Privacy Policy

Last updated: 8 August 2026 · Version 2026-08-08

This Privacy Policy explains what data WhatsTeam handles, in which role, and what happens to it. It is written for a Hong Kong-first service and follows the framing of the Personal Data (Privacy) Ordinance (“PDPO”); for customers elsewhere, the equivalent controller/processor concepts apply.

1. Two roles: your company’s data vs. account data

WhatsTeam handles data in two distinct roles:

  • Customer Data — WhatsApp conversations, contact lists, media files and CRM records that a customer company connects or uploads. The customer company is the data user / controller of this data. WhatsTeam is its processor: we store and process it only to provide the service, on the company’s instructions.
  • Account Data — the data we need to run WhatsTeam itself: names, work emails, hashed passwords, workspace settings, and service logs. For this data WhatsTeam is the data user / controller.

If you are a customer of one of our customers (for example, you messaged a company that uses WhatsTeam), that company decides how your data is used — direct your requests to them, and we will assist them in responding.

2. Customer Data we process

When a company connects a WhatsApp number, we process on its behalf:

  • messages (text, images, voice notes, documents, and other media) sent and received on connected numbers, including message metadata such as timestamps and phone numbers;
  • contact names and phone numbers, including CRM names the company assigns;
  • deal and pipeline records the company creates or imports.

Messages are synced continuously while a number is connected so the workspace stays complete and searchable.

3. Account Data we collect

  • name and work email of each workspace user;
  • password (stored only as a salted hash — we cannot read it);
  • company name, logo and workspace settings;
  • technical logs needed to run and secure the service (for example authentication events and error logs).

The public marketing pages collect only anonymous, aggregate counters (page views and button clicks) with no cookies, no identifiers and no IP address storage.

4. What we use data for

We use data only to provide, secure and improve the service: syncing and backing up conversations, powering search and analytics, drafting AI-assisted replies, providing support, and billing.

We do not sell data. We do not use Customer Data for advertising. We do not use your conversations to train our own AI models.

5. AI processing

AI features (reply drafting, style analysis) send relevant message content to third-party AI model providers through our routing provider, OpenRouter, Inc., strictly to generate the requested output. Providers used this way are bound by their API terms; we route to providers whose terms do not permit training on API data, and we do not send more context than the feature needs.

A workspace can ask us to disable AI features entirely, or for specific connected numbers.

6. Subprocessors and hosting

We use a small number of service providers to run WhatsTeam:

  • Replit, Inc. — application hosting and managed PostgreSQL database (data encrypted in transit and at rest);
  • OpenRouter, Inc. — AI model routing for the AI features described above;
  • Stripe, Inc. — payment processing, once paid plans launch (Stripe receives billing details; we never store full card numbers).

We will update this list when providers change. Hosting is currently in the United States; by using the service you consent to your data being transferred to and processed in that location.

7. Security

  • all traffic is encrypted in transit (TLS) and stored data is encrypted at rest;
  • passwords are stored as salted hashes; session cookies are HttpOnly;
  • access to Customer Data inside a workspace is permission-scoped: admins control which team members see which numbers;
  • personal (non-team) accounts connected through our personal bridge have message bodies additionally encrypted at the application layer.

No system is perfectly secure. If we become aware of a breach affecting your data we will notify affected customers without undue delay.

8. Retention, export and deletion

Customer Data is retained while the workspace subscription is active, so the company keeps its full history. Companies can export their data at any time by contacting us.

When a workspace is deleted or a subscription ends, we delete its Customer Data within 60 days, except where law requires longer retention. Anonymous aggregate metrics are kept for up to one year.

Account Data is deleted when the account is deleted, except minimal records we must keep for legal or accounting reasons.

9. Cookies

We use only essential cookies: a session cookie to keep you signed in. No advertising cookies, no third-party trackers, no analytics cookies — which is why there is no cookie banner.

10. Your rights

Under the PDPO you may request access to and correction of personal data we hold about you as a data user. Where GDPR or similar laws apply to you, you may also have rights to erasure, restriction and portability.

Send requests to hello@whatsteam.app. If your data is inside a customer’s workspace (you are their customer or employee), we will refer the request to that company and assist them in responding.

11. Changes to this policy

We will post updates here and, for material changes, notify workspace admins inside the service or by email. The date at the top identifies the current version.

12. Contact

Privacy questions and requests: hello@whatsteam.app