Privacy Policy


Be Mobile Labs
Effective date: 9 June 2023
Last updated: 9 September 2026

This Privacy Policy explains how Be Mobile Labs LLC ("Be Mobile Labs", "we", "us" or "our") collects, uses, shares and protects personal information when you visit https://www.bemobilelabs.com (the "Site"), use our software products, applications and integrations (including any application we operate on Meta, Google, LinkedIn, X or other third-party platforms), engage us for design, development, automation or AI services, or otherwise interact with us (together, the "Services").

This policy is written to satisfy the disclosure requirements of the Meta Platform Terms and Developer Policies, the Google API Services User Data Policy, the LinkedIn API Terms of Use, the X Developer Agreement and Policy, the EU and UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), other US state privacy laws, the CAN-SPAM Act, the Telephone Consumer Protection Act ("TCPA") and the Children's Online Privacy Protection Act ("COPPA").

If you do not agree with this policy, please do not use the Services.

1. WHO WE ARE AND HOW TO CONTACT US

Be Mobile Labs is a digital product studio that designs and builds websites, mobile applications, custom software, workflow automations and AI voice and chat agents for business clients.

  • Legal entity: Be Mobile Labs LLC, a Delaware limited liability company

  • Registered address: 254 Chapman Rd, Ste 208 #22568, Newark, Delaware 19702, United States

  • Email: info@bemobilelabs.com

  • Phone: +1 (213) 222-6298

  • Website: https://www.bemobilelabs.com

For the purposes of the GDPR and UK GDPR, Be Mobile Labs is the "controller" of the personal information described in this policy, except where we process information on behalf of a client (see Section 4).

2. SCOPE OF THIS POLICY

This policy applies to:

  1. Visitors to the Site, including anyone who submits a contact, quote, booking or newsletter form.

  2. Clients, prospective clients and their staff who engage us for Services.

  3. Users of software we operate ourselves, such as our CRM, dashboards, mobile apps and AI agents ("Our Apps").

  4. Individuals whose information reaches us through third-party platform integrations that a client or user has authorised, such as Facebook Login, Facebook Pages, Instagram, Meta Lead Ads, Messenger, WhatsApp Business, Google services, LinkedIn or X (together, "Platform Data").

  5. People who call, text or chat with an AI voice or chat agent that we operate.

  6. Job applicants, suppliers and business contacts.

This policy does not apply to third-party websites, platforms or services that we link to or integrate with. Their own privacy policies govern their handling of your information.

3. INFORMATION WE COLLECT

3.1 Information you give us directly

  • Contact and identity details: name, email address, phone number, company name, job title, postal address and the content of your message when you contact us, request a quote, book a meeting or subscribe to updates.

  • Account details: username, password (stored in hashed form), profile photo, role and preferences when you create an account in one of Our Apps.

  • Project information: briefs, documents, designs, credentials to systems you ask us to work in, brand assets, customer lists and any other material you share with us to deliver a project.

  • Payment and billing details: billing name and address, tax identifiers and transaction records. Card and bank details are collected and processed by our payment processor (currently Stripe) and are never stored on our systems.

  • Communications: emails, chat messages, support tickets, call recordings and transcripts (see Section 3.4), meeting notes and feedback, including testimonials you agree to let us publish.

  • Recruitment information: CV, portfolio, employment history and references if you apply to work with us.

3.2 Information collected automatically

When you use the Site or Our Apps we and our service providers collect:

  • Device and connection data: IP address, browser type and version, operating system, device identifiers, language, time zone and screen size.

  • Usage data: pages viewed, links clicked, referring URL, time spent, scroll depth, form interactions, session recordings where enabled, crash reports and in-app events.

  • Approximate location derived from your IP address.

  • Cookies and similar technologies as described in Section 8.

3.3 Platform Data from third-party services

When you or a client connect a third-party account to Our Apps, or interact with a business through an integration we operate, we may receive information from that platform. We only request the permissions needed for the feature you are using, and we use the data only for that feature.

  • Meta (Facebook, Instagram, Messenger, WhatsApp)

    • Facebook Login: public profile (name, profile picture, Facebook user ID) and, where you grant it, email address.

    • Facebook Pages and Instagram Business accounts: Page or account IDs, names, posts, comments, messages, insights and audience metrics needed to publish content, respond to conversations or report performance for the account owner.

    • Meta Lead Ads: the fields a person submits in a lead form (typically name, email, phone and answers to custom questions) so that the advertiser's CRM can receive the lead and follow up.

    • Messenger and WhatsApp Business Platform: message content, sender identifiers and timestamps needed to deliver conversations to the business and, where the business uses one, to its AI agent.

    • Meta Pixel and Conversions API: website event data (page views, form submissions, purchases) used for measurement and advertising on behalf of the Site and clients.

  • Google: when you sign in with Google or connect Google services (for example Calendar, Gmail, Sheets, Google Ads or Google Business Profile) we receive basic profile information and the specific data covered by the scopes you approve. Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • LinkedIn: when you sign in with LinkedIn or connect a LinkedIn Page or Ad account we receive your basic profile (name, photo, headline, email where granted), Page content and analytics, lead form submissions from LinkedIn Lead Gen Forms and campaign metrics.

  • X (Twitter): when you connect an X account we receive your public profile, posts, mentions, direct messages where you grant access, and analytics needed to publish or report for that account.

  • Other integrations: CRMs (for example HubSpot, Salesforce, GoHighLevel), calendars, email providers, payment platforms, telephony providers and automation tools (for example n8n, Make, Zapier) that a client asks us to connect.

We never sell Platform Data, use it to build or augment user profiles for unrelated purposes, use it for surveillance, discrimination or eligibility decisions, or transfer it to data brokers or advertising networks. Platform Data is handled in accordance with each platform's terms, listed in Section 15.

3.4 AI voice and chat agents, call recording and SMS

Some of Our Apps are AI agents that answer or place phone calls, reply to text messages and chat on websites and messaging apps on behalf of a business.

  • Disclosure: our agents identify themselves as automated or AI assistants at the start of a conversation and, where required by law, state that the call may be recorded.

  • What we collect: caller ID, phone number, the audio of the call, a transcript, the information you provide during the conversation (for example your name, address, appointment preferences, service needs), sentiment and intent classifications and outcome data (for example whether an appointment was booked).

  • Recording and transcription: calls are recorded and transcribed to deliver the service, to route information to the business, for quality assurance and to improve the agent's accuracy. In jurisdictions that require the consent of all parties, recording only proceeds after the required notice or consent.

  • Text messaging: if you opt in to receive SMS or WhatsApp messages from us or from a business using our agents, we collect your mobile number, your consent record (date, time and method) and the content of the exchange. Message frequency varies. Message and data rates may apply. Reply STOP to opt out and HELP for help. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties, except as necessary to deliver the messages (for example our telephony provider).

  • Do not share sensitive information such as payment card numbers, government identifiers or health details with an AI agent unless the business you are contacting specifically asks for it through a secure process.

3.5 Information from other sources

We may receive information from business partners, referral sources, publicly available sources (for example a company website or LinkedIn profile) and data enrichment or verification providers, and we combine it with information we already hold.

3.6 Sensitive information

We do not seek to collect sensitive personal information (such as health, biometric, precise geolocation, racial or ethnic origin, religious beliefs, sexual orientation, financial account numbers or government identifiers) unless a client's project requires it and appropriate safeguards and consents are in place. We do not use or disclose sensitive personal information for purposes that would require a "limit the use" right under the CPRA.

4. WHEN WE ACT AS A PROCESSOR FOR OUR CLIENTS

Much of our work involves handling personal information on behalf of a client, for example customer records in a CRM we built, leads from a client's Meta Lead Ads, or conversations handled by an AI agent for a client's business. In those cases the client is the controller (or "business" under the CCPA) and we act as a processor (or "service provider") under a written agreement with that client.

If you interact with a business that uses our technology, the business's privacy policy governs how your information is used, and you should direct privacy requests to that business. We will help our clients respond to your requests where required. We only process client data on the client's documented instructions, and we do not use it for our own purposes except as permitted by law and our agreement with the client (for example to secure and maintain the service).

5. HOW WE USE INFORMATION

We use personal information for the following purposes and on the following legal bases (the legal basis applies where the GDPR or UK GDPR governs our processing):

  • Providing the Services — Examples: Responding to enquiries, preparing proposals, delivering projects, operating Our Apps, running AI agents, processing payments — Legal basis: Performance of a contract; steps prior to a contract

  • Operating integrations — Examples: Publishing content to a connected Page, retrieving leads, syncing calendars, delivering messages — Legal basis: Performance of a contract; consent (where you connect an account)

  • Account management — Examples: Creating and securing accounts, authenticating users, providing support — Legal basis: Performance of a contract

  • Communications — Examples: Service notices, invoices, security alerts, replies to your messages — Legal basis: Performance of a contract; legitimate interests

  • Marketing — Examples: Newsletters, case studies, event invitations and promotional messages you have signed up for — Legal basis: Consent; legitimate interests (existing customers), always with the ability to opt out

  • Analytics and improvement — Examples: Measuring how the Site and Our Apps are used, testing new features, training and evaluating our AI agents on de-identified or client-authorised data — Legal basis: Legitimate interests; consent for non-essential cookies

  • Advertising and measurement — Examples: Using pixels and conversion APIs to measure campaigns and reach audiences on Meta, Google, LinkedIn and X — Legal basis: Consent (where required); legitimate interests

  • Safety, security and fraud prevention — Examples: Detecting abuse, protecting systems, verifying identity — Legal basis: Legitimate interests; legal obligation

  • Legal compliance — Examples: Tax and accounting records, responding to lawful requests, enforcing our terms — Legal basis: Legal obligation; legitimate interests

  • Business transfers — Examples: Due diligence and transfer in connection with a merger, acquisition or sale of assets — Legal basis: Legitimate interests

We do not use automated decision-making that produces legal or similarly significant effects about you without human involvement. Our AI agents make routine conversational decisions (for example offering an appointment slot) but do not decide eligibility for credit, employment, housing, insurance or similar matters.

6. HOW WE SHARE INFORMATION

We share personal information only as described here. We do not sell personal information, and we do not share it for cross-context behavioural advertising except through the advertising cookies and pixels you can control as described in Section 8.

  • Service providers that process information on our behalf under contract, limited to what they need to perform their services. Current categories and examples:

    • Website hosting and content delivery: Framer, Vercel, Amazon Web Services, Google Cloud Platform

    • Databases and back-end services: Firebase, Supabase, MongoDB Atlas

    • Payments and invoicing: Stripe

    • Email, scheduling and CRM: Google Workspace, HubSpot, GoHighLevel, Calendly

    • Telephony and messaging: Twilio, Vapi, Retell and similar providers

    • AI model providers: OpenAI, Anthropic, Google, ElevenLabs and similar providers, used under terms that prohibit them from training on our customers' data

    • Analytics and error monitoring: Google Analytics, Microsoft Clarity, Sentry

    • Automation platforms: n8n, Make, Zapier

  • Third-party platforms you connect, to the extent necessary to operate the integration (for example sending a reply to Messenger or publishing a post to LinkedIn).

  • Our clients, when we act on their behalf (Section 4) or when you contact a client's business through technology we operate.

  • Professional advisers such as lawyers, accountants, insurers and auditors.

  • Authorities and other parties when required by law, subpoena or court order, to protect our rights, property or safety or those of others, or to investigate fraud or security issues.

  • Business transfers: a successor or acquirer in a merger, acquisition, financing, reorganisation or sale of assets, subject to this policy.

  • With your consent or at your direction, for example when you agree to be quoted in a testimonial.

We may share aggregated or de-identified information that cannot reasonably be used to identify you, for example benchmark statistics about AI agent performance.

7. DATA RETENTION

We keep personal information only as long as necessary for the purposes described above, and then delete or anonymise it. Typical retention periods:

  • Enquiries and prospect data: up to 24 months after our last contact.

  • Client project files and account data: for the duration of the engagement and up to 7 years afterwards for contractual, tax and legal purposes, unless the client instructs earlier deletion.

  • Call recordings and transcripts: 90 days by default, or the period agreed with the client; transcripts needed for a booked appointment or support case are retained with that record.

  • Platform Data: only as long as the integration is active and the data is needed for the feature. Platform Data is deleted within 30 days after you disconnect the integration or ask us to delete it, or sooner where the platform requires it (see Section 15).

  • Marketing data: until you unsubscribe, plus a suppression record so we honour your choice.

  • Analytics data: 14 to 26 months depending on the tool.

  • Backups: up to 35 days, after which deleted data is purged from backup cycles.

8. COOKIES AND SIMILAR TECHNOLOGIES

We use cookies, pixels, local storage and SDKs on the Site and in Our Apps.

  • Strictly necessary: required for security, load balancing, session management and remembering your cookie choices. These cannot be switched off.

  • Analytics and performance: help us understand how visitors use the Site, for example Google Analytics and Microsoft Clarity.

  • Functionality: remember your preferences, for example language or a previously started form.

  • Advertising and measurement: allow us and our advertising partners to measure campaign performance and show relevant ads. These include the Meta Pixel, Google Ads and Google Tag Manager, the LinkedIn Insight Tag and the X Pixel. These partners may combine the data with information they hold about you under their own privacy policies.

Where required by law, non-essential cookies are set only after you give consent through our cookie banner, and you can change your choices at any time via the "Cookie settings" link in the footer. You can also control cookies in your browser settings, use the opt-outs offered by Google (https://tools.google.com/dlpage/gaoptout), Meta (Ad preferences in your Facebook settings), LinkedIn (https://www.linkedin.com/psettings/guest-controls) and X (https://twitter.com/settings/account/personalization), or use industry tools such as https://optout.aboutads.info and https://www.youronlinechoices.eu.

We honour Global Privacy Control (GPC) browser signals as a request to opt out of the sale or sharing of personal information under applicable US state laws. We do not respond to other "Do Not Track" signals because there is no common standard for them.

9. YOUR RIGHTS AND CHOICES

Depending on where you live, you may have the following rights. We honour these rights for all users to the extent reasonably possible, regardless of location.

  • Access: obtain a copy of the personal information we hold about you.

  • Correction: ask us to fix inaccurate or incomplete information.

  • Deletion: ask us to delete your personal information (see also the Data Deletion Instructions at https://www.bemobilelabs.com/data-deletion).

  • Portability: receive your information in a structured, commonly used, machine-readable format.

  • Restriction and objection: ask us to limit how we use your information, or object to processing based on legitimate interests, including profiling.

  • Withdraw consent: at any time, without affecting the lawfulness of processing before withdrawal. You can disconnect a third-party platform in the app settings or from the platform's own settings (for example Facebook Settings > Apps and Websites).

  • Opt out of marketing: use the unsubscribe link in any email, reply STOP to any text message, or contact us.

  • Opt out of sale or sharing and limit sensitive data use (US state laws): we do not sell personal information; to opt out of sharing for cross-context behavioural advertising, use the cookie banner, the "Do Not Sell or Share My Personal Information" link in the footer, or a GPC signal.

  • Non-discrimination: we will not treat you differently for exercising your rights.

  • Appeal: if we decline a request, you may appeal by replying to our decision, and we will respond within the period required by law.

  • Complain: you can lodge a complaint with your data protection authority. In the EU, see https://edpb.europa.eu/about-edpb/about-edpb/members_en. In the UK, the Information Commissioner's Office at https://ico.org.uk. In California, the California Privacy Protection Agency at https://cppa.ca.gov.

To exercise any right, email info@bemobilelabs.com or call +1 (213) 222-6298. We will verify your identity using the email address or phone number associated with your data, and may ask for additional information where necessary. You may use an authorised agent to submit a request; we will ask the agent for proof of your written authorisation. We respond within 30 days (GDPR) or 45 days (CCPA/CPRA), extendable once where permitted, and we will tell you if we need more time.

10. SECURITY

We use administrative, technical and physical safeguards appropriate to the sensitivity of the information, including encryption in transit (TLS) and at rest, role-based access control, multi-factor authentication for our systems, least-privilege access to client environments, logging and monitoring, secure development practices, vendor due diligence and staff confidentiality obligations. Access tokens for third-party platforms are stored encrypted and are revoked when an integration is disconnected.

No method of transmission or storage is completely secure. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law, and in the case of Platform Data we will notify the relevant platform as its terms require.

11. INTERNATIONAL DATA TRANSFERS

We are based in the United States and our service providers operate in the United States, the European Economic Area, the United Kingdom and other countries. When we transfer personal information out of the EEA, UK or Switzerland, we rely on adequacy decisions, the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where appropriate. You can request a copy of the relevant safeguards by contacting us.

12. CHILDREN'S PRIVACY

The Site and Services are intended for adults and businesses. We do not knowingly collect personal information from children under 13 (or under 16 where a higher age applies, for example in parts of the EU). If you believe a child has provided us with personal information, contact us and we will delete it. Where a client's product is directed at children, we implement COPPA-compliant consent flows agreed with the client, and the client's privacy policy governs.

13. MARKETING COMMUNICATIONS AND TELEPHONE CALLS

  • Email: we send marketing emails only with your consent or, for existing customers, about similar services, and every email includes an unsubscribe link. We comply with the CAN-SPAM Act and equivalent laws.

  • Telephone and SMS: we and our AI agents call or text you only where you have provided the required consent, where you have an existing business relationship with us or the business you contacted, or where the call is informational (for example confirming an appointment you requested). Calls to numbers on the US National Do Not Call Registry are made only with prior express consent. Consent to receive calls or texts is not a condition of purchasing any goods or services.

  • Push notifications: Our Apps ask for permission before sending push notifications, and you can disable them in your device settings.

14. THIRD-PARTY LINKS AND EMBEDDED CONTENT

The Site may contain links to third-party websites and embedded content (for example calendars, videos, maps and social feeds). Those third parties may collect information about you in accordance with their own policies. We are not responsible for their practices.

15. PLATFORM-SPECIFIC DISCLOSURES

15.1 Meta (Facebook, Instagram, Messenger, WhatsApp)

  • We use Meta products in accordance with the Meta Platform Terms (https://developers.facebook.com/terms), Developer Policies, Business Tools Terms and the WhatsApp Business Terms.

  • We request only the permissions needed for the features in use, and we use Platform Data only to provide those features to the person or business that authorised access, to improve that experience, or as otherwise permitted by the Platform Terms and this policy.

  • We do not sell, license or purchase Platform Data; do not place it in a search engine or directory; do not use it to make decisions about eligibility, including for credit, employment, housing, insurance or public benefits; and do not use it for surveillance.

  • We keep Platform Data current, delete it when the person or business asks, when the platform requests it, when the feature no longer requires it, or when the person removes the app from their account, and in any case in line with the Platform Terms' deletion requirements.

  • You can remove our app's access at any time at Facebook Settings > Apps and Websites, or Instagram Settings > Apps and Websites. Removal revokes our access token; to have retained data deleted, follow the Data Deletion Instructions at https://www.bemobilelabs.com/data-deletion or contact us.

  • We maintain the technical and organisational security measures required by the Platform Terms, keep records of our processing and will cooperate with Meta's audit and monitoring requests.

15.2 Google

  • Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

  • We use Google user data only to provide or improve user-facing features that are prominent in the requesting application's interface, we do not transfer it to others except as necessary to provide those features, for security, to comply with law, or as part of a merger or acquisition with prior notice, and we never use it for advertising or allow humans to read it except with your consent, for security purposes, to comply with law, or for internal operations on aggregated and anonymised data.

  • You can revoke access at https://myaccount.google.com/permissions.

15.3 LinkedIn

  • We use the LinkedIn APIs in accordance with the LinkedIn API Terms of Use and Marketing API Program terms. Member data is used only to provide the features the member or Page administrator has requested, is not stored longer than LinkedIn permits, is refreshed or deleted as LinkedIn requires, and is never used to build profiles, for recruiting or sales prospecting outside the authorised product, or shared with third parties.

  • You can revoke access at https://www.linkedin.com/psettings/permitted-services.

15.4 X (Twitter)

  • We use the X API in accordance with the X Developer Agreement and Policy. X content and account data is used only for the features you authorise, is not used for surveillance or to infer sensitive characteristics, is not shared with government entities except as required by law, and is deleted when you disconnect your account or the content is deleted on X.

  • You can revoke access at https://twitter.com/settings/connected_apps.

15.5 Apple and Google app stores

Our mobile apps distributed through the App Store and Google Play comply with the Apple App Store Review Guidelines and Google Play Developer Program Policies, including the requirement to offer in-app account deletion where an app allows account creation. Each app's store listing includes a link to this policy and a summary of the data it collects.

16. ADDITIONAL INFORMATION FOR CALIFORNIA RESIDENTS

This section supplements the rest of the policy for residents of California under the CCPA/CPRA.

Categories of personal information collected in the last 12 months: identifiers (name, email, phone, IP address, account IDs); customer records (billing details); commercial information (services purchased, project history); internet or network activity (usage data, cookies); geolocation data (approximate, from IP); audio and electronic information (call recordings, chat transcripts); professional or employment information (job title, employer, applicant details); inferences (for example interest in particular services); and sensitive personal information only in the limited circumstances described in Section 3.6.

Sources: you, your devices, our clients, third-party platforms you connect, service providers and public sources.

Business purposes: as described in Section 5.

Disclosures for a business purpose: to the service providers and other recipients described in Section 6.

Sale or sharing: we do not sell personal information. We may "share" identifiers and internet activity with advertising partners through cookies and pixels for cross-context behavioural advertising; you can opt out as described in Section 8 and Section 9. We do not knowingly sell or share the personal information of consumers under 16.

Retention: as described in Section 7.

Rights: as described in Section 9, including the right to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information and non-discrimination. Requests can be made at info@bemobilelabs.com or +1 (213) 222-6298.

Shine the Light: California Civil Code section 1798.83 permits residents to request certain information about our disclosure of personal information to third parties for their direct marketing purposes. We do not make such disclosures.

Residents of Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia and other states with comprehensive privacy laws have similar rights, including the right to appeal, and may exercise them in the same way.

17. ADDITIONAL INFORMATION FOR THE EEA, UK AND SWITZERLAND

  • Our legal bases are set out in Section 5. Where we rely on legitimate interests, we have balanced those interests against your rights and you may object at any time.

  • You have the rights listed in Section 9, including the right to lodge a complaint with a supervisory authority.

  • We transfer data outside the EEA, UK and Switzerland only with the safeguards described in Section 11.

  • We do not require you to consent to non-essential cookies as a condition of using the Site.

18. CHANGES TO THIS POLICY

We may update this policy from time to time. We will post the updated version on the Site with a new "Last updated" date and, where the changes are material, notify you by email or through Our Apps before they take effect. Continued use of the Services after the effective date means the updated policy applies.

19. CONTACT US

Questions, requests or complaints about this policy can be sent to:

Be Mobile Labs LLC
254 Chapman Rd, Ste 208 #22568, Newark, Delaware 19702, United States
Email: info@bemobilelabs.com
Phone: +1 (213) 222-6298

Data deletion requests: https://www.bemobilelabs.com/data-deletion
Terms and Conditions: https://www.bemobilelabs.com/terms-and-conditions