Privacy Policy
C2A (Connect to Action) · Operated by 1BY0 SOLUTIONS · Last updated: September 2026
This Privacy Policy describes how C2A (“we”, “our”, “the app”) collects, uses, and protects information on the C2A website at https://c2a.app/ and the C2A Android app on Google Play.
1. Who we are
C2A (Connect to Action) is operated by 1BY0 SOLUTIONS (“we”, “our”). C2A is a lead management platform for businesses. Business users (“App Admins”) connect lead sources such as RCS campaigns and Facebook Lead Ads to manage and follow up with prospects.
2. Information we collect
- Account data: name, email, mobile number, login credentials (to create and secure your C2A workspace). Email is used to log in, respond to queries you start, and send notices you request (for example account or security alerts).
-
Lead data: names, phone numbers, email addresses, and form answers submitted by prospects, plus follow-up activity in your workspace (status, notes, assignment).
- Name — identify the person and personalise follow-up.
- Phone — contact them about their enquiry (calls / SMS / WhatsApp / RCS).
- Email — send replies, quotes, or appointment details about that enquiry.
- Facebook / Meta integration: when you connect Facebook Lead Ads, we receive access tokens and Page identifiers needed to sync leads. We fetch lead form submissions (including contact details) from Meta on your behalf.
- RCS integration: interaction data from RCS campaigns (e.g. CTA clicks) sent by your messaging provider.
- Technical data: IP address, device type, and app usage logs for security and troubleshooting. We may also collect aggregate, anonymous statistics (for example which features are used) to improve C2A.
- Cookies and session tokens: we use cookies on the website and similar tokens in the app to keep you logged in. Details are in our Cookie Policy.
- Consent records: whether service and/or marketing consent was given, and when (where captured by a C2A form or provided by the channel).
3. How we use information
- Service communication: deliver leads to the correct business account and assigned staff; enable follow-up related to the enquiry.
- Marketing communication: only if the person gave a separate, affirmative, unticked-by-default marketing opt-in. We do not use pre-ticked marketing consent.
- Reporting and product improvement in aggregate.
- Comply with legal obligations.
We do not sell personal data to third parties.
Detailed lead-form notice (DPDP): https://c2a.app/consent/
Example form with consent UI: https://c2a.app/lead-form/
3A. Consent (DPDP Act, India)
Where C2A or a connected lead form relies on consent, that consent must be free, specific, informed, unconditional, and based on clear affirmative action. Service follow-up and marketing are presented as separate choices. Marketing boxes are never pre-ticked.
Withdraw consent: email support@c2a.app (subject “Withdraw consent — C2A”) with the phone/email used on the form, or ask the business that received your lead. See also Lead Form Consent Notice.
4. Facebook Connect / Meta data
When you tap Connect → Facebook in C2A, you sign in with your own Facebook account and choose the Page(s) you manage. C2A only accesses Pages and lead data you explicitly authorize.
- Who operates C2A: 1BY0 SOLUTIONS
- Product website: https://c2a.app/
- Privacy Policy: https://c2a.app/privacy/
- Terms & Conditions: https://c2a.app/terms/
- Support / data deletion: support@c2a.app
- OAuth callback (server): https://c2a.app/api/integrations/meta/callback
- Legal entity: 1BY0 SOLUTIONS
- App name: C2A (Connect to Action)
- Data use: Lead contact details from authorized Facebook Pages are stored securely per customer account. We do not sell personal data.
- Consent on Meta forms: Businesses must configure clear, affirmative consent on Lead Ads (no pre-ticked marketing). Link https://c2a.app/consent/ and https://c2a.app/privacy/ in the form privacy / disclaimer fields.
- Disconnect: Users can disconnect Facebook at any time under Connect → Meta (Facebook). Disconnecting stops new Meta leads from syncing.
Access is used only to import and display leads in your C2A account. Meta may record when our app accesses your data, as described in Meta’s own policies.
5. Data storage and security
We use reasonable technical and organisational measures to protect personal data, including:
- HTTPS/TLS for public endpoints (c2a.app and the API)
- Passwords stored using hashing (not as plain text)
- Integration access tokens encrypted at rest where implemented
- Tenant isolation so one organisation’s leads are not mixed with another’s
- Access to lead data restricted to authorised users in your organisation (App Admin and assigned staff)
More detail is on our Security page. No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact support@c2a.app immediately.
6. Data retention, sharing and deletion
Retention: We retain account and lead data while the business account is active and as needed for follow-up, security, dispute resolution, and legal compliance, or until a valid deletion/withdrawal request is processed (subject to lawful retention).
Sharing: Lead data is shared with the customer organisation that owns the form/campaign and their authorised staff; with Meta, RCS, or WhatsApp providers as needed to receive or send the lead; and with infrastructure processors acting on our instructions. We do not sell personal data.
We may also disclose information if required by law or a valid court order, to investigate fraud or security incidents, or to protect the rights, property, or safety of 1BY0 SOLUTIONS, our users, or others.
Deletion: You may request deletion of your account or specific leads by contacting us, using in-app account settings where available, or via Account deletion and Data export & deletion. Disconnecting Facebook stops new Meta leads from syncing.
After we process a deletion request, copies may remain for a limited time in encrypted backups used only for disaster recovery, until those backups rotate in the ordinary course of operations. We do not restore deleted personal data from backups into the live product except as needed to recover from a system failure.
7. Your rights
Depending on your location, you may have rights to access, correct, or delete personal data, and to withdraw consent where processing is based on consent. You can:
- Update profile and organisation details in the C2A app where those screens are available
- Request export or deletion via Data export & deletion
- Request account deletion via Account deletion
- Email support@c2a.app
We may need to verify your identity before fulfilling a request. Some data must be retained where the law requires it.
8. Third-party links and services
C2A may link to or connect with third-party services (for example Meta, RCS, WhatsApp, maps, or payment providers). Those services have their own privacy policies. We are not responsible for their practices. See also Integrations terms.
9. International and cross-border processing
1BY0 SOLUTIONS is based in India. We may process personal data in India and in other countries where our hosting, infrastructure, or service providers operate. If you access C2A from outside India, your information may be transferred to and processed in India or those other locations. We use processors under contract and take steps appropriate to the nature of the transfer and applicable law.
10. Children
C2A is a business (B2B) product. It is not directed at children under 18. We do not knowingly collect personal data from children. If you believe we have collected such data, contact support@c2a.app and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change. Material changes may also be notified by email to account holders or by a notice in the C2A app or on https://c2a.app/. Continued use of C2A after an update constitutes acceptance of the revised policy, except where applicable law requires additional consent.
12. Contact
1BY0 SOLUTIONS
For privacy questions or deletion requests:
Email: support@c2a.app
Contact page: https://c2a.app/contact/
Account deletion: https://c2a.app/account-deletion/
Data export / deletion: https://c2a.app/data-requests/
All policies: https://c2a.app/legal/
Terms: https://c2a.app/terms/
Cookies: https://c2a.app/cookies/
Security: https://c2a.app/security/
DPA: https://c2a.app/dpa/
Have an Indian privacy/technology lawyer review final policies before production. Compliance depends on your business model, data flows, and customers.
13. Grievance Officer
Unresolved privacy or service complaints may be escalated to our Grievance Officer:
- Role: Grievance Officer, 1BY0 SOLUTIONS (C2A)
- Email: support@c2a.app (subject: “Grievance — C2A”)
- Company details: https://c2a.app/company/
We aim to acknowledge within 48 hours and resolve within 15 days where practicable.