional account, WhatsApp Business account or LinkedIn page: the account/page IDs and names, granted permissions, and access tokens.
- Access tokens are encrypted at rest using envelope encryption (a per-workspace data key wrapped by a master key held only in server configuration) and are never shown back in the interface.
- Posts the Customer drafts, schedules or publishes through Nexus, and the engagement metrics (reach, impressions, likes, comments) the platforms return for those posts.
2.5 Technical and usage data
- IP address, browser/device type, pages and features used, and server logs needed to operate, secure and debug the Service.
3. How we use data
- To provide the Service: show conversations in a unified inbox, send the replies and posts a Customer authors or schedules, run the CRM, analytics and campaigns the Customer configures.
- To authenticate users, enforce workspace separation and permissions, and keep the Service secure (fraud and abuse prevention).
- To provide support, send service and security notices, and (for Customers’ account contacts only) product updates they can opt out of.
- To bill for paid plans and comply with legal obligations.
We do not sell personal data, we do not use Customer Data for advertising, and we do not use one Customer’s data to serve another Customer.
Where the GDPR or similar laws apply, our legal bases are: performance of a contract (providing the Service), legitimate interests (security, service improvement, B2B communications), legal obligation, and consent where required.
4. Meta Platform data (Facebook, Instagram, Messenger, WhatsApp)
Nexus integrates with Meta’s APIs only when a Customer chooses to connect its own Facebook Page, Instagram professional account or WhatsApp Business account. Data we receive from Meta (“Platform Data”) is used only to:
- Publish and schedule posts that the connected business creates in Nexus, and show that business the results (post status and insights);
- Receive and reply to messages on behalf of the connected business in its Nexus inbox (including automated or AI-assisted replies the business enables);
- Show the connected business information about its own Page/account (name, picture, IDs) so it can manage the connection.
We process Platform Data in accordance with the Meta Platform Terms and Developer Policies, the WhatsApp Business policies, and Instagram’s terms. In particular, we do not sell, license or purchase Platform Data; we do not use it for advertising, profiling for third parties, or eligibility decisions; we do not transfer it to data brokers; and we share it only with the sub-processors listed below as needed to run the Service.
When a business disconnects an account in Nexus, or removes the Nexus app from its Facebook/Instagram settings, we delete the stored access tokens immediately and stop receiving Platform Data for that account. To request deletion of all data, see our Data Deletion instructions.
5. LinkedIn and Google data
LinkedIn: when a Customer connects a LinkedIn member or organization page, we store the access token (encrypted) and page identifiers and use them solely to publish the posts the Customer schedules and to read those posts’ basic metrics, in line with LinkedIn’s API Terms of Use.
Google: if you use “Sign in with Google”, we receive only your basic profile (email, name, Google account ID) and use it solely to sign you in. Nexus’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. AI features
If a Customer enables AI features (suggested replies, AI agent replies, intent detection, content drafting or knowledge-base search), the relevant message text, conversation context and knowledge-base content are sent to our AI providers to generate the result: Anthropic (language model) and Voyage AI (text embeddings for knowledge-base search). Under these providers’ commercial API terms, inputs and outputs are not used to train their models. AI-generated replies are labeled in the Nexus inbox, and Customers can turn AI features off at any time.
7. Sharing and sub-processors
We share data only with the following categories of service providers, under contracts that limit their use to providing services to us, or when required by law:
| Provider | Purpose | Data involved |
|---|---|---|
| Cloud VPS hosting provider | Servers, database, file storage and backups that run Nexus | All Service data (encrypted in transit; tokens encrypted at rest) |
| Anthropic, PBC (USA) | AI replies, intent detection, content drafting | Message text and context sent for an AI task |
| Voyage AI (USA) | Embeddings for knowledge-base search | Knowledge-base text and search queries |
| Meta Platforms, Inc. (Facebook, Instagram, Messenger, WhatsApp) | Sending/receiving messages and publishing posts for connected accounts | Outgoing messages and posts; account identifiers |
| LinkedIn Corporation | Publishing posts for connected LinkedIn pages | Posts and account identifiers |
| Google LLC | “Sign in with Google” | Sign-in request |
| Email delivery provider | Sending emails (notifications, campaigns, email-channel replies) | Recipient address and email content |
| Payment processor | Billing for paid plans | Billing contact and payment details |
We may also disclose data if required to comply with law or valid legal process, to protect the rights and safety of our users or the public, or as part of a merger or acquisition (with notice to affected Customers).
8. Retention
- Account and Customer Data is kept for as long as the workspace is active. After a workspace is deleted, its data is deleted from our live systems within 30 days.
- Backups are rotated automatically and kept for no longer than 14 days, so deleted data disappears from backups within that window.
- Access tokens for connected social accounts are deleted immediately when the account is disconnected.
- Server logs are kept for a limited period (normally no longer than 90 days) for security and troubleshooting.
- We may keep limited records longer where the law requires it (for example invoices for tax purposes).
9. Deletion and your rights
Customers and team members can at any time:
- Disconnect any social account (this revokes and deletes its stored tokens);
- Delete an individual Contact (deletion cascades to that Contact’s conversations, messages and CRM records) or export everything held about a Contact from the Contact’s record in Nexus — to answer a GDPR access or erasure request;
- Delete their workspace and account, or ask us to do it by emailing info@startip.net.
Step-by-step instructions are on our Data Deletion page. We complete deletion requests within 30 days.
Contacts of our Customers (people who message a business that uses Nexus) should first contact that business, which controls their data. You may also email us and we will forward your request and assist the business.
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent. California residents have the rights described in the CCPA/CPRA; we do not sell or “share” personal information for cross-context behavioral advertising. You can lodge a complaint with your local data protection authority. We will not discriminate against you for exercising your rights.
10. Security
All traffic is encrypted with TLS (HTTPS). Each workspace’s data is isolated at the database level using PostgreSQL row-level security. Third-party access tokens are envelope-encrypted at rest. Passwords are hashed with Argon2. Access is role-based (Owner, Admin, Agent, Viewer). No system is perfectly secure; if we become aware of a breach affecting your data we will notify affected Customers and authorities as required by law.
11. Cookies and browser storage
The marketing website does not use advertising or tracking cookies. It stores your language choice (English/Arabic) in your browser’s local storage and loads fonts from Google Fonts, which receives your IP address to deliver them. The Nexus web console uses your browser’s local storage to keep you signed in and remember preferences; these are strictly necessary for the Service. The web-chat widget stores a visitor identifier so a conversation continues across page loads.
12. International transfers
Startip is based in the United States and our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
13. Children
Nexus is a business service and is not directed to children under 16. We do not knowingly collect personal data from children through our own sign-up.
14. Changes to this policy
We may update this policy. We will post the new version here with a new “Last updated” date and, for material changes, notify Customers by email or in the app before they take effect.
15. Contact us
Startip L.L.C — operator of Nexus
United States
Privacy & data requests: info@startip.net
Nexus