Wassel wassel.app
Compliance & Privacy Policy

Privacy Policy

Last Updated: September 09, 2026

This Privacy Policy explains how Wassel ("we", "us", or "our") collects, processes, and safeguards information on behalf of businesses, e-commerce merchants, and enterprise platforms that integrate with our service via direct connection with Meta's official WhatsApp Business Cloud API. We are fully committed to international data protection principles and transparency.

1. Information We Collect

To maintain reliable message routing and technical infrastructure, we collect and process the following categories of data:

  • Phone Numbers: Recipient customer phone numbers and registered WhatsApp Business Phone Number IDs.
  • WhatsApp Business Account IDs (WABA): Official Meta-assigned account identifiers required for routing and authorization.
  • Message Delivery Metadata: Timestamps, delivery receipts, read statuses, and unique Message IDs.
  • Webhook Event Payload Logs: Real-time event notifications transmitted by Meta's webhook infrastructure to verify delivery lifecycle.

2. How We Use Information

We act strictly as a Data Processor on behalf of our business clients. All processed data is used solely to:

  • Deliver automated transactional notifications, interactive messages, and customer updates via WhatsApp Cloud API.
  • Synchronize customer interactions, quick replies, and order updates in real time.
  • Provide accurate delivery diagnostics, throughput reports, and analytics to business administrators.

Strict Data Monetization Prohibition: We do not sell, rent, or monetize your customer data, contact lists, or messaging history to any third party for marketing or advertising purposes under any circumstances.

3. Third-Party Processing (Meta Platforms Inc.)

All message content and routing payloads are transmitted directly and securely to Meta Platforms Inc. via the official WhatsApp Business Cloud API. Your use of our service is also governed by the WhatsApp Business Policy and Meta Platform Terms.

4. Data Retention & Security

  • Encryption in Transit: End-to-end transport encryption utilizing modern TLS 1.3 cryptographic suites for all network communications.
  • Encryption at Rest: Sensitive authentication credentials, OAuth tokens, and webhook secrets are stored with enterprise AES-256 encryption.
  • Retention Duration: Data is retained strictly as long as the merchant's account remains active. Upon disconnection or submission of a data deletion request, integration credentials and metadata are purged permanently.

5. Contact & Data Protection Officer (DPO)

If you have questions regarding this Privacy Policy, your data protection rights, or wish to contact our Data Protection Officer, reach out to us at: