We are dedicated to safeguarding developer credentials, organization structures, and message flows. Read below to understand how we secure and transiently process your data.

This Privacy Policy outlines how Waplix ('we', 'our', 'us', or 'the Platform') collects, utilizes, discloses, processes, and protects your information when you access or interact with our website, developer dashboards, instance node servers, RESTful APIs, and collaborative team communication utilities (collectively, the 'Services').
Waplix acts as a Data Controller concerning the personal data collected from our direct customers—specifically, developers, small businesses, agencies, and billing representatives who register accounts and select subscription plans. In this capacity, we collect and manage account credentials, profile details, payment telemetry, and technical logs related to dashboard usage.
Waplix acts as a Data Processor concerning the customer contact data, phone number lists, and message body payloads routed through our virtual instance nodes on behalf of our customers. Under these circumstances, Waplix processes data strictly in accordance with client API payloads, webhook relays, and standard device sync frameworks. It is the sole legal responsibility of our customers to secure proper opt-in consent and provide clear privacy disclosures to their end-users before initiating automated notifications or team-assigned chat sessions.
We collect various categories of information depending on how you interact with our services and which dashboard configurations you deploy. Below is a detailed breakdown of the data types involved:
Account & Registration Data: When you sign up for Waplix, we collect your name, email address, password hashes, organization name, developer configuration preferences, and dashboard settings. This information is required to establish your user session and manage access controls.
Instance Sync & Device Metadata: To connect your phone number to Waplix, you scan a secure QR code which establishes a virtual device pairing link (reproducing a browser-session connection). We collect and store device metadata, including paired phone numbers, operating system versions, connection status flags (connected/disconnected), and heartbeat timestamps. We do NOT store your physical smartphone storage logs, contact databases, or files unless they are explicitly selected to be sent via the API.
Message Routing Data & Logs: When you trigger REST API endpoints or receive incoming customer chats, we process incoming and outgoing message metadata. This includes message IDs, status metrics (queued, sent, delivered, read), recipient phone numbers, media mime-types, and delivery timestamps. Message bodies and media content are processed transitively as outlined in Section 4 of this policy.
Billing & Financial Telemetry: We collect cardholder details, billing addresses, tax identifiers, and transaction history profiles. All card payments are processed securely through certified, PCI-DSS compliant third-party payment gateways (such as Stripe). Waplix does not store raw credit card numbers on our internal databases.
Technical Analytics & Telemetry: We automatically collect device details, browser types, Internet Protocol (IP) addresses, referral sources, landing page clicks, page views, and API latency metrics. We use this telemetry to monitor server utilization, prevent denial-of-service abuses, and optimize dashboard responsiveness.
We process your data strictly under legal bases outlined by GDPR, CCPA, and global privacy standards. Waplix uses the information we collect for the following specific purposes:
Provisioning Services & Node Isolation: To initialize your virtual device connection nodes, generate your unique API authentication tokens, and route inbound and outbound messages. This processing is essential to fulfill the performance of our contract with you.
Queue Sequencing & Heartbeat Monitoring: To manage message transmission staggering queues, prevent account blocks through human-like rate limiting, automatically reconnect dropped device pairings, and update dashboard telemetry graphs in real-time.
Billing and Account Management: To process monthly or annual subscription fees, verify transaction validity, handle reseller partner commission calculations, issue invoice PDF documents, and update billing history metrics.
Customer Support & System Alerts: To respond to your developer inquiries, provide technical troubleshooting logs, and dispatch automated emails regarding instance disconnections, system maintenance cycles, or security updates.
Security Monitoring & Compliance Audits: To detect fraudulent signups, prevent platform abuse (such as unsolicited spam broadcasts or scanning unauthorized numbers), and verify API signature header hashes to secure webhooks endpoints.
Analytics and System Optimizations: To study aggregate platform latency rates, identify bottleneck database queries, optimize browser dashboard loading speeds, and design new collaborative inbox tools.
Unlike traditional CRM providers that compile massive database archives of all historical customer chat content, Waplix employs a secure, transient processing architecture designed to limit data exposure risk.
Volatile Queue Memory: When you send an API request containing message body text, media urls, or interactive poll options, the payload is parsed and stored temporarily in our active memory queue. Once our server node establishes connection with the device pairing sync framework and dispatches the message to WhatsApp servers, the message body is deleted from Waplix's memory.
No Persistent Chat Storage: We do NOT persist customer message text bodies, attachments, PDFs, or media files on Waplix database servers once they have been successfully dispatched. We only store message metadata (sender/recipient numbers, status, timestamps, and log IDs) for dashboard tracking purposes.
Incoming Webhook Relays: Incoming customer replies trigger immediate webhook relays to your designated server URL. The message body payload is Relayed in real-time. If your server is offline, Waplix queues the webhook event for up to 24 hours, attempting retries at staggered intervals, before purging the content from our temporary webhook queue. We highly recommend configuring secure SSL endpoints with signature verification headers on your receiver servers to prevent packet interceptions.
Shared Inbox Cache: If you use the Waplix Shared Team Inbox dashboard, we maintain a temporary chat interface cache of recent active conversations (typically stored for up to 30 days) to display scrollable threads to your agents. You can purge this cache manually anytime through the settings console.
Waplix employs enterprise-grade administrative, technical, and physical security measures to safeguard your credentials and instance connections from unauthorized access, modification, or exposure.
Data Residency: Waplix hosting infrastructure, database clusters, and virtual node servers are located in secure data centers within the European Union (AWS / DigitalOcean facilities). These data centers maintain certified SOC 2, ISO 27001, and physical security credentials.
Encryption Standards: All communication between your servers and our REST APIs, or between your browser and our dashboard, is encrypted in transit using Transport Layer Security (TLS 1.3). Database contents, including account hashes, session keys, and billing references, are encrypted at rest using AES-256 protocols.
Access Controls: Internal access to database clusters is strictly limited to authorized engineering staff who require access to maintain system operations. All administrator access requires multi-factor authentication (MFA) and is audited through secure access logs.
Retention Policies: We retain account profiles, agency configurations, and billing logs for as long as your account remains active. Operational logs, API request histories, and webhook dispatch lists are automatically pruned and deleted after 30 days. Shared Inbox message caches are stored for 30 days before automatic cleanup, unless manually purged earlier by the workspace supervisor.
Waplix partners with a limited number of trusted third-party service providers (Subprocessors) to assist in platform hosting, payment gateway security, and system notification relays. These providers process data under strict Data Processing Agreements (DPAs) and are forbidden from using your data for other purposes:
Amazon Web Services (AWS) & DigitalOcean LLC: Provide cloud hosting, database clustering, virtual server node environments, and secure network infrastructure in the EU.
Stripe Inc.: Manages payment gateway transactions, subscription renewals, invoice processing, and financial security telemetry. Waplix does not capture or store raw credit card numbers.
SendGrid & Postmark: Manage outbound system email relays, dashboard password reset alerts, and developer registration confirmations.
Google Analytics: Collects aggregate website traffic telemetry and user interaction click-data on our landing pages. Google Analytics does not have access to your developer dashboard data, API keys, or WhatsApp messaging payloads.
Waplix respects your data privacy rights and provides comprehensive tools to access, modify, or erase your information under the European General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).
Right to Access: You have the right to request a complete export of the personal data Waplix holds about your account. You can request this export directly from the dashboard settings page.
Right to Rectification: You can update, correct, or change your account details, billing profiles, organization names, and linked phone numbers at any time through the console.
Right to Erasure ('Right to be Forgotten'): You can request the permanent deletion of your Waplix account and all associated dashboard logs. Deleting your account will immediately terminate your subscription plans, de-allocate your hosting nodes, and purge your history records from our servers.
Right to Portability: You can download your transaction histories and API log stats in standardized formats (CSV / JSON) for transfer to other platforms.
Data Deletion Requests: To submit a formal data erasure request, please email our compliance officer at privacy@waplix.io. We will verify your identity before processing deletion requests and complete the removal within 30 days.
Waplix may update this Privacy Policy periodically to reflect shifts in WhatsApp policies, changes in server architecture, or new compliance directives. We will notify active users of material changes via email or dashboard alerts prior to the update taking effect.
If you have legal compliance inquiries, questions regarding data transfers, or require a signed copy of our Data Processing Addendum (DPA), please reach out to our privacy team at:
Waplix Compliance Operations: C-Block, Suite 305, Tech Hub Towers, Berlin, Germany. Email: privacy@waplix.io.
Sign up for Waplix today and connect your physical or virtual instance in under 30 seconds. Scale customer outreach, run developer API triggers, and automate alerts effortlessly.