1. Introduction
Chatify (“we”, “our”, or “us”) provides a multi-tenant WhatsApp Business Cloud API and Meta Marketing SaaS portal. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you access or use our platform, including our web dashboard, messaging services, API integrations, and related tools.
By accessing or using Chatify, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
2. Roles and Responsibilities
Under applicable data protection regulations (including the GDPR, CCPA, and Meta Developer Platform Terms):
- Business Tenant (Data Controller): You, the business account holder, act as the Data Controller regarding customer contact lists, message content, and marketing campaigns you manage through the platform.
- Chatify (Data Processor): We act as the Data Processor, transmitting, queueing, and processing data on your behalf according to your instructions and Meta Cloud API protocols.
- End Customer (Data Subject): The individual recipients who receive messages or initiate conversations with business phone numbers via WhatsApp.
3. Information We Collect
We collect information that you provide directly to us, as well as data received automatically through our integrations:
A. Account & Identity Information
When you register for Chatify, we collect your business name, account holder email address, username, role designations, and cryptographically hashed passwords. We do not store raw, unencrypted passwords.
B. Meta WhatsApp Cloud API Credentials
To enable messaging functionality, you configure Meta credentials, including your WhatsApp Business Account ID (WABA ID), Phone Number ID, Meta System User permanent access tokens, Facebook Page ID, Ad Account ID, and Meta Dataset (Pixel) ID. All access tokens are securely stored and encrypted at rest.
C. Audience Contacts & Recipient Directories
Contacts uploaded by the business tenant, including standard E.164 phone numbers, contact names, business-defined tags, and demographic snapshots captured during marketing campaign dispatches for reporting and delivery verification.
D. Communication Content & Media
Inbound and outbound WhatsApp message content, message delivery receipts (sent, delivered, read, failed), WhatsApp Message IDs (wamid) for deduplication, and media files (images, documents, voice notes).
E. Advertising & Referral Metadata
Contextual referral payloads from Click to WhatsApp (CTWA) ads (such as source ID and headline) and server-to-server Conversions API (CAPI) events for ad attribution.
4. How We Use Information
We process collected data exclusively for legitimate operational purposes:
- Facilitating two-way customer communication via Meta Graph API v26.0 endpoints.
- Managing broadcast queues and message dispatch throttling through background worker processes.
- Executing automated conversational flows and interactive messaging.
- Attributing ad interactions and delivering conversion events via Meta Conversions API.
- Maintaining system health, error telemetry, and preventing spam or abuse.
5. WhatsApp & Meta Compliance Standards
Chatify enforces strict compliance with Meta Developer Policies and WhatsApp Business Terms:
- 24-Hour Customer Care Window: Businesses may send free-form messages only within 24 hours of an inbound customer message. Outside this window, only pre-approved Meta Message Templates can be dispatched.
- 72-Hour Free Conversation Window: Conversations initiated via Click to WhatsApp ads benefit from Meta fee waivers; referral data is strictly isolated to tenant routing.
- Automated Opt-Out Processing: If an end contact sends standard opt-out keywords (including
STOPorUNSUBSCRIBE), our system immediately marks the recipient as opted out and prevents further marketing broadcast messages to that number.
6. Multi-Tenant Security & Data Isolation
We implement comprehensive security measures to safeguard your information:
- Row-Level Security (RLS): All database records (contacts, conversations, messages, campaigns) are partitioned by tenant account ID. No business tenant can access another tenant’s data.
- Webhook Authentication: Incoming Meta webhooks are authenticated via HMAC-SHA256 signature verification using your registered app secret.
- Encryption: All data is encrypted in transit using TLS 1.3, and sensitive tokens and credentials are encrypted at rest.
- Queue Throttling: Asynchronous message dispatches enforce rate limits to protect sender phone number reputation and prevent account suspension.
7. Third-Party Sub-processors
To provide our platform services, we engage trusted infrastructure providers:
- Meta Platforms, Inc. – WhatsApp Cloud API & Advertising Infrastructure (Location: United States / Global)
- Supabase / PostgreSQL – Cloud Database & Authentication Storage (Location: SOC2 / ISO Compliant Regions)
- Redis – In-Memory Job Queuing & Pub/Sub Streaming (Location: Encrypted Server Infrastructure)
- OpenAI LLC – Optional AI Flow Node Processing, if enabled (Location: United States)
We never sell, rent, or trade personal data or customer contacts to third-party data brokers or advertisers.
8. Data Retention
We retain personal data only as long as necessary to fulfill the purposes described in this policy:
- Contact Directories: Maintained for the duration of the tenant’s active subscription or until deleted by the tenant.
- Message Logs & Receipts: Retained for 12 months for delivery analytics, troubleshooting, and support audit trails, after which they are archived or deleted.
- Temporary Media Files: Purged after 90 days unless archived.
- Conversions API Telemetry: Kept for 30 days locally for debugging delivery status.
9. Data Subject Rights & Meta Data Deletion
Depending on your jurisdiction, you and your contacts have the right to access, rectify, restrict, or request the permanent deletion of personal data.
Meta User Data Deletion Instructions
If you connected Chatify via Meta Login or Meta Embedded Signup and wish to delete your platform data, you can initiate a deletion request through your Facebook settings:
- Navigate to your Facebook Profile > Settings & Privacy > Settings.
- Go to Apps and Websites and find Chatify.
- Click Remove and select the option to request deletion of your information.
- Alternatively, email us at privacy@chatify.io with your WABA ID or registered phone number.
Upon confirmation, all associated contact lists, messages, and credentials will be permanently erased from our databases within 30 days.
10. Contact Us
If you have any questions, comments, or data privacy requests regarding this Privacy Policy, please contact our compliance office:
Chatify Data Protection Office
Email: privacy@chatify.io
Subject Line: Privacy Policy & Data Subject Rights
