Privacy Policy
Effective date: 17 May 2025 · Last updated: 10 August 2026
Waaru is operated by Narayana Nexus, incorporated in India. We run the Waaru platform at waaru.app, which helps businesses automate and manage customer conversations on WhatsApp.
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights over it. It applies to businesses that sign up for Waaru (“customers”) and to end users whose WhatsApp messages are processed through Waaru on behalf of our customers.
This Policy is governed by India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025. By creating an account, you accept this Privacy Policy and our Terms of Service.
1. Our role in relation to your data
For Waaru customers (businesses that sign up):
We are a Data Fiduciary. We determine the purpose and means of processing your personal data — your account details, billing information, and how you use the platform.
For end users (the customers who message your WhatsApp number):
We are a Data Processor. We process end-user message data only on your instruction, to operate the automations you have configured. The business using Waaru is the Data Fiduciary for their own customers. This relationship is governed in detail by our Data Processing Agreement, which forms part of our Terms of Service.
2. What data we collect and why
2.1 Account data you provide at signup
| Data | Purpose | Legal basis |
|---|---|---|
| Full name | Account identification | Consent |
| Work email | Authentication, transactional emails, product updates | Consent |
| Mobile number | Account profile | Consent |
| Company name, website, industry, size | Workspace setup | Consent |
| Google profile (if using Google login) | Authentication | Consent |
We do not store your Google profile picture.
2.2 WhatsApp connection data
| Data | Purpose |
|---|---|
| WhatsApp Business Account ID | Linking your Meta account to Waaru |
| Phone number and Phone Number ID | Sending and receiving messages |
| Business profile (name, description) | Displaying in your dashboard |
| Meta access tokens | Authenticating API calls to Meta on your behalf |
Meta access tokens are stored using AES-256 encryption at rest. Tokens are rotated automatically when you reconnect your WhatsApp instance from the dashboard. We never store your Meta App Secret — only the access tokens required to make API calls on your behalf.
2.3 WhatsApp conversation data (your customers’ data)
When your automation runs through Waaru, we process:
| Data | Purpose |
|---|---|
| Message content (text, media) | Running your flows, showing conversation history in your inbox |
| Your customers’ phone numbers | Routing conversations |
| WhatsApp display names | Showing names in your inbox |
| Media files sent in conversations | Delivering and storing files |
| WhatsApp Form submission responses | Storing form answers as variables in your flows |
This data belongs to your customers. We process it solely to operate your automations as you have configured them. We do not use your customers’ message content for our own marketing, analytics, or any purpose beyond running your flows and inbox.
Current product boundary: The authenticated MVP does not use an AI model to generate customer replies and does not route WhatsApp message content to a third-party AI model provider.
2.4 Connected commerce data
When a business explicitly connects a Shopify store, Waaru processes only the store data requested by the approved actions that the business runs:
| Data | Purpose |
|---|---|
| Store domain, Shopify account identifiers, OAuth tokens, and granted permissions | Establishing and maintaining the connection |
| Customer identifiers, name, email address, phone number, default address for search confirmation, and up to ten addresses for an explicit profile action | Finding the correct customer for support, confirming contact or delivery details, and avoiding an incorrect match |
| Recent order, fulfilment, product, inventory, and location data | Answering order, shipment, product, and availability questions configured by the business |
Customer lookup accepts an exact Shopify customer ID, email address, or phone number, or a bounded name search. Waaru does not silently choose between ambiguous customer matches. The platform exposes reviewed actions rather than an unrestricted Shopify API proxy.
Shopify OAuth credentials and connector action inputs and outputs are encrypted at rest. Waaru processes connected-store customer data only on the business's instruction to run its configured support and automation workflows. It is not used for Waaru marketing or advertising.
2.5 Billing data
The current MVP is free and does not require a platform subscription or billing identifier for feature access. If a paid service is introduced, this policy will be updated before payment data is collected for that service.
2.6 Technical and usage data
| Data | Purpose |
|---|---|
| Session tokens | Keeping you logged in |
| IP address (server logs) | Security and fraud prevention |
| Features used, flows created, messages sent | Aggregate product operations and improvement |
| Your bot flow configurations | Running your automations |
2.7 How we use your data to improve and market Waaru
In addition to operating the platform, we use data about your Waaru account and usage for the following purposes:
| Purpose | Data used |
|---|---|
| Sending product updates, feature announcements, and tips | Your email address |
| Informing you about product changes or features relevant to your usage | Features you use and account preferences |
| Publishing aggregated, anonymised platform statistics | Anonymised — never linked to your identity |
| Internal analytics to understand feature adoption and improve the product | Usage patterns — never sold to third parties |
By creating an account you agree to receive product updates and occasional marketing communications from Waaru. You can opt out at any time by clicking the unsubscribe link in any email, or by emailing [email protected]. Opting out of marketing does not affect transactional emails such as billing receipts, security alerts, and authentication emails.
We never use the message content of your customers’ WhatsApp conversations for marketing purposes.
Optional product interaction analytics and masked session replay start only after you choose them in Waaru. You can withdraw either choice from Product analytics settings. Inputs are masked. Inbox, contact, template, upload, preview, and message content is excluded.
3. Third-party services we use
| Service | Purpose | Their privacy policy |
|---|---|---|
| Meta Platforms Ireland Limited | WhatsApp Cloud API — sending and receiving messages | facebook.com/policy.php |
| Amazon Web Services (AWS) | Cloud infrastructure, database, and storage — hosted in Mumbai, India | aws.amazon.com/privacy |
| Vercel Inc. | Public website hosting and deployment | vercel.com/legal/privacy-policy |
| PostHog Inc. | Optional product analytics and privacy-masked session replay | posthog.com/privacy |
| Google Analytics | Website traffic analytics — page views, referrers, geographic data | policies.google.com/privacy |
| Google Tag Manager | Tag management for analytics and tracking | policies.google.com/privacy |
| Resend Inc. | Authentication and transactional emails | resend.com/legal/privacy-policy |
| Google LLC | Google OAuth login where selected | policies.google.com/privacy |
| Shopify Inc. | Connected-store OAuth, customer support lookups, and commerce actions selected by the business | shopify.com/legal/privacy |
| Cloudflare Inc. | DNS proxy, DDoS protection, security filtering, and Turnstile CAPTCHA on signup/login forms | cloudflare.com/privacypolicy |
| Google Workspace | Internal team collaboration and email — does not process customer data | workspace.google.com/privacy |
Cross-border data transfers
Some of the services listed above are hosted or operated outside India. By using Waaru, you acknowledge and consent to the transfer of your data to these countries as follows:
| Service | Data Location | What is transferred |
|---|---|---|
| Vercel | United States | Public website requests and lead-generation submissions |
| PostHog | European Union | Optional pseudonymised product analytics |
| Meta/Ireland | Ireland / United States | WhatsApp message data (for message delivery) |
| United States | Analytics and OAuth data, where those services are used | |
| Shopify | Merchant-selected Shopify service locations | Connected-store data requested by the business |
Waaru's AWS environments are isolated by deployment. Staging currently runs in the United States (us-east-1); production is designed for the Mumbai, India Region (ap-south-1) before production customer data is accepted. We will update this policy if the production data location changes.
All cross-border transfers are conducted under standard contractual clauses as required under the DPDP Act, 2023, and applicable laws. We ensure that these third parties provide adequate protection for your personal data.
The shared inbox runs within Waaru’s controlled application infrastructure and the sub-processors listed above.
We do not sell your data to any third party.
4. WhatsApp data deletion
You can request deletion of your WhatsApp conversation data at any time. Disconnecting a WhatsApp Business Account (WABA) stops Waaru from using that connection, but it does not by itself authorise deletion of workspace data that may belong to other workspace members or be subject to retention duties.
Upon WABA disconnection:
- Waaru stops using the disconnected connection for new messaging
- Existing workspace history remains subject to the retention rules below until an authorised, scoped deletion request is completed
- You can separately request removal of the Meta connection records or deletion of WhatsApp data
Upon verified account closure:
- We review the requester's authority, the impact on other workspace members, the requested scope, and applicable retention duties
- Approved data is deleted within 30 days, except for the limited records we must retain under applicable law
- Closing a workspace and disconnecting or deleting provider-side Meta assets are separate controlled actions
To request deletion: Choose the exact scope and verify your email at waaru.app/data-deletion. We review verified requests before changing account, WhatsApp, or Meta connection data. You can follow the private status link from the verification email or contact [email protected]. We process valid deletion requests within 30 days and send confirmation when the review is resolved.
Exception: We may retain certain data where required by applicable law, a court order, or a request from a competent government or regulatory authority. In such cases, data will be retained only to the extent and for the duration required, and will not be used for any other purpose.
5. Data retention
| Data type | Retention |
|---|---|
| Account data | For the lifetime of the account; approved account-closure data is deleted within 30 days, subject to legal retention |
| WhatsApp conversation records | Retained while the workspace is active or until an approved scoped deletion request is completed |
| Conversation media | The workspace policy is configurable from 100 to 180 days; eligible expired media is deleted by the retention process |
| Reusable flow, template, or saved-reply media | Retained while it remains a reusable workspace asset or until an approved deletion applies |
| Payment records, if any | As required by applicable tax and accounting law |
| Terminal integration actions and provider event receipts | Up to 90 days; retired credential versions and expired authorisation sessions are removed after 7 days |
| Active connected-service credentials | While the connection remains active; retired versions follow the 7-day rotation cleanup above |
| Server logs | Up to 180 days in production and 30 days in staging |
| Analytics data (PostHog, Google Analytics) | Retained under the configured service policy. You can withdraw optional Waaru product analytics from your account settings. |
Notwithstanding the above, we may retain certain data for longer periods where required by applicable law, a court order, or a request from a competent government or regulatory authority. In such cases, data will be retained only to the extent and for the duration required, and will not be used for any other purpose.
6. Your rights under the DPDP Act, 2023
As a data principal under the DPDP Act, you have the right to:
- Access — Know what personal data we hold about you
- Correction — Ask us to correct inaccurate data
- Erasure — Request deletion of your personal data (subject to legal retention requirements)
- Grievance redressal — Raise a complaint with our Grievance Officer
- Nominate — Nominate another person to exercise rights on your behalf in case of death or incapacity
To exercise any of these rights, email us at [email protected]. We will respond within 30 days.
7. Data security
We use industry-standard security measures including:
- Encryption in transit (TLS) for all data
- Encrypted storage for sensitive tokens (Meta API keys, access tokens) using AES-256
- Row-level tenant isolation so one customer cannot access another’s data
- Authentication via signed JWT tokens with short expiry
- Timing-safe comparison for all webhook signature verification
- Cloudflare Turnstile CAPTCHA on signup and login forms to prevent automated bot attacks
While we take data security seriously, no system is completely immune to risk. We recommend that you do not share your Waaru account credentials and that you contact us immediately at [email protected] if you suspect any unauthorised access.
8. Children’s data
Waaru is a B2B platform for businesses. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided us data, contact us at [email protected] and we will delete it promptly.
9. Changes to this policy
We will update this page when our practices change and revise the “Last updated” date at the top. For material changes, we will notify registered customers by email at least 14 days before the change takes effect. Continued use of Waaru after that date constitutes acceptance of the updated policy.
10. Grievance Officer
In accordance with the DPDP Act, 2023, our Grievance Officer can be contacted at:
Email: [email protected]
Narayana Nexus, Gondia, Maharashtra, India
We will acknowledge grievances within 48 hours and resolve them within 30 days.