Privacy Policy
Last updated: August 7, 2026
This Privacy Policy for Wappigo describes how and why we access, collect, store, use, disclose, and protect personal information when you use our website, web application, mobile applications, APIs, Meta and WhatsApp integrations, and related omnichannel messaging services.
1. What Information Do We Collect?
We collect personal information that you provide to us, that is generated when you use the Services, or that is received from connected channels such as Meta's WhatsApp Business Platform, WhatsApp Cloud API, Meta Graph API, webhooks, and other messaging providers. The personal information we collect may include the following:
• Names• Phone numbers• Email addresses• Usernames• Passwords• Contact preferences• Billing addresses• Message content, templates, conversation history, delivery/read statuses, metadata, and logs• Customer, recipient, imported contact, and segmentation data• WhatsApp Business Account IDs, phone number IDs, page/account identifiers, channel settings, and integration status• Webhook payloads, event data, API request/response data, IP addresses, device data, and audit logs• Images, documents, audio, video, stickers, and other files sent or received through connected channels
2. How Do We Process Your Information?
We process information to create and secure accounts, authenticate users, connect messaging channels, send and receive messages, route webhooks, display conversations in the team inbox, manage templates, store conversation history, process media, provide analytics and support, prevent abuse and fraud, maintain audit logs, comply with legal and platform obligations, and improve the Services. If AI-assisted features are enabled, message or support content may be processed to generate drafts, summaries, classifications, or automation suggestions.
3. What Legal Bases Do We Rely On?
We process personal information only when we have a valid legal basis under applicable law. Depending on the context, we rely on performance of a contract, consent, legitimate interests, legal obligations, establishment or defense of legal claims, and other lawful bases recognized by KVKK, GDPR, and similar privacy laws. For recipient messaging, our customer is responsible for obtaining any required opt-in, consent, or other lawful basis before uploading contact data or sending messages.
4. When and With Whom Do We Share Your Personal Information?
We may share or disclose information with service providers and subprocessors that help us operate the Services, including hosting and storage providers such as AWS, Meta and WhatsApp for Business Platform delivery, analytics providers, email and notification providers, payment providers, customer support tools, security providers, AI service providers where enabled, professional advisers, authorities when legally required, and parties involved in a business transfer. We do not sell your personal information.
5. Do We Use Cookies and Other Tracking Technologies?
We may use cookies, local storage, SDKs, pixels, logs, and similar technologies to operate authentication sessions, remember preferences, secure accounts, prevent abuse, debug crashes, measure usage, improve performance, and understand product adoption. You can control cookies through your browser settings, but some features may not function without essential cookies.
6. Is Your Information Transferred Internationally?
Your information may be transferred to, stored in, and processed in Turkey, the European Economic Area, the United States, or other countries where we or our service providers operate. These countries may have different data protection laws than your country. Where required, we rely on appropriate transfer mechanisms, contractual safeguards, platform terms, consent, or other lawful transfer bases.
7. How Long Do We Keep Your Information?
We keep personal information only for as long as necessary to provide the Services, meet legal and accounting obligations, resolve disputes, enforce agreements, maintain security, and comply with platform requirements. Account data is generally deleted or anonymized within 30 days after account closure unless retention is required by law, unresolved disputes, payment records, security logs, backups, or platform compliance obligations. Message, contact, media, and webhook data may be retained according to your workspace settings, subscription, backup cycle, and legal requirements.
8. How Do We Keep Your Information Safe?
We use technical and organizational measures designed to protect personal information, including access controls, password hashing, encryption in transit where supported, network and infrastructure security, logging, role-based access, backup controls, and monitoring. Access to production data is limited to authorized personnel and service providers with a business need. However, no electronic transmission or storage system can be guaranteed to be 100% secure.
9. Do We Collect Information From Minors?
We do not knowingly collect data from or market to children under 18 years of age. This service is not directed to children under 13 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor.
10. What Are Your Privacy Rights?
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal information; withdraw consent; object to certain processing; and lodge a complaint with a data protection authority. Under Turkish KVKK and similar laws, you may also request information about processing purposes, recipients, transfers, correction, deletion, anonymization, and damages where applicable.
11. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems include a Do-Not-Track (DNT) setting. Because no uniform industry standard currently exists for responding to DNT signals, we do not respond to DNT signals at this time. You can still control cookies and tracking through browser settings, device settings, and any consent tools we make available.
12. Do United States Residents Have Specific Privacy Rights?
If you are a resident of certain US states, you may have rights to know, access, correct, delete, or receive a copy of personal information, and to opt out of certain targeted advertising, sale, sharing, or profiling activities where applicable. We do not sell personal information. To exercise rights, contact us using the information below.
13. Do We Make Updates to This Notice?
We may update this Privacy Policy from time to time. The updated version will be indicated by an updated date at the top of this Privacy Policy. If we make material changes, we may notify you either by prominently posting a notice or by directly sending you a notification.
14. How Can You Contact Us About This Notice?
If you have questions or comments about this notice, or if you want to exercise privacy rights, contact us at info@wappigo.com. If your request relates to data controlled by one of our business customers, we may forward the request to that customer or ask you to contact them directly.
15. How Can You Review, Update, or Delete the Data We Collect From You?
You may request access, correction, deletion, export, or restriction of personal information by contacting info@wappigo.com or by using the account and data deletion tools made available in the Services, including the Meta data deletion callback at /meta/data-deletion where applicable. We will verify and respond to requests within the period required by applicable law. We may retain information where required for legal, security, accounting, dispute, backup, or platform compliance reasons.
16. Contact Us
If you have any questions about this Privacy Policy, please contact us at info@wappigo.com or through the contact page on our website.
17. How Do We Use Meta Platform Data and Permissions?
Wappigo accesses Meta Platform Data only after an authorized workspace administrator connects a channel and grants the relevant permissions. The permissions currently requested are business_management, whatsapp_business_management, whatsapp_business_messaging, instagram_business_basic, and instagram_business_manage_messages. We use business_management only during WhatsApp Embedded Signup to identify and associate the business assets selected by the administrator; whatsapp_business_management to retrieve and manage authorized WhatsApp Business Accounts, phone numbers, webhook subscriptions, templates, and business settings; whatsapp_business_messaging to send, receive, synchronize, and display permitted customer messages, delivery status, and media; instagram_business_basic to perform direct Instagram Login and retrieve the connected professional account's ID, username, name, and profile picture; and instagram_business_manage_messages to receive, synchronize, display, and reply to customer-initiated Instagram direct messages within Meta's permitted messaging window. We do not request or use Meta Platform Data for advertising, Instagram comments, content publishing, insights, or Human Agent messaging. We do not sell Meta Platform Data or create profiles outside the Services. Access tokens and credentials are access-restricted and protected using encryption in transit and application-level encryption at rest. You may revoke access in Meta settings, disconnect the channel in Wappigo, contact info@wappigo.com, or use Meta's signed data-deletion callback at https://v2.wappigo.com/meta/data-deletion. Disconnection or a valid Meta deletion request removes the affected connection credentials and related channel messages, conversations, and archived media from active systems, subject to limited legal, security, and backup retention.