Privacy Policy
Last updated: [placeholder date]
Draft — not legal advice
1. Who we are
Wafonic ("Wafonic," "we," "us," or "our") is operated by [full registered legal entity name], [registered business address] ("Company"). This Privacy Policy explains how we collect, use, share, and protect information when you use the Wafonic website, dashboard, and API (together, the "Service").
By using the Service, you agree to the collection and use of information as described here. If you don't agree, please don't use the Service.
2. Information we collect
2.1 Account & business information
Name, email address, password (hashed, never stored in plain text), business name, and any team member information you invite into your account.
2.2 WhatsApp messaging data
To provide the Service, we process:
- The WhatsApp number(s) you connect, and whether connected via QR Connect or API Connect (Meta Business API).
- Message content, timestamps, delivery/read status, and media you send or receive through the Service.
- Contact information for the people you message (name, phone number, and any custom fields/tags you add).
- For API Connect (Meta Business API) numbers: your WhatsApp Business Account (WABA) ID, phone number ID, and the access credentials needed to send/receive on your behalf.
2.3 Meta Platform Data (Facebook Login / WhatsApp Embedded Signup)
If you connect a WhatsApp number via API Connect using Facebook Login / Embedded Signup, Meta shares certain information with us based on the permissions you grant during that flow, specifically: whatsapp_business_management, whatsapp_business_messaging, and business_management. This includes your WhatsApp Business Account ID, phone number ID, your Meta Business Manager ID, and an access token scoped to send/receive messages and manage message templates on your behalf.
We use this data solely to operate the WhatsApp messaging features of the Service you've requested. We do not use Meta Platform Data for advertising, do not sell it, and do not share it beyond what's described in Section 4. Access tokens and any equivalent credentials are encrypted at rest (AES-256-CBC, unique per credential) and are never displayed in full after initial setup.
2.4 Shopify integration data
If you connect a Shopify store, we receive order and customer data needed to send the alerts you configure — order number, customer name/phone, order total, fulfillment/cancellation/refund status, and (if you enable it) reply-to-confirm/cancel responses from your customer. We do not access your Shopify store's data beyond what a given enabled alert requires.
2.5 Usage & log data
IP address, browser/device information, pages visited, and API request logs, for security, debugging, and abuse prevention.
2.6 Billing information
Your selected plan, billing history, and payment method reference. Payments made via bank transfer, mobile payment (e.g. JazzCash), or other supported methods are processed through the relevant payment channel — we do not store full card numbers on our own servers.
3. How we use information
We use the information above to:
- Provide, operate, and maintain the Service (send/receive messages, run automations, manage your team inbox and contacts, connect and manage numbers, provide the API and webhooks).
- Process Shopify orders into the WhatsApp alerts you've configured.
- Communicate with you about your account, billing, and Service updates.
- Monitor, secure, and improve the Service, including detecting abuse and enforcing our Terms.
- Comply with legal obligations.
We do not sell your personal information or the personal information of your contacts.
4. How we share information
We share information only as necessary to provide the Service:
- Meta / WhatsApp — to send and receive messages, subscribe to webhooks, and manage templates on API Connect (Meta Business API) numbers.
- Shopify — to read the order/customer data needed for alerts you've enabled on a connected store.
- Service providers — email delivery (for account/system notifications), hosting and infrastructure providers, all bound by confidentiality obligations and used only to operate the Service.
- Legal requirements — if required by law, subpoena, or to protect the rights, property, or safety of Wafonic, our users, or the public.
- Business transfers — if Wafonic is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction, subject to this Policy.
We do not share your data with third parties for their own advertising purposes.
5. Data security
- Access tokens, App Secrets, and other sensitive credentials are encrypted at rest (AES-256-CBC, per-credential initialization vectors).
- Access to production data is restricted to authorized personnel who need it to operate or support the Service.
- No method of transmission or storage is 100% secure; we can't guarantee absolute security, but we work to protect your information using industry-standard practices.
6. Data retention
We retain your account and messaging data for as long as your account is active and as needed to provide the Service. You can configure automatic cleanup of older messages from your dashboard settings. When you delete a WhatsApp instance ("Wipe Data" / "Delete Instance"), the associated message history and configuration are permanently removed, as described at the point of that action in the dashboard. When you close your account, we delete or anonymize your data within [placeholder retention period, e.g. 30 days], except where we're required to retain it longer for legal, tax, or security reasons.
7. Your rights & choices
Depending on your location, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can access and update most account information directly from your dashboard. For anything else, contact us using the details in Section 11.
8. Data deletion
You can request deletion of your Wafonic account and associated data at any time by:
- Using the account deletion / "Danger Zone" options in your dashboard settings (where available), or
- Emailing [privacy/support email] with the subject "Data deletion request" from the email address associated with your account.
We will process deletion requests within [placeholder turnaround time, e.g. 30 days], except for information we're required to retain by law. This also applies to data obtained via Facebook Login / WhatsApp Embedded Signup — deleting your Wafonic account deletes the associated Meta Platform Data we hold.
This section doubles as the "Data Deletion Instructions" Meta's App Dashboard asks for — link directly to this anchor (#data-deletion) in App Dashboard → Settings → Basic → "User Data Deletion."
9. Children's privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
10. International data transfers
We may process and store information in countries other than your own. Where required, we take steps to ensure your information receives an adequate level of protection wherever it's processed.
11. Changes to this policy
We may update this Privacy Policy from time to time. We'll post the updated version here with a new "Last updated" date, and for material changes, we'll provide additional notice (e.g. email or an in-app notice).
12. Contact us
Questions about this Privacy Policy or how we handle your data:
- Email: [privacy/support email]
- Address: [registered business address]