Legal

Privacy Policy

walpio (“walpio”, “we”, “us”) is a WhatsApp Business gateway operated from India and provided to business customers worldwide. This policy explains what data we handle, why, who else processes it, how long we keep it and the choices you have. It describes what the service actually does today.

1. Who this covers

Three situations are covered: (a) visitors to this website, (b) people who contact us through the get-started form or by email, and (c) client workspaces — businesses that use the walpio service. For the personal data of a client's own customers (the people a client messages on WhatsApp), the client is the data controller and walpio processes that data on the client's instructions.

2. What we collect

3. How we use data

4. Service providers (sub-processors)

ProviderWhat it does for walpio
CloudflareHosts this website and the walpio service, runs its database and stores its backups, and routes form notifications by email. It also counts visits to this website (Cloudflare Web Analytics).
Meta PlatformsDelivers WhatsApp messages through the WhatsApp Business Cloud API, under the client's own Meta account and Meta's own terms.

Emails you send us, and the form notifications, arrive in the walpio team's email inbox. We disclose data to authorities only where the law requires it. This list is kept current on this page; the date at the top shows when it last changed.

5. Where data lives

The service runs on Cloudflare's global network, so data may be processed outside your country. Meta processes messages under its own terms. We deliberately minimise what we store — metadata, short previews and encrypted credentials rather than full conversations. The two places where we hold full message text for a limited time are described in section 2.

6. Security

Meta credentials are encrypted at rest with AES-256-GCM. Webhooks from Meta are verified by cryptographic signature on every event, and the callbacks we send clients are signed. Passwords and API keys are stored only as hashes, and API keys can be revoked at any time. Access to production systems is restricted to the people who operate the service.

7. How long we keep data

8. Your rights, export and deletion

You can ask us to access, correct, export or delete personal data we hold about you, or object to its use, by emailing [email protected]. Clients can ask for an export of their workspace data, or its deletion, the same way. These requests are handled by our team rather than automatically; we respond within 30 days. If you are a customer of one of our clients, we will refer your request to that client, since they control that data.

9. Children

The service is for businesses and is not directed at children under 18.

10. Changes

If this policy changes, we will update this page and the date above. If a change materially affects how we handle client data, we will also tell clients by email.

11. Contact

Questions about privacy: [email protected].