Privacy Policy
Last updated: 10 August 2026 · Version 2026-08-10
This Privacy Policy explains what data WhatsTeam handles, in which role, and what happens to it. It is written for a Hong Kong-first service and follows the framing of the Personal Data (Privacy) Ordinance (“PDPO”); for customers elsewhere, the equivalent controller/processor concepts apply.
1. Two roles: your company’s data vs. account data
WhatsTeam handles data in two distinct roles:
- Customer Data — WhatsApp conversations, contact lists, media files and CRM records that a customer company connects or uploads. The customer company is the data user / controller of this data. WhatsTeam is its processor: we store and process it only to provide the service, on the company’s instructions.
- Account Data — the data we need to run WhatsTeam itself: names, work emails, hashed passwords, workspace settings, and service logs. For this data WhatsTeam is the data user / controller.
If you are a customer of one of our customers (for example, you messaged a company that uses WhatsTeam), that company decides how your data is used — direct your requests to them, and we will assist them in responding.
2. Customer Data we process
When a company connects a WhatsApp number, we process on its behalf:
- messages (text, images, voice notes, documents, and other media) sent and received on connected numbers, including message metadata such as timestamps and phone numbers;
- contact names and phone numbers, including CRM names the company assigns;
- deal and pipeline records the company creates or imports.
Messages are synced continuously while a number is connected so the workspace stays complete and searchable.
3. Account Data we collect
- name and work email of each workspace user;
- password (stored only as a salted hash — we cannot read it);
- company name, logo and workspace settings;
- technical logs needed to run and secure the service (for example authentication events and error logs).
The public marketing pages collect anonymous usage analytics only: our own aggregate counters (page views and button clicks, with no cookies, no identifiers and no IP address storage) and anonymous, cookieless product analytics via PostHog (see Sections 6 and 9). Marketing visitors are not identified.
4. What we use data for
We use data only to provide, secure and improve the service: syncing and backing up conversations, powering search and analytics, drafting AI-assisted replies, providing support, and billing.
We do not sell data. We do not use Customer Data for advertising. We do not use your conversations to train our own AI models.
5. AI processing
AI features (reply drafting, style analysis) send relevant message content to third-party AI model providers through our routing provider, OpenRouter, Inc., strictly to generate the requested output. Providers used this way are bound by their API terms; we route to providers whose terms do not permit training on API data, and we do not send more context than the feature needs.
A workspace can ask us to disable AI features entirely, or for specific connected numbers.
6. Subprocessors and hosting
We use a small number of service providers to run WhatsTeam:
- Replit, Inc. — application hosting and managed PostgreSQL database (data encrypted in transit and at rest);
- OpenRouter, Inc. — AI model routing for the AI features described above;
- PostHog, Inc. — product analytics: anonymous and cookieless on the public marketing pages; after you sign in, usage events (page views and feature actions such as sending a message or generating an AI draft) are linked to your account so we can improve the service. For signed-in users we also record how the app interface is used (session recordings of clicks, navigation and page layout) to find where people get stuck; all on-screen text and every input field is masked before capture, so message content, phone numbers and contact names are never sent to PostHog. Marketing visitors are never recorded. Recordings are stored on PostHog’s US infrastructure (see the hosting note below);
- Stripe, Inc. — payment processing, once paid plans launch (Stripe receives billing details; we never store full card numbers).
We will update this list when providers change. Hosting is currently in the United States; by using the service you consent to your data being transferred to and processed in that location.
7. Security
- all traffic is encrypted in transit (TLS) and stored data is encrypted at rest;
- passwords are stored as salted hashes; session cookies are HttpOnly;
- access to Customer Data inside a workspace is permission-scoped: admins control which team members see which numbers;
- personal (non-team) accounts connected through our personal bridge have message bodies additionally encrypted at the application layer.
No system is perfectly secure. If we become aware of a breach affecting your data we will notify affected customers without undue delay.
8. Retention, export and deletion
Customer Data is retained while the workspace subscription is active, so the company keeps its full history. Companies can export their data at any time by contacting us.
When a workspace is deleted or a subscription ends, we delete its Customer Data within 60 days, except where law requires longer retention. Anonymous aggregate metrics are kept for up to one year.
Account Data is deleted when the account is deleted, except minimal records we must keep for legal or accounting reasons.
9. Cookies
We use only essential cookies: a session cookie to keep you signed in. No advertising cookies and no analytics cookies — which is why there is no cookie banner.
Our product analytics (PostHog) runs without cookies: on the public marketing pages it is fully anonymous with nothing stored on your device; after you sign in to the app, an analytics identifier tied to your account is kept in your browser’s local storage (not a cookie) and is cleared when you sign out.
10. Your rights
Under the PDPO you may request access to and correction of personal data we hold about you as a data user. Where GDPR or similar laws apply to you, you may also have rights to erasure, restriction and portability.
Send requests to hello@whatsteam.com. If your data is inside a customer’s workspace (you are their customer or employee), we will refer the request to that company and assist them in responding.
11. Changes to this policy
We will post updates here and, for material changes, notify workspace admins inside the service or by email. The date at the top identifies the current version.
12. Contact
Privacy questions and requests: hello@whatsteam.com