LEGAL

Privacy Policy

Effective date: 26 July 2026

1. Introduction

This Privacy Policy describes how Command Tempo Pte. Ltd. ("Command Tempo", "we", "us", or "our") collects, uses, and handles information across our products and services. We are a software company that builds custom workflow tools for businesses; some of those services include messaging and automation delivered via the WhatsApp Business Platform (operated by Meta Platforms, Inc.). In that capacity we enable businesses to send utility messages, marketing communications, and automated workflow interactions through WhatsApp.

Our services also integrate with third-party platforms that our clients already use to run their business, including Google Workspace (Google Sheets, Google Drive, Gmail, and Google Calendar). Where we access data from a Google account, we do so only with the account holder's authorisation and in accordance with the Google API Services User Data Policy, including its Limited Use requirements. See Section 12 for full details.

By using our services or receiving messages from us or our clients via WhatsApp, you acknowledge the practices described in this policy.

2. Who We Are

Command Tempo Pte. Ltd. (UEN 202625972K) is a Singapore-incorporated software company. We build custom workflow tools for businesses, which can include communication and automation with their customers via WhatsApp. Where we provide such services, we process personal data on behalf of our clients in our capacity as a data processor, and in some instances as a data controller for operational purposes.

For questions about this policy, please contact us at: hello@cmdtempo.dev.

3. Information We Collect

We may collect or process the following types of information in connection with our services:

3.1 Information you or our clients provide

  • Phone numbers used to send or receive WhatsApp messages
  • Names or identifiers provided by our clients for message personalisation
  • Message content, including text, media, and automated workflow responses
  • Business contact details provided by client organisations

3.2 Automatically collected information

  • Message delivery and read status metadata (provided by WhatsApp/Meta)
  • Webhook event data including timestamps, message IDs, and status updates
  • Technical logs related to message delivery and system performance

3.3 Google user data

Where a client connects a Google account to our services, we access only the data covered by the scopes they have explicitly authorised on the Google consent screen:

  • Google Sheets and Google Drive: the contents and file metadata (such as file name, ID, and last-modified time) of the specific spreadsheets and files the client authorises us to read or write — used to pull figures into reports and dashboards, and to write results back.
  • Gmail: the content and metadata of messages we send, draft, or process on the client's explicit instruction — used to deliver scheduled reports and to draft or send replies the client has configured.
  • Google Calendar: event details including titles, times, locations, and attendees on the calendars the client connects — used to create, update, and read bookings.
  • OAuth credentials: access and refresh tokens issued by Google, stored encrypted at rest. We never receive, see, or store your Google account password.

We request the narrowest scopes needed for the features a client has enabled. Connecting a Google account is always optional, and clients may connect some integrations without connecting others.

3.4 Information we do not collect

We do not collect payment information, government identification numbers, or sensitive personal data (such as health or financial data) unless explicitly required by a specific client use case and with appropriate safeguards in place.

4. How We Use Information

We use the information we process for the following purposes:

  • Delivering utility messages such as order updates, appointment reminders, and service notifications on behalf of our clients
  • Sending marketing or promotional messages where the end user has provided consent to the relevant business (our client)
  • Operating automated workflows and responding to webhook events triggered by user interactions
  • Maintaining and improving the reliability, security, and performance of our platform
  • Complying with legal obligations and Meta/WhatsApp platform policies
  • Troubleshooting technical issues related to message delivery

5. Legal Basis for Processing

We process personal data based on the following grounds:

  • Contractual necessity: to fulfil our obligations to our clients under service agreements
  • Legitimate interests: for platform security, fraud prevention, and service improvement
  • Legal obligation: to comply with applicable laws and WhatsApp's platform requirements

Where our clients are the data controllers, they are responsible for ensuring an appropriate legal basis exists for their communications with end users (e.g. obtaining consent for marketing messages).

6. Data Sharing and Disclosure

We do not sell, rent, or share your personal data with third-party companies for their own marketing purposes. We may share data in the following limited circumstances:

  • With Meta Platforms, Inc. as required to operate the WhatsApp Business Platform. Meta's own Privacy Policy applies to data processed through WhatsApp's infrastructure.
  • With our clients (businesses) who have engaged us to send messages on their behalf. These clients are responsible for their own data handling practices.
  • With legal or regulatory authorities if required by applicable law, court order, or governmental authority.
  • In connection with a business transfer, such as a merger or acquisition, where data may be transferred to a successor entity.
  • With third-party AI model providers acting as our sub-processors, strictly to generate output requested by the client (for example, drafting a reply or summarising a report). This is the only category of third party that receives Google user data, it is used for inference only, and it is never used to train or improve any AI model. See Section 12.

We do not transfer Google user data to advertising platforms, data brokers, or information resellers under any circumstances.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this policy or as required by law:

  • Message content and metadata: retained for up to 90 days for troubleshooting and audit purposes, then deleted or anonymised
  • Operational logs: retained for up to 12 months
  • Client account data: retained for the duration of the client relationship and as required for legal or regulatory compliance
  • Google user data: retained only for as long as the relevant integration remains connected and is needed to provide the feature. When a client disconnects a Google integration, revokes access from their Google Account, or closes their account, we revoke the stored tokens and delete the associated Google user data within 30 days, except where retention is required by law

You may request deletion of your data by contacting us at hello@cmdtempo.dev.

8. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. These include:

  • Encryption of data in transit (TLS) and at rest
  • Access controls and authentication for internal systems
  • Regular security assessments and monitoring
  • Incident response procedures for data breaches

While we take reasonable steps to protect your information, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

9. Cross-Border Data Transfers

Our services operate primarily across Southeast Asia. Data processed through the WhatsApp Business Platform may be transferred to and stored on servers operated by Meta Platforms, Inc. in the United States or other countries. Meta applies standard contractual clauses and other safeguards to such transfers.

If you are located in a jurisdiction with specific data transfer requirements, please contact us for further information.

10. Your Rights

Depending on your country of residence, you may have the following rights regarding your personal data:

  • Access: request a copy of personal data we hold about you
  • Correction: request correction of inaccurate or incomplete data
  • Deletion: request erasure of your personal data, subject to legal retention requirements
  • Objection: object to certain types of processing, including direct marketing
  • Withdrawal of consent: where processing is based on consent, withdraw it at any time

To exercise any of these rights, please contact us at hello@cmdtempo.dev. We will respond within a reasonable timeframe in accordance with applicable law.

Please note that for messages sent by our clients' businesses, you should direct your request to the relevant business, as they are the data controller for that communication.

11. WhatsApp and the Meta Platform

Some of our services are built on the WhatsApp Business Platform provided by Meta Platforms, Inc. By receiving messages through WhatsApp, your use of WhatsApp is also governed by Meta's Terms of Service and Privacy Policy, available at https://www.whatsapp.com/legal/privacy-policy.

We are an independent technology provider and are not affiliated with, endorsed by, or a partner of Meta Platforms, Inc.

12. Google User Data and Limited Use

Our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

12.1 Scopes we request and why

We request only the narrowest scopes necessary for the features a client has chosen to enable. Each connection is authorised by the account holder through Google's own consent screen, and no scope is requested for a feature the client is not using:

  • Google Sheets / Google Drive: to read figures from the spreadsheets a client nominates and to write generated reports and results back to their Drive. Without this access, automated reporting and dashboard features cannot function.
  • Gmail: to send scheduled reports and to draft or send replies that the client has explicitly configured. Without this access, we cannot deliver email on the client's own address.
  • Google Calendar: to create, read, and update bookings and appointments on the calendars a client connects. Without this access, bookings captured through messaging workflows cannot reach the client's calendar.

12.2 How we use Google user data

Google user data is used solely to provide and improve user-facing features that are visible and prominent in our services — the reports, dashboards, bookings, and messaging workflows the client has set up. We do not use Google user data for any purpose the client has not requested.

12.3 What we never do

We do not, under any circumstances:

  • Sell Google user data
  • Transfer or sell Google user data to advertising platforms, data brokers, or information resellers
  • Use Google user data for serving advertisements, including retargeting, personalised advertising, or interest-based advertising
  • Use Google user data to determine credit-worthiness or for lending purposes

12.4 Human access to Google user data

Our personnel do not read Google user data, except in the following limited circumstances:

  • Where we have obtained the client's affirmative agreement to view specific files, messages, or events — for example, when they ask us to investigate a particular report or booking
  • Where it is necessary for security purposes, such as investigating abuse or a suspected security incident
  • Where required to comply with applicable law
  • Where the data has been aggregated and de-identified, and is used for internal operations such as monitoring reliability and performance

12.5 AI and machine learning

Some features send Google user data to third-party AI model providers in order to generate output the client has asked for — for example, drafting a message or summarising figures from a spreadsheet. This is inference only. Google user data is not used to train, retrain, fine-tune, or otherwise develop or improve any generalised or personalised AI or machine-learning model, whether ours or a provider's. We contract with our AI providers on terms that prohibit training on data we submit.

12.6 Revoking access

A client may disconnect a Google integration at any time from within our services, or revoke our access directly at myaccount.google.com/permissions. Revoking access stops all further data access immediately. We then revoke the stored tokens and delete the associated Google user data within 30 days, as described in Section 7. To request deletion sooner, email hello@cmdtempo.dev.

13. Opting Out of Messages

You may opt out of receiving WhatsApp messages from a business using our platform at any time by:

  • Replying "STOP" to any message you receive
  • Contacting the business directly to request removal from their messaging list
  • Contacting us at hello@cmdtempo.dev to flag your opt-out request

Please note that opting out of marketing messages does not necessarily prevent you from receiving transactional or service-critical messages related to an existing relationship with the business.

14. Cookies and Website Analytics

This section applies to visitors of our website at cmdtempo.dev, and is separate from the Google user data described in Section 12.

  • Google Analytics (GA4): we use Google Analytics to understand how visitors find and use our website. It sets cookies and collects information such as pages viewed, approximate location derived from IP address, referring source, and device and browser type. This is used in aggregate to improve the site. Google's handling of this data is governed by the Google Privacy Policy. You can opt out using the Google Analytics Opt-out Browser Add-on.
  • Google Fonts: our pages load typefaces from Google Fonts, which involves a request to Google's servers that includes your IP address and user agent.

We do not use website analytics data for advertising, retargeting, or profiling, and we do not combine it with Google user data obtained through the integrations described in Section 12. Most browsers allow you to block or delete cookies through their settings.

15. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately at hello@cmdtempo.dev and we will take steps to delete it.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or platform policies. We will update the effective date at the top of this document. We encourage you to review this policy periodically.

Material changes will be communicated to our clients and, where practicable, to affected users.

17. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us:

Command Tempo Pte. Ltd. (UEN 202625972K)

Email: hello@cmdtempo.dev

Address: 75C Redhill Road, #03-74, Redhill Rise, Singapore 153075

Website: cmdtempo.dev

/tempo

© 2026 cmdtempo. Built for businesses that run properly.

Legal Privacy Policy Terms of Service