Privacy Policy

Effective Date: April 25, 2026

🔒

We do NOT sell your data

🔐

API tokens encrypted at rest

Meta Platform Policy compliant

1. Overview

This Privacy Policy describes how BotAsk.in ("we", "us", or "our") collects, uses, stores, and protects information when you use our WhatsApp Business Automation platform ("Service").

We are committed to transparency. This policy is designed to help you understand exactly what data we handle, why we handle it, and how we protect it — including specific disclosures required for Meta Business Verification.

By using the Service, you agree to the collection and use of information in accordance with this policy.

2. Data We Collect

A. Account & Business Data

  • Business name, owner name, email address, mobile number
  • Business domain and GSTIN (for billing purposes)
  • Subscription plan and payment history (payment details processed by our payment gateway — we do not store card numbers)

B. WhatsApp Business Account Data (via Meta API)

  • WhatsApp Business Account ID (WABA ID)
  • Phone Number ID and display phone number
  • Meta-verified business name and quality rating
  • Message templates (names, content, approval status)
  • Meta API access token (stored encrypted — see Section 4)

C. Customer Conversation Data

  • Customer WhatsApp phone numbers and display names
  • Inbound and outbound message content and timestamps
  • Message delivery and read status
  • Customer opt-out preferences
  • AI-extracted task data (customer requests, follow-up items)

D. Usage & Technical Data

  • System logs (API calls, errors, webhook events) — retained 30 days
  • Campaign analytics (sent, delivered, read, failed counts)
  • Session tokens (stored as encrypted, HTTP-only cookies)
  • IP address (for security and fraud prevention only)

3. WhatsApp Data Handling

📋 Meta Business Verification Disclosure

This section specifically addresses how we handle data obtained via the WhatsApp Business API, as required by Meta's Platform Terms.

Data Source: We receive WhatsApp message data via Meta's official Webhooks API. This data flows from Meta's servers to our platform in real-time when your customers message your WhatsApp Business number.

Message Storage: Inbound and outbound message content is stored in a dedicated, isolated MongoDB database for each client (tenant-separated architecture). Messages are not stored in shared databases across clients.

Purpose of Processing: WhatsApp message data is processed exclusively to:

  • Display conversations in your real-time inbox
  • Enable AI-powered automated response generation
  • Power CRM features (contact management, tags)
  • Extract action items and tasks from conversations
  • Generate campaign analytics

No Training on Customer Data: Customer WhatsApp messages are never used to train AI models by BotAsk.in. When automation is enabled, message context is forwarded to your configured workflow automation (N8N) to generate replies based on your system prompt and knowledge base — we do not use your messages to train third-party models.

End-to-End Encryption: WhatsApp's end-to-end encryption applies at the consumer messaging layer. The WhatsApp Business API (Cloud API) provides message content to platform operators (us) in accordance with Meta's platform terms. This is a standard, Meta-approved data flow.

Customer Opt-Outs: We permanently record and honor all customer opt-out requests. Opted-out contacts are blocked from receiving further automated messages at the platform level and cannot be overridden by operators.

4. Meta API Tokens & Encryption

// Token Security Implementation

Storage: MongoDB (tenant-isolated database)

Encryption: AES-256-GCM symmetric encryption

Key Source: TOKEN_ENCRYPTION_KEY environment variable

Key Storage: Render Secret Manager (never in codebase)

Transmission: HTTPS only (TLS 1.2+)

In Memory: Decrypted only at API call time

What is the Meta API Token? When you connect your WhatsApp Business Account, Meta issues a long-lived access token that allows our platform to send and receive messages on your behalf. This token is equivalent to a password — we treat it with the highest level of security.

Encryption at Rest: Your Meta API access token is never stored in plain text. Before being saved to the database, it is encrypted using AES-256-GCM (the same standard used by banks and government systems). The encryption key is stored separately as an environment variable — not in the database or source code.

Access Control: Decrypted tokens are only loaded into memory at the moment an API call to Meta must be made (sending a message, syncing templates, etc.). They are immediately discarded from memory after use.

No Token Logging: API tokens are explicitly excluded from all logging systems. They will never appear in server logs, error reports, or analytics.

Token Revocation: Upon account deletion or disconnection of the Meta account, the encrypted token is permanently deleted from our database within 24 hours.

5. How We Use Your Data

We use collected data strictly to:

  • Provide the Service: Process WhatsApp messages, generate AI responses, manage campaigns and CRM
  • Account Management: User authentication, session management, and security
  • Communication: Sending service-critical emails (account alerts, billing, security notifications)
  • Service Improvement: Analyzing aggregated, anonymized usage patterns to improve platform performance
  • Legal Compliance: Maintaining records as required by applicable laws and responding to lawful requests
  • Security & Fraud Prevention: Detecting and preventing unauthorized access or policy violations

We do not use your data for advertising, cross-client analytics, or any purpose beyond delivering the Service to you.

6. We Do Not Sell Your Data

🚫 We do not sell, rent, trade, or monetize your data.

BotAsk.in does not sell personal data, business data, or customer data to any third party, data broker, advertiser, or analytics company. Our revenue comes solely from subscription fees paid by you for use of our platform. Your data is not our product.

This commitment extends to all data types: your business information, your customers' WhatsApp phone numbers and messages, your campaign performance data, and your Meta API credentials.

7. Data Sharing & Sub-processors

We share data only with the following categories of trusted sub-processors, and only to the extent necessary to operate the Service:

Meta Platforms, Inc.

USA

WhatsApp Cloud API — message sending/receiving, template management

N8N (self-hosted / your instance)

As configured by operator

Workflow automation — inbound message context for AI replies, tasks, and integrations you configure

MongoDB Atlas

India / Singapore

Database hosting — all data encrypted at rest (AES-256)

Render.com

USA

Application hosting & secret management

Redis / BullMQ

Self-hosted

Campaign job queue processing (no message content stored)

We also share data when required by law (court orders, government requests) — in such cases, we will notify you unless legally prohibited from doing so.

8. Data Retention

Data TypeRetention Period
Account & billing dataDuration of account + 7 years (tax compliance)
WhatsApp message history30 days rolling window
System & API logs30 days rolling window
Campaign records & analytics12 months from campaign date
Customer contacts (CRM)Until manually deleted or account closure
Meta API access tokensUntil Meta account disconnected or account closed
Session cookies30 days (auto-expired)

Upon account deletion, all data is permanently purged from our systems within 30 days, except where retention is required by law.

9. Security Measures

We implement industry-standard security measures to protect your data:

  • Encryption at Rest: All sensitive fields (API tokens, passwords) are encrypted using AES-256-GCM
  • Encryption in Transit: All data transmitted over HTTPS (TLS 1.2+). HTTP requests are automatically redirected to HTTPS
  • Authentication: Passwords are hashed using bcrypt (cost factor 12). Session tokens are signed and stored in HTTP-only, Secure, SameSite=Strict cookies
  • Tenant Isolation: Each client's data is stored in a separate database. Cross-tenant data access is architecturally impossible
  • Webhook Verification: All incoming Meta webhooks are verified using HMAC-SHA256 signature validation before processing
  • Access Control: Internal staff access to production data requires multi-factor authentication and is logged for audit purposes
  • Dependency Security: Regular dependency audits and security patches

Despite these measures, no system is 100% secure. In the event of a data breach affecting your data, we will notify you within 72 hours as required by applicable law.

10. Your Data Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of all personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your account and all associated data (subject to legal retention requirements)
  • Portability: Export your customer contacts, campaign history, and message logs in machine-readable format (JSON/CSV)
  • Restriction: Request restriction of processing in certain circumstances
  • Objection: Object to processing of your data for specific purposes

To exercise any of these rights, contact privacy@botask.in. We will respond within 30 days. Identity verification may be required before processing certain requests.

For customer data (your WhatsApp contacts), you — as the data controller — are responsible for honoring their data rights. Our platform provides data export and deletion tools to help you comply.

11. Cookies & Tracking

We use only the following cookies on our platform:

  • Session Cookie: A single, HTTP-only session cookie (named botask_session) used to authenticate your login. This cookie is essential for the Service to function and cannot be disabled. It expires after 30 days of inactivity.

We do not use advertising cookies, third-party tracking pixels, Google Analytics, Facebook Pixel, or any cross-site tracking technology on our authenticated platform pages.

Our public landing page (https://botask.in) may include basic anonymous analytics to measure page performance. No personal data is collected in this process.

12. Children's Privacy

The BotAsk.in platform is designed for business use only and is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@botask.in.

13. Meta Platform Policy Compliance

📋 Required Disclosure for Meta Business Verification

The following disclosures are made in compliance with Meta's Platform Terms and WhatsApp Business Policy requirements for verified technology partners.

Platform Relationship: BotAsk.in is an independent technology provider that integrates with Meta's WhatsApp Business Cloud API. We are not affiliated with, endorsed by, or a subsidiary of Meta Platforms, Inc.

Data Use Limitation: All data received through Meta's APIs (WhatsApp messages, WABA information, phone number data) is used solely to provide the messaging automation service. This data is not used for:

  • Advertising or ad targeting
  • Training machine learning models (beyond real-time inference)
  • Creating consumer profiles for sale
  • Any purpose beyond those disclosed in this Privacy Policy

User Consent: We require all platform users to confirm they have obtained proper WhatsApp opt-in consent from their message recipients before using our campaign and broadcast features.

Webhook Security: All Meta webhook payloads are verified using HMAC-SHA256 with the Meta App Secret before any data is processed. Unverified payloads are rejected with HTTP 403.

Incident Response: In the event of a security incident involving Meta API data, we will notify Meta and affected clients within 24 hours of discovery.

14. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes (changes to how we collect, use, or share data), we will:

  • Send an email notification to all registered users
  • Display a prominent banner in the portal for 14 days
  • Update the "Effective Date" at the top of this page

The current version of this Privacy Policy is always available at https://botask.in/privacy.

15. Contact Us

For privacy-related questions, data requests, or concerns, please contact:

BotAsk.in — Privacy Office

Email: privacy@botask.in

Website: https://botask.in

Response Time: Within 30 days for data requests; within 72 hours for security incidents