Privacy Policy

What personal data Wapito processes for your account and your linked WhatsApp numbers, why it is processed, exactly how long each kind is kept, who else touches it and what you can ask us to do about it.

1. Who this policy is from

This policy explains what Wapito does with personal data when you use the dashboard, the REST API and the webhook delivery service. Wapito is operated by an independent team; the registered entity and address will be named here once the selling entity is registered, and until then this draft is under legal review. Questions go to support@wapito.com.

It covers two different relationships. For your own account data we are the controller and decide what happens to it. For the WhatsApp traffic flowing through your channels we are your processor: you decide what is sent to whom, and we act on your instructions.

2. What we collect

Only what the service needs to work. There is no advertising profile, no data broker and no enrichment of your contact lists.

  • Account data: the email address you sign in with, your display name if you give one, and your authentication records from Firebase Auth.
  • Channel configuration: the name you gave the channel, the WhatsApp number once it is linked, webhook URLs and their secrets, event filters, proxy settings and the SHA-256 hash of the channel token.
  • Message traffic in transit: the messages and events your channel sends and receives, processed to deliver them to your webhook and, for media, stored briefly so your endpoint can fetch the file.
  • Operational data: API request metadata (method, route, status code, duration, request id, IP address), webhook delivery attempts and their response codes, rate-limit counters and daily usage totals.
  • Billing data: your Stripe customer and subscription identifiers, invoice records and payment status. Card numbers are entered on Stripe and never reach us.
  • Website data: the analytics events described below, and the preferences your browser stores locally such as theme and the code language you last selected.

3. Why we process it, and on what basis

To provide the service you asked for — creating channels, linking numbers, sending messages, delivering events — which is performance of our contract with you.

To bill you, to keep accounting records and to answer tax and legal obligations, which is a legal obligation or contract performance as the case may be.

To keep the service working and safe: debugging, capacity planning, enforcing quotas, detecting abuse and unsolicited bulk messaging, and investigating bans. That is our legitimate interest in running a service that is not overrun by spam, balanced against your interests.

To send you service email you cannot reasonably opt out of — a channel that has disconnected, a trial about to end, a failed payment, a security notice. Marketing email, if we ever send any, will be opt-in and separately unsubscribable.

4. Messages and the people you message

Wapito is a pipe, not an archive. An inbound message is transformed into an event, delivered to your webhook and then dropped by the retention jobs; message bodies are not kept in a browsable store and nobody at Wapito reads your conversations. Media files are copied off the engine only so your endpoint has a stable link to fetch, and are deleted when the window below expires.

The people you message are not our customers. You are responsible for having a lawful basis for contacting them, for telling them who is messaging them and why, and for honouring their objections. The Acceptable Use Policy makes that a condition of using the service, not a suggestion.

5. How long we keep it

Automatically, on a schedule, and the same periods the security page publishes. Deleting a channel unlinks the WhatsApp session and removes its credentials; deleting your account removes the account record and every channel on it.

WhatWhereKept for
WhatsApp session credentialsThey are what keeps your number linked. Deleting the channel deletes them and unlinks the device.Postgres on the Wapito VMUntil you delete the channel or log the number out
Channel API tokensThe token itself is shown once, at creation. We store only its hash, so a database copy cannot be used to call the API.Firestore, SHA-256 hash onlyUntil you rotate the token or delete the channel
Message media (images, audio, documents)Inbound files are copied off the engine so your webhook gets a stable link. After that window the file is deleted.Disk on the Wapito VM24 hours on Sandbox, 7 days on Premium
Raw inbound engine eventsA short buffer so an event can be replayed if processing failed. It is not a message archive.Postgres on the Wapito VM3 days
Webhook jobs and delivery attemptsSo the Logs tab can show you what was delivered, with the status code and the retry schedule.Postgres on the Wapito VM30 days
API request log (method, route, status, duration, IP)Debugging, abuse investigation and rate-limit enforcement. Request and response bodies are not stored.Postgres on the Wapito VM14 days
Rate-limit countersSliding windows for the per-minute and per-day limits on your plan.Postgres on the Wapito VM2 days
Daily usage counters (sent, received, requests, checks)The Usage tab and quota enforcement. Counters are numbers, never message content.Firestore90 days
Account record (email, plan, channel list, billing state)Your login, what you are entitled to, and which channels are yours.Firebase Auth and FirestoreUntil you delete your account
Payment records (amount, date, invoice id)Invoicing and accounting. Card numbers never reach Wapito — Stripe holds them.Firestore and StripeAs long as tax law requires, typically seven years

6. Who else processes it

Three processors, each doing one job under contract, and none of them permitted to use your data for their own purposes.

  • Google Cloud and Firebase — Authentication, Firestore, Cloud Functions, static hosting and the virtual machine the API and engine run on. (https://firebase.google.com/support/privacy)
  • Stripe — Subscriptions, payments and invoices. Card details are entered on Stripe and never reach Wapito. (https://stripe.com/privacy)
  • Resend — Transactional email: connection alerts, trial reminders and billing notices. (https://resend.com/legal/privacy-policy)

7. Where the data is

Our servers run in Google Cloud in the United States, and Stripe and Resend are United States companies. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is therefore transferred outside your region; those transfers rely on the Standard Contractual Clauses or an equivalent mechanism in each processor's data-processing terms.

WhatsApp traffic necessarily also passes through WhatsApp's own infrastructure, which is operated by Meta and governed by Meta's terms rather than ours.

8. How it is protected

Tokens are stored only as SHA-256 hashes, webhook payloads are signed, database access is limited to the service and to the people who operate it, and secrets live in environment configuration rather than in the repository. The engineering detail, including what we deliberately do not claim, is on the security page.

The full technical description is on the security page .

9. Your rights

Depending on where you live, you have some or all of the following rights over the personal data we hold about you as controller: to know what we hold and get a copy of it, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw a consent you have given.

Exercise any of them by writing to support@wapito.com from the address on the account. We answer within thirty days and we do not charge for it. Where you are asking about data we hold as your processor — the traffic on your channels — we will point you back to your own records, because those instructions are yours to act on.

If you think we have handled your data badly, please tell us first. You also have the right to complain to your local data protection authority.

10. Cookies and analytics

Signing in stores your Firebase authentication session in your browser's own storage rather than in a cookie we set. It is strictly necessary — sign-in does not work without it — and it never leaves your device except as the token your browser sends us to prove who you are. A few preferences are stored the same way: the colour theme, the code language you last selected, and where you arrived from.

We use Google Analytics 4 to count page views and a small number of product events such as "a channel was created". Google Analytics sets its own first-party cookies to recognise a returning browser. There is no advertising cookie, no remarketing tag and no cross-site tracking pixel on this site, and analytics is switched off entirely when no measurement id is configured.

11. Children

Wapito is a developer tool for adults. It is not directed at children, we do not knowingly collect data from anyone under eighteen, and an account found to belong to a child will be closed.

12. Changes to this policy

When this policy changes, the review date at the top changes with it, and a material change is announced by email or in the dashboard before it takes effect. The retention periods above are generated from the same configuration the retention jobs use, so they change only when the jobs do.

Draft — under legal review. This document was written by the Wapito team and has not yet been reviewed by a qualified lawyer. It describes how we actually operate and we intend to be bound by it, but wording and the governing jurisdiction may change before launch.