Sift Tech LLC
Privacy Policy
Effective date: January 1, 2026
Sift Tech builds AI products and delivers AI engineering services for businesses. This policy explains what data we collect across everything we do, why we collect it, who else sees it, and how you can get it deleted. In short: we collect only what we need to run our products and deliver our services, we do not sell personal data, we do not use your content for advertising or to train AI models, and you can email [email protected] at any time to access, correct, or delete your data.
1. Who we are and what this policy covers
Sift Tech LLC is a limited liability company registered with Sharjah Media City (Shams) free zone, Sharjah, United Arab Emirates (License No. 2643451.01). Our registered address is Sharjah Media City, Sharjah, UAE. This is our company-wide privacy policy — it covers everything we operate and offer:
Our websites — sift-tech.com and the sites of our products, including marketing content and contact forms.
Our products:
- ARP — “Your Digital Smart Employee” — an AI assistant platform (admin console at arp.sift-tech.com) that businesses hire to answer their customers’ messages over WhatsApp, Facebook Messenger, Instagram DMs, and website chat widgets. It includes our chat and helpdesk platform at chat.sift-tech.com (built on the open-source Chatwoot platform and operated by us), the Sift Tech mobile app (Android and iOS) that business staff use to read and reply to conversations, and workflow automations run on the business’s behalf — for example, saving an enquiry to a spreadsheet, recording a booking or order, or sending a reminder.
- ExSift — our data transformation engine (hosted at exsift.com), which uses agentic AI workflows to turn documents and unstructured business data into structured intelligence.
Our professional services — AI consulting and audits, custom AI agent builds, ad-hoc automations, systems integrations, and our enterprise and SMB service engagements.
In this policy, “customers” means the businesses that buy our products or services. “End users” means the people who interact with a business through our products — for example, a clinic’s patient or a restaurant’s customer messaging that business via ARP. If a specific product publishes its own privacy notice, that notice adds detail for that product; this policy still applies.
2. Our two roles: controller and processor
We handle personal data in two different roles:
- Where we decide how data is used — for visitors to our websites, for the accounts our customers and their staff hold on our products, and for our business contacts in consulting and service engagements — Sift Tech is the data controller and this policy applies directly.
- Where we handle data on a customer’s instructions — end users’ conversations processed through ARP, documents and business data a customer submits to ExSift or shares with us during an engagement, and data flowing through automations or integrations we build and run for a customer — that customer is the data controller and Sift Tech is a processor / service provider.
If you are an end user of one of our customers, that business is your first point of contact for privacy questions — its own privacy policy applies to your relationship with it. That said, we will always help, and we honor deletion requests sent directly to us regardless of which role we are in. See Access and deletion.
3. Data we collect
From end users of our customers (collected as a processor, on the customer’s behalf — mainly through ARP):
- The name or handle and profile details the messaging channel shares with us — for WhatsApp, your phone number; for Facebook Messenger and Instagram, your name and platform ID.
- Message content and any attachments you send.
- Conversation history and metadata, such as timestamps and which channel a message came from.
- Facts the assistant is asked to remember to serve you better — for example, preferences or an upcoming appointment.
- Records created while serving you, such as bookings, orders, and enquiries.
From our customers and their staff (collected as a controller for accounts, and as a processor for submitted content):
- Account details: name, email address, and password. Passwords are stored hashed — we cannot read them.
- Roles and permissions within the customer’s account.
- Sign-in records and audit logs.
- Device push notification tokens, if you use the mobile app.
- Content you submit to our products for processing — for example, documents uploaded to ExSift — which we process only to provide the service.
- Billing and usage records.
From clients of our professional services:
- Business contact details of the people we work with — names, emails, phone numbers, job titles.
- Project materials and data shared with us for the engagement — for example, systems documentation for an audit, or sample data for building a custom agent or automation. We use these only to deliver the engagement.
From website visitors (collected as a controller):
- Whatever you submit through our contact forms, such as your name, email, and message.
- Basic technical logs, such as IP address and browser type, kept for security and troubleshooting.
Cookies. We use only functional and session cookies — for example, to keep you signed in. We do not use advertising trackers, and we do not currently use analytics tools on our sites. If that changes, we will name the tool here first.
4. How we use data
We use the data above to:
- Run our products — answering messages (including generating AI responses on a business’s behalf), routing conversations to human agents, processing documents and data submitted for transformation, running configured automations, and sending enabled notifications.
- Deliver our professional services — consulting, audits, custom builds, and integrations — using engagement data only for that engagement.
- Operate, secure, and improve our services — including preventing abuse and fraud.
- Measure usage for billing, and manage our customer accounts.
- Respond to enquiries you send us.
Two things we do not do: we do not sell personal data, and we do not use your content or conversations for advertising.
5. How AI is involved
AI is at the core of what we build. Content handled by our products and by solutions we build for customers — messages sent to a business using ARP, documents submitted to ExSift, data flowing through a custom agent or automation — may be processed by AI language models to generate responses or structured output.
- When you chat with a business through ARP, you may be talking to an AI assistant acting on that business’s behalf. The conversation can be transferred to a human agent at any time — either because you ask, or because the business’s rules hand it over.
- AI outputs can be imperfect. The business you are dealing with remains responsible for the service it provides to you.
- We do not use customers’ content or conversations to train our own AI models or anyone else’s. Content is sent to AI model providers only to generate a response or result in the moment (see the next section).
6. Third parties and subprocessors
We share data with the following providers, only as needed to run our services:
- Meta Platforms (WhatsApp Business Platform, Facebook Messenger, Instagram) — delivers messages where a business uses our messaging channels. Meta’s own terms and privacy policies apply to those channels.
- AI model providers — OpenAI, and OpenRouter as a routing provider — receive content so a response or result can be generated.
- Google Firebase Cloud Messaging and Apple Push Notification service — deliver push notifications for the mobile app.
- Cloudflare — DNS, TLS, and traffic proxying for our sites and services.
- Oracle Cloud Infrastructure — hosting for our platforms.
- Google services (for example, Google Sheets) — only where a customer’s configured automation or integration sends data there.
Where a custom build or integration for a specific customer involves other providers, we name them to that customer in the engagement. We bind our processors to confidentiality and data-protection terms consistent with this policy.
International transfers. Some of these providers process data outside your country. Where that happens, we rely on appropriate safeguards, such as contractual data-protection commitments with each provider.
7. How long we keep data
We keep product and account data while the customer’s account is active, and afterwards only as long as needed for legal and billing purposes. After an account is closed, we delete or anonymize its data on request.
Engagement materials from professional services are kept for the duration of the engagement and any agreed support period, then deleted or returned as agreed with the client.
You do not have to wait for account closure — anyone can request deletion at any time, as described in the next section.
8. Access and deletion
Anyone — an end user, a customer’s staff member, a services client, or a website visitor — may request access to, correction of, or deletion of their personal data by emailing [email protected]. Depending on where you live, laws such as the EU GDPR and the UAE Personal Data Protection Law may also give you rights to restrict or object to processing and to data portability; we honor these on the same contact.
To request deletion:
- Email [email protected] with the identifier you used — for example, the phone number or handle you messaged from, or your account email — and, if you are an end user, the name of the business you interacted with.
- We verify that the request comes from you.
- We delete your data from our systems within 30 days and send you a confirmation.
End users can also ask the business they interacted with directly — as the controller of that data, it can instruct us to delete it. Either route works; we honor both.
Mobile app account deletion. If you use the Sift Tech mobile app, you can request deletion of your account and its associated data the same way — email [email protected] and we will complete it within 30 days.
9. How we protect data
- All data is encrypted in transit (TLS).
- Access to personal data is limited to staff who need it, protected by access controls.
- Each customer’s data is isolated from other tenants on our platforms.
- Administrative actions are recorded in audit logs.
No system is perfectly secure, but if we learn of a breach affecting your data, we will notify affected parties and authorities as the law requires.
10. Children
Our services are not directed at children — under 16 where that is the local age of consent, and in any case under 13. We do not knowingly collect personal data from children. If you believe a child has provided us data, email [email protected] and we will delete it.
11. The Sift Tech mobile app
- Push notifications are opt-in and controlled through your device’s operating system settings. You can turn them off at any time.
- Camera and photo access is requested only if you choose to attach media to a message, and is used solely to send that media. We never access your camera or photos in the background.
- Account deletion for app users is described in Access and deletion.
12. Changes to this policy
We may update this policy as our services or the law change. When we do, we will update the effective date at the top of this page, and for significant changes we will notify customers directly. The current version always lives at sift-tech.com/privacy.
13. Contact us
Data Protection Officer
Sift Tech LLC
Email: [email protected]
Postal address: Sharjah Media City (Shams), Sharjah, United Arab Emirates
Our Terms of Service describe the rules for using our services.