Legal
Privacy Policy
Last updated: 26 September 2026
walpio (“walpio”, “we”, “us”) is a WhatsApp Business gateway operated from India and provided to business customers worldwide. This policy explains what data we handle, why, who else processes it, how long we keep it and the choices you have. It describes what the service actually does today.
1. Who this covers
Three situations are covered: (a) visitors to this website, (b) people who contact us through the get-started form or by email, and (c) client workspaces — businesses that use the walpio service. For the personal data of a client's own customers (the people a client messages on WhatsApp), the client is the data controller and walpio processes that data on the client's instructions.
2. What we collect
- Website visitors: this site uses Cloudflare Web Analytics to count visits. It uses no cookies or other browser storage. It reports the page you viewed, the site that referred you, your browser, operating system, device type and country, and how fast the page loaded. We see only totals, not individual visitors, and it does not track you across other websites. The site sets no advertising cookies. Your light/dark theme choice is kept in your own browser. Cloudflare, which hosts the site, processes technical request data such as your IP address to deliver pages and protect the site from attacks.
- The get-started form: your name, work email, company, WhatsApp or phone number, the plan you pick, your expected monthly messages, your message, and which page you came from. We store the request in our database and email a copy to our team through Cloudflare Email Routing. Your IP address is used only to count submissions per address, so repeated submissions can be stopped; that counter is deleted within a few hours.
- Email: whatever you choose to send us, such as your name, address, company and message.
- Client workspaces:
- team members' names, email addresses and passwords (passwords are stored only as hashes); sign-in attempts are counted per IP address for a few hours to stop password guessing; and the browsers and IP addresses each login has signed in from, with the email address only as a hash, so that someone guessing the password elsewhere cannot lock that person out;
- an activity log of changes made in the workspace: who made each change, when, and what it was (which can name a customer's number, for example when the client marks a contact as opted out). For a change made by a team member in the dashboard, or by a walpio operator on the client's behalf, it also records the IP address the change came from. We keep the log for about 13 months for security and to protect the account: if an account is misused, it shows who changed what, and from where. The workspace's admins can see it, IP addresses included, on the dashboard's Activity page;
- the connected WhatsApp Business account and phone-number identifiers, and the Meta access credentials the client provides, encrypted with AES-256-GCM;
- API keys, stored only as hashes;
- the client's WhatsApp contacts: WhatsApp number or Meta's business-scoped user ID, profile name or username, notes the client adds, opt-out status, and a preview (up to 160 characters) of the latest message in each conversation;
- message metadata — direction, recipient, timestamps, delivery status and errors, the template used, the pricing category Meta reports and the client's own reference — and a preview of up to 160 characters for the client's message log.
We do not keep an archive of conversations, and the WhatsApp Cloud API gives the client no conversation history to read back from Meta. Our message log keeps, for each message, the metadata and the 160-character preview above, and that preview is all the dashboard shows. The full text of a message a customer sends reaches the client only through the client's own callback URL, if the client has set one, so a client that needs the full text should store it from its callbacks. We hold full message content in two places, each for a limited time:
- a message waiting to be retried keeps its full content until Meta accepts it or the send finally fails;
- each callback we send the client is kept in our callback delivery log so it can be retried. For an incoming message the callback includes its full text, the customer's number or WhatsApp user ID, and their profile name; the log keeps the text, profile name and username only until the callback is delivered or given up (about 8 hours of retries, never more than 72 hours) and then keeps the delivery record alone — the event, the IDs, the customer's number or user ID, the times and the result — for 30 days. The nightly backup never holds the text.
When walpio refuses a send because no approved template fits its wording, the activity log records the refusal with the first 160 characters of the message, so the client can see what to fix.
- Billing: we do not take card payments online and hold no card details. Plans are agreed with each client and invoiced directly; we keep the billing contact and invoice records.
3. How we use data
- To answer your request and, if you become a client, to set up and provide the service: sending WhatsApp messages through Meta's official Cloud API, tracking delivery, applying the 24-hour customer service window, and showing clients their own message logs.
- To keep the service secure: authentication, abuse prevention, rate limiting, troubleshooting and records of administrative actions.
- To manage plan agreements and invoices.
- We do not sell personal data, and we do not use client message data for advertising or for training anything.
4. Service providers (sub-processors)
| Provider | What it does for walpio |
|---|---|
| Cloudflare | Hosts this website and the walpio service, runs its database and stores its backups, and routes form notifications by email. It also counts visits to this website (Cloudflare Web Analytics). |
| Meta Platforms | Delivers WhatsApp messages through the WhatsApp Business Cloud API, under the client's own Meta account and Meta's own terms. |
Emails you send us, and the form notifications, arrive in the walpio team's email inbox. We disclose data to authorities only where the law requires it. This list is kept current on this page; the date at the top shows when it last changed.
5. Where data lives
The service runs on Cloudflare's global network, so data may be processed outside your country. Meta processes messages under its own terms. We deliberately minimise what we store — metadata, short previews and encrypted credentials rather than full conversations. The two places where we hold full message text for a limited time are described in section 2.
6. Security
Meta credentials are encrypted at rest with AES-256-GCM. Webhooks from Meta are verified by cryptographic signature on every event, and the callbacks we send clients are signed. Passwords and API keys are stored only as hashes, and API keys can be revoked at any time. Access to production systems is restricted to the people who operate the service.
7. How long we keep data
- Message records (metadata and the 160-character preview): up to about 13 months.
- Callbacks sent to a client: the delivery record 30 days; for an incoming message, its full text and the sender's profile name only until the callback is delivered or given up (72 hours at most).
- IP-based counters for form submissions and sign-in attempts: a few hours.
- The browsers and IP addresses a login has signed in from: 90 days after that login last signed in from them, and deleted with the workspace.
- The activity log (records of administrative actions, with the IP address of each change made in the dashboard or by a walpio operator, and refused sends with their first 160 characters): up to about 13 months. Deleting a workspace deletes its activity log too, except one record that the deletion was made (when, and by which of our accounts), which expires on the same schedule.
- Backups: a copy of the database is taken nightly and kept for 35 days, so deleted data can remain in a backup for up to 35 days.
- Get-started requests and email: as long as needed to handle the request and any resulting business relationship, or until you ask us to delete them.
- Workspace account data (team, contacts with the preview of each contact's latest message, templates, settings): while the workspace is active. A contact's name, username, notes and message preview are cleared once the contact has exchanged no message for about 13 months; whether they opted out is kept. When a client closes its workspace, we delete this data on request.
- Invoices and billing records: as long as the law requires.
8. Your rights, export and deletion
You can ask us to access, correct, export or delete personal data we hold about you, or object to its use, by emailing [email protected]. Clients can ask for an export of their workspace data, or its deletion, the same way. These requests are handled by our team rather than automatically; we respond within 30 days. If you are a customer of one of our clients, we will refer your request to that client, since they control that data.
9. Children
The service is for businesses and is not directed at children under 18.
10. Changes
If this policy changes, we will update this page and the date above. If a change materially affects how we handle client data, we will also tell clients by email.
11. Contact
Questions about privacy: [email protected].