Privacy policy
Effective 24 August 2026
The short version: your business data belongs to your business, it is isolated at the database level, we don't sell it or run ads on it, and you can export or delete it at any time. The sections below say the same thing precisely. How the isolation and encryption actually work is on the Security page.
What BaseBlock is
BaseBlock is a business platform: you design your own tables and run your CRM, inventory, billing, payroll, and public website on top of them. This policy covers the BaseBlock web app, the BaseBlock mobile app, and websites published through BaseBlock, and explains what data we handle and why.
Who operates BaseBlock
BaseBlock is operated by Colour Nepal Pvt. Ltd., a company registered in Nepal (registration number 361973/81/82), at Sinamangal-9, Kathmandu, Nepal. That company is responsible for the data described in this policy, and it is who you are contracting with when you use BaseBlock. Write to support@baseblock.io with any question about it, including a request to see or delete what we hold.
Data you give us
Your account: an email address and a password. Passwords are handled by our authentication provider (Supabase Auth) and stored only as salted hashes — BaseBlock never sees or stores a plaintext password.
Your business data: the tables, rows, files, chat messages, and settings your workspace creates. This data belongs to your business. It is isolated per workspace by database-enforced row-level security, and BaseBlock does not sell it, mine it for advertising, or share it with other workspaces — ever.
Provider credentials your business chooses to connect: if you connect your own payment gateway (eSewa, Khalti, Fonepay), courier (NCM, Pathao), or email/SMS provider, those credentials are stored for your workspace only and used server-side only, to act on your behalf. BaseBlock holds no shared merchant account and never processes card data itself.
Messages from Facebook, Instagram and WhatsApp
If your business connects a Facebook Page, an Instagram professional account, or a WhatsApp Business number, the messages your customers send to you arrive in your workspace’s Inbox. What we receive from Meta is what the customer sent: their message text and any attachment, the platform’s own identifier for them, and the display name the platform provides. On WhatsApp that identifier is the customer’s phone number, because that is how the WhatsApp Business Platform addresses a person.
It is used for one thing: showing you the conversation and letting you — or an automation you built — reply to it. It is stored in your workspace, isolated by the same row-level security as every other table, and it is never used for advertising, never shared with another workspace, and never sold. BaseBlock does not read it to train anything.
Replies leave under your own account, not ours: the Page access token or WhatsApp number your business connected is the one that sends. Disconnecting a channel stops it immediately, and deleting the workspace deletes the conversations with it — see data deletion. The platform’s own rules also apply to you directly, including WhatsApp’s 24-hour limit on replying to a customer who has gone quiet.
Data we collect automatically
Sign-in session tokens (kept in cookies on the web and secure storage in the mobile app) keep you logged in. Operational records — an append-only audit log of significant actions in your workspace, and delivery logs for automations you configure — exist so your business can see who did what.
The BaseBlock marketing site and app do not run third-party advertising or cross-site tracking. If your business adds its own Google Analytics id to a website you publish through BaseBlock, analytics for that site are collected by Google under your own Google account and Google’s terms.
Who processes data on our behalf
BaseBlock runs on established infrastructure providers acting as processors: Supabase (database, authentication, file storage — encrypted in transit and at rest) and Vercel (application hosting). Payment, courier, messaging and AI providers your business connects process the data you send them under their own terms, using your own accounts — for example, if you turn on AI reply drafts with your own Anthropic API key, the conversation being answered is sent to Anthropic to write a suggested reply, which a person reviews before anything is sent. AI reply drafts are off unless you turn them on.
Your control: export and deletion
Your data is never locked in: any table can be exported to CSV at any time. Deleting a workspace permanently removes all of its rows across every table through database cascades. To delete your account entirely, use the account-deletion option in the app or contact us through the support contact shown on the app-store listing you installed BaseBlock from — deletion removes your login and the memberships tied to it.
Websites your business publishes
If your business publishes a website or storefront through BaseBlock, visitors’ form submissions, wholesale-access requests, and orders on that site are collected for that business and land in its workspace tables. The business you’re buying from or contacting is responsible for how it uses that information; this policy governs BaseBlock’s handling of the underlying platform data.
Children
BaseBlock is a business tool and is not directed at children under 13, and we do not knowingly collect their data.
Changes to this policy
If this policy changes materially, the change will be visible on this page with an updated effective date. Continued use of BaseBlock after a change means the updated policy applies.