Privacy policy

Last updated: 8 October 2026

This policy explains how CRMConvo ("we") handles personal data when businesses use CRMConvo (the "service") and when people message those businesses on WhatsApp. Questions: [email protected].

Our role

  • For the accounts of our customers (the businesses and their team members), we are the controller.
  • For WhatsApp conversations and contacts a business manages in CRMConvo, the business is the controller and we process the data on its behalf, only to provide the service.

Data we process

  • Account data: name, email address, password (stored only as a secure hash), role and the accounts you belong to.
  • WhatsApp data of the business: phone numbers, WhatsApp profile names, messages and media, delivery and read statuses, message templates, quality rating and messaging limits.
  • Contact records the business keeps: names, notes, tags, and opt-in and opt-out records with their source.
  • Meta connection data: IDs of the business portfolio, WhatsApp Business Account and phone number, and the access token Meta issues for them. Tokens are encrypted at rest and never shown in the browser.
  • Technical data: IP address, browser type, and logs of requests and errors, kept for security and troubleshooting.

Data from Meta

When a business connects WhatsApp, Meta asks it to grant CRMConvo the permissions whatsapp_business_management and whatsapp_business_messaging. We use them only to send and receive the business's WhatsApp messages, read its templates, phone number status and limits, and keep the connection working. We do not sell this data, do not use it for advertising, and do not share it with anyone except as described below. We follow the Meta Platform Terms and the WhatsApp Business policies.

Why we process it

  • To provide the service under our contract with the business.
  • To keep the service secure, prevent abuse and fix problems (legitimate interests).
  • To meet legal obligations, for example tax records or lawful requests.

Service providers

  • Meta Platforms (WhatsApp Business Platform): delivers WhatsApp messages.
  • Hetzner Online GmbH, Germany: hosts our servers and database in the EU.
  • Cloudflare: DNS and network security in front of the service.
  • Resend: sends account emails such as invitations, when email is enabled.

Some providers may process data outside the European Economic Area. In that case transfers rely on the European Commission's standard contractual clauses or another lawful basis.

How long we keep data

We keep data while the business account is active. When an account is closed or deletion is requested, we delete its data from our active systems within 30 days, unless the law requires us to keep part of it longer. Meta keeps its own copies of WhatsApp messages under its own policies.

Security

Connections use HTTPS. Access tokens and app secrets are encrypted with AES-256-GCM. Access to data is limited by role inside each business account, and every account's data is kept separate.

Your rights

Depending on where you live, you can ask to access, correct, delete, restrict or export your data, and object to some processing. You can also complain to your data protection authority. If you messaged a business that uses CRMConvo, please contact that business first; we will help it answer your request. To delete data, see Data deletion.

Cookies

We use only the cookies needed to keep you signed in and remember interface choices. No advertising or tracking cookies.

Children

The service is for businesses and is not meant for anyone under 16.

Changes

We will update this page when our practices change and change the date at the top. Important changes are announced to account owners.