We Make It Auto
Home Privacy Terms Let's Talk
Privacy & Data

Privacy Policy

How We Make It Auto collects, uses and protects information across our website, AI automation systems, integrations, SMS/MMS and email communications.

Effective September 1, 2026 wemakeitauto.com
We Make It Auto is operated by LoopBrackets (PRIVATE) Ltd. · loopbrackets.com
Covered here
Personal & Client Data
SMS/MMS & Email
AI & Cross-Border Processing
Page Contents

Mobile Messaging Privacy

We do not sell, rent, share, or otherwise disclose mobile phone numbers, SMS opt-in information, or messaging consent to third parties or affiliates for their own marketing or promotional purposes. We may disclose limited mobile information to service providers solely as necessary to transmit messages, provide customer support, maintain security, or operate the messaging program, subject to appropriate restrictions. Mobile messaging opt-in data and consent are excluded from any broader data-sharing permissions described elsewhere in this Policy.

1. Company and Scope

This Privacy Policy describes how LoopBrackets (PRIVATE) Ltd., doing business as We Make It Auto (“We Make It Auto,” “WMA,” “we,” “us,” or “our”), collects, uses, discloses, stores, transfers and otherwise processes Personal Information in connection with wemakeitauto.com and our business operations.

This Policy applies to website visitors, prospects, business contacts and clients, and to Personal Information processed in connection with our AI automation systems, AI voice/chat/WhatsApp/SMS/email solutions, CRM and workflow integrations, custom software development, analytics, marketing, support and maintenance services (collectively, the “Services”).

This Policy does not govern third-party websites or platforms that operate under their own privacy policies, even where those platforms are integrated with our Services.

2. Our Role: Controller and Service Provider / Processor

Information We Control

We generally act as a controller, business, or equivalent entity when we determine why and how Personal Information is processed for our own website, sales, client administration, billing, marketing, security, analytics and internal operations.

Client Data

Clients may provide information concerning their customers, prospects, employees, contractors, suppliers or other individuals through CRMs, APIs, databases, communications platforms, AI systems or automation workflows (“Client Data”). For Client Data, the client generally determines the purposes and means of processing and We Make It Auto generally acts as a processor, service provider, contractor, subprocessor or equivalent role.

We process Client Data only as reasonably necessary to provide Services, comply with a Statement of Work (“SOW”), Data Processing Agreement (“DPA”), documented client instructions and applicable law.

3. Information We Collect

Identity, Contact and Business Information

  • Name, business name, employer, job title, email address and phone number.
  • Postal or billing address, account information, business size, industry, CRM/technology stack, workflow requirements, project information and communications.

Billing and Transaction Information

We may process billing addresses, invoice information, transaction history, payment status and subscription information. Full payment-card information is generally processed by our payment provider rather than stored directly by us.

Technical and Usage Information

  • IP address, browser type, operating system, device identifiers and approximate location derived from IP.
  • Referring URLs, pages viewed, session activity, clickstream data, timestamps, cookie identifiers, security logs and diagnostic information.

Communications and Messaging Data

We may process email, SMS/MMS, WhatsApp, website-chat, telephone and video-meeting communications. Where permitted by law and appropriate notice or consent has been provided, this may include call recordings, transcripts, summaries and AI-generated analyses.

Client, API and CRM Data

Our Services may connect to CRM systems, communication platforms, scheduling tools, databases, cloud storage, APIs, webhook endpoints and workflow automation platforms. The categories of Client Data processed depend on the client’s configuration.

AI Inputs and Outputs

When AI functionality is used, we may process prompts, messages, call transcripts, chat histories, uploaded files, CRM context, knowledge-base content, classifications, summaries, extracted information, model responses and other AI-generated outputs.

4. How We Collect Information

We may collect Personal Information directly from you; from our clients; through forms, booking pages and our website; through connected applications and APIs; from service providers and business partners; from publicly available business sources; and through cookies or similar technologies.

Providing a phone number or email address does not, by itself, constitute consent to promotional SMS or email where applicable law requires consent. Marketing consent is collected through the applicable opt-in mechanism or another legally permitted basis.

5. How We Use Information

  • Provide, configure and support AI automation, CRM, integration and custom software Services.
  • Manage onboarding, project delivery, accounts, subscriptions, billing and customer support.
  • Monitor performance, debug systems, maintain security, prevent fraud and improve Services.
  • Respond to inquiries and communicate about requested services.
  • Send marketing and promotional communications where permitted by applicable law and consistent with the recipient’s choices.
  • Comply with law, enforce contracts, protect rights and respond to valid legal requests.

6. SMS/MMS and Mobile Messaging Privacy

If you expressly opt in to a We Make It Auto SMS/MMS program, we may use the mobile number you provide to send recurring marketing, promotional, informational, customer-care or service-related messages consistent with the consent you gave and the applicable messaging program.

Message frequency may vary. Message and data rates may apply depending on your wireless plan. You may reply STOP to opt out and HELP for help, subject to the instructions in the applicable messaging program.

SMS marketing consent is voluntary and is not a condition of purchasing, requesting, or receiving our Services. Where our forms collect both marketing and non-marketing SMS consent, those choices should be presented separately.

No Marketing Sharing of Mobile Opt-In Data

We do not sell, rent, share or disclose mobile phone numbers, SMS opt-in information or messaging consent to third parties or affiliates for their own marketing or promotional purposes. Limited disclosures to messaging vendors, telecommunications providers, CRM/automation providers or customer-support vendors may occur solely as necessary to operate the messaging program or provide requested Services. Those providers are not authorized by us to use the mobile opt-in data for their own marketing.

Consent Records

We may retain records showing when and how consent was obtained, the language displayed at the time of opt-in, the source form or campaign, the mobile number, timestamps, consent status and opt-out history. We use these records for compliance, suppression and dispute-resolution purposes.

Opt-Out and Revocation

You may withdraw SMS consent at any time by replying STOP or using another reasonable method made available to you. We may send a single confirmation message acknowledging the opt-out. We will maintain suppression records as reasonably necessary to prevent further marketing messages and demonstrate compliance.

If you later wish to rejoin the program, you must opt in again through an authorized enrollment method.

7. Promotional Email Communications

Where permitted by applicable law, We Make It Auto may send emails concerning our services, offers, promotions, educational content, consultations, events and related business opportunities.

For recipients in jurisdictions requiring prior consent, including Canada where CASL applies, we will rely on express consent, valid implied consent or another permitted basis. Email consent is independent from SMS consent unless the opt-in form clearly and lawfully states otherwise.

Commercial marketing emails will identify the sender as required by applicable law and will include a clear method to unsubscribe. We will process unsubscribe requests within applicable legal timeframes and maintain suppression records so opted-out addresses are not re-added to marketing lists without a new lawful basis.

Unsubscribing from marketing emails does not prevent us from sending transactional or service communications that are necessary to administer an existing client relationship, respond to a request, provide security notices or complete a transaction.

8. AI and Public Model Training

By default, We Make It Auto does not use Client Data, customer conversations, CRM records, prompts, files or other Client Data to train, improve or fine-tune public or general-purpose AI models.

We will not intentionally contribute Client Data to public model-training datasets unless the client expressly authorizes the use in writing, required notices or consents have been obtained, and the processing is documented in the applicable SOW or DPA.

Client-specific fine-tuning, retrieval-augmented generation, embeddings, private knowledge bases or other AI customization may be performed only for agreed client purposes.

9. Legal Grounds for Processing

Where applicable law requires a legal basis, we may rely on contractual necessity, consent, legitimate interests, compliance with legal obligations, or another lawful basis recognized by the relevant jurisdiction.

Where processing relies on consent, consent may be withdrawn as permitted by law. Withdrawal does not affect the lawfulness of processing completed before withdrawal.

10. Third-Party Service Providers and Subprocessors

We may use cloud hosts, database providers, AI platform APIs, analytics services, CRM/automation platforms, communication providers, email/SMS vendors, payment processors, security providers and other vendors to provide the Services.

Depending on a client implementation, examples may include OpenAI, Anthropic, Google, Microsoft/Azure, Amazon Web Services, Meta/WhatsApp, Twilio, HighLevel/LeadConnector, Make, n8n, Zapier, HubSpot, Salesforce, Zoho, Pipedrive and other client-selected platforms.

A provider listed here is not necessarily used for every client. Project-specific subprocessors may be identified in the applicable SOW/DPA or at https://wemakeitauto.com.

Nothing in this section authorizes a vendor or affiliate to use SMS opt-in data or mobile consent for its own marketing or promotional purposes.

11. Other Disclosures of Personal Information

We may disclose Personal Information to service providers necessary to operate the Services; to systems or recipients designated by a client; in connection with a bona fide merger, financing, acquisition, restructuring or sale; or where reasonably necessary to comply with law, protect safety, prevent fraud, enforce agreements or establish legal rights.

If a corporate transaction occurs, mobile opt-in/consent data remains subject to applicable privacy, messaging and consent restrictions.

12. International and Cross-Border Transfers

Because we provide international digital services and use cloud infrastructure, Personal Information may be processed outside the country, state, province or territory in which an individual resides, including potentially in Pakistan, the United States, Canada, the European Economic Area, the United Kingdom and jurisdictions where approved providers operate.

Where required, we use contractual, technical and organizational safeguards such as DPAs, confidentiality obligations, access restrictions, transfer assessments, Standard Contractual Clauses where appropriate and supplementary measures.

Where Quebec law applies, transfers outside Quebec will be assessed as required by applicable Quebec privacy law.

13. Cookies, Analytics and Advertising Technologies

Our website may use cookies, pixels, tags, scripts and similar technologies for essential functionality, security, preferences, analytics, performance measurement and, if enabled, advertising or retargeting.

14. U.S. State Privacy Rights

Residents of certain U.S. states may have rights, where applicable, to confirm processing; access, correct or delete Personal Information; obtain portable data; opt out of sale, sharing, targeted advertising or certain profiling; limit certain uses of sensitive data; appeal certain decisions; and exercise privacy rights without unlawful discrimination.

California

Where the CCPA/CPRA applies, California residents may have rights to know/access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive Personal Information, and receive non-discriminatory treatment for exercising rights.

We Make It Auto does not sell Personal Information for monetary consideration as a core business model.

15. Canadian Privacy Rights

Where Canadian privacy legislation applies, individuals may have rights relating to access, correction, transparency, withdrawal of consent, challenging compliance and complaints regarding our privacy practices.

Commercial electronic messages sent to Canadian recipients will be handled in accordance with applicable Canadian anti-spam requirements, including consent, sender identification and a functioning unsubscribe mechanism where required.

Canadian Personal Information may be processed by service providers outside Canada and may therefore be subject to the laws of the receiving jurisdiction.

16. Quebec Privacy Rights

Where Quebec privacy legislation applies, individuals may have rights including access, rectification, withdrawal of certain consent, information regarding processing and retention, and information regarding transfers outside Quebec.

Person Responsible for Protection of Personal Information: Muhammad Safdar Ali Khan

Email: [email protected]

17. GDPR and Other International Rights

Where the GDPR, UK GDPR or similar legislation applies, individuals may have rights to be informed, access, rectify, erase in certain circumstances, restrict processing, receive data portability, object to certain processing, withdraw consent, object to direct marketing and receive safeguards relating to certain automated decision-making.

You may also have the right to complain to the competent supervisory authority.

18. Automated Decision-Making and Profiling

Our technology may support automated lead classification, message routing, recommendations, summaries, prioritization, workflow decisions, appointment qualification and similar operations.

Unless expressly agreed in an SOW, our Services are not intended to independently make legally significant decisions concerning credit, employment, housing, insurance, medical treatment, legal rights or similarly high-impact matters without appropriate client controls and human oversight.

19. Data Retention

Data CategoryTypical Retention
Website / sales inquiries12 months after contract end
Client contracts / billing recordsContract term
Client DataContract term and 15 days, unless SOW/DPA states otherwise
Support records12 months
Application / security logs90 days
AI conversation recordsclient-configured period
Voice recordings30 days where recording is enabled
SMS / email consent & suppression recordsAs needed to document consent, opt-out and compliance
BackupsRolling deletion within approximately 30 days
Tax / accounting recordsAs required by applicable law

20. Security

We maintain administrative, technical and organizational safeguards designed to protect Personal Information against unauthorized access, disclosure, misuse, alteration, destruction and loss. Depending on the environment, controls may include encryption, multi-factor authentication, least-privilege access, role-based access controls, secure credential management, logging, monitoring, backups, vendor review and incident-response procedures.

Before publication, confirm that any specific security standard you state publicly matches your actual infrastructure: data in transit TLS 1.2+, data at rest ACME protocol and secret management.

No electronic transmission, cloud system or AI platform can be guaranteed to be completely secure.

21. Security Incidents

If we become aware of a security or confidentiality incident involving Personal Information, we will investigate and take reasonable measures appropriate to the circumstances. Where legally required, we will notify affected clients, individuals, regulators or other competent authorities. For Client Data, incident obligations may also be governed by the applicable DPA or SOW.

22. Children

Our website and Services are designed primarily for businesses and business professionals and are not directed toward children. We do not knowingly solicit Personal Information directly from children under the age applicable in the relevant jurisdiction. Clients must not use our Services to process children’s information in violation of applicable law.

23. Data Subject Requests

To exercise applicable privacy rights, submit a request to [Insert Privacy/DSAR Email] or [Insert DSAR Form URL]. Please provide your name, contact information, state/province/country, the right you wish to exercise and enough information to identify the relevant records.

We may request reasonable identity verification. Authorized agents may submit requests where permitted by law. Where applicable law provides a right to appeal a denied request, appeal instructions will be provided.

24. Client-Controlled Information

If your information is processed through a system operated for one of our clients, that client generally controls the Personal Information. Requests concerning such data should normally be directed to the client. We may refer or forward the request to the client or assist the client as required by law or contract.

25. Changes to this Policy

We may update this Privacy Policy to reflect legal developments, new technologies, changes to our Services, subprocessors or privacy practices. The “Last Updated” date will identify the most recent revision. Where required by law, we will provide additional notice or obtain consent before materially changing how Personal Information is processed.

Contact Information

LoopBrackets (PRIVATE) Ltd., doing business as We Make It Auto

Website: https://wemakeitauto.com

Registered Address: Office no 311, 3rd floor, Al Qadir Heights, New Garden Town, Lahore, Pakistan

Privacy Officer / Person Responsible for Privacy: Adv Sarmad Rehman

Privacy / DSAR Email: [email protected]

We Make It Auto

Privacy or messaging questions?

Contact us about privacy rights, mobile messaging consent, promotional communications or this policy.

Contact Privacy Team View Terms of Service
We Make It Auto

© We Make It Auto. All rights reserved.

Home Privacy Terms
We Make It Auto is a brand/project operated by LoopBrackets (PRIVATE) Ltd. · Corporate website: loopbrackets.com