Welcome to AiWapi ("we", "our", "us", or "Platform"), owned and operated by SparkBit Technologies, having its principal place of operations in India. AiWapi provides software solutions, multi-agent live chat workspaces, broadcast automation, conversational chatbots, and API middleware built on top of the official Meta WhatsApp Cloud API / WhatsApp Business Platform.
This Privacy Policy applies to all users ("Business Users", "Clients", or "Customers") who register on https://aiwapi.in, integrate our developer REST APIs, or access our Android/iOS mobile application. It governs how we collect, store, transmit, and protect both your direct account credentials and the messaging telemetry generated during the execution of your WhatsApp communication workflows.
Core Principle: AiWapi strictly serves as an enterprise software layer and technology conduit. We never sell, monetize, rent, or repurpose your business conversations, contacts, or message payloads for advertising or third-party marketing.
AiWapi utilizes Meta's official WhatsApp Business Cloud API. It is essential to understand the distribution of responsibilities between your business, AiWapi, and Meta Platforms, Inc. under global data protection frameworks (such as the EU GDPR, UK GDPR, and India's Digital Personal Data Protection Act - DPDP):
| Entity |
Role in Data Ecosystem |
Responsibilities |
| Your Business (Client) |
Data Controller |
Determines purpose of messaging, gathers verified end-user opt-ins, ensures compliance with WhatsApp Commerce Policy, and manages customer relationships. |
| AiWapi (SparkBit) |
Data Processor |
Processes, formats, queues, routes, and displays WhatsApp message payloads, automated bot flows, and inbox chats solely according to your instructions. |
| Meta Platforms, Inc. |
API & Telecom Infra |
Operates global WhatsApp Cloud API data centers, orchestrates telephone network handshake, and enforces platform spam/health policies. |
When you connect your WhatsApp Business Account (WABA) using Meta Embedded Signup or configure your Phone Number ID and Permanent System Access Tokens, your authorization communicates directly with Meta's Graph API endpoints. You remain the sole owner of your data.
We collect only the minimum requisite information necessary to deliver high-performance messaging, automation, and billing features:
A. Account & Business Registration Information
- Identity Data: Full name, authorized company representative name, email address, password hash (via bcrypt with cryptographic salt), and mobile contact number.
- Company Information: Organization name, registered address, GST/Tax identification numbers, industry category, and timezone.
- Billing & Financial Data: Transaction references, plan tier subscriptions, payment gateway receipt tokens (we do not store raw credit/debit card numbers; all payments are processed through PCI-DSS Level-1 compliant gateways).
B. WhatsApp Cloud API & Integration Credentials
- Meta Credentials: WhatsApp Business Account ID (WABA ID), Phone Number ID, App ID, Meta Business Manager ID, and encrypted Permanent Access Tokens.
- Webhook Signatures: Webhook callback verification tokens and Meta App Secret verification hashes used to authenticate incoming event payloads.
- API Keys: Unique, persistent developer REST API authorization bearer tokens generated for external software, CRM, and eCommerce integrations.
C. Messaging Data, Payloads & Telemetry
- Contact Metadata: End-customer WhatsApp phone number (WhatsApp ID / WAID), saved contact names, custom attribute fields, and user tags.
- Message Content: Inbound and outbound message text bodies, quick-reply and button click payloads, list selections, and template parameter variable values.
- Media Assets: URLs or binary caches of media uploaded by you or received from customers (PDFs, invoices, images, audio notes, video clips, and document attachments) necessary for display in the Team Shared Inbox.
- Status & Delivery Telemetry: Real-time message status webhooks (e.g.,
sent, delivered, read, failed), timestamp records, error response codes, and conversation pricing categories (Marketing, Utility, Authentication, Service).
D. Device & Technical Log Data
- IP address, browser type and version, mobile operating system (iOS/Android), FCM push notification device tokens (for app alerts), session timestamps, and API rate-limit monitoring logs.
AiWapi strictly processes your data based on contractual necessity and legitimate business interests in delivering our software services:
- Message Dispatch & Receiving: Relaying inbound/outbound messages between your software, our multi-agent web/app inbox, and Meta’s WhatsApp Cloud API servers in real time.
- Multi-Agent Inbox Collaboration: Organizing conversations, assigning chats to support agents, tagging leads, and tracking resolution status.
- AI Chatbot & Flow Automation: Executing visual chatbot trees, intent matching, automated FAQ responses, and seamless escalation to human representatives.
- Broadcasts & Marketing Campaigns: Scheduling approved WhatsApp Message Templates, managing recipient batches, and monitoring delivery rates.
- Security, Fraud & Spam Prevention: Validating webhook signatures, preventing unauthorized API requests, enforcing rate limits, and defending against DDoS threats.
- Customer Support & System Diagnostics: Debugging failed template approvals, investigating API error codes returned by Meta Graph API, and optimizing response latency.
No Algorithmic Profiling: We do not conduct automated profiling, sentiment-based surveillance, or unauthorized data scraping on your customer interactions.
We employ industry-leading defensive architecture to ensure that your business conversations and credentials remain resilient against unauthorized access, leakage, or interception:
- End-to-End Transit Security: All data transmitted between your browser/app, AiWapi servers, and Meta Cloud API is encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS) with strong cipher suites.
- Encryption at Rest: Database storage, customer phone numbers, API keys, and Meta access tokens are encrypted using AES-256 (Advanced Encryption Standard).
- Webhook Payload Verification: Inbound Meta webhooks are authenticated via HMAC-SHA256 signature matching against your Meta App Secret, mitigating spoofing attacks.
- Strict Role-Based Access Control (RBAC): Within AiWapi, only authorized agents assigned by your business administrator can view designated conversation queues. Internal SparkBit technical staff access is restricted under principle-of-least-privilege (PoLP).
- Secure Data Centers: Our server infrastructure is hosted within Tier-3/Tier-4 ISO 27001, SOC-2 compliant cloud hosting facilities featuring 24/7 physical security, automated firewalls, and continuous failover backups.
As a provider of WhatsApp Business API software, AiWapi requires all Business Users to strictly uphold Meta's WhatsApp Business Messaging Policy regarding consent:
- Explicit Opt-In: You must obtain clear, affirmative opt-in from end-customers before initiating non-service (marketing/utility) template messages. The opt-in must clearly state the business name and message intent.
- Immediate Opt-Out Mechanism: You must honor customer opt-out requests instantly. AiWapi provides automated opt-out detection for standard keywords (including
STOP, UNSUBSCRIBE, CANCEL, QUIT, or OPTOUT).
- Respecting 24-Hour Customer Care Windows: Customer-initiated service chats must be serviced within Meta’s 24-hour customer service window unless approved templates are utilized.
Zero Spam Tolerance: Sending unsolicited messages or purchasing third-party phone lists violates both WhatsApp’s terms and AiWapi’s acceptable use policy, leading to immediate account suspension.
AiWapi does not sell or barter personal data. We disclose data solely to trustworthy subprocessors who enable platform functionality under strict confidentiality and data protection agreements:
| Subprocessor |
Purpose / Function |
Location / Compliance |
| Meta Platforms, Inc. (WhatsApp) |
WhatsApp Cloud API communication routing and template approval. |
Global / GDPR & Meta Data Terms Compliant |
| Cloud Hosting & DB Providers |
Encrypted backend compute, database storage, and file hosting. |
India / Global SOC 2 & ISO 27001 Certified |
| Payment Gateways (Razorpay / Stripe) |
Subscription billing and transaction handling. |
PCI-DSS Level 1 Compliant |
| Firebase Cloud Messaging (Google) |
Push notification delivery for real-time mobile app alerts. |
Global / Google Cloud Security |
| Law Enforcement / Legal Bodies |
Only when compelled by valid court order, statute, or government regulation. |
As required by applicable jurisdiction |
Under applicable data protection laws (including EU GDPR, CCPA, and India's DPDP Act), you possess the following enforceable rights:
- Right of Access: Request a complete copy of the personal information and business account records we hold about you.
- Right to Rectification: Request correction of inaccurate, obsolete, or incomplete contact and profile details.
- Right to Erasure ("Right to be Forgotten"): Request full deletion of your AiWapi account, contacts, chat histories, and API credentials from active servers.
- Right to Data Portability: Export your contacts, broadcast logs, and message transcripts in a structured, machine-readable format (JSON/CSV).
- Right to Restrict Processing: Request suspension of processing in instances of dispute or pending correction.
- Right to Withdraw Consent: Revoke authorization for marketing emails or disconnect your Meta WABA account at any time via the platform settings.
To exercise any of these rights, email us at support@aiwapi.in. We respond to all verified requests within 30 days without undue delay.
We maintain data only as long as necessary to satisfy service agreements, legal obligations, and accounting standards:
- Active Account Data: Maintained for the duration of your active subscription and service engagement.
- Message Logs & Analytics: Stored for operational and analytics review for 90 to 180 days (or as configured in your enterprise retention settings), after which logs are automatically purged or anonymized.
- Account Cancellation & Deletion: Upon receiving an explicit account termination request or subscription cancellation, all associated API tokens, webhook records, and message caches are permanently expunged within 30 days, excluding statutory tax invoices which are retained as required by financial regulations.
AiWapi strictly prohibits the use of our WhatsApp Cloud API services for activities that infringe upon WhatsApp Commerce Policies and applicable laws. You agree not to send messages involving:
- Illegal drugs, narcotics, prescription medicines, or tobacco products.
- Weapons, ammunition, explosives, or hazardous materials.
- Gambling, betting, unlicensed lotteries, or real-money gaming where prohibited.
- Adult content, pornography, sexually explicit products, or escort services.
- Multi-level marketing (MLM), predatory loans, deceptive financial schemes, or phishing scams.
- Hate speech, harassment, political misinformation, or defamatory campaigns.
Violations result in immediate API termination, Meta phone number blocking, and notification to regulatory authorities if warranted.
Our marketing website (aiwapi.in) uses cookies and browser local storage to ensure smooth navigation:
- Essential Cookies: Required for secure login authentication, session integrity, and CSRF protection.
- Performance & Analytics Cookies: Google Analytics (
gtag.js) cookies used in aggregate to analyze traffic trends, conversion metrics, and page load performance. IP addresses are anonymized.
- Managing Preferences: You can modify or block cookie preferences through your web browser settings at any time.
For inquiries, clarifications, data access requests, or privacy concerns regarding this policy or our WhatsApp Cloud API integration, please contact our designated Grievance & Data Protection Officer:
Corporate Entity
SparkBit Technologies
Operating the AiWapi WhatsApp Business API Automation Platform | India
We review and periodically update this Privacy Policy to align with evolving Meta Developer Policies and international statutory laws. Material changes will be highlighted via in-app alerts and email notifications to registered administrators.