Privacy Policy
Version: 2026-08-25 · Last updated: 25 August 2026This Privacy Policy explains how Chatson (“the Platform”, “we”, or “us”) collects, uses, stores, and protects personal data you provide when registering for and using customer-support, conversation-management, and WhatsApp integration services.
1. Data we collect
- Account data: organisation / brand name, admin email, login and security records.
- Support data: visitor messages, attachments, contact details, assignment and conversation status.
- Integration data: WABA ID, Phone Number ID, display name, webhook events and message status. WhatsApp API tokens are encrypted and stored only on the server and are never returned to the browser.
- Technical data: IP address, browser, device, error and audit logs.
2. Purpose of use
We use data to provide login, the support inbox, human and AI-assisted replies, WhatsApp Cloud API send/receive, notifications, security, troubleshooting, auditing, and service improvement.
3. Third-party services
If you connect WhatsApp Business, data is sent to Meta / the WhatsApp Business Platform under your authorisation to complete account linking, messaging, webhooks, and status sync. Meta’s processing of related data is also subject to its privacy policy and commercial terms.
4. Retention and deletion
We retain data only for as long as needed to provide the service, perform contracts, handle disputes, comply with law, or maintain security. Account admins may export or request cleanup of conversation data via platform features, except where law or audit requirements require retention.
5. Security
We apply access controls, server-side token encryption, webhook signature verification, event deduplication, and auditing. You must not share access tokens, app secrets, or other keys in front-end code, public issues, screenshots, or messages.
6. Your rights
Where applicable law allows, you may request access, correction, export, restriction of processing, or deletion of personal data, and may withdraw unfinished integration authorisations. We may need to verify your account identity when you make a request.
7. Policy updates and contact
We may update this policy due to service, legal, or Meta platform requirements. Registration records the document version you accepted. For privacy enquiries, contact the service provider using your registered admin email.
This document is the platform working version. Before production launch, have your company counsel review it against the actual company name, operating regions, retention periods, and contact details.