Privacy Policy
Effective: 1 July 2025 · Last updated: 3 August 2026
WaBot takes the privacy of your business and customer data seriously. This Privacy Policy explains what we collect, why we collect it, how we use it, and what rights you have over your data.
1. Data We Collect
We collect only what is necessary to provide the Service:
- Account data: email address, business name, password (stored as a secure hash — never plain text).
- WhatsApp data: the phone number you connect, incoming message content, and conversation metadata (timestamps, message IDs).
- Knowledge base: text, URLs, and documents (PDF, DOCX, XLSX) you upload. This content is indexed to power your bot's replies.
- Payment data: screenshots of wallet / bank transfers and transaction references. We do not store card numbers or banking credentials.
- Usage data: dashboard activity, feature usage, and error logs used to improve reliability.
- Team member data: email addresses of team members you invite, their role, and acceptance status.
2. How We Use Your Data
- To provide the core Service: WhatsApp auto-reply, knowledge base retrieval, AI response generation.
- To verify and activate your subscription after manual payment.
- To send transactional communications: payment confirmations, team invitations, and service alerts.
- To improve platform reliability using anonymized, aggregated usage analytics.
- To investigate and respond to support requests or security incidents.
3. What We Do NOT Do
- We do not sell your data to any third party.
- We do not share your WhatsApp conversations with advertisers or data brokers.
- We do not use your knowledge base or conversation data to train AI models.
- We do not access your conversations without your explicit permission (e.g., during a support session you initiate).
- We do not send you marketing emails without your consent.
4. WhatsApp Data & Disclaimer
- Incoming message content is stored temporarily to generate a reply and log conversation history. You can reset this history from the dashboard at any time.
- We do not re-read or re-process your WhatsApp messages for any purpose beyond generating your bot's reply and maintaining conversation context.
- Your WhatsApp session credentials (QR session) are managed through the Evolution API service. WaBot does not store your WhatsApp password.
5. Third-Party Services We Use
WaBot relies on the following sub-processors to deliver the Service:
- Supabase — PostgreSQL database with pgvector, row-level security, and authentication. Hosts your business data.
- OpenRouter / LongCat — AI model inference providers. Message content is sent to these APIs to generate replies. They are bound by their own privacy and data use policies.
- Evolution API — WhatsApp session management and message routing.
- Resend / email provider — Transactional email delivery for invitations and notifications.
- Vercel — Hosting and serverless compute for the web platform.
We share only the minimum data necessary with each sub-processor. We do not authorize sub-processors to use your data for their own purposes.
6. Data Storage & Security
- Data is stored in Supabase-managed PostgreSQL, hosted on Supabase's infrastructure in the Seoul (ap-northeast-2) region, with row-level security (RLS) policies enforced at the database level, isolating each business's data.
- Passwords are hashed using bcrypt and never stored in plain text.
- All communication between your browser and our servers is encrypted using TLS (HTTPS).
- Admin access to production data is restricted and logged.
- Despite these measures, no system is 100% secure. In the event of a data breach affecting your account, we will notify you as soon as reasonably practicable.
7. Data Retention
- Active accounts: data is retained for as long as your account is active.
- Cancelled accounts: data is retained for 30 days after cancellation, then permanently deleted unless you request earlier deletion.
- WhatsApp conversation history: retained for the life of your account. You can reset it at any time from the Playground page.
- Payment screenshots: retained for 12 months for financial record-keeping, then deleted.
- Logs: system logs are retained for up to 90 days for debugging and security review.
8. Your Rights
You have the following rights regarding your data. To exercise any of them, contact us:
- Access: request a summary of the personal data we hold about you.
- Correction: ask us to correct inaccurate or incomplete data.
- Deletion: request deletion of your account and associated data. We will process this within 30 days.
- Portability: request an export of your knowledge base and conversation history in a common format (JSON or CSV).
- Objection: object to processing of your data for a specific purpose. Contact us and we will review the request.
9. Children's Privacy
WaBot is intended for use by businesses and adults aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that a minor has created an account, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered account holders and via a notice on the dashboard. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after changes are in effect constitutes your acceptance.
11. Contact
For privacy questions, data access requests, or deletion requests:
- Email: support@wabot.pk
- WhatsApp: +92 322 2766318
We aim to respond to all privacy inquiries within 5 business days.