Privacy Policy
Last updated: 13 September 2026
Wapi (“we”, “us”) provides a platform that lets businesses send and receive messages through the WhatsApp Business Platform (Meta's WhatsApp Cloud API). This policy explains what we collect, how we use it, and the choices available to you.
Who is responsible for your data
For businesses using Wapi, we act as a processor on your behalf for the customer data you upload and the messages you send and receive. You are the controller of your customers' data and are responsible for having a lawful basis and appropriate consent (opt-in) to message them.
Information we collect
- Account data: your name, email, and workspace name.
- WhatsApp connection data: your WhatsApp Business Account ID, phone number ID, display number, and access tokens obtained through Meta Embedded Signup (tokens are encrypted at rest).
- Contacts: phone numbers and any attributes you upload for your audience.
- Messages & metadata: message content, templates, and delivery/read status returned by Meta.
- Usage data: basic logs needed to operate and secure the service.
How we use information
- To send messages and campaigns on your instruction via the WhatsApp Cloud API.
- To display your inbox, delivery status, and analytics.
- To secure the service, prevent abuse, and comply with Meta's policies.
Sharing
We share message content and recipient numbers with Meta Platforms as required to deliver your messages through the WhatsApp Cloud API. We use Supabase for database, authentication, and storage. We do not sell your data.
Retention
We retain account and messaging data for as long as your workspace is active. You may request deletion at any time (see our Data Deletion page); we delete or anonymize data within 30 days of a verified request, subject to legal retention needs.
Security
Access tokens and sensitive secrets are encrypted at rest. Access to workspace data is restricted by row-level security so one workspace cannot read another's data.
Contact
Questions or requests: support@getwapi.shop.