AderSale
Home Privacy Terms Data deletion
Back to site

Privacy Policy

Last updated: 23 August 2026. This page is the English text of the Hebrew original; where the two differ, the Hebrew governs.

Controller

The service is provided under the brand AderSale and operated by Aderet Nahir, Israel. Contact: info@adersale.com. AderSale processes conversations on behalf of, and on the instructions of, the business you contacted.

What is collected

From WhatsApp conversations: the sender's phone number and WhatsApp display name, the text of messages exchanged, message identifiers and timestamps, and an automatically generated interest score and short summary of the conversation. The agent processes text only — the content of voice notes, images and files is neither processed nor stored; what is kept is a record that such a message arrived, with its caption if one was attached, so a human can see the customer reached out. The text of a tapped button or list choice is kept as a text message, and delivery and read receipts are stored as a status on the message they refer to. From business users of the dashboard: email, name, role, an optional mobile number used solely for password recovery, a scrypt hash of the password, and sign-in records holding IP address and user agent so users can review and revoke their own devices.

The contact form also records your agreement to be contacted on WhatsApp, and the exact wording of that agreement as it appeared on screen. The box is not pre-ticked and must be ticked to send the form, so we may reply on WhatsApp to the number you gave; you can ask us to stop at any time, by replying or by email. If you would rather not use WhatsApp, email us directly at info@adersale.com.

This website sets no cookies, runs no third-party code, has no analytics, and makes no external requests at all.

Contact form

The form on the home page stores what you type into it — name, business name, contact details, your message, the form language and the time of submission — together with a one-way, salted hash of the IP address it was sent from. That hash is used solely to detect automated submissions and abuse of the form; the IP address cannot be recovered from it, and it is never used for advertising, profiling or tracking. The submitter's user agent is not stored. Submissions are used only to reply to your enquiry, are never shared with third parties, and are deleted automatically after 24 months or earlier on request.

Purposes

Generating a reply to an incoming enquiry; scoring and summarising it so a human can prioritise; displaying conversations and response metrics in the business's dashboard; and operating the account (sign-in, invitations, password recovery). Data is never sold or rented, and is not used for advertising or for profiling outside the business you contacted.

Processors

Running the service requires Meta Platforms (WhatsApp Business Cloud API — message delivery), OpenRouter (routing to the language model that drafts the reply and scores the conversation) and Anthropic (the Claude models OpenRouter routes to, and which the Claude Code path also calls where a business is configured to use it — Anthropic receives the transcript either way). The conversation transcript is sent to these providers for those purposes. Dashboard-user data is not. Beyond this, data is disclosed only where legally required.

Retention

Conversations and messages are kept for as long as the business account is active; there is no automatic deletion, and erasure is carried out on request (see Data deletion). Sign-in records expire after at most 14 days, or 24 hours of inactivity, and expired rows are removed by a daily cleanup. Inbound message identifiers, kept so the same message is never answered twice, are deleted after 30 days. Invitation links last 72 hours and are single-use; password-reset links last one hour; one-time codes last 10 minutes, allow 5 attempts and 3 requests per hour. The activity log (sign-ins and settings changes, including IP address) is kept for up to 12 months and then removed by the daily cleanup. Database backups are kept for up to 90 days and then deleted; a backup taken before a data deletion may hold that data until the window lapses. The register of deletion requests (confirmation code, source and handling status) is retained after handling, as the record that the request was honoured. Technical server logs rotate automatically under a size cap; phone numbers in them are masked and secrets are never written to them.

Security

All traffic is served over HTTPS. Each business's WhatsApp access token is encrypted at rest with AES-256-GCM, under a key held in a file only the server's superuser can read and handed to the service at start-up — so the account the service runs as, and anyone reaching the database through it, cannot read the key off disk. Passwords are stored only as scrypt hashes. Session rows store a hash of the cookie rather than the cookie, so signing out is real revocation. Every webhook delivery from Meta is HMAC-verified before it is processed. Each business's data is isolated at the database layer; one business cannot see another's conversations.

Your rights

To access, correct or erase your data, write to info@adersale.com. If this document changes, the date at the top is updated, and business customers are notified by email of any material change.

AderSale

An AI sales agent that answers WhatsApp leads in Hebrew and hands the ready ones to a salesperson.

Service

  • How it works
  • Capabilities
  • FAQ
  • Sign in

Legal

  • Privacy Policy
  • Terms of Service
  • Data deletion
  • Business details
  • info@adersale.com
AderSale · Operated by Aderet Nahir, Israel
עב EN