Privacy Policy
Effective 27 July 2026 · Operated by Tirgiji Tech Solutions Private Limited
WabaCRM is a WhatsApp messaging and customer-relationship tool operated by Tirgiji Tech Solutions Private Limited (“we”, “us”). This policy explains what personal data the service handles, why, and what you can do about it. It covers wabacrm.com, the WabaCRM web application and the WabaCRM mobile apps.
Two different sets of people appear in this document, and the difference matters:
- Our customers — the businesses that hold a WabaCRM workspace, and the team members who sign in to it. For their data we are the controller.
- Our customers' contacts — the people those businesses message on WhatsApp. For their data we are a processor: the business decides who to contact and what to say, and we carry it out on their instructions.
If you received a WhatsApp message you did not want, the business that sent it is the right first point of contact. Replying STOP to that conversation opts you out immediately, and we honour it across every workspace that message came from. You can also write to us at support@wabacrm.com and we will pass the request on.
What we collect
Account and workspace data
- Name, email address, and optionally a phone number and profile picture.
- A password, stored only as a bcrypt hash — we cannot read it, and neither can anyone with access to our database.
- Workspace name, company name, time zone, locale and currency.
- Sign-in timestamps and IP address, kept so a workspace owner can spot access they do not recognise.
Contact data uploaded or captured by our customers
- First and last name, phone number in E.164 format, email address, company, job title.
- Notes, tags, pipeline status, lead source, and any custom fields the workspace defines.
- Consent state — whether the contact accepts broadcasts, and whether they have opted out.
WhatsApp message data
- The content of messages sent and received through the workspace's connected WhatsApp number, including text, media, and template messages.
- Delivery state and timestamps (sent, delivered, read, failed) and any error Meta returns.
- Raw webhook payloads from Meta, retained for 30 days so a delivery problem can be diagnosed, then discarded.
WhatsApp Business Account credentials
- WhatsApp Business Account ID, phone number ID, and the access token Meta issues when a customer connects their number.
- The two-step verification PIN set during number registration.
Access tokens and PINs are encrypted at rest and are never displayed back in the browser, returned by our API, or written to logs.
Mobile app device identifier
- A random identifier generated on your device the first time you sign in to the WabaCRM mobile app, and stored on that device.
It is not your phone's IMEI, advertising ID, or any identifier the device already had, and it is not used for advertising, profiling or tracking you across apps or websites. Its only purpose is to keep one sign-in per device: it lets us sign out a lost or stolen phone without ending your sessions everywhere else. It is deleted when you sign out.
Billing and support data
- Plan, contact allowance, invoices and payment status.
- Support tickets and their attachments.
We do not collect payment card details. Where a payment gateway is used it handles the card directly and we store only a reference and the outcome.
Why we process it
| Purpose | Legal basis |
|---|---|
| Running the service — delivering messages, storing conversations, showing the inbox | Performance of our contract with the customer |
| Processing contact data on a customer's behalf | The customer's instructions, under our terms; the customer is responsible for having a lawful basis to message their contacts |
| Billing and collecting payment | Performance of contract; legal obligation for tax records |
| Security, abuse prevention, diagnosing faults | Our legitimate interest in a service that works and is not abused |
| Service messages to workspace owners, by email and by WhatsApp to the number on the account — password resets, a welcome and help finishing setup, invoice and renewal notices, a note when the contact allowance fills up, ticket replies | Performance of contract. Onboarding help can be paused from the link in any such message or from workspace settings; billing notices cannot, because they concern money owed. |
| Offers and news about WabaCRM, by email or WhatsApp | Consent, given by ticking the box at registration or in workspace settings, withdrawable at any time from the same place or from the link in every such message. Nobody receives these without it. |
We do not sell personal data. We do not use message content or contact data to train machine learning models. We do not use it for advertising.
Who we share it with
These are the only third parties that receive personal data through normal operation:
| Recipient | What they receive | Why |
|---|---|---|
| Meta Platforms, Inc. | Message content, recipient phone numbers, template content | WhatsApp message delivery through the WhatsApp Business Cloud API. Meta's own handling is governed by their terms and privacy policy. |
| Contabo Asia Private Limited | All service data, as it sits on the servers | Running the application and its database, in India |
| Payment gateway, where enabled | Billing contact and amounts | Taking payment |
| Hostinger | Recipient address and message body of email we send to workspace owners | Sending password resets, ticket replies, billing notices, onboarding help and — with consent — offers |
We may also disclose data where the law requires it, or to establish or defend a legal claim. If we are ever compelled to hand over customer data, we will tell the affected customer unless we are legally prohibited from doing so.
Where it is stored
Service data is stored on servers in India, operated on our behalf by Contabo Asia Private Limited. Message delivery necessarily involves Meta's infrastructure, which operates globally. Where data leaves India we rely on the transfer mechanisms available to us, including standard contractual clauses.
How long we keep it
- Contacts and conversations — for as long as the workspace exists. Deleting a contact removes it from the workspace immediately; the underlying record is retained briefly so that chat history is not orphaned, then purged.
- Raw webhook payloads — 30 days.
- Sign-up details before the address is confirmed — what is typed on the sign-up form is held for up to 7 days while we wait for the emailed code, then deleted if the sign-up is never completed.
- Closed accounts — deleted within 30 days of a workspace being closed, except where we must keep invoices for tax purposes.
- Invoices — as long as tax law in India requires.
Security
- All traffic is served over HTTPS.
- Passwords are hashed with bcrypt; WhatsApp access tokens and two-step PINs are encrypted at rest.
- Every workspace's data is isolated at the query layer, so one customer's records cannot be read from another's session.
- Access within a workspace is governed by roles, so an agent sees only the conversations assigned to them unless granted wider access.
- Inbound WhatsApp webhooks are verified by signature before being processed.
No system is perfectly secure. If we discover a breach affecting personal data we will notify affected customers and the relevant authority as the law requires.
Your rights
Depending on where you live — including under the Digital Personal Data Protection Act in India and the GDPR in the EU and UK — you may have the right to access your data, correct it, delete it, obtain a copy in a portable format, object to processing, or withdraw consent.
Workspace owners can exercise most of these directly in the application: contacts and conversations can be exported and deleted, and a workspace can be closed. For anything else, or if you are a contact rather than a customer, write to support@wabacrm.com. We respond within 30 days.
Full instructions for deleting your data, including the route for people who never held an account, are on the data deletion page.
Children
WabaCRM is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child's data has reached us, tell us and we will remove it.
Cookies
We use a session cookie to keep you signed in and a CSRF token cookie to protect forms against cross-site request forgery. Both are strictly necessary for the service to work.
On the public marketing pages only — never inside the product — we use the Meta Pixel,
which sets two first-party cookies (_fbp and, after a click on one of our
ads, _fbc) so that we can tell which advertising brought a customer to us.
These are not set on any page behind a login, and message content and contact data are
never sent to Meta for advertising.
Changes
We will post any change to this policy on this page and update the effective date. If a change materially affects how we handle personal data, we will tell workspace owners by email before it takes effect.
Contact
Tirgiji Tech Solutions Private Limited
Plot No. 3, Ambedkar Chauraha, Takrohai, Indira Nagar, Lucknow, Uttar Pradesh 226016, India
support@wabacrm.com
WhatsApp is a trademark of Meta Platforms, Inc. WabaCRM is an independent product and is not endorsed by or affiliated with Meta.
Questions about this document? Email support@wabacrm.com.