Mirage Group SHPK ("Mirage Group", "we", "us", "our") is a hospitality technology company registered in Albania (NUIS available on request). "Mirage Group Chat" (the "App", accessible at https://chat.hubpms.com) is a multi-channel guest-communication platform used by hotels, villas, and short-stay operators ("Tenants") to receive and reply to messages from their guests across WhatsApp Business, Facebook Messenger, Instagram Direct, SMS, email and an embeddable webchat widget.
Within the meaning of GDPR and Meta Platform Terms 4.a, Mirage Group acts as a data processor on behalf of each Tenant (who is the data controller of their own guest conversations).
When a Tenant connects their Facebook Page, Instagram Business account, or WhatsApp Business account to Mirage Group Chat via Meta's Login flow, we receive and store only the data strictly necessary to provide the service:
| Permission | Data received | Purpose |
|---|---|---|
| public_profile | Tenant administrator's Meta user ID, name, profile picture | Identify the agent currently signed in to Mirage Group Chat |
| pages_show_list | List of Facebook Pages the Tenant manages | Allow the Tenant to choose which Page to connect |
| pages_manage_metadata | Page subscription to webhooks | Receive inbound messenger messages in real time |
| pages_messaging | Messenger conversations and message content with the Page | Display the conversation in the Tenant's inbox and let the agent reply |
| pages_read_engagement | Reaction/read metadata on Page conversations | Show delivery and read receipts to the agent |
| instagram_basic, instagram_business_basic | Linked Instagram Business account ID, username, profile picture | Identify the IG account inside the Tenant's inbox |
| instagram_manage_messages, instagram_business_manage_messages | Instagram Direct conversations sent to the connected Business account | Display IG DMs in the inbox and allow replies within Meta's 24-hour messaging window |
| whatsapp_business_messaging | Inbound and outbound WhatsApp Business messages, phone-number IDs, message templates the Tenant approved with Meta | Two-way WhatsApp messaging with the Tenant's guests |
| whatsapp_business_management | WABA ID, phone-number assets, template list and status | Allow the Tenant to view and pick approved templates when sending utility/marketing messages |
| Human Agent | — | Allows a human Tenant agent (not a bot) to reply within Meta's 7-day extended messaging window when the guest reached out first |
We do not request user emails, friend lists, posts, ads, audiences, or any data unrelated to inbox messaging.
When a guest of a Tenant writes to the Tenant via WhatsApp, Messenger, Instagram DM, SMS, email or the embedded webchat widget, we receive and store the message content, the guest's display name (or phone number / email), the message timestamp, and any attachments the guest sent (images, files, voice notes). This data is owned by the Tenant.
We do not sell or rent personal data. We do not use Meta Platform Data to build advertising profiles, train large foundation models, or for any purpose outside delivering the Tenant's own guest communications.
We share data strictly with sub-processors required to run the service:
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | EC2 hosting, RDS PostgreSQL database, S3 attachment storage, SES transactional email | EU (Frankfurt) |
| Stripe Inc. | Card payment processing for Tenant subscriptions | EU / US (with SCCs) |
| Anthropic PBC | Claude API for optional AI features (auto-reply, summary, translation) — only when the Tenant opts in | US (with SCCs) |
| Meta Platforms Inc. | Inbound and outbound messaging via WhatsApp, Messenger, Instagram APIs | EU / US (with SCCs) |
Any end user whose data we process can:
Send the request to privacy@hubpms.com. We respond within 30 days. To request deletion of all data associated with a Meta user ID, see Section 10 below.
End users can request immediate deletion of all data tied to their Facebook user ID, Instagram account, or WhatsApp number by emailing privacy@hubpms.com with the subject "Meta Data Deletion Request" and including the relevant Page ID / IG handle / WhatsApp number. We confirm deletion within 30 days.
Tenants can self-serve disconnection inside Mirage Group Chat at Settings → Channels → Disconnect. Disconnection revokes the OAuth grant with Meta and triggers deletion of all Platform Data within 30 days.
The App is not directed to anyone under 16. We do not knowingly collect data from children.
We will post material changes on this page and, where required, notify Tenants by email at least 14 days before the change takes effect.
This policy is governed by the laws of Albania, with respect to GDPR for European data subjects.