Privacy policy
This policy explains what personal data the WA Signal service handles, why, and what happens to it. WA Signal is operated by Sellzzy Digital Commerce ("we", "us"), and is reachable at app.wasignal.io.
On this page
1. The two roles we play
WA Signal is used by businesses ("merchants") to talk to their own customers on WhatsApp. That means personal data reaches us in two very different ways, and our responsibilities differ for each.
| Whose data | Our role | What that means |
|---|---|---|
| The merchant and their team — the people who log in | Controller | We decide what account data we need to run the service, and we answer to those people directly. |
| The merchant's customers — people who message the merchant on WhatsApp | Processor | We hold and process that data only on the merchant's instructions. The merchant is responsible for having a lawful basis to message their customers and for their own privacy notice. |
If you messaged a business on WhatsApp and want your data removed, the business you contacted controls it. See Data deletion — we will help, but we act on the merchant's instruction.
2. What data we handle
Merchant account data
- Business name, default currency and account settings.
- For each team member: name, email address, role, account status, time of last sign-in.
- A one-way hash of the password (scrypt with a per-user salt). We never store the password itself and cannot recover it.
- Session records, stored only as a hash of the session token, with an expiry date.
Conversation data, on the merchant's behalf
- The customer's WhatsApp phone number and the profile name WhatsApp supplies.
- Message content in both directions — text, captions, media identifiers, and the raw message payload Meta delivers — along with delivery status and timestamps.
- Workflow information the merchant's team adds: conversation stage, assignment, internal notes, unread counts.
Ad attribution data
- Meta's Click-to-WhatsApp click identifier (
ctwa_clid), plus the ad identifier, ad headline, source URL and the time of the click, when Meta provides them with an incoming message.
Order data
- Order reference, customer phone number, amount, currency, line items and status — either entered by the merchant's team or sent to us by the merchant's own systems through our API.
Integration credentials
- The merchant's WhatsApp Business Account ID, phone number ID, access token, Meta app secret, Conversions API dataset ID and Conversions API token. Tokens and secrets are encrypted before they are written to the database.
Operational logs
- Server access logs, error messages, and a record of each event we queued for Meta including the response Meta gave us.
WA Signal does not use advertising cookies or third-party analytics or tracking pixels on this site. Signing in stores a session token in your browser's session storage so that you stay signed in; closing the tab clears it.
3. Why we handle it
- To provide the service — deliver incoming WhatsApp messages to the merchant's inbox, send their replies, and keep the conversation history they rely on.
- To report conversions to Meta — see section 4, which is the specific purpose of this product.
- To authenticate people and enforce the roles a merchant has assigned to their team.
- To keep the service working and secure — diagnose faults, retry failed deliveries, prevent abuse, and apply rate limits.
- To meet legal obligations where they apply to us.
We do not sell personal data. We do not use merchant or customer data to train machine learning models, and we do not use one merchant's data for the benefit of another.
4. What we send to Meta
This is the core of what WA Signal does, so we describe it precisely.
When a merchant marks a conversation as qualified, or confirms an order, we send a conversion event to Meta's Conversions API for Business Messaging, using the merchant's own dataset and their own access token. The event contains:
- The event name —
LeadorPurchase. - The time of the event and a stable event identifier used to prevent duplicates.
- The merchant's WhatsApp Business Account ID and the
ctwa_clidfrom the original ad click. - For a purchase, the order value, the currency and the order reference.
We apply the following limits, enforced in the software itself:
- Events are only sent for conversations that began from a Click-to-WhatsApp ad and therefore carry a
ctwa_clid. Organic conversations are recorded in the inbox but never reported. - Events are only sent within Meta's seven-day attribution window from the ad click. Later than that, the event is marked expired and discarded.
- We do not send message content, customer names, or customer phone numbers to the Conversions API.
Separately, sending and receiving WhatsApp messages necessarily involves Meta, because WhatsApp is Meta's platform. Meta's own terms and privacy policy govern that processing.
5. Who else can see it
We share personal data only with the following, and only as far as the service requires:
| Who | What for |
|---|---|
| Meta Platforms, Inc. | Delivering and receiving WhatsApp messages, and reporting conversion events to the merchant's dataset. |
| DigitalOcean | Hosting the servers and database that run the service. |
| The merchant's own systems | Where a merchant configures an outbound webhook, we send them their own events — new contacts, received messages, stage changes and confirmed orders — signed so they can verify the source. |
We may also disclose data where we are legally required to, or where it is necessary to establish or defend a legal claim. If our business is transferred, data may transfer with it, and we will say so before that takes effect.
6. How it is protected
- All traffic to the service uses HTTPS.
- WhatsApp access tokens, Meta app secrets and Conversions API tokens are encrypted with AES-256-GCM before being stored, using a key held outside the database.
- Passwords are stored as scrypt hashes with per-user salts, and are verified in constant time.
- Incoming webhooks from Meta are verified against the merchant's own app secret, so we can reject traffic that did not come from Meta.
- Every merchant's data is separated by account, and every request is checked against the signed-in person's account and role.
- Sign-in and sign-up are rate limited. Session tokens are stored as hashes and expire after 30 days.
- The database is backed up on a schedule.
No system is perfectly secure. If a breach affects your personal data, we will notify affected merchants without undue delay and describe what happened and what we are doing about it.
7. How long we keep it
| Data | Kept for |
|---|---|
| Conversations, contacts, orders and conversion events | As long as the merchant's account is open, unless they delete them sooner. |
| Team member accounts | Until removed by the merchant, or the account is closed. |
| Sessions | 30 days, or until sign-out. |
| Integration credentials | Until replaced or the account is closed. |
| Server logs | A rolling window, currently a few weeks. |
When a merchant account is deleted, everything belonging to it — team members, contacts, messages, orders and conversion events — is deleted from the live database together with it. Encrypted backups are retained on a rolling schedule and are overwritten in the ordinary course.
8. Your choices and rights
Depending on where you live, you may have the right to ask for a copy of your personal data, to have it corrected or deleted, to restrict or object to how it is used, and to complain to a data protection authority.
- If you are a merchant or team member, write to us at support@wasignal.io. You can also change your own name and password from within the app at any time.
- If you are a customer who messaged a business, contact that business first — they control your data. If you contact us, we will pass the request to them and support them in acting on it.
We will respond within 30 days. We may need to verify who you are before acting on a request. Full instructions are on the Data deletion page.
9. Where data is stored
Our servers and database are hosted with DigitalOcean. Because WhatsApp is operated by Meta, message data is necessarily processed by Meta on infrastructure of their choosing, in accordance with their terms. Where personal data moves between countries, we rely on the safeguards available to us for those transfers.
10. Children
WA Signal is a tool for businesses and is not directed at children. We do not knowingly collect personal data from children. If you believe a child's data has reached us, tell us and we will remove it.
11. Changes to this policy
We will update this page when the service changes in a way that affects it, and we will move the "last updated" date at the top. If a change materially affects merchants, we will tell them directly rather than relying on this page alone.
12. Contact us
Sellzzy Digital Commerce
Email: support@wasignal.io
Registered address: ADD REGISTERED BUSINESS ADDRESS
If you are unhappy with how we have handled your data, you may complain to the data protection authority in your country.