Privacy Policy
Last updated: 16 September 2026
This Privacy Policy explains how ReMessage (“we”, “us”), operating the service ReMessage at https://remessage.needup.in, collects, uses, shares and protects personal data. Our registered address is TODO: Street, City, State, PIN, India.
We are the data controller for the personal data described in this policy. If you have any question about this policy or wish to exercise your rights, contact us at remessage@gmail.com.
1. Who this policy covers
- Customers: businesses and their team members who create an account on ReMessage.
- End users: people who exchange WhatsApp messages with one of our customers through the platform.
- Visitors: people who browse our website.
For end-user data, our customers decide why and how the data is processed. In that relationship the customer is the data controller and we act as a data processor on their behalf.
2. Data we collect
Account data
- Name, email address and password (stored only as a secure hash).
- Workspace name, time zone, business hours and team member roles.
Data received from Meta (Platform Data)
- WhatsApp Business Account ID, phone number ID and display phone number.
- Access tokens issued for your WhatsApp Business Account, stored encrypted with AES-256-GCM.
- Message templates, their approval status, quality rating and messaging limits.
- The Meta user ID and basic public profile of the person who authorises the connection.
Conversation data
- Inbound and outbound WhatsApp messages, including text, images, video, audio, documents and interactive replies.
- Message metadata such as timestamps and delivery, read and failure statuses.
- Contact details stored by our customers: phone number, name, email, tags, custom fields and notes.
Technical data
- IP address, browser type and pages visited, used for security and to keep the service running.
- An essential session cookie that keeps you signed in. See our Cookie Policy.
We do not collect special categories of personal data, and we ask that customers do not send such data through the platform.
3. How we use data
- To provide the service: sending and receiving WhatsApp messages, running chatbot flows and delivering broadcasts.
- To authenticate users and secure accounts.
- To show analytics such as message volume, delivery rates and response times to the account owner.
- To provide customer support when you contact us.
- To meet legal obligations and enforce our Terms of Service.
We do not sell personal data. We do not use the content of customer conversations to train machine learning models, and we do not use Platform Data received from Meta for advertising.
4. Legal bases for processing
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract: processing needed to provide the service you signed up for.
- Legitimate interests: keeping the service secure, preventing abuse and improving reliability.
- Consent: where required, for example marketing messages that our customers send to their own contacts, for which the customer must obtain opt-in.
- Legal obligation: where we must retain or disclose data under applicable law.
5. Sharing and sub-processors
We share personal data only with the service providers below, who process it on our behalf under contractual confidentiality and security obligations:
- DigitalOcean, LLC (United States) — Cloud server hosting and database storage.
- Meta Platforms, Inc. — the WhatsApp Business Platform through which messages are delivered.
- AI providers (optional): if a customer enables the AI reply feature with their own API key, the relevant conversation text is sent to their chosen provider, such as Anthropic or OpenAI, to generate a suggested reply. This feature is off by default.
We may also disclose data where required by law. See our Government Requests Policy.
6. International transfers
Our servers and service providers may be located outside your country, including in the United States. Where personal data is transferred out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. Retention
- Conversation and contact data is kept while the account is active, so that customers keep their message history.
- When an account is deleted, we delete the associated data within 30 days, except where the law requires longer retention.
- Webhook event logs are automatically deleted after 14 days.
- Backups are rotated and overwritten within 35 days.
8. Security
- All traffic is encrypted in transit with HTTPS.
- WhatsApp access tokens and AI API keys are encrypted at rest using AES-256-GCM.
- Passwords are hashed with bcrypt and never stored in readable form.
- Incoming webhooks from Meta are verified with an HMAC-SHA256 signature.
- Each workspace is logically isolated so one customer can never read another customer's data.
- Access to production systems is limited to authorised personnel.
More detail is available on our Security page.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent at any time. You also have the right to complain to a supervisory authority, such as the Information Commissioner's Office in the United Kingdom.
To exercise a right, email remessage@gmail.com. We respond within 30 days. If you are an end user who messaged a business using ReMessage, please contact that business directly, since they control your data. You can also see our Data Deletion Instructions.
10. Children
The service is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. We will change the “last updated” date above and, for significant changes, notify account owners by email.
12. Contact
ReMessage
TODO: Street, City, State, PIN, India
Email: remessage@gmail.com
Phone: +91 00000 00000