Skip to main content
Waaru
Legal

Privacy Policy

Effective date: 17 May 2025 · Last updated: 10 August 2026

Waaru is operated by Narayana Nexus, incorporated in India. We run the Waaru platform at waaru.app, which helps businesses automate and manage customer conversations on WhatsApp.

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights over it. It applies to businesses that sign up for Waaru (“customers”) and to end users whose WhatsApp messages are processed through Waaru on behalf of our customers.

This Policy is governed by India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025. By creating an account, you accept this Privacy Policy and our Terms of Service.

1. Our role in relation to your data

For Waaru customers (businesses that sign up):

We are a Data Fiduciary. We determine the purpose and means of processing your personal data — your account details, billing information, and how you use the platform.

For end users (the customers who message your WhatsApp number):

We are a Data Processor. We process end-user message data only on your instruction, to operate the automations you have configured. The business using Waaru is the Data Fiduciary for their own customers. This relationship is governed in detail by our Data Processing Agreement, which forms part of our Terms of Service.

2. What data we collect and why

2.1 Account data you provide at signup

DataPurposeLegal basis
Full nameAccount identificationConsent
Work emailAuthentication, transactional emails, product updatesConsent
Mobile numberAccount profileConsent
Company name, website, industry, sizeWorkspace setupConsent
Google profile (if using Google login)AuthenticationConsent

We do not store your Google profile picture.

2.2 WhatsApp connection data

DataPurpose
WhatsApp Business Account IDLinking your Meta account to Waaru
Phone number and Phone Number IDSending and receiving messages
Business profile (name, description)Displaying in your dashboard
Meta access tokensAuthenticating API calls to Meta on your behalf

Meta access tokens are stored using AES-256 encryption at rest. Tokens are rotated automatically when you reconnect your WhatsApp instance from the dashboard. We never store your Meta App Secret — only the access tokens required to make API calls on your behalf.

2.3 WhatsApp conversation data (your customers’ data)

When your automation runs through Waaru, we process:

DataPurpose
Message content (text, media)Running your flows, showing conversation history in your inbox
Your customers’ phone numbersRouting conversations
WhatsApp display namesShowing names in your inbox
Media files sent in conversationsDelivering and storing files
WhatsApp Form submission responsesStoring form answers as variables in your flows

This data belongs to your customers. We process it solely to operate your automations as you have configured them. We do not use your customers’ message content for our own marketing, analytics, or any purpose beyond running your flows and inbox.

Current product boundary: The authenticated MVP does not use an AI model to generate customer replies and does not route WhatsApp message content to a third-party AI model provider.

2.4 Connected commerce data

When a business explicitly connects a Shopify store, Waaru processes only the store data requested by the approved actions that the business runs:

DataPurpose
Store domain, Shopify account identifiers, OAuth tokens, and granted permissionsEstablishing and maintaining the connection
Customer identifiers, name, email address, phone number, default address for search confirmation, and up to ten addresses for an explicit profile actionFinding the correct customer for support, confirming contact or delivery details, and avoiding an incorrect match
Recent order, fulfilment, product, inventory, and location dataAnswering order, shipment, product, and availability questions configured by the business

Customer lookup accepts an exact Shopify customer ID, email address, or phone number, or a bounded name search. Waaru does not silently choose between ambiguous customer matches. The platform exposes reviewed actions rather than an unrestricted Shopify API proxy.

Shopify OAuth credentials and connector action inputs and outputs are encrypted at rest. Waaru processes connected-store customer data only on the business's instruction to run its configured support and automation workflows. It is not used for Waaru marketing or advertising.

2.5 Billing data

The current MVP is free and does not require a platform subscription or billing identifier for feature access. If a paid service is introduced, this policy will be updated before payment data is collected for that service.

2.6 Technical and usage data

DataPurpose
Session tokensKeeping you logged in
IP address (server logs)Security and fraud prevention
Features used, flows created, messages sentAggregate product operations and improvement
Your bot flow configurationsRunning your automations

2.7 How we use your data to improve and market Waaru

In addition to operating the platform, we use data about your Waaru account and usage for the following purposes:

PurposeData used
Sending product updates, feature announcements, and tipsYour email address
Informing you about product changes or features relevant to your usageFeatures you use and account preferences
Publishing aggregated, anonymised platform statisticsAnonymised — never linked to your identity
Internal analytics to understand feature adoption and improve the productUsage patterns — never sold to third parties

By creating an account you agree to receive product updates and occasional marketing communications from Waaru. You can opt out at any time by clicking the unsubscribe link in any email, or by emailing [email protected]. Opting out of marketing does not affect transactional emails such as billing receipts, security alerts, and authentication emails.

We never use the message content of your customers’ WhatsApp conversations for marketing purposes.

Optional product interaction analytics and masked session replay start only after you choose them in Waaru. You can withdraw either choice from Product analytics settings. Inputs are masked. Inbox, contact, template, upload, preview, and message content is excluded.

3. Third-party services we use

ServicePurposeTheir privacy policy
Meta Platforms Ireland LimitedWhatsApp Cloud API — sending and receiving messagesfacebook.com/policy.php
Amazon Web Services (AWS)Cloud infrastructure, database, and storage — hosted in Mumbai, Indiaaws.amazon.com/privacy
Vercel Inc.Public website hosting and deploymentvercel.com/legal/privacy-policy
PostHog Inc.Optional product analytics and privacy-masked session replayposthog.com/privacy
Google AnalyticsWebsite traffic analytics — page views, referrers, geographic datapolicies.google.com/privacy
Google Tag ManagerTag management for analytics and trackingpolicies.google.com/privacy
Resend Inc.Authentication and transactional emailsresend.com/legal/privacy-policy
Google LLCGoogle OAuth login where selectedpolicies.google.com/privacy
Shopify Inc.Connected-store OAuth, customer support lookups, and commerce actions selected by the businessshopify.com/legal/privacy
Cloudflare Inc.DNS proxy, DDoS protection, security filtering, and Turnstile CAPTCHA on signup/login formscloudflare.com/privacypolicy
Google WorkspaceInternal team collaboration and email — does not process customer dataworkspace.google.com/privacy

Cross-border data transfers

Some of the services listed above are hosted or operated outside India. By using Waaru, you acknowledge and consent to the transfer of your data to these countries as follows:

ServiceData LocationWhat is transferred
VercelUnited StatesPublic website requests and lead-generation submissions
PostHogEuropean UnionOptional pseudonymised product analytics
Meta/IrelandIreland / United StatesWhatsApp message data (for message delivery)
GoogleUnited StatesAnalytics and OAuth data, where those services are used
ShopifyMerchant-selected Shopify service locationsConnected-store data requested by the business

Waaru's AWS environments are isolated by deployment. Staging currently runs in the United States (us-east-1); production is designed for the Mumbai, India Region (ap-south-1) before production customer data is accepted. We will update this policy if the production data location changes.

All cross-border transfers are conducted under standard contractual clauses as required under the DPDP Act, 2023, and applicable laws. We ensure that these third parties provide adequate protection for your personal data.

The shared inbox runs within Waaru’s controlled application infrastructure and the sub-processors listed above.

We do not sell your data to any third party.

4. WhatsApp data deletion

You can request deletion of your WhatsApp conversation data at any time. Disconnecting a WhatsApp Business Account (WABA) stops Waaru from using that connection, but it does not by itself authorise deletion of workspace data that may belong to other workspace members or be subject to retention duties.

Upon WABA disconnection:

  • Waaru stops using the disconnected connection for new messaging
  • Existing workspace history remains subject to the retention rules below until an authorised, scoped deletion request is completed
  • You can separately request removal of the Meta connection records or deletion of WhatsApp data

Upon verified account closure:

  • We review the requester's authority, the impact on other workspace members, the requested scope, and applicable retention duties
  • Approved data is deleted within 30 days, except for the limited records we must retain under applicable law
  • Closing a workspace and disconnecting or deleting provider-side Meta assets are separate controlled actions

To request deletion: Choose the exact scope and verify your email at waaru.app/data-deletion. We review verified requests before changing account, WhatsApp, or Meta connection data. You can follow the private status link from the verification email or contact [email protected]. We process valid deletion requests within 30 days and send confirmation when the review is resolved.

Exception: We may retain certain data where required by applicable law, a court order, or a request from a competent government or regulatory authority. In such cases, data will be retained only to the extent and for the duration required, and will not be used for any other purpose.

5. Data retention

Data typeRetention
Account dataFor the lifetime of the account; approved account-closure data is deleted within 30 days, subject to legal retention
WhatsApp conversation recordsRetained while the workspace is active or until an approved scoped deletion request is completed
Conversation mediaThe workspace policy is configurable from 100 to 180 days; eligible expired media is deleted by the retention process
Reusable flow, template, or saved-reply mediaRetained while it remains a reusable workspace asset or until an approved deletion applies
Payment records, if anyAs required by applicable tax and accounting law
Terminal integration actions and provider event receiptsUp to 90 days; retired credential versions and expired authorisation sessions are removed after 7 days
Active connected-service credentialsWhile the connection remains active; retired versions follow the 7-day rotation cleanup above
Server logsUp to 180 days in production and 30 days in staging
Analytics data (PostHog, Google Analytics)Retained under the configured service policy. You can withdraw optional Waaru product analytics from your account settings.

Notwithstanding the above, we may retain certain data for longer periods where required by applicable law, a court order, or a request from a competent government or regulatory authority. In such cases, data will be retained only to the extent and for the duration required, and will not be used for any other purpose.

6. Your rights under the DPDP Act, 2023

As a data principal under the DPDP Act, you have the right to:

  • Access — Know what personal data we hold about you
  • Correction — Ask us to correct inaccurate data
  • Erasure — Request deletion of your personal data (subject to legal retention requirements)
  • Grievance redressal — Raise a complaint with our Grievance Officer
  • Nominate — Nominate another person to exercise rights on your behalf in case of death or incapacity

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

7. Data security

We use industry-standard security measures including:

  • Encryption in transit (TLS) for all data
  • Encrypted storage for sensitive tokens (Meta API keys, access tokens) using AES-256
  • Row-level tenant isolation so one customer cannot access another’s data
  • Authentication via signed JWT tokens with short expiry
  • Timing-safe comparison for all webhook signature verification
  • Cloudflare Turnstile CAPTCHA on signup and login forms to prevent automated bot attacks

While we take data security seriously, no system is completely immune to risk. We recommend that you do not share your Waaru account credentials and that you contact us immediately at [email protected] if you suspect any unauthorised access.

8. Children’s data

Waaru is a B2B platform for businesses. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided us data, contact us at [email protected] and we will delete it promptly.

9. Changes to this policy

We will update this page when our practices change and revise the “Last updated” date at the top. For material changes, we will notify registered customers by email at least 14 days before the change takes effect. Continued use of Waaru after that date constitutes acceptance of the updated policy.

10. Grievance Officer

In accordance with the DPDP Act, 2023, our Grievance Officer can be contacted at:

Email: [email protected]

Narayana Nexus, Gondia, Maharashtra, India

We will acknowledge grievances within 48 hours and resolve them within 30 days.