Privacy Policy
Last Updated: 8 May 2026 · Effective From: 8 May 2026
Published in compliance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — Rule 3(1)(a) — and the Digital Personal Data Protection Act, 2023.
1. Introduction
Zapwa ("Zapwa", "we", "our", or "us") is a WhatsApp Business SaaS platform operated by Etechinfo Consultant Pvt. Ltd., a company incorporated in India and having its registered office at H-187, Sector 63, Noida, Uttar Pradesh 201301, India. Our CIN and other statutory details are available upon request at legal@zapwa.in.
This Privacy Policy explains how we collect, use, disclose, transfer, and safeguard personal data when you visit our website at zapwa.in, use our platform at app.zapwa.in, or otherwise interact with us (collectively, the "Service"). This policy applies to all users of the Service, including business customers ("Tenants") and the end-users of those customers whose data is processed through our platform.
This Privacy Policy is published in compliance with Rule 3(1)(a) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("IT Rules 2011").
By accessing or using the Service, you acknowledge that you have read, understood, and agreed to the collection, use, and sharing of your personal data as described in this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
2. Definitions
The following terms have the meanings given to them below, consistent with the DPDP Act 2023 and the IT Rules 2011:
- Personal Data — Any data about an individual who is identifiable by or in relation to such data, including name, email address, phone number, IP address, and any combination of data that can identify a natural person.
- Sensitive Personal Data or Information (SPDI) — As defined under Rule 3 of the IT Rules 2011: passwords, financial information, physical or mental health conditions, sexual orientation, biometric data, and similar categories. Zapwa does not intentionally collect SPDI beyond encrypted passwords.
- Data Principal — The individual to whom the personal data relates. Under the DPDP Act, this is the natural person whose data is being processed.
- Data Fiduciary — The entity that determines the purpose and means of processing personal data. Our business customers (Tenants) are Data Fiduciaries for the data of their end-users.
- Data Processor — The entity that processes personal data on behalf of a Data Fiduciary. Zapwa acts as a Data Processor for the personal data of Tenants' end-users, and as a Data Fiduciary for the personal data of Tenant administrators and users.
- Customer / Tenant — A business or organisation that subscribes to and uses the Zapwa platform under a paid or trial subscription.
- End-User — A natural person who receives WhatsApp messages sent by a Tenant through the Zapwa platform.
- Service / Platform / Zapwa — The multi-tenant WhatsApp Business SaaS platform operated by Etechinfo Consultant Pvt. Ltd., available at app.zapwa.in and related subdomains.
- Consent — A free, specific, informed, unconditional, and unambiguous indication of the Data Principal's wishes by which they signify their agreement to the processing of their personal data for a specified purpose.
- Cookies — Small text files placed on your browser or device by a website to store information about your session, preferences, or usage patterns.
3. Information We Collect
(a) Information You Provide Directly
When you register for a Zapwa account, subscribe to a plan, or contact us, we collect:
- Account registration data: Your full name, work email address, phone number, and a password (stored exclusively as a bcrypt hash — never in plaintext).
- Business information: Company or business name, GST number (optional), registered address, industry sector, and business type.
- Payment information: We use third-party payment gateways (Razorpay and/or Stripe) for transaction processing. We store only transaction IDs, invoice amounts, subscription status, and payment dates. We do not store card numbers, CVVs, UPI credentials, or net banking credentials on our servers.
- Communications: Records of your interactions with our support team, including emails, ticket content, and any attachments you submit.
(b) Information We Collect Automatically
When you access or use the Service, we automatically collect certain technical data:
- Log data: IP address, browser type and version, operating system, device type, referral URL, pages viewed, timestamps of access, and HTTP response codes.
- Session data: Authentication tokens (JWT), session identifiers, and CSRF tokens necessary for secure login and navigation.
- Usage analytics: Feature usage patterns, campaign volumes, page interactions, and error logs, collected on a first-party basis to help us improve the platform. We do not use Google Analytics, Meta Pixel, or any third-party behavioural tracking on our platform.
(c) Information From Your Use of the WhatsApp Business API
When you connect your WhatsApp Business Account (WABA) to Zapwa and use the platform to send messages, we collect and process:
- WABA credentials: Your WhatsApp Business Account ID (WABA ID), Phone Number ID, and access tokens provided by Meta's Embedded Signup flow. Access tokens are stored encrypted at rest (AES-256).
- Message content (transient): The text and parameters of messages you send through the platform. Message content is processed to deliver the messages and populate your team inbox. It is retained for up to 90 days, after which it is permanently and automatically deleted.
- Message metadata: Message IDs, delivery timestamps, read receipt timestamps, failure reasons, and message type (template vs. session).
- Webhook events: Delivery status updates, read receipts, incoming message notifications, and account status updates received from Meta via webhooks. Webhook event logs are retained for 30 days.
- Contact lists uploaded by you: Phone numbers, contact names, custom fields (e.g., order ID, customer tier), and opt-in status records. These are stored for as long as your account is active and are deleted upon a valid account deletion request.
- Template content: Message templates you create and submit for Meta approval through the platform, including template text, media parameters, and category classifications.
(d) Information From Third Parties
- Meta / WhatsApp: When you connect your WABA using Meta's Embedded Signup flow, Meta shares your WABA ID, phone number ID, and access tokens with us for the purpose of enabling API access.
- Payment gateways: Upon payment processing, our payment gateway shares a transaction confirmation, transaction ID, and payment method type (e.g., card, UPI, net banking) — but not card numbers or other sensitive payment credentials.
4. How We Use Your Information
We use the personal data we collect for the following purposes:
- Provide and maintain the Service: Process your messages through the Meta WhatsApp Cloud API, populate your team inbox, manage your campaigns, and maintain your account workspace.
- Process transactions: Manage your subscription, process payments through our payment gateway, and issue GST-compliant invoices.
- Authenticate users: Verify your identity when you log in, maintain secure sessions, and protect against unauthorised access using JWT-based authentication.
- Send service-related communications: Email you about your account, subscription renewals, payment receipts, security alerts, platform updates, and policy changes.
- Provide customer support: Respond to your queries, troubleshoot issues, and escalate problems where necessary.
- Prevent fraud and abuse: Monitor for unusual activity, detect policy violations, verify compliance with Meta's messaging policies, and protect the platform from misuse.
- Comply with legal obligations: Respond to valid legal requests, court orders, or government directions under the IT Act 2000 and applicable Indian law.
- Improve the Service: Analyse aggregated, anonymised usage analytics to identify platform improvements, fix bugs, and develop new features.
- Marketing (with consent only): With your explicit consent, send you product updates, feature announcements, and promotional offers. You may opt out at any time using the unsubscribe link in any marketing email.
- Enforce Terms of Service: Investigate violations of our Terms of Service or Meta's WhatsApp Business Policy, and take appropriate action including account suspension or termination.
We do not train artificial intelligence or machine learning models on the personal data or message content of our customers or their end-users. We do not sell, rent, or trade your personal data or your end-users' data to any third party for advertising or marketing purposes.
5. Legal Basis for Processing
Under the DPDP Act, 2023 (for Indian Users)
The DPDP Act 2023 requires that personal data be processed only for lawful purposes with the consent of the Data Principal, or for legitimate uses as specified in the Act. Our processing is based on:
- Consent: For marketing communications, optional analytics features, and any processing not strictly necessary for the performance of the Service. Consent is obtained explicitly and may be withdrawn at any time.
- Legitimate Uses: For processing necessary for the performance of our contract with you (providing the Service), for compliance with legal obligations, for protecting the safety of users, and for fraud prevention — all as permitted under Section 7 of the DPDP Act 2023.
Under the GDPR (for Users in the European Economic Area)
| Processing Purpose | Legal Basis |
|---|---|
| Providing and maintaining the Service | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and managing subscriptions | Contract (Art. 6(1)(b)) |
| Authentication and account security | Legitimate interests (Art. 6(1)(f)) — security and fraud prevention |
| Legal compliance and responding to government requests | Legal obligation (Art. 6(1)(c)) |
| Anonymised platform analytics | Legitimate interests (Art. 6(1)(f)) — service improvement |
| Marketing communications | Consent (Art. 6(1)(a)) |
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, and in accordance with applicable legal requirements:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data (profile, email, credentials) | Until account deletion request, then 30 days, then permanently deleted | Service delivery |
| Message content | 90 days from send/receive date, then permanently deleted | Service delivery, inbox functionality |
| Message metadata (IDs, timestamps, status) | 90 days from send/receive date | Analytics, troubleshooting |
| Contact lists and opt-in records | Until account deletion; consent logs retained per DPDP Rules | Service delivery, compliance |
| Webhook event logs | 30 days | Debugging, security monitoring |
| Audit logs and security logs | 7 years | Indian tax law (GST Act), legal compliance |
| Billing records and invoices | 7 years | Indian tax law (GST Act, Income Tax Act) |
| Backup snapshots | 30 days rolling — auto-purged | Business continuity |
| Anonymised analytics data | Indefinite (no PII retained) | Service improvement |
Upon a valid account deletion request, we initiate deletion of all active data immediately. Backup snapshots are purged within 30 days. Tax and audit records are anonymised where possible and retained only to the minimum extent required by law.
8. Data Security
We implement and maintain reasonable security practices and procedures as required under Rule 8 of the IT Rules 2011 and in accordance with the DPDP Act 2023. Our technical and organisational security measures include:
- Encryption in transit: All data transmitted between your browser and our servers, and between our servers and Meta, is encrypted using TLS 1.2 or higher. We do not allow unencrypted HTTP connections to our platform.
- Encryption at rest: Sensitive data including WhatsApp access tokens is encrypted at rest using AES-256. Passwords are stored exclusively as bcrypt hashes and are never stored or transmitted in plaintext.
- Access controls: Role-based access control (RBAC) is enforced at both the application and database layers. Admin accounts require multi-factor authentication (MFA). Principle of least privilege is applied to all internal systems.
- Webhook security: All incoming webhook events from Meta are verified using HMAC-SHA256 signature verification to prevent spoofing and replay attacks.
- JWT-based authentication: User sessions are managed using signed JSON Web Tokens (JWT) with short expiry windows. Tokens are invalidated on logout.
- Tenant isolation: Each business workspace is fully isolated at the data layer. Cross-tenant data access is prevented by design at the database query level.
- Security audits: We conduct regular security reviews of our codebase, infrastructure, and access controls. We maintain an incident response plan for security breaches.
- Incident response: In the event of a data breach, we will notify affected users and, where required, the Data Protection Board of India and relevant authorities, within the timelines specified by applicable law.
While we take these measures seriously, no internet-based service can guarantee absolute security. You are responsible for maintaining the confidentiality of your login credentials and notifying us promptly at support@zapwa.in if you suspect unauthorised access to your account.
9. Your Rights
Under the DPDP Act, 2023 (Indian Users)
As a Data Principal under the Digital Personal Data Protection Act 2023, you have the following rights regarding your personal data:
- Right to Access: You may request a summary of the personal data we hold about you and the purposes for which it is being processed. We will provide this within 30 days of a verified request.
- Right to Correction and Erasure: You may request correction of inaccurate personal data or erasure of personal data that is no longer necessary for the purpose for which it was collected. See our Data Deletion Instructions for the erasure process.
- Right to Grievance Redressal: You have the right to have your grievances addressed by our Grievance Officer. See Section 15 below.
- Right to Nominate: You may nominate another individual to exercise your data rights in the event of your death or incapacity, in accordance with Section 14 of the DPDP Act.
- Right to Withdraw Consent: Where our processing is based on your consent, you may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
Under the GDPR (EEA Users)
If you are located in the European Economic Area, you have the following additional rights under the General Data Protection Regulation:
- Right of Access (Art. 15): Obtain a copy of your personal data in a structured, machine-readable format.
- Right to Rectification (Art. 16): Request correction of inaccurate personal data.
- Right to Erasure (Art. 17): Request deletion of your personal data under certain conditions.
- Right to Restriction of Processing (Art. 18): Request that we limit how we use your personal data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests, including profiling.
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent for consent-based processing at any time, without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: Lodge a complaint with the supervisory authority in your EU member state if you believe our processing infringes the GDPR.
To exercise any of these rights, please email privacy@zapwa.in with your registered email address and proof of identity. We will respond within 30 days of a verified request. For erasure requests, please see our Data Deletion Instructions.
10. Data Transfers
Zapwa processes personal data primarily within India. Our primary servers are located in the Mumbai region. Backup servers are located in Singapore. All data transfers to Singapore are covered by appropriate contractual safeguards, including Data Processing Agreements with our cloud infrastructure providers.
Certain data is necessarily transferred to Meta Platforms, Inc. (USA) as part of the WhatsApp Business Cloud API messaging process. These transfers are subject to Meta's Standard Contractual Clauses and Privacy Policy.
For transfers of personal data from the European Economic Area (EEA) to countries not recognised as providing adequate protection, we rely on Standard Contractual Clauses (SCCs) as the legal transfer mechanism under GDPR.
For data originating in India, we comply with the applicable cross-border data transfer restrictions and notification requirements under the DPDP Act 2023 and any regulations notified thereunder, including any data localisation requirements for specific categories of sensitive data.
12. Children's Privacy
The Service is intended for use by businesses and professionals and is not directed at individuals under the age of 18 years. We do not knowingly collect, process, or store personal data from minors. If we become aware that we have inadvertently collected personal data from a person under 18, we will take immediate steps to delete that data.
If you are a parent or guardian and believe that a minor has provided us with personal data without your consent, please contact us at privacy@zapwa.in and we will promptly investigate and delete the data.
13. Third-Party Links
Our website and platform may contain links to third-party websites, services, or resources (including Meta's developer documentation and our payment gateway). These third-party sites have their own privacy policies, and we are not responsible for their content, privacy practices, or data handling. We encourage you to review the privacy policies of any third-party sites you visit through links on our platform.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, the services we offer, or applicable legal requirements. The revised policy will be posted on this page with an updated "Last Updated" date.
For material changes — that is, changes that significantly affect your rights or our data practices — we will provide at least 30 days' advance notice via email to your registered email address and/or via a prominent notice within the platform. Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes.
If you do not agree to the revised Privacy Policy, you must stop using the Service and may request deletion of your account under Section 15 below.
15. Grievance Redressal Mechanism
In accordance with Rule 5(9) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and Section 13 of the DPDP Act 2023, we have designated a Grievance Officer to address complaints relating to the processing of personal data and our compliance with applicable law.
Grievance Officer Details
Name: Akhilesh Kumar
Designation: Grievance Officer & Data Protection Officer
Company: Etechinfo Consultant Pvt. Ltd.
Email: grievance@zapwa.in
Phone: +91 9953153142
Address: H-187, Sector 63, Noida, Uttar Pradesh 201301, India
Response timelines: We will acknowledge receipt of your grievance within 24 hours of receipt and will resolve the grievance within 15 (fifteen) calendar days of acknowledgment. If resolution requires additional time due to complexity, we will inform you of the revised timeline.
Escalation: If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India once it is constituted under the DPDP Act 2023, in accordance with the procedures notified by the Government of India.
16. Contact Us
For any questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us through the following channels:
General: hello@zapwa.in
Privacy & Data Requests: privacy@zapwa.in
Data Protection Officer: dpo@zapwa.in
Grievance Officer: grievance@zapwa.in
Phone: +91 9953153142
Address: Etechinfo Consultant Pvt. Ltd., H-187, Sector 63, Noida, Uttar Pradesh 201301, India