ChatCoat App Icon
ChatCoat Application

Official Legal & Compliance

Privacy Policy>WhatsApp Business (Cloud API)

WhatsApp Business Cloud API Privacy Policy

Effective Date: September 4, 2026 • Application: ChatCoat

1. WhatsApp Business & Meta Platform Compliance

ChatCoat integrates with the Meta WhatsApp Cloud API (v25.0) to provide two-way customer communication, conversational inbox management, delivery tracking, and manual agent reply functionality for registered organizations.

2. Information We Collect via WhatsApp Cloud API

When an organization connects its WhatsApp Business Account to ChatCoat and communicates with customers, we process and store only the minimal data necessary to provide conversation management:

Business Account & Phone Data

  • WhatsApp Business Account ID (WABA ID)
  • Meta Phone Number ID and Display Phone Number
  • Verified Business Profile Name and Quality Rating
  • Encrypted System User or OAuth API access tokens

Customer Interaction Data

  • Customer WhatsApp Phone Number / ID (wa_id)
  • Customer Profile Name (as provided by Meta webhook)
  • Inbound and Outbound Message Text and Media IDs
  • Meta Message ID (wamid) and Delivery Status (sent, delivered, read)
  • Customer Service Window timestamp (24-hour expiration)

3. Purpose of WhatsApp Data Processing

All WhatsApp customer data is processed exclusively for the following authorized business purposes:

  • Conversational Inbox: Rendering incoming customer inquiries in the ChatCoat dashboard so customer care agents can review message history and reply.
  • 24-Hour Service Window Enforcement: Calculating and strictly enforcing Meta’s 24-hour customer care window. Outbound free-form messages are automatically restricted once 24 hours of customer inactivity elapse.
  • Message Delivery Tracking: Receiving delivery receipts (sent, delivered, read, failed) from Meta Cloud API to display delivery status ticks to agents.
  • Duplicate Prevention: Using unique Meta `wamid` identifiers to ensure message idempotency and prevent duplicate processing.

4. Data Protection & Security Measures

ChatCoat implements enterprise-grade technical and organizational security controls to protect all WhatsApp data:

  • Token Encryption at Rest: All Meta WhatsApp access tokens are encrypted using authenticated symmetric cryptography (AES-256 / Fernet) before storage in our PostgreSQL database.
  • Webhook Signature Verification: Every inbound webhook from Meta is validated via HMAC-SHA256 signature verification (`x-hub-signature-256`) against the configured App Secret. Unsigned or invalid requests are immediately rejected.
  • Strict Multi-Tenant Isolation: All conversations, phone numbers, and message logs are strictly partitioned by `organization_id`. No organization can access or view another tenant’s WhatsApp conversations.
  • Encryption in Transit: All communications with Meta Cloud API and between user browsers and ChatCoat servers are conducted over TLS 1.3 encryption (HTTPS).

5. No Sale or Commercial Exploitation of WhatsApp Data

ChatCoat never sells, leases, rents, trades, or commercializes WhatsApp message contents, customer phone numbers, or metadata to third parties, data brokers, or advertisers. WhatsApp data is never used to build advertising profiles, train public generative models, or target unsolicited commercial marketing.

6. Meta WhatsApp Permissions & Scopes

ChatCoat requests only the minimum necessary WhatsApp permissions required for conversation management:

whatsapp_business_messaging

Used to receive incoming customer messages via webhooks and dispatch outbound agent replies within the 24-hour customer care window.

whatsapp_business_management

Used to identify registered business phone numbers, read account status and quality ratings, and manage webhook subscriptions.

7. Data Retention, Revocation & Deletion Rights

Organizations and end-users maintain complete control over their WhatsApp data:

  • Disconnecting WhatsApp: Organizations can disconnect their WhatsApp Business Account at any time from the Integrations dashboard, which immediately revokes API access and clears active tokens.
  • User Data Deletion: Users can request full deletion of their customer records, conversation threads, and associated message data by visiting our public User Data Deletion Page or contacting us at support@chatcoat.com.
  • Automated Data Purging: Deleted conversations and messages are permanently purged from database tables and automated backups in accordance with standard data retention schedules.

8. Contact Us & Data Protection Officer

If you have any questions, compliance requests, or inquiries regarding this WhatsApp Business Privacy Policy, please contact:

Application: ChatCoat

Support & Compliance Email: support@chatcoat.com

Official Domain: https://www.chatcoat.com