Privacy Policy
Last updated: 2026-07-20
1. Introduction
Watinza ("we", "us", "our") operates a software platform that allows businesses ("Customers") to send approved message templates to their opted-in customers through the official Meta WhatsApp Business Cloud API. This Privacy Policy explains what data we collect, how we use it, and the rights you have over it.
Watinza is registered at 30 N Gould St #40311, Sheridan, WY 82801, United States, with operations also in Lahore, Pakistan. You can reach our data-protection team at privacy@watinza.com or +92 324 4464042.
2. Data we collect
2.1 From Customers (businesses using Watinza)
- Account information: name, business email, password (stored as a salted PBKDF2 hash).
- Workspace metadata: workspace name, plan, audit log of actions taken inside the platform.
- Meta connection credentials: WhatsApp Business Account ID, Phone Number ID, and a permanent access token issued by Meta to your business. Tokens are stored encrypted at rest.
2.2 From End-Customers (recipients of messages)
- Contact information uploaded by the Customer: phone number (E.164), name, email, tags, and custom attributes.
- Message metadata: WhatsApp message ID, send/delivery/read timestamps, error codes returned by Meta.
- Inbound message content received from WhatsApp via Meta's webhook.
- Opt-out status: when an end-customer sends a STOP / UNSUBSCRIBE keyword we automatically flip their opt-in flag to OFF and record the timestamp + reason.
3. Lawful basis
Customers act as the "data controller" for their end-customer contact lists. Watinza acts as a "data processor" on their behalf. Customers warrant that they have a lawful basis (consent, contract, or legitimate interest) to message the end-customers they upload, in compliance with applicable law and Meta's Business Messaging Policy.
4. How we use data
- To authenticate your account and provide the platform.
- To send WhatsApp messages on your behalf via Meta's API using credentials you authorize.
- To deliver inbound message events from Meta to your inbox view.
- To detect opt-out keywords automatically and stop further sends to that recipient.
- To compute per-tenant analytics (delivery, read, failure counts).
- To maintain an audit log of sensitive actions for security and compliance.
5. Data sharing
We do not sell or rent personal data. We share data only with:
- Meta Platforms — to send and receive WhatsApp messages via the Cloud API. Subject to Meta's privacy practices.
- Cloudflare — our hosting provider (Cloudflare Pages, Workers, D1). Data is processed at the edge and stored encrypted at rest.
- Legal authorities, only when required by valid legal process.
6. Retention
- Live tenant data is retained for the lifetime of your account.
- Account deletion: when you delete your workspace, your data is soft-deleted immediately and hard-deleted within 30 days.
- Audit logs are retained for up to 24 months from the time of the event.
- Inbound messages are retained for up to 12 months unless you delete them earlier.
7. Your rights (end-customers)
If you are an end-customer whose number was uploaded to Watinza by one of our Customers:
- You can opt out at any time by replying STOP, UNSUBSCRIBE, CANCEL or QUIT to any message — we detect these keywords automatically and stop future sends.
- You can request access to or deletion of your data by contacting the Customer who sent you messages, or by emailing us at privacy@watinza.com. We will route your request to the relevant Customer.
8. Your rights (Customers)
- Access: download a JSON export of all your workspace data via Settings → Account → Export.
- Rectification: edit contacts, templates, and account info directly inside the dashboard.
- Deletion: delete individual records or your entire workspace via Settings → Account → Delete.
- Portability: the JSON export is machine-readable and may be moved to another provider.
9. Security
- Passwords are hashed with PBKDF2-SHA256 (100,000 iterations, per-user salt).
- Sessions are opaque tokens stored server-side; cookies are HttpOnly, Secure, SameSite=Lax.
- All HTTP traffic uses TLS (HTTPS).
- Access tokens for Meta are restricted to the minimum scopes required (whatsapp_business_messaging, whatsapp_business_management).
10. Children
Watinza is not directed to anyone under the age of 16. We do not knowingly collect data from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced inside the dashboard. The "Last updated" date at the top reflects the most recent version.
12. Contact
For privacy questions or data-subject requests:
Watinza — Data Protection
Email: privacy@watinza.com
Phone: +92 324 4464042
USA: 30 N Gould St #40311, Sheridan, WY 82801
Pakistan: Johar Town, Near Thokar, Lahore, Punjab
For instructions on how to request deletion of your data, see our Data Deletion page.