Privacy Policy

Last updated: June 2025

MetaBSP ("we," "us," or "our") is a WhatsApp Business Solution Provider authorized by Meta Platforms, Inc. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform, including our website and API services.


1. Information We Collect

We collect several categories of information to provide and improve our services:

Business Information
  • Business name, legal entity type, and registration details

  • Business phone numbers registered with WhatsApp Business

  • Business verification documents submitted to Meta

  • Tax identification numbers (where required)

  • Billing information and payment method details

WhatsApp Data
  • WhatsApp Business Account (WABA) ID and associated phone number IDs

  • Message templates submitted and their approval status

  • Message delivery receipts and read receipts

  • Webhook event payloads received from Meta

  • Message content you send through our API (temporarily cached)

  • Business profile information (name, description, website, address)

Contact and End-User Data
  • Phone numbers of contacts you message through our platform

  • Contact display names (if provided)

  • Opt-in and opt-out records for your messaging campaigns

  • Message history between your business and its customers

Technical Data
  • IP addresses and geolocation data

  • Browser type, version, and operating system

  • API request logs including endpoints accessed and response codes

  • Authentication tokens and session identifiers

  • Device identifiers for mobile access

2. How We Use WhatsApp Data

WhatsApp data processed through our platform is used strictly to provide the services you have subscribed to:

  • Facilitating the sending and receiving of WhatsApp messages on your behalf

  • Storing message templates and managing their submission to Meta for approval

  • Processing webhook events from Meta and routing them to your configured endpoints

  • Generating analytics and delivery reports for your messaging campaigns

  • Troubleshooting delivery failures and API errors

  • Maintaining audit logs for compliance and security purposes

We do not use message content for advertising purposes, and we do not sell WhatsApp message data to third parties. Access to message content is strictly limited to authorized personnel for support and debugging purposes, subject to access controls and audit logging.

3. How User Consent is Collected

As a WhatsApp Business Solution Provider, we require all businesses using our platform to comply with WhatsApp's Business Policy and Messaging Policy, which mandate that businesses obtain explicit opt-in consent from end users before messaging them.

Businesses using MetaBSP are responsible for:

  • Obtaining clear, affirmative consent from contacts before sending them WhatsApp messages

  • Clearly disclosing the nature and frequency of messages at the point of opt-in

  • Providing a simple mechanism for contacts to opt out at any time

  • Maintaining records of consent for audit purposes

  • Honoring opt-out requests promptly (within 24 hours)

MetaBSP provides tools to help businesses manage opt-in/opt-out records, but ultimate responsibility for consent compliance lies with the business using our platform.

4. Data Retention

We retain different categories of data for different periods based on business necessity and legal requirements:

  • Message content: 90 days from the date of transmission, then permanently deleted

  • Contact phone numbers and opt-in records: Retained indefinitely while your account is active, or until you request deletion

  • API request logs and webhook logs: 1 year from the date of the request

  • Account information and billing records: Duration of your account plus 7 years for tax compliance

  • Message delivery receipts: 1 year from transmission date

  • Template submission history: Duration of your account

  • Security and audit logs: 2 years

You may request early deletion of your data at any time. See Section 8 for details on how to request data deletion.

5. Data Encryption and Security

We implement industry-standard security measures to protect your data:

  • AES-256 encryption for all data at rest, including databases and file storage

  • TLS 1.3 for all data in transit between your systems, our platform, and Meta's APIs

  • Encrypted storage of API keys, access tokens, and webhook secrets

  • Database encryption at the disk level using AES-256

  • Encrypted backups stored in geographically separate locations

6. Data Sharing and Disclosure

We share your information only in the following circumstances:

  • With Meta Platforms, Inc. as required to operate the WhatsApp Business API

  • With your designated webhook endpoints as configured in your account

  • With payment processors for billing purposes (we do not store full card numbers)

  • With cloud infrastructure providers (AWS/GCP) who process data under our instructions

  • When required by law, court order, or government request

  • With your explicit consent for any other purpose

7. Your Rights – GDPR and CCPA

Depending on your jurisdiction, you may have the following rights regarding your personal data:

GDPR (EU/EEA Residents)
  • Right to access your personal data

  • Right to rectification of inaccurate data

  • Right to erasure ("right to be forgotten")

  • Right to restriction of processing

  • Right to data portability

  • Right to object to processing

  • Right to withdraw consent at any time

CCPA (California Residents)
  • Right to know what personal information is collected about you

  • Right to delete personal information

  • Right to opt-out of the sale of personal information (we do not sell personal information)

  • Right to non-discrimination for exercising your rights

To exercise these rights, contact us at privacy@meta.sanjusk.in or submit a request through our data deletion page.

8. How to Delete Your Data

You can request deletion of your data at any time by visiting our Data Deletion page. Upon receiving a valid deletion request, we will:

  • Permanently delete your account data within 30 days

  • Remove all message content and contact data

  • Revoke all API keys and access tokens

  • Send a confirmation email when deletion is complete

9. How Businesses Revoke Access

Businesses can revoke MetaBSP's access to their WhatsApp Business Account at any time by:

  • Navigating to Meta Business Suite → Business Settings → Connected Apps and removing MetaBSP

  • Visiting Facebook Settings → Business Integrations and removing the MetaBSP integration

  • Contacting our support team at support@meta.sanjusk.in to initiate immediate access revocation

  • Deleting your MetaBSP account through the Account Settings page

Upon revocation, we will cease processing any new WhatsApp data within 24 hours and will retain historical data per our retention schedule unless a deletion request is submitted.

10. Cookies

We use cookies and similar tracking technologies. For detailed information, please see our Cookie Policy.

11. Children's Privacy

Our platform is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal information from minors.

12. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by email and by posting the updated policy on this page with a revised "Last updated" date. Your continued use of our services after changes constitute acceptance of the updated policy.

13. Contact Us

For privacy-related inquiries, please contact our Data Protection Officer:

  • Email: privacy@meta.sanjusk.in

  • Subject line: Privacy Inquiry – [Your Name/Company]

  • Response time: Within 72 hours for routine inquiries, 30 days for formal GDPR/CCPA requests