Privacy Policy
1. About this policy
MAKO is a conversational AI messaging platform operated by You Better Ask ABN 45 693 250 645 (“we”, “us”, “our”). This policy explains how we collect, hold, use, and disclose personal information when providing MAKO — including the operator dashboard at mako.youbetterask.ai, the messaging channels we connect (such as WhatsApp, LINE, and website chat), and payment links — in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Our company website has its own privacy policy covering youbetterask.ai and its forms and tools.
2. Who this policy covers
This policy covers two groups of people:
- Business users— staff of the businesses (“brands”) that use MAKO to manage their customer conversations.
- End customers — people who message a business through a channel powered by MAKO, such as a WhatsApp number, a LINE account, or a website chat widget.
If you are an end customer, the business you messaged controls your information — we process it on their behalf to provide the messaging service. Requests about your information are best directed to that business first; we assist them in responding, and you can also contact us directly using the details below.
3. What personal information we collect
- Business user accounts — email address, password (stored only as a secure hash), role, and optional two-factor authentication enrolment.
- Conversation data — the content of messages exchanged with a business, including attachments and media; your platform identifier (such as a WhatsApp phone number, LINE user ID, or an anonymous website-chat visitor ID); your display name; and message delivery metadata such as timestamps and delivery status.
- Order and payment details — items ordered, amounts, currency, payment status, and pickup details where a business takes orders or payments through MAKO. We never collect or store card details — they are captured directly by our payment providers (Stripe and Square).
- Business content — AI instructions, knowledge-base documents, and workflow settings supplied by businesses, which may occasionally include personal information the business chooses to include.
- Technical data — server logs (including IP addresses) and an audit trail of actions taken in the operator dashboard.
4. How we collect personal information
- Directly from business users when they create and use their accounts.
- From messaging platforms — Meta’s WhatsApp Business Platform and LINE — when an end customer messages a business.
- Through the MAKO chat widget embedded on a business’s website.
- In the course of providing the service — for example AI-generated replies, conversation summaries, and order records created from a conversation.
5. Why we collect and use personal information
We collect and use personal information to:
- Deliver messages between end customers and businesses.
- Generate AI replies on behalf of a business, in its configured style.
- Let business staff monitor conversations and respond personally.
- Produce conversation summaries and reporting for the business.
- Create and fulfil orders and payment links requested in a conversation.
- Keep the platform secure, including maintaining audit records.
- Comply with legal obligations.
We do not sell or rent personal information, we do not use conversation content for advertising, and we will not use your personal information for direct marketing without your consent.
6. AI processing of conversations
Each business chooses an AI provider — Anthropic (Claude), OpenAI, or Google (Gemini) — and messages sent to that business are processed by the chosen provider to generate replies. Replies to your messages may therefore be AI-generated, and business staff can view any conversation and take over from the AI at any time.
Under the API terms of our AI providers, content submitted through their APIs is not used to train their models by default.
7. How we store and protect your information
Your personal information is stored on server infrastructure hosted by DigitalOcean, with media attachments stored in DigitalOcean Spaces object storage. We take reasonable steps to protect your information from misuse, interference, loss, unauthorised access, modification, and disclosure, including:
- HTTPS encryption on all traffic
- Strict per-business isolation enforced inside the database itself
- Encryption at rest (AES-256-GCM) for stored API keys and credentials
- Passwords stored only as secure hashes
- Optional two-factor authentication on business user accounts
- Restricted server access
8. Third-party services
To deliver MAKO, we share certain information with the following third-party providers. Each operates under its own privacy policy:
- Meta (WhatsApp Business Platform) — delivers WhatsApp messages between end customers and businesses
- LINE — delivers LINE messages between end customers and businesses
- Anthropic, OpenAI, Google— AI providers that process conversation content to generate replies, according to each business’s configuration
- Stripe and Square — process payments; card details are handled entirely by them and never touch our servers
- DigitalOcean — cloud hosting and media storage
We do not sell or rent your personal information to any third party.
9. Overseas disclosure
Some of the third-party services we use are based overseas — primarily the United States (Meta, Anthropic, OpenAI, Google, Stripe, Square) and Japan (LINE). By using MAKO or messaging a business that uses MAKO, you consent to the transfer of your personal information to these overseas recipients. We take reasonable steps to ensure these providers comply with comparable privacy standards.
10. Cookies and local storage
MAKO uses only functional cookies and browser storage:
- A session token that keeps business users signed in to the dashboard.
- A chat token stored in the end customer’s browser so a website chat session can continue across page visits.
We do not use advertising cookies, third-party analytics, or tracking across other websites on the MAKO platform.
11. Access and correction
Under the Australian Privacy Principles, you have the right to request access to the personal information we hold about you, and to request corrections if it is inaccurate, incomplete, or out of date. Business users can view and update most account information in the dashboard, or contact us directly. End customers should contact the business they messaged — we will assist that business in responding — or contact us using the details below.
12. Data breach notification
We comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.
13. Complaints
If you believe we have breached the Australian Privacy Principles, you may lodge a complaint by emailing us. We will investigate and respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the OAIC.
14. Changes to this policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised “Last updated” date. We encourage you to review this page periodically.
Data Deletion Policy
1. Your right to request deletion
You have the right to request the deletion of personal information we hold about you. This includes conversation history, contact records, media attachments, order and payment-link records, and business user accounts.
2. How to request deletion
If you are an end customer, the quickest path is to ask the business you messaged — they can request deletion on your behalf. You can also email us directly at hello@youbetterask.aiwith the subject line “Data Deletion Request”. Include the following details so we can locate your records:
- Your full name
- The identifier you used — your WhatsApp phone number, LINE display name, or the email address on your account
- The business you messaged, if applicable
- A description of which data you would like deleted
3. What we will delete
Upon a verified deletion request, we will delete the following where applicable:
- Conversation and message history, including media attachments
- Your contact record
- Order and payment-link records, subject to the exceptions below
- Business user account details
Please note that anonymised or aggregated data that cannot be used to identify you may be retained for analytical purposes.
4. Timeframe
We will process your deletion request and remove your personal data within 30 days of receiving a verified request. You will receive an email confirmation once the deletion is complete.
5. Exceptions
We may retain certain information where required to:
- Comply with a legal obligation — for example, records of completed payments may need to be kept for tax and financial reporting
- Establish, exercise, or defend legal claims
- Detect and prevent fraud or security incidents
If an exception applies, we will inform you of the specific reason and retain only the minimum data necessary.
6. Third-party data
Where your data has been shared with third-party services, we will take reasonable steps to request deletion from those services as well. Please note that third-party providers — including Meta, LINE, Stripe, and Square — are subject to their own data retention policies, and payment providers may be required to retain transaction records under financial regulations.