Privacy Policy
What personal data Wapito processes for your account and your linked WhatsApp numbers, why it is processed, exactly how long each kind is kept, who else touches it and what you can ask us to do about it.
1. Who this policy is from
This policy explains what Wapito does with personal data when you use the dashboard, the REST API and the webhook delivery service. Wapito is operated by an independent team; the registered entity and address will be named here once the selling entity is registered, and until then this draft is under legal review. Questions go to support@wapito.com.
It covers two different relationships. For your own account data we are the controller and decide what happens to it. For the WhatsApp traffic flowing through your channels we are your processor: you decide what is sent to whom, and we act on your instructions.
2. What we collect
Only what the service needs to work. There is no advertising profile, no data broker and no enrichment of your contact lists.
- Account data: the email address you sign in with, your display name if you give one, and your authentication records from Firebase Auth.
- Channel configuration: the name you gave the channel, the WhatsApp number once it is linked, webhook URLs and their secrets, event filters, proxy settings and the SHA-256 hash of the channel token.
- Message traffic in transit: the messages and events your channel sends and receives, processed to deliver them to your webhook and, for media, stored briefly so your endpoint can fetch the file.
- Operational data: API request metadata (method, route, status code, duration, request id, IP address), webhook delivery attempts and their response codes, rate-limit counters and daily usage totals.
- Billing data: your Stripe customer and subscription identifiers, invoice records and payment status. Card numbers are entered on Stripe and never reach us.
- Website data: the analytics events described below, and the preferences your browser stores locally such as theme and the code language you last selected.
3. Why we process it, and on what basis
To provide the service you asked for — creating channels, linking numbers, sending messages, delivering events — which is performance of our contract with you.
To bill you, to keep accounting records and to answer tax and legal obligations, which is a legal obligation or contract performance as the case may be.
To keep the service working and safe: debugging, capacity planning, enforcing quotas, detecting abuse and unsolicited bulk messaging, and investigating bans. That is our legitimate interest in running a service that is not overrun by spam, balanced against your interests.
To send you service email you cannot reasonably opt out of — a channel that has disconnected, a trial about to end, a failed payment, a security notice. Marketing email, if we ever send any, will be opt-in and separately unsubscribable.
4. Messages and the people you message
Wapito is a pipe, not an archive. An inbound message is transformed into an event, delivered to your webhook and then dropped by the retention jobs; message bodies are not kept in a browsable store and nobody at Wapito reads your conversations. Media files are copied off the engine only so your endpoint has a stable link to fetch, and are deleted when the window below expires.
The people you message are not our customers. You are responsible for having a lawful basis for contacting them, for telling them who is messaging them and why, and for honouring their objections. The Acceptable Use Policy makes that a condition of using the service, not a suggestion.
5. How long we keep it
Automatically, on a schedule, and the same periods the security page publishes. Deleting a channel unlinks the WhatsApp session and removes its credentials; deleting your account removes the account record and every channel on it.
| What | Where | Kept for |
|---|---|---|
| WhatsApp session credentialsThey are what keeps your number linked. Deleting the channel deletes them and unlinks the device. | Postgres on the Wapito VM | Until you delete the channel or log the number out |
| Channel API tokensThe token itself is shown once, at creation. We store only its hash, so a database copy cannot be used to call the API. | Firestore, SHA-256 hash only | Until you rotate the token or delete the channel |
| Message media (images, audio, documents)Inbound files are copied off the engine so your webhook gets a stable link. After that window the file is deleted. | Disk on the Wapito VM | 24 hours on Sandbox, 7 days on Premium |
| Raw inbound engine eventsA short buffer so an event can be replayed if processing failed. It is not a message archive. | Postgres on the Wapito VM | 3 days |
| Webhook jobs and delivery attemptsSo the Logs tab can show you what was delivered, with the status code and the retry schedule. | Postgres on the Wapito VM | 30 days |
| API request log (method, route, status, duration, IP)Debugging, abuse investigation and rate-limit enforcement. Request and response bodies are not stored. | Postgres on the Wapito VM | 14 days |
| Rate-limit countersSliding windows for the per-minute and per-day limits on your plan. | Postgres on the Wapito VM | 2 days |
| Daily usage counters (sent, received, requests, checks)The Usage tab and quota enforcement. Counters are numbers, never message content. | Firestore | 90 days |
| Account record (email, plan, channel list, billing state)Your login, what you are entitled to, and which channels are yours. | Firebase Auth and Firestore | Until you delete your account |
| Payment records (amount, date, invoice id)Invoicing and accounting. Card numbers never reach Wapito — Stripe holds them. | Firestore and Stripe | As long as tax law requires, typically seven years |
6. Who else processes it
Three processors, each doing one job under contract, and none of them permitted to use your data for their own purposes.
- Google Cloud and Firebase — Authentication, Firestore, Cloud Functions, static hosting and the virtual machine the API and engine run on. (https://firebase.google.com/support/privacy)
- Stripe — Subscriptions, payments and invoices. Card details are entered on Stripe and never reach Wapito. (https://stripe.com/privacy)
- Resend — Transactional email: connection alerts, trial reminders and billing notices. (https://resend.com/legal/privacy-policy)
7. Where the data is
Our servers run in Google Cloud in the United States, and Stripe and Resend are United States companies. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is therefore transferred outside your region; those transfers rely on the Standard Contractual Clauses or an equivalent mechanism in each processor's data-processing terms.
WhatsApp traffic necessarily also passes through WhatsApp's own infrastructure, which is operated by Meta and governed by Meta's terms rather than ours.
8. How it is protected
Tokens are stored only as SHA-256 hashes, webhook payloads are signed, database access is limited to the service and to the people who operate it, and secrets live in environment configuration rather than in the repository. The engineering detail, including what we deliberately do not claim, is on the security page.
The full technical description is on the security page .
9. Your rights
Depending on where you live, you have some or all of the following rights over the personal data we hold about you as controller: to know what we hold and get a copy of it, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw a consent you have given.
Exercise any of them by writing to support@wapito.com from the address on the account. We answer within thirty days and we do not charge for it. Where you are asking about data we hold as your processor — the traffic on your channels — we will point you back to your own records, because those instructions are yours to act on.
If you think we have handled your data badly, please tell us first. You also have the right to complain to your local data protection authority.
11. Children
Wapito is a developer tool for adults. It is not directed at children, we do not knowingly collect data from anyone under eighteen, and an account found to belong to a child will be closed.
12. Changes to this policy
When this policy changes, the review date at the top changes with it, and a material change is announced by email or in the dashboard before it takes effect. The retention periods above are generated from the same configuration the retention jobs use, so they change only when the jobs do.
Draft — under legal review. This document was written by the Wapito team and has not yet been reviewed by a qualified lawyer. It describes how we actually operate and we intend to be bound by it, but wording and the governing jurisdiction may change before launch.