Syren Stack
Syren StackPreSchool · Syren Stack

Privacy Policy

Effective date: [EFFECTIVE DATE]

Last updated: [EFFECTIVE DATE]

This Privacy Policy explains how Syren Stack ("we", "us", "our") collects, uses, stores, shares, and protects information in connection with PreSchool (the "App" or "Service"), our management and communication platform for kindergartens and preschools. This Policy covers, in particular, the App's Facebook integration, which lets a school connect its Facebook Page so our chatbot can automatically reply to messages the Page receives from parents and customers.

By using the App or connecting your Facebook Page, you agree to this Policy. If you do not agree, please do not connect your Page or use the App.

1Who this Policy applies to

This Policy covers two groups of people:

  • Page Owners — the school or business representatives who sign in to the App and connect a Facebook Page.
  • Page Visitors — people (typically parents/customers) who send a message to a connected Facebook Page and interact with our chatbot.

2Information we collect

2.1 From Page Owners (via Facebook Login)

When a Page Owner signs in with Facebook and connects a Page, we receive, with your permission:

  • Your name, Facebook user ID, and profile picture
  • Your email address (if granted)
  • The list of Facebook Pages you manage, and the Page you choose to connect (Page ID, Page name)
  • A Page access token that allows the App to send and receive messages on behalf of the connected Page

2.2 From Page Visitors (via the connected Page)

When a Page Visitor messages a connected Page, we receive and process:

  • The Page-scoped ID (PSID) assigned by Facebook to that person
  • Public profile information Facebook makes available (such as name and profile picture)
  • The content of messages sent to and from the Page, including text and any attachments (images, files)
  • Message timestamps and delivery/read metadata

We do not collect a Page Visitor's private Facebook profile beyond what the Messenger Platform provides for the conversation.

2.3 Technical and usage data

We automatically collect basic technical data needed to operate and secure the service, such as IP address, device/browser type, log records, and error diagnostics.

3How we use information

We use the information above to:

  • Authenticate Page Owners and connect the selected Facebook Page
  • Receive incoming messages and generate automated replies through our chatbot
  • Support booking and tour-request flows and related follow-up
  • Send operational notifications to Page Owners (e.g., new bookings, task updates)
  • Maintain, secure, debug, and improve the service
  • Comply with legal obligations

We do not use message content for advertising, and we do not sell any personal information.

4Facebook / Meta Platform data

The App uses Facebook Login and the Messenger/Pages APIs. We request only the permissions needed to operate the service, which may include:

`public_profile`, `email`— To identify and contact the Page Owner
`pages_show_list`— To display the Pages you manage so you can choose one to connect
`pages_messaging`— To receive messages sent to your Page and send automated replies
`pages_manage_metadata`— To subscribe your Page to message webhooks
`pages_read_engagement`— To read basic Page and conversation context needed to reply

Our use and transfer of information received from Meta APIs adheres to the Meta Platform Terms and Developer Policies, including the Limited Use requirements.

5AI processing and third-party sub-processors

To generate chatbot replies, message content sent to a connected Page is transmitted to third-party Large Language Model (LLM) providers solely to produce a response. These providers act as our sub-processors and are contractually restricted to processing the data only to provide their service. Depending on configuration, providers may include: [LIST YOUR PROVIDERS, e.g., Google (Gemini), OpenAI, DeepSeek].

We also rely on infrastructure and hosting providers to run the service: [LIST HOSTING/VPS PROVIDER(S)].

Because some of these providers operate outside Vietnam, relevant data may be processed in other countries (see Section 9).

We do not share personal information with any other third parties except: (a) as required by law or valid legal process; (b) to protect our rights, safety, or property; or (c) in connection with a merger, acquisition, or sale of assets, subject to this Policy.

6Data retention

We retain information only as long as needed for the purposes described in this Policy:

  • Page Owner account and connection data — kept while your Page remains connected and for a reasonable period afterward for security and legal reasons.
  • Message/conversation data — retained for [RETENTION PERIOD, e.g., 90 days / 12 months] to operate the chatbot, then deleted or anonymized.
  • Page access tokens — deleted when you disconnect your Page or delete your account.

When you disconnect a Page or delete your account, we delete or anonymize the associated data within [e.g., 30 days], except where retention is required by law.

7Your rights and choices

Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing.

Page Owners can disconnect a Page at any time from the App, and can revoke the App's access from Facebook → Settings → Business Integrations.

To exercise any right, contact us at ntrongtin11702@gmail.com.

8How to request data deletion

You can request deletion of your data at any time in either of these ways:

  1. 1Self-service: disconnect your Page and/or delete your account within the App, which removes your associated data.
  2. 2Email request: send a deletion request to ntrongtin11702@gmail.com with the Facebook account or Page name involved. We will confirm and complete the deletion within [e.g., 30 days].

Page Visitors who have messaged a connected Page may also request deletion of their conversation data by emailing ntrongtin11702@gmail.com or by contacting the Page they interacted with.

Data Deletion instructions URL: [PUBLIC URL WHERE THESE INSTRUCTIONS ARE HOSTED]

9International data transfers

Your information may be transferred to, stored, or processed in countries other than Vietnam, including where our AI, hosting, and infrastructure providers operate. Where required, we use appropriate safeguards for such transfers.

10Data security

We use reasonable technical and organizational measures to protect information, including encryption in transit, access controls, and secure storage of access tokens. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11Children's privacy

The App is intended for use by Page Owners and adult Page Visitors. It is not directed to children, and we do not knowingly collect personal information directly from children through the chatbot. If you believe a child has provided personal information, contact us at ntrongtin11702@gmail.com and we will delete it.

12Changes to this Policy

We may update this Policy from time to time. We will post the updated version at this URL and revise the "Last updated" date above. Material changes will be communicated where appropriate.

13Contact us

SYREN STACK

  • Address: 25/18/5/3 Nguyễn Minh Châu, P. Tân Phú, TP. Hồ Chí Minh
  • Email: ntrongtin11702@gmail.com
  • Website: [WEBSITE URL]

If you have questions or complaints about this Policy or our data practices, please contact us using the details above.