This policy explains what personal data Baatcheet
("we", "us") collects when a business uses our WhatsApp automation service, and
what we do with it. It covers both the businesses who sign up with us and the
people who message those businesses on WhatsApp.
1. Who this applies to
Client businesses — businesses that connect their WhatsApp
Business account to our service.
End customers — people who send WhatsApp messages to those
businesses. We process their messages on the business's behalf.
2. What we collect
From client businesses, when they connect their account:
Business name and the display name shown to their customers
WhatsApp Business Account ID, business phone number and phone number ID
Meta business portfolio ID
An access token issued by Meta, which lets us send and receive messages on
the business's behalf
From end customers, when they message a client business:
Their WhatsApp phone number and WhatsApp profile name
The content of messages they send to the business
Message timestamps and delivery or read status
We do not ask for or store payment card details, government ID, or contact lists.
3. Why we process it
To deliver messages between a business and its customers
To generate automated replies to incoming messages
To produce message statistics and reports for the business, such as message
volume and response times
To diagnose faults and keep the service running
We do not sell personal data, and we do not use message content for advertising.
4. Who we share it with
Meta Platforms, Inc. — message delivery runs on the WhatsApp
Business Platform, so message content necessarily passes through Meta. Meta's
own handling is governed by its
WhatsApp Business terms.
Our AI provider — message text may be sent to a third-party
AI service to generate a reply. That provider processes it only to produce the
reply.
Hosting and infrastructure providers that run our servers.
Authorities, where the law requires it.
Each client business only ever has access to its own conversations. Businesses
cannot see each other's data.
5. How we protect it
Meta access tokens are encrypted before they are stored.
Every incoming webhook is cryptographically verified before it is processed,
so we do not act on forged requests.
All traffic between your device, our servers and Meta is over HTTPS.
Access to our systems is limited to staff who need it.
No system is perfectly secure, and we cannot guarantee absolute security.
6. How long we keep it
Messages and conversation records: retained while the business
remains a client, and for up to 12 months afterwards.
Access tokens: deleted when a business disconnects its account
or asks us to.
A client business can ask us to delete its data at any time using the contact
details below. Deleting the connection in Meta's WhatsApp Manager also revokes our
access immediately.
7. Your rights
Depending on where you live, you may have the right to access the personal data we
hold about you, correct it, have it deleted, or object to how we use it. To
exercise any of these, contact us at the address below and we will respond within
30 days.
If you are an end customer and want your messages to a business removed, contact
that business directly — they control their own conversation records — or contact
us and we will pass the request on.
8. Children
Our service is not directed at children under 13, and we do not knowingly collect
their data. If you believe a child's data has reached us, contact us and we will
delete it.
9. Changes to this policy
We may update this policy. The "last updated" date at the top always reflects the
current version, and we will notify client businesses of significant changes.