Skip to content

Legal

Privacy Policy

This policy is a starting point for the WhaOne service. It is not legal advice and does not invent a registered legal entity, company number, or office address. Last updated 17 September 2026.

1. Who this covers

WhaOne is a multi-tenant software platform that helps businesses operate WhatsApp communication through Meta's official WhatsApp Business Platform. This policy describes information processed when you visit this website or use a WhaOne workspace.

2. Account and website data

If you create an account, WhaOne stores the name, email, password hash, and organization name you submit, plus session records needed to keep you signed in. Visiting public pages may produce ordinary web server logs such as IP address, user agent, and request time. This website does not add a third-party marketing tracker.

3. Customer workspace data

When a business uses WhaOne, the workspace may contain contacts, conversation metadata, message content received or sent through official Meta APIs, templates, campaign plans, automation definitions, team membership, notes, and usage records. That workspace data belongs to the customer organization. WhaOne processes it to provide the service, not to operate the customer's WhatsApp account as WhaOne's own number.

4. WhatsApp and Meta

Message delivery uses Meta's official Cloud API and webhooks. Meta processes WhatsApp traffic under Meta's terms and policies. WhaOne does not scrape WhatsApp Web and does not provide an unofficial WhatsApp client. Each customer connects their own Meta business assets.

5. Sharing

WhaOne shares data with infrastructure providers needed to run the service (for example hosting, database, object storage, and email delivery when those are configured) and with Meta when a workspace is connected for WhatsApp. WhaOne does not sell personal information. Operators do not use a client-supplied organization header to browse another tenant.

6. Security

Implemented controls include tenant isolation, role-based access, hashed sessions, Argon2id password hashing, encrypted WhatsApp access tokens, audit logging, and API rate limiting. See the Security page. No certification (including SOC 2, ISO 27001, or GDPR certification) is claimed here.

7. Retention

Account and workspace data are kept while the workspace is active and as needed to operate, secure, and debug the service. Specific retention windows can depend on deployment configuration. This policy does not invent a numeric retention SLA.

8. Requests

Organization owners can manage much of their workspace data inside the product. To request access, correction, or deletion of WhaOne-associated data, follow the Data Deletion instructions. People who only messaged a business on WhatsApp should contact that business; WhaOne does not replace the customer's relationship with their end users.

A public privacy email is not published in this deployment. Use the in-product workspace or the Contact page for the currently available channel.

9. Changes

WhaOne may update this policy as the product changes. The date at the top of this page will change when the text is revised. Continued use of the service after an update means the revised policy applies to later use.