Privacy Policy
Last updated: May 1, 2026
This Privacy Policy describes how Wave Inbox ("we", "us", or "our") collects, uses, and shares information when businesses use our customer messaging platform to communicate with their customers via Meta-owned channels including WhatsApp Business, Facebook Messenger, and Instagram Direct (the "Service").
Wave Inbox is a B2B SaaS tool used by small and medium businesses to consolidate customer conversations from these channels into a unified inbox. We act as a data processor on behalf of the businesses that use our Service; the businesses themselves are the data controllers for the conversations they hold with their customers.
1. Information We Collect
When a customer initiates a conversation with a business that uses Wave Inbox, we receive and store:
- Contact identifiers: WhatsApp phone number (E.164 format) for WhatsApp users; Page-Scoped ID (PSID) for Facebook Messenger users; Instagram-Scoped ID (IGSID) for Instagram Direct users; display name and profile picture URL as provided by the respective Meta platform.
- Message content: text, voice notes, images, videos, audio recordings, documents, location shares, and any other media voluntarily sent by the customer to the business's connected Page or WhatsApp number.
- Metadata: timestamps, message IDs, delivery and read receipts, conversation history.
- Marketing attribution: click identifiers (such as
fbclid, gclid, ttclid), UTM parameters, and Meta messaging_referrals payload (ad ID, campaign ID, source) when the customer arrives via a click-to-message ad.
- Account info: for authorized business users (agents) of the platform, we collect email address, name, and authentication credentials.
- Transactional data: purchase confirmations, payment receipts (when shared by the customer), and conversion events triggered by the business.
2. How We Use Your Information
- Service delivery: route incoming messages to the correct business inbox; allow business agents to read and reply to customers; deliver agent replies back to the originating Meta channel.
- AI-assisted responses: when enabled by the business, provide smart reply suggestions and automated first-touch responses to assist agents in handling high message volumes.
- Conversation organization: tagging, filtering, and routing of conversations by sector, product, or campaign for the business operating the inbox.
- Marketing measurement: attribute conversions back to originating ad campaigns via Meta's Conversions API and equivalent endpoints, enabling the business to measure and optimize advertising spend.
- Service improvement: aggregated and anonymized analytics about platform usage to improve features and reliability.
- Compliance and security: fraud prevention, abuse mitigation, audit logging, and compliance with legal obligations.
3. Legal Basis for Processing
We process information based on:
- Consent: the customer voluntarily initiates a conversation by sending a message to the business's WhatsApp number, Facebook Page, or Instagram account, or by clicking a "Send Message" call-to-action in an advertisement.
- Contractual necessity: to provide the messaging service requested by both the customer and the business operating the inbox.
- Legitimate interest: to improve our Service, prevent fraud and abuse, and measure marketing performance for the business client.
- Legal obligation: to comply with applicable laws including LGPD (Brazil), GDPR (EU), and other regional privacy regulations.
4. Sharing Your Information
We do not sell personal information. We share information only as necessary to operate the Service:
- Meta Platforms, Inc. — Messages necessarily transit through Meta's infrastructure (WhatsApp Cloud API, Messenger Platform, Instagram Messaging API) for delivery to and from the customer.
- Service providers and sub-processors:
- Supabase (PostgreSQL hosting and authentication)
- Vercel (frontend application hosting)
- Anthropic (AI inference for smart reply suggestions, when enabled by the business)
- Groq (audio transcription, when enabled by the business)
- Cloud infrastructure providers serving the regions where our Service operates
All sub-processors are bound by data processing agreements with confidentiality and security obligations.
- Advertising platforms — when the business chooses to send conversion events back for attribution measurement: Meta Conversions API, Google Ads, TikTok Events API. Identifiers are hashed before transmission where applicable.
- The business operating the inbox: the business that configured the connected Page, IG account, or WhatsApp number naturally has full access to the messages exchanged with that customer.
- Authorities: when required by valid legal process (search warrants, court orders, lawful government requests).
5. Data Retention
We retain data for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Typical retention periods:
- Message content: up to 24 months from last interaction.
- Transactional records: up to 5 years (Brazilian tax compliance).
- Marketing attribution data: up to 90 days.
- Audit and security logs: up to 12 months.
- Account credentials of business users: until account deletion request.
End-customers may request earlier deletion at any time per Section 6.
6. Your Rights
Depending on your jurisdiction (GDPR, LGPD, CCPA, and similar), you may have the following rights:
- Access the data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data (right to be forgotten).
- Restrict or object to certain processing.
- Request data portability.
- Withdraw consent at any time (which may end the conversation thread).
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at privacy@waveinbox.space. We respond within 30 days. For end-customers who interacted with a business via Wave Inbox, please also contact the business directly, as they are the primary data controller.
7. Security
We implement industry-standard technical and organizational measures to protect data:
- TLS 1.2+ encryption in transit for all webhook, API, and client traffic.
- Encryption at rest for stored conversation data and access tokens.
- HMAC-SHA256 signature verification on all incoming Meta webhooks.
- Row-level security (RLS) on all database tables enforcing tenant isolation.
- Role-based access control for business users.
- Audit logging of administrative actions.
- Regular security reviews and dependency updates.
No system is 100% secure; we encourage users to avoid sharing highly sensitive information (financial credentials, government IDs, health records) via messaging channels.
8. International Transfers
Data may be processed in countries other than the user's home country, including the United States and Brazil. We ensure adequate safeguards are in place (such as Standard Contractual Clauses or equivalent mechanisms recognized by GDPR and LGPD).
9. Children's Privacy
Our Service is intended for businesses and adults conducting commerce. We do not knowingly collect data from individuals under the age of 13 (or 16 in the European Union, or as defined by local law). If a parent or guardian believes a child has provided us with personal data, please contact us at privacy@waveinbox.space for prompt removal.
10. Meta Platform Compliance
Wave Inbox complies with Meta Platform Terms, Developer Policies, and Messenger Platform Policy:
- We respect the 24-hour standard messaging window. Outside this window we use only message tags expressly permitted by Meta and only for their permitted use cases.
- We do not use Platform Data for purposes other than those declared in our App Review submission.
- We honor user opt-outs and do not message users who have requested to stop receiving communications.
- We do not sell, license, or transfer Platform Data to third parties for advertising or any other commercial purpose.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top indicates the latest revision. Material changes will be communicated to business users via email. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
For questions about this Privacy Policy, to exercise your rights, or to report a privacy concern, contact:
Wave Inbox — Privacy Team
Email: privacy@waveinbox.space
Data Protection Officer: dpo@waveinbox.space