Back to WapticLast updated: September 2026

Privacy Policy

Waptic ("we", "us", "Waptic") provides WhatsApp Business automation and inbox services. This Privacy Policy explains what data we collect, why we collect it, and the choices you have.

1. Who we are

Waptic is operated from Ajman, United Arab Emirates. For privacy questions, contact hello@waptic.com.

2. What we collect

  • Account data — email, name, hashed password, team membership, subscription tier.
  • WhatsApp Business data — via the official WhatsApp Business Cloud API you connect: your messages, contacts, media, message status events, and business profile.
  • Usage data — IP address, browser, timestamps, feature usage, error logs.
  • Billing data — held by our payment processor Stripe. We only receive card brand and last 4 digits.

3. How we use your data

  • To provide the service — routing WhatsApp messages, running the AI auto-reply you configure, generating campaign reports.
  • To secure the service — abuse detection, rate limiting, incident investigation.
  • To send you transactional emails (password resets, receipts, security alerts).
  • To comply with legal obligations and enforce our Terms.

4. WhatsApp Business messages

Messages exchanged between you and your customers are stored to power the inbox, search, exports, and AI auto-reply. We retain messages for as long as your account is active. You can request deletion at any time by emailing hello@waptic.com.

5. AI processing

If you enable AI auto-reply, message content is sent to third-party AI providers (currently xAI / Grok) solely to generate a reply. We do not use your messages to train models.

6. Sub-processors

  • Stripe — payment processing
  • xAI (Grok) — AI response generation, when enabled
  • Meta / WhatsApp Cloud API — message delivery
  • Hostinger — infrastructure hosting

7. Data retention

Account and message data is retained for the life of your account plus 30 days after cancellation, after which it is permanently deleted. Backup copies are purged within 90 days.

8. Your rights

You can access, correct, export, or delete your data at any time. Contact hello@waptic.com.

9. Security

Data is stored on encrypted volumes with regular backups. Passwords are hashed with bcrypt. All traffic is TLS-encrypted. We do not have a bug-bounty program yet — please email us any responsible disclosures.

10. Changes

We may update this policy. Material changes will be announced in-app and by email at least 14 days before they take effect.

This policy is a plain-language summary. It does not replace legal advice. If you are subject to specific jurisdictional requirements (GDPR, CCPA), contact us for a data processing agreement.

Questions? hello@waptic.com