Privacy Policy — Mirage Group Chat

Operator: Mirage Group SHPK · App: Mirage Group Chat (chat.hubpms.com) · Effective date: 1 June 2026 · Last updated: 9 June 2026

1. Who we are

Mirage Group SHPK ("Mirage Group", "we", "us", "our") is a hospitality technology company registered in Albania (NUIS available on request). "Mirage Group Chat" (the "App", accessible at https://chat.hubpms.com) is a multi-channel guest-communication platform used by hotels, villas, and short-stay operators ("Tenants") to receive and reply to messages from their guests across WhatsApp Business, Facebook Messenger, Instagram Direct, SMS, email and an embeddable webchat widget.

Within the meaning of GDPR and Meta Platform Terms 4.a, Mirage Group acts as a data processor on behalf of each Tenant (who is the data controller of their own guest conversations).

Data Protection / Privacy contact
Email: privacy@hubpms.com
Postal: Mirage Group SHPK, Tirana, Albania
Response SLA: within 30 days for data subject requests.

2. What data we collect via Meta Platforms

When a Tenant connects their Facebook Page, Instagram Business account, or WhatsApp Business account to Mirage Group Chat via Meta's Login flow, we receive and store only the data strictly necessary to provide the service:

PermissionData receivedPurpose
public_profileTenant administrator's Meta user ID, name, profile pictureIdentify the agent currently signed in to Mirage Group Chat
pages_show_listList of Facebook Pages the Tenant managesAllow the Tenant to choose which Page to connect
pages_manage_metadataPage subscription to webhooksReceive inbound messenger messages in real time
pages_messagingMessenger conversations and message content with the PageDisplay the conversation in the Tenant's inbox and let the agent reply
pages_read_engagementReaction/read metadata on Page conversationsShow delivery and read receipts to the agent
instagram_basic, instagram_business_basicLinked Instagram Business account ID, username, profile pictureIdentify the IG account inside the Tenant's inbox
instagram_manage_messages, instagram_business_manage_messagesInstagram Direct conversations sent to the connected Business accountDisplay IG DMs in the inbox and allow replies within Meta's 24-hour messaging window
whatsapp_business_messagingInbound and outbound WhatsApp Business messages, phone-number IDs, message templates the Tenant approved with MetaTwo-way WhatsApp messaging with the Tenant's guests
whatsapp_business_managementWABA ID, phone-number assets, template list and statusAllow the Tenant to view and pick approved templates when sending utility/marketing messages
Human AgentAllows a human Tenant agent (not a bot) to reply within Meta's 7-day extended messaging window when the guest reached out first

We do not request user emails, friend lists, posts, ads, audiences, or any data unrelated to inbox messaging.

3. What guests send us

When a guest of a Tenant writes to the Tenant via WhatsApp, Messenger, Instagram DM, SMS, email or the embedded webchat widget, we receive and store the message content, the guest's display name (or phone number / email), the message timestamp, and any attachments the guest sent (images, files, voice notes). This data is owned by the Tenant.

4. Other data we collect directly

5. How we use the data

We do not sell or rent personal data. We do not use Meta Platform Data to build advertising profiles, train large foundation models, or for any purpose outside delivering the Tenant's own guest communications.

6. Sharing of data

We share data strictly with sub-processors required to run the service:

Sub-processorPurposeRegion
Amazon Web Services (AWS)EC2 hosting, RDS PostgreSQL database, S3 attachment storage, SES transactional emailEU (Frankfurt)
Stripe Inc.Card payment processing for Tenant subscriptionsEU / US (with SCCs)
Anthropic PBCClaude API for optional AI features (auto-reply, summary, translation) — only when the Tenant opts inUS (with SCCs)
Meta Platforms Inc.Inbound and outbound messaging via WhatsApp, Messenger, Instagram APIsEU / US (with SCCs)

7. Data retention

8. Your rights (GDPR / CCPA)

Any end user whose data we process can:

Send the request to privacy@hubpms.com. We respond within 30 days. To request deletion of all data associated with a Meta user ID, see Section 10 below.

9. Security

10. Data Deletion — Meta Platform Data

End users can request immediate deletion of all data tied to their Facebook user ID, Instagram account, or WhatsApp number by emailing privacy@hubpms.com with the subject "Meta Data Deletion Request" and including the relevant Page ID / IG handle / WhatsApp number. We confirm deletion within 30 days.

Tenants can self-serve disconnection inside Mirage Group Chat at Settings → Channels → Disconnect. Disconnection revokes the OAuth grant with Meta and triggers deletion of all Platform Data within 30 days.

11. Children

The App is not directed to anyone under 16. We do not knowingly collect data from children.

12. Changes to this policy

We will post material changes on this page and, where required, notify Tenants by email at least 14 days before the change takes effect.

13. Governing law

This policy is governed by the laws of Albania, with respect to GDPR for European data subjects.