Official Legal & Compliance
WhatsApp Business Cloud API Privacy Policy
Effective Date: September 4, 2026 • Application: ChatCoat
1. WhatsApp Business & Meta Platform Compliance
ChatCoat integrates with the Meta WhatsApp Cloud API (v25.0) to provide two-way customer communication, conversational inbox management, delivery tracking, and manual agent reply functionality for registered organizations.
- WhatsApp Business Terms of Service: Compliant with WhatsApp Business Terms of Service.
- WhatsApp Business Policy: Compliant with WhatsApp Business Policy, including strict adherence to spam prohibition, opt-in consent, and customer care window guidelines.
- Meta Platform Terms: Compliant with Meta Platform Terms and Developer Policies.
2. Information We Collect via WhatsApp Cloud API
When an organization connects its WhatsApp Business Account to ChatCoat and communicates with customers, we process and store only the minimal data necessary to provide conversation management:
Business Account & Phone Data
- WhatsApp Business Account ID (WABA ID)
- Meta Phone Number ID and Display Phone Number
- Verified Business Profile Name and Quality Rating
- Encrypted System User or OAuth API access tokens
Customer Interaction Data
- Customer WhatsApp Phone Number / ID (wa_id)
- Customer Profile Name (as provided by Meta webhook)
- Inbound and Outbound Message Text and Media IDs
- Meta Message ID (wamid) and Delivery Status (sent, delivered, read)
- Customer Service Window timestamp (24-hour expiration)
3. Purpose of WhatsApp Data Processing
All WhatsApp customer data is processed exclusively for the following authorized business purposes:
- Conversational Inbox: Rendering incoming customer inquiries in the ChatCoat dashboard so customer care agents can review message history and reply.
- 24-Hour Service Window Enforcement: Calculating and strictly enforcing Meta’s 24-hour customer care window. Outbound free-form messages are automatically restricted once 24 hours of customer inactivity elapse.
- Message Delivery Tracking: Receiving delivery receipts (sent, delivered, read, failed) from Meta Cloud API to display delivery status ticks to agents.
- Duplicate Prevention: Using unique Meta `wamid` identifiers to ensure message idempotency and prevent duplicate processing.
4. Data Protection & Security Measures
ChatCoat implements enterprise-grade technical and organizational security controls to protect all WhatsApp data:
- Token Encryption at Rest: All Meta WhatsApp access tokens are encrypted using authenticated symmetric cryptography (AES-256 / Fernet) before storage in our PostgreSQL database.
- Webhook Signature Verification: Every inbound webhook from Meta is validated via HMAC-SHA256 signature verification (`x-hub-signature-256`) against the configured App Secret. Unsigned or invalid requests are immediately rejected.
- Strict Multi-Tenant Isolation: All conversations, phone numbers, and message logs are strictly partitioned by `organization_id`. No organization can access or view another tenant’s WhatsApp conversations.
- Encryption in Transit: All communications with Meta Cloud API and between user browsers and ChatCoat servers are conducted over TLS 1.3 encryption (HTTPS).
5. No Sale or Commercial Exploitation of WhatsApp Data
ChatCoat never sells, leases, rents, trades, or commercializes WhatsApp message contents, customer phone numbers, or metadata to third parties, data brokers, or advertisers. WhatsApp data is never used to build advertising profiles, train public generative models, or target unsolicited commercial marketing.
6. Meta WhatsApp Permissions & Scopes
ChatCoat requests only the minimum necessary WhatsApp permissions required for conversation management:
whatsapp_business_messagingUsed to receive incoming customer messages via webhooks and dispatch outbound agent replies within the 24-hour customer care window.
whatsapp_business_managementUsed to identify registered business phone numbers, read account status and quality ratings, and manage webhook subscriptions.
7. Data Retention, Revocation & Deletion Rights
Organizations and end-users maintain complete control over their WhatsApp data:
- Disconnecting WhatsApp: Organizations can disconnect their WhatsApp Business Account at any time from the Integrations dashboard, which immediately revokes API access and clears active tokens.
- User Data Deletion: Users can request full deletion of their customer records, conversation threads, and associated message data by visiting our public User Data Deletion Page or contacting us at support@chatcoat.com.
- Automated Data Purging: Deleted conversations and messages are permanently purged from database tables and automated backups in accordance with standard data retention schedules.
8. Contact Us & Data Protection Officer
If you have any questions, compliance requests, or inquiries regarding this WhatsApp Business Privacy Policy, please contact:
Application: ChatCoat
Support & Compliance Email: support@chatcoat.com
Official Domain: https://www.chatcoat.com