Privacy Policy
Last updated: 18 March 2026
1. Introduction
Wadwin ("we", "us", or "our") operates a WhatsApp CRM platform for small and medium businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at wadwin.com (the "Service").
We are committed to complying with applicable data protection laws including the Hong Kong Personal Data (Privacy) Ordinance (PDPO), the EU General Data Protection Regulation (GDPR), and relevant data protection legislation in Singapore, Malaysia, and other jurisdictions where our customers operate.
2. Information We Collect
2.1 Account Information
When you register, we collect your name, email address, and authentication credentials via Clerk.
2.2 WhatsApp Business Data
To provide the Service, you connect your WhatsApp Business Account (WABA). We store your:
- WABA ID and Phone Number ID (Meta Business identifiers)
- Access tokens (encrypted at rest)
- Inbound and outbound WhatsApp message content
- Contact phone numbers and names from your conversations
2.3 Usage Data
We collect information about how you use the Service, including pages visited, features used, and message counts.
2.4 Payment Data
Credit card and payment information is processed by Stripe. We do not store full card numbers. We store transaction records (amount, date, credits purchased) for billing purposes.
3. How We Use Your Information
- To provide, operate, and maintain the Service
- To process your WhatsApp messages and display them in your inbox
- To process payments and manage your credit balance
- To send you service-related notifications (account alerts, billing)
- To improve and develop new features
- To comply with legal obligations
4. Data Sharing
We do not sell your personal data. We share data only with:
- Meta (Facebook): To send and receive WhatsApp messages via the WhatsApp Business API
- Supabase: Our database provider (data stored in their secure infrastructure)
- Clerk: Our authentication provider
- Stripe: Our payment processor
- Vercel: Our hosting provider
- Legal authorities: When required by law
5. Data Retention
We retain your data for as long as your account is active. Message data is retained for 12 months by default. You may request deletion of your data at any time by contacting us. Upon account termination, we delete your data within 30 days.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict processing of your data
- Data portability (receive your data in a machine-readable format)
- Withdraw consent at any time
To exercise these rights, contact us at privacy@wadwin.com.
7. Security
We implement industry-standard security measures including encryption in transit (TLS) and at rest, access controls, and regular security reviews. However, no method of transmission over the internet is 100% secure.
8. Cookies
We use essential cookies for authentication and session management. We do not use advertising or tracking cookies. You can control cookies through your browser settings.
9. Children's Privacy
The Service is not directed to children under 18. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by email or a prominent notice on the Service. Continued use after changes constitutes acceptance.
11. Contact Us
For privacy-related questions or to exercise your rights, contact us at: privacy@wadwin.com