1. Scope
This Privacy Policy applies to the Waery website, customer dashboard, APIs, plugins, integrations, support interactions and related services (the “Service”). It does not govern independent websites, applications or services operated by Customers, Meta, WhatsApp, payment processors or other third parties.
2. Our Data Roles
For account, website, billing, security and support information, Waery generally determines why and how information is processed and acts as the data controller or data fiduciary, as applicable.
For contacts, messages, media and other Customer Data submitted by a Customer, the Customer generally decides the purpose and means of processing. Waery processes that data as a service provider or processor on the Customer’s documented instructions. Contacts should first direct requests about business messages to the business that contacted them.
3. Information We Collect
3.1 Account and organisation information
- name, business name, email address, phone number and login credentials;
- team membership, role, permissions and account preferences;
- billing address, tax information, subscription, invoice and payment status; and
- communications with sales, onboarding and support.
3.2 Technical and usage information
- IP address, browser, device, operating system, language and approximate location;
- login events, session information, audit logs, API requests and webhook delivery logs;
- feature usage, error reports, performance metrics and security signals; and
- cookie identifiers and preferences.
3.3 Connected platform information
When a Customer connects Meta or another integration, we may receive business account identifiers, WhatsApp Business Account ID, Phone Number ID, display number, verified name, quality status, template information, access tokens and webhook events. Supported secrets are encrypted at rest.
3.4 Customer communication data
Depending on enabled features, Waery may process contact names, telephone numbers, email addresses, labels, consent status, message content, attachments, delivery status, conversation metadata, automation results and integration payloads.
3.5 Payment information
Payments may be processed by third-party payment providers. We generally receive transaction identifiers, amount, currency, status and limited billing details rather than full card or banking credentials.
4. How We Use Information
We process information to:
- create and administer accounts and subscriptions;
- connect business messaging accounts and deliver requested communications;
- provide inbox, template, automation, API, webhook and integration functionality;
- authenticate users, secure the Service, prevent fraud and investigate abuse;
- measure performance, troubleshoot errors and improve functionality;
- provide onboarding, customer support and service communications;
- process payments, generate invoices and maintain financial records;
- enforce our terms, protect legal rights and comply with lawful requests; and
- send product or marketing communications where permitted, with an opt-out option.
We do not sell personal data. We do not use Customer message content to advertise unrelated third-party products.
5. Legal Bases and Consent
Depending on location and context, processing may rely on performance of a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, consent, or another basis recognised by applicable law.
Customers are responsible for providing required privacy notices and obtaining lawful consent or another valid basis before uploading contacts or sending WhatsApp messages. Consent must be specific enough to cover the messages sent and should be recorded so it can be demonstrated.
6. How Information Is Shared
We may share information only as reasonably necessary with:
- service providers that provide hosting, storage, security, email, analytics, customer support or infrastructure;
- Meta and WhatsApp to provide the WhatsApp Business Platform connection and messaging functionality;
- payment processors to process charges, refunds and fraud checks;
- Customer-authorised integrations when the Customer enables an API, plugin, webhook or external application;
- professional advisers such as auditors, accountants and legal counsel under confidentiality duties;
- authorities or other parties where required by law, valid legal process, safety or protection of rights; and
- a successor organisation in connection with a merger, financing, acquisition or sale, subject to appropriate safeguards.
Providers are authorised to process information only for the services they provide to us and are expected to apply appropriate security and confidentiality controls.
7. WhatsApp and End-User Data
Messages and status events travel through Meta’s WhatsApp Business Platform and are also subject to Meta and WhatsApp terms and privacy practices. Waery cannot control Meta’s independent processing.
If you receive a message from a business using Waery, that business is primarily responsible for the message, its recipient list, lawful basis, content and response to your privacy request. You can use WhatsApp controls to block or report a business and may contact the business directly to withdraw consent.
8. Cookies and Similar Technologies
Waery may use essential cookies for authentication, session security, CSRF protection, load balancing and preferences. Optional analytics or marketing cookies should only be used where enabled and legally permitted. Browser controls can block cookies, but essential account functionality may then fail.
9. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Policy, including:
- account and Customer Data while the account is active;
- billing and tax records for periods required by applicable law;
- security, API and audit logs for a limited period appropriate to risk;
- backups until they are overwritten through normal backup cycles; and
- information needed to resolve disputes, enforce agreements or comply with legal obligations.
Plan-specific data retention may be shown in the dashboard. After valid deletion, some information may remain temporarily in protected backups and will not be restored except for disaster recovery or legal necessity.
10. Security
We use measures designed to protect information, which may include HTTPS, password hashing, encryption of supported credentials, role-based access, tenant separation, request validation, audit logs, backups and monitoring. No online service is completely secure, and we cannot guarantee absolute security.
Customers must use strong passwords, restrict team and API access, rotate exposed credentials, validate webhooks and keep integrations updated.
11. Privacy Rights and Choices
Subject to applicable law, individuals may have rights to request access, correction, completion, deletion, restriction, withdrawal of consent, objection, portability or information about processing. You may also opt out of non-essential marketing communications.
Account holders can update certain details in the dashboard. Other requests may be submitted through our contact page. We may need to verify identity and authority before acting. Where Waery processes data solely for a Customer, we may forward the request to that Customer or ask you to contact them directly.
You may raise a grievance or complaint with Waery and, where applicable, with the competent data protection or consumer authority.
12. International Data Transfers
Waery, Meta and service providers may process information in countries other than the country where it was collected. Where required, we use contractual, organisational or legal safeguards intended to protect transferred information.
13. Children’s Privacy
The Service is intended for businesses and is not directed to children under 18. We do not knowingly permit minors to create business accounts. If you believe a child has provided account information, contact us so we can investigate.
14. Changes to this Policy
We may update this Policy to reflect legal, technical or operational changes. The updated Policy will be posted with a revised effective date. Material changes may also be notified in the dashboard or through registered contact details.
15. Contact and Grievances
Privacy questions, data requests and grievances may be submitted through the Waery contact page. Include your name, registered email, organisation, relationship to the data and a clear description of the request. Do not send passwords, access tokens or full payment credentials.
