Privacy Policy
Zappio ("we", "us", "our") is operated by TABSYST ENTERPRISE SOLUTIONS LLP. This policy describes what information we collect when you use the Zappio platform, how we use it, and the choices you have. We aim to keep this short and plain-spoken — if anything is unclear, email [email protected].
1. What we collect
Account information
- Your name, email address, and password (stored as a scrypt hash).
- The tenant (workspace) you belong to and your role within it.
WhatsApp data you choose to connect
- The Phone Number ID, WhatsApp Business Account (WABA) ID, and an access token for the WhatsApp Business Platform numbers you connect. Tokens are encrypted at rest (AES-256-GCM).
- WhatsApp messages, message status (sent/delivered/read), media, and contact phone numbers that flow through your connected numbers, while you are a customer of Zappio.
- The display name and verified business name of your WhatsApp number, as returned by Meta.
Meta Platform Data. Data we obtain through the Meta permissions we hold — whatsapp_business_messaging (sending & receiving messages on your connected number), whatsapp_business_management (your WABA's numbers, templates and quality rating), whatsapp_business_manage_events (delivery/read webhook events) and business_management (your Business Manager identity during Embedded Signup) — is "Platform Data" under Meta's terms. We use it only to operate the Zappio inbox and the features you enable. We never use Platform Data for advertising, never sell it, and never share it except as listed below. It is deleted when you disconnect the number, delete the project, or request deletion (see Data retention).
Other integrations you choose to connect
- Shopify shop domain and Admin API token (encrypted at rest), and read-only order/customer data we fetch when looking up an order for one of your conversations.
Enquiries from our website
- When you fill a form or the chat on getzappio.com, we store your name, WhatsApp number, country, business type and message, plus the page you came from and any campaign tags or Google Ads click identifier in the link you arrived on. We use it only to reply to you and to learn which pages and campaigns bring enquiries.
- The forms are protected by Cloudflare Turnstile, which checks that a person, not a bot, is sending them.
Usage data
- Server logs (request paths, response status codes, errors) for operational monitoring.
- Aggregated counts (conversations, messages, broadcast deliveries) for billing & analytics.
- On the public website only: Google Analytics, loaded through Google Tag Manager, records pages viewed, the site that referred you, your approximate location and device, and events such as a form sent or a WhatsApp button tapped. It never receives your phone number or message.
2. How we use information
- To provide the service: send/receive WhatsApp messages on your behalf, run automations you configure, and display your inbox.
- To keep the service secure: authenticate users, verify webhook signatures, refresh access tokens before they expire.
- To improve reliability: monitor errors and track usage trends.
- To communicate with you about your account.
3. Who we share it with
We do not sell your data. We share information only with the parties needed to operate the service:
- Meta / WhatsApp — every message you send and receive flows through the WhatsApp Business Platform (Meta), under Meta's terms.
- Shopify — only if you connect a Shopify store, and only the queries needed to look up orders for your conversations.
- Google — website analytics (Google Analytics and Tag Manager) on getzappio.com, and, when we advertise on Google, measurement of which ads lead to an enquiry.
- Cloudflare — delivers the website and runs the Turnstile check on its forms.
- Hosting & infrastructure providers — for running the service.
- Legal authorities — only when required by law.
4. Data retention
Conversation history is retained while your workspace is active so your team has access to it. You can request export or deletion of your tenant's data at any time by writing to [email protected]; we will action it within 30 days. Encrypted access tokens are deleted when you disconnect a number or delete the project.
5. Security
WhatsApp and Shopify access tokens are encrypted at rest with AES-256-GCM. User passwords are stored as scrypt hashes. Session cookies are HTTP-only and HMAC-signed. We never log message bodies in clear text; only counts and metadata.
6. Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. Contact [email protected] and we will respond within 30 days.
7. Cookies
The Zappio app (app.getzappio.com) uses a single HTTP-only session cookie to keep you signed in, and (for master admins) an acting_tenant cookie used for impersonation. The app sets no third-party tracking or advertising cookies.
The public website (getzappio.com) uses Google Analytics cookies to count visits and enquiries. When we advertise on Google, Google Ads may also set cookies that tell us an enquiry came from an ad. Cloudflare may set a cookie when its bot check runs. The site stores your first landing page and campaign tags in your browser so an enquiry can be credited to the page you came from; you can clear them at any time in your browser settings.
8. Children
Zappio is a business tool and is not directed at children under 16. We do not knowingly collect personal information from children.
9. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced in the product and via email. The "Effective" date above always reflects the current version.
10. Contact
TABSYST ENTERPRISE SOLUTIONS LLP
Email: [email protected]
Phone: +91 90377 73737
Jurisdiction: Kerala, India