Privacy Policy
How WhatsInfinity collects, uses, stores, and protects information when you use our platform and Meta integrations.
Legal entity & product identification (Meta App Review)
- Application / service name: WhatsInfinity
- Operator / data controller for the platform: Jaimik.com, Surat, Gujarat, India
- Public website: whatsinfinity.com
- Privacy & data requests: privacy@whatsinfinity.app
- Support & deletion requests: support@whatsinfinity.app
- Last updated: July 2026
1. Scope & agreement
This Privacy Policy applies to the WhatsInfinity web application, APIs, and related services (the "Service") operated by Jaimik.com ("we", "us", "our"). By creating an account, connecting Meta/WhatsApp assets, or otherwise using the Service, you agree to this Policy and our Terms of Service.
If you use the Service on behalf of a business, you represent that you have authority to bind that business and that you will provide appropriate notices to your customers and staff.
2. Roles: controller vs processor
- Jaimik.com is the data controller for account data, billing records, platform logs, and information we need to operate and secure the Service.
- For end-customer data you upload or sync (phone numbers, message content, lead form answers, etc.), you are the data controller and we act as a data processor processing that data on your documented instructions to provide messaging, automation, and reporting.
- Meta Platforms Technologies (Facebook, Instagram, WhatsApp) are independent controllers for data processed under their own terms when you use their products.
3. Information we collect
3.1 Account & identity
- Name, email address, username, password hash, role (agency/client), business name
- OAuth identifiers if you sign in with Google or Facebook (where enabled)
- Agency–client relationships, invite metadata, plan and usage limits
3.2 WhatsApp & Meta Business data
- WhatsApp Business Account (WABA) ID, phone number ID, display phone number, verified business name
- Encrypted WhatsApp / Meta user access tokens and token expiry metadata
- Approved message template names, languages, categories, components, and sync status
- Message delivery status (queued, sent, delivered, read, failed) and related logs
- Webhook events received from Meta (including delivery receipts and, where configured, leadgen events)
3.3 Customer & campaign data (your data)
- Customer phone numbers, names, tags, custom fields, opt-in notes you store
- Flow assignments, broadcast recipients, queue and execution history
- CSV import files and mapping configuration you provide
3.4 Lead Ads (Facebook / Instagram)
- Facebook Page ID, lead form ID, field mapping configuration
- Lead identifiers and field values retrieved via Meta APIs (e.g.
leads_retrieval) after a leadgen webhook - Processing logs (success/failure, timestamps) for troubleshooting
3.5 Mobile app device access
- Contacts: optional import into your CRM. Nothing is uploaded until you select contacts and confirm import.
- Camera, photos, and documents: optional. Used only when you attach media in customer chat to send through WhatsApp Cloud API during an open messaging session.
- Push tokens: if you enable notifications for inbound messages and account alerts.
- Biometrics: Face ID / fingerprint stay on-device; we store only an unlock trust token.
3.6 Technical & security
- IP address, browser type, device class, approximate region from IP
- Authentication sessions, refresh tokens, audit logs for sensitive actions
- Error reports and performance metrics needed to maintain the Service
4. How we use information
- Provide, maintain, and improve the Service (dashboards, queues, templates, analytics)
- Authenticate users and enforce role-based access per workspace
- Send service-related email (security alerts, plan expiry, support)
- Comply with law, respond to lawful requests, and enforce our terms
- Detect abuse, fraud, and policy violations
We do not sell personal information. We do not use your customer lists or lead data for our own advertising or to build unrelated profiles.
5. Legal bases (where applicable)
Depending on your jurisdiction, we rely on one or more of:
- Contract: to deliver the Service you subscribed to
- Legitimate interests: security, fraud prevention, product improvement (balanced against your rights)
- Legal obligation: tax, regulatory, or court requirements
- Consent: where required for optional integrations or marketing communications from us
You (the business user) must establish your own lawful basis and consent for messaging your customers and for Lead Ads collection text on Meta forms.
6. Meta Platform & WhatsApp Business Platform
Our Service integrates with Meta products under the Meta Platform Terms, Developer Policies, and WhatsApp Business Platform / Commerce policies. When you connect:
- We receive and store tokens and identifiers necessary to call Meta APIs on your behalf
- We send messages only as instructed by your templates, flows, and broadcasts
- We subscribe to webhooks for message status and (if enabled) leadgen events
Meta may process data according to its own privacy policies. You can review Meta's policies at facebook.com/privacy and WhatsApp Business documentation.
7. Facebook Login, Google Login & permissions
If you use Facebook Login or Google Login, we receive information permitted by those flows (typically email, name, and profile identifier) to create or link your account. We request only permissions needed for WhatsApp Embedded Signup, Lead Ads, and Page management features you enable—not legacy social graph permissions such as friends lists.
You may revoke app access in Facebook Settings → Apps and Websites or Google Account permissions; revoking access may disable integrations until you reconnect. See data deletion instructions for removing data stored on our servers.
8. Lead Ads & leads_retrieval
When you map a Lead Ad form, Meta may notify us of a new lead. We use Meta's APIs to retrieve form field values only for leads associated with Pages and forms you authorize. We use this data to:
- Create or update a customer record in your isolated workspace
- Optionally enroll the contact in a WhatsApp automation flow you configured
- Display processing status in your dashboard and logs
You must ensure lead form privacy disclosures mention your business, purpose, and how individuals can contact you for access or deletion. We process lead data only to provide the Service to you.
9. Sharing & disclosure
We may share information only in these situations:
- Service providers: hosting, email, monitoring—under contracts requiring confidentiality and security
- Meta / Google: as required to operate integrations you enable
- Legal: if required by law, court order, or to protect rights, safety, and integrity
- Business transfer: in connection with a merger or acquisition, with notice where required
We do not share customer phone lists with other tenants or unrelated third parties.
10. International transfers
Primary infrastructure may be located in India. If data is accessed from other countries, you acknowledge that laws may differ. Where required, we implement appropriate safeguards (contractual clauses, encryption, access controls).
11. Security measures
- HTTPS/TLS for data in transit
- Encryption at rest for sensitive tokens (e.g. WhatsApp access tokens)
- Role-based access, tenant isolation by client/agency workspace
- Parameterized database queries, input sanitization, rate limiting on authentication
- Audit logging for high-risk administrative actions
No method of transmission or storage is 100% secure. Report suspected incidents to privacy@whatsinfinity.app promptly.
12. Retention
- Active subscription: account and operational data retained while the account is active
- Terminated account: removed immediately when you delete in the mobile app, or within 30 days of a confirmed email request. In-app deletion sends a confirmation email to your registered address.
- Message logs: typically retained up to 7 days unless your plan or configuration states otherwise
- Webhook forward logs: may be retained up to 7 days for operations
- Billing records: retained as required by tax and accounting law
13. Your rights
Subject to applicable law (including GDPR where relevant and India's DPDP Act where applicable), you may:
- Access personal data we hold about your user account
- Correct inaccurate account data
- Request deletion or export (see data deletion — includes in-app Delete account in Settings)
- Object to or restrict certain processing where legally required
- Withdraw consent where processing is consent-based (without affecting prior lawful processing)
- Lodge a complaint with a supervisory authority in your country
End consumers (people who messaged your business or submitted a lead form) should contact your business first; we will assist you as processor when you instruct us.
14. Children
The Service is intended for businesses and users aged 18+. We do not knowingly collect personal information from children. Contact us if you believe a child's data was submitted in error.
15. Cookies & similar technologies
See our Cookie Policy for details on session cookies, security tokens, and third-party cookies from Meta/Google login flows.
16. Marketing & communications from us
We may email you about product updates, security, billing, or policy changes related to your account. You may opt out of non-essential marketing emails where offered. Transactional and legal notices may still be sent.
17. Your obligations to your customers
As a business user you agree to:
- Obtain valid opt-in before WhatsApp marketing or promotional messages
- Honor opt-out / STOP requests promptly
- Use approved templates and correct categories (Marketing vs Utility vs Authentication)
- Comply with Meta restrictions (including US marketing limitations where applicable)
- Maintain accurate privacy notices on websites and lead forms
18. Changes to this Policy
We may update this Policy to reflect legal, technical, or product changes. Material changes will be posted on this page with an updated "Last updated" date. Continued use after the effective date constitutes acceptance where permitted by law.
19. Contact & data protection requests
Jaimik.com
Surat, Gujarat, India
Email: privacy@whatsinfinity.app
Support: support@whatsinfinity.app
User data deletion (Meta-required URL): https://whatsinfinity.com/data-deletion · static: /data-deletion.html
Related policies
Meta Developer Console: use static URLs /privacy.html and /data-deletion.html for Privacy Policy and User Data Deletion fields.