Privacy Policy
Effective 27 July 2026 · Operated by Tirgiji Tech Solutions Private Limited
WabaCRM is a WhatsApp messaging and customer-relationship tool operated by Tirgiji Tech Solutions Private Limited (“we”, “us”). This policy explains what personal data the service handles, why, and what you can do about it. It covers wabacrm.com, the WabaCRM web application and the WabaCRM mobile apps.
Two different sets of people appear in this document, and the difference matters:
- Our customers — the businesses that hold a WabaCRM workspace, and the team members who sign in to it. For their data we are the controller.
- Our customers' contacts — the people those businesses message on WhatsApp. For their data we are a processor: the business decides who to contact and what to say, and we carry it out on their instructions.
If you received a WhatsApp message you did not want, the business that sent it is the right first point of contact. Replying STOP to that conversation opts you out immediately, and we honour it across every workspace that message came from. You can also write to us at support@wabacrm.com and we will pass the request on.
What we collect
Account and workspace data
- Name, email address, and optionally a phone number and profile picture.
- A password, stored only as a bcrypt hash — we cannot read it, and neither can anyone with access to our database.
- Workspace name, company name, time zone, locale and currency.
- Sign-in timestamps and IP address, kept so a workspace owner can spot access they do not recognise.
Contact data uploaded or captured by our customers
- First and last name, phone number in E.164 format, email address, company, job title.
- Notes, tags, pipeline status, lead source, and any custom fields the workspace defines.
- Consent state — whether the contact accepts broadcasts, and whether they have opted out.
WhatsApp message data
- The content of messages sent and received through the workspace's connected WhatsApp number, including text, media, and template messages.
- Delivery state and timestamps (sent, delivered, read, failed) and any error Meta returns.
- Raw webhook payloads from Meta, retained for 30 days so a delivery problem can be diagnosed, then discarded.
WhatsApp Business Account credentials
- WhatsApp Business Account ID, phone number ID, and the access token Meta issues when a customer connects their number.
- The two-step verification PIN set during number registration.
Access tokens and PINs are encrypted at rest and are never displayed back in the browser, returned by our API, or written to logs.
Billing and support data
- Plan, contact allowance, invoices and payment status.
- Support tickets and their attachments.
We do not collect payment card details. Where a payment gateway is used it handles the card directly and we store only a reference and the outcome.
Why we process it
| Purpose | Legal basis |
|---|---|
| Running the service — delivering messages, storing conversations, showing the inbox | Performance of our contract with the customer |
| Processing contact data on a customer's behalf | The customer's instructions, under our terms; the customer is responsible for having a lawful basis to message their contacts |
| Billing and collecting payment | Performance of contract; legal obligation for tax records |
| Security, abuse prevention, diagnosing faults | Our legitimate interest in a service that works and is not abused |
| Service email — password resets, billing notices, ticket replies | Performance of contract |
We do not sell personal data. We do not use message content or contact data to train machine learning models. We do not use it for advertising.
Who we share it with
These are the only third parties that receive personal data through normal operation:
| Recipient | What they receive | Why |
|---|---|---|
| Meta Platforms, Inc. | Message content, recipient phone numbers, template content | WhatsApp message delivery through the WhatsApp Business Cloud API. Meta's own handling is governed by their terms and privacy policy. |
| Contabo Asia Private Limited | All service data, as it sits on the servers | Running the application and its database, in India |
| Payment gateway, where enabled | Billing contact and amounts | Taking payment |
| Hostinger | Recipient address and message body of service email | Sending password resets, ticket replies and billing notices |
We may also disclose data where the law requires it, or to establish or defend a legal claim. If we are ever compelled to hand over customer data, we will tell the affected customer unless we are legally prohibited from doing so.
Where it is stored
Service data is stored on servers in India, operated on our behalf by Contabo Asia Private Limited. Message delivery necessarily involves Meta's infrastructure, which operates globally. Where data leaves India we rely on the transfer mechanisms available to us, including standard contractual clauses.
How long we keep it
- Contacts and conversations — for as long as the workspace exists. Deleting a contact removes it from the workspace immediately; the underlying record is retained briefly so that chat history is not orphaned, then purged.
- Raw webhook payloads — 30 days.
- Closed accounts — deleted within 30 days of a workspace being closed, except where we must keep invoices for tax purposes.
- Invoices — as long as tax law in India requires.
Security
- All traffic is served over HTTPS.
- Passwords are hashed with bcrypt; WhatsApp access tokens and two-step PINs are encrypted at rest.
- Every workspace's data is isolated at the query layer, so one customer's records cannot be read from another's session.
- Access within a workspace is governed by roles, so an agent sees only the conversations assigned to them unless granted wider access.
- Inbound WhatsApp webhooks are verified by signature before being processed.
No system is perfectly secure. If we discover a breach affecting personal data we will notify affected customers and the relevant authority as the law requires.
Your rights
Depending on where you live — including under the Digital Personal Data Protection Act in India and the GDPR in the EU and UK — you may have the right to access your data, correct it, delete it, obtain a copy in a portable format, object to processing, or withdraw consent.
Workspace owners can exercise most of these directly in the application: contacts and conversations can be exported and deleted, and a workspace can be closed. For anything else, or if you are a contact rather than a customer, write to support@wabacrm.com. We respond within 30 days.
Full instructions for deleting your data, including the route for people who never held an account, are on the data deletion page.
Children
WabaCRM is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us, tell us and we will remove it.
Cookies
We use a session cookie to keep you signed in and a CSRF token cookie to protect forms against cross-site request forgery. Both are strictly necessary for the service to work. We do not use advertising or cross-site tracking cookies.
Changes
We will post any change to this policy on this page and update the effective date. If a change materially affects how we handle personal data, we will tell workspace owners by email before it takes effect.
Contact
Tirgiji Tech Solutions Private Limited
Plot No. 3, Ambedkar Chauraha, Takrohai, Indira Nagar, Lucknow, Uttar Pradesh 226016, India
support@wabacrm.com
WhatsApp is a trademark of Meta Platforms, Inc. WabaCRM is an independent product and is not endorsed by or affiliated with Meta.
Questions about this document? Email support@wabacrm.com.