Privacy Policy
Last updated: 1 October 2026
Wapi is operated by Kanoi Traders (“we”, “us”). Wapi provides a platform that lets businesses send and receive messages through the WhatsApp Business Platform (Meta's WhatsApp Cloud API). This policy explains what we collect, how we use it, and the choices and rights available to you, including under India's Digital Personal Data Protection Act, 2023.
Who is responsible for your data
For your own account (your name, email and workspace), Kanoi Traders decides how the data is used and is responsible for it (the “data fiduciary”). For the customer data you upload and the messages you send and receive, we act only on your instructions as a processor. You are responsible for that data and for having a lawful basis and the recipient's consent (opt-in) before messaging them.
Information we collect
- Account data: your name, email, and workspace name.
- WhatsApp connection data: your WhatsApp Business Account ID, phone number ID, display number, and access tokens obtained through Meta Embedded Signup (tokens are encrypted at rest).
- Contacts: phone numbers and any attributes you upload for your audience. If you connect a number you also use on the WhatsApp Business app, the contacts and chat history Meta shares at that time.
- Messages & metadata: message content, templates, media you attach, and delivery/read status returned by Meta.
- Billing data: your subscription status. Card and UPI details are entered with our payment processor and are not stored by us.
- Usage data: basic logs and error reports needed to operate and secure the service.
How we use information
- To send messages and campaigns on your instruction via the WhatsApp Cloud API.
- To display your inbox, delivery status, account alerts, and analytics.
- To send you service emails such as password resets.
- To bill your subscription.
- To secure the service, prevent abuse, and comply with Meta's policies and the law.
Who we share it with
We do not sell your data. We share it only with the service providers that run Wapi:
- Meta Platforms: message content and recipient numbers, to deliver your messages.
- Supabase: database, sign-in, and file storage.
- Vercel: hosting of the website and app.
- Resend: delivery of service emails such as password resets.
- Sentry: error monitoring, so we can find and fix problems.
- Razorpay: subscription payments.
Our database and app servers are located in Japan (Tokyo region), so your data is stored and processed outside India.
Retention
We retain account and messaging data for as long as your workspace is active. You may request deletion at any time (see our Data Deletion page); we delete or anonymize data within 30 days of a verified request, subject to legal retention needs.
Your rights
You can ask us to give you a summary of the personal data we hold about you, to correct or update it, or to erase it, and you can withdraw consent at any time. You may also nominate another person to exercise these rights on your behalf. Write to us at support@getwapi.in. If your request concerns data that a business uploaded to Wapi (for example, you received a WhatsApp message from one of our customers), we will pass it to that business, which is responsible for that data.
Security
Access tokens and sensitive secrets are encrypted at rest. Access to workspace data is restricted by row-level security so one workspace cannot read another's data.
Grievance officer
If you have a complaint about how we handle your data or about the service, contact our grievance officer, Subham Kanoi (Kanoi Traders), at support@getwapi.in. We will respond within the time required by applicable law. If you are not satisfied with our response, you may approach the Data Protection Board of India.
Changes
We may update this policy. We will post the new version here with a new “last updated” date and, for significant changes, tell account holders by email.