Privacy at a Glance

Table of Contents
  1. Definitions and Scope
  2. Information We Collect
  3. Legal Basis for Processing
  4. How We Use Your Information
  5. AI Processing and Disclosure
  6. WhatsApp Messaging Compliance
  7. Data Sharing and Third Parties
  8. Sub-Processors
  9. International Data Transfers
  10. Data Retention and Deletion
  11. Data Security
  12. Your Rights (All Jurisdictions)
  13. GDPR-Specific Rights (EEA/UK)
  14. CCPA/CPRA Rights (California)
  15. India DPDPA Rights
  16. Meta Platform Data Deletion
  17. Cookies and Tracking
  18. Children's Privacy
  19. Third-Party Links
  20. Data Breach Notification
  21. Grievance Officer (India)
  22. Changes to This Policy
  23. Contact Us

1 Definitions and Scope

This Privacy Policy ("Policy") describes how ChatOrbit ("the Company", "we", "us", or "our"), operated by Hiren Chheta, collects, uses, stores, shares, and protects information when you use our WhatsApp Business automation platform, website, dashboard, APIs, and all related services (collectively, the "Service").

This Policy applies to:

Data Controller vs. Data Processor: ChatOrbit acts as a Data Processor when handling end-user messages on behalf of Business Users. The Business User is the Data Controller for their customers' personal data. When ChatOrbit collects data directly from Business Users (e.g., account registration), ChatOrbit acts as the Data Controller.

By using our Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, please discontinue use of the Service.

2 Information We Collect

2.1 Information You Provide Directly

Data CategorySpecific Data PointsPurpose
Account Registration Full name, email address, phone number, business name, business address, business category Create and manage your account
WhatsApp Business Details Phone Number ID, WhatsApp Business Account ID (WABA ID), business profile info, Meta App credentials (access tokens) Connect your WhatsApp Business Account to our platform
Payment & Billing Billing name, billing address, GST/tax ID. Card details are processed by Razorpay; we do NOT store full card numbers, CVV, or expiry dates. Process subscriptions and payments
AI Training Data Product catalogs, FAQs, business descriptions, custom instructions, knowledge base documents Train your AI assistant to respond accurately
Custom Replies Keyword triggers, auto-reply templates, flow configurations Configure automated messaging workflows
Support Communications Emails, chat messages, or feedback you send to our support team Provide customer support and improve Service

2.2 Information Collected Through WhatsApp Messaging

When your customers interact with your WhatsApp Business number via our platform, we process the following on your behalf:

Data CategorySpecific Data PointsPurpose
Message Content Text messages, media files (images, documents, audio, video, stickers) exchanged between your business and customers Deliver and display messages; power AI responses
Customer Identifiers Phone numbers and WhatsApp profile names as provided by WhatsApp Business API Identify customers in conversations; CRM functionality
Message Metadata Timestamps, delivery status (sent, delivered, read), message IDs Track delivery; analytics; troubleshooting
Order Data Items, quantities, amounts, order status extracted from conversations Order management and payment tracking
Important — End-User Data: We process end-user data strictly on behalf of the Business User (Data Controller). We do not use end-user data for our own marketing, advertising, or profiling. We do not sell end-user data. Business Users are responsible for ensuring they have proper legal basis and consent to communicate with their customers.

2.3 Information Collected Automatically

Data CategorySpecific Data PointsPurpose
Device & Browser Browser type and version, operating system, device type, screen resolution Optimize dashboard experience
Usage Data Features used, pages visited, click patterns, session duration Improve Service; analytics
Log Data IP addresses, access timestamps, referral URLs, error logs Security monitoring; debugging
Cookies & Similar Tech Session cookies, preference cookies (see Section 17) Authentication; user preferences

2.4 Information We Do NOT Collect

3 Legal Basis for Processing

We process personal data based on the following legal grounds, as required by GDPR (Article 6), India's DPDPA (Section 4), and similar regulations:

Legal BasisApplicable Processing Activities
Consent Marketing emails; optional analytics cookies; AI training on your data; processing end-user data (consent obtained by Business User)
Performance of Contract Account creation; providing the Service; processing payments; sending and receiving WhatsApp messages; customer support
Legitimate Interest Service improvement; fraud prevention; security monitoring; aggregated analytics (with safeguards ensuring your rights are not overridden)
Legal Obligation Tax compliance; responding to lawful government requests; data breach notifications

You may withdraw consent at any time where consent is the legal basis for processing. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

4 How We Use Your Information

We use the information we collect for the following specific purposes:

What we do NOT do with your data: We do not sell, rent, lease, or trade personal data. We do not use end-user message content for advertising. We do not build advertising profiles from your data or your customers' data.

5 AI Processing and Disclosure

ChatOrbit uses artificial intelligence to power automated customer responses. This section explains exactly how AI is used, what data it processes, and how we ensure transparency.

5.1 How AI Works in ChatOrbit

5.2 AI Transparency and Labeling

5.3 AI Data Safeguards

6 WhatsApp Messaging Compliance

ChatOrbit operates in strict compliance with Meta's WhatsApp Business Policy, WhatsApp Commerce Policy, and WhatsApp Business Terms of Service.

6.1 Opt-In Requirements

We require that Business Users obtain verifiable customer opt-in before sending business-initiated messages through WhatsApp. This means:

6.2 24-Hour Messaging Window

We enforce Meta's 24-hour customer service window policy:

6.3 Opt-Out Mechanism

Customers can opt out of receiving WhatsApp messages at any time by:

Business Users using ChatOrbit must honor opt-out requests promptly (within 24 hours). Our platform provides opt-out tracking and automation to help ensure compliance.

6.4 Content Restrictions

ChatOrbit enforces content policies consistent with Meta's WhatsApp Business Policy:

7 Data Sharing and Third Parties

We share personal data only when necessary and only with the categories of recipients listed below. We never sell personal data.

RecipientData SharedPurposeSafeguards
Meta / WhatsApp Messages, phone numbers, WABA credentials Deliver messages via WhatsApp Cloud API Meta's Data Processing Terms; encryption
AI Providers (OpenAI) Conversation context, training data excerpts Generate AI responses DPA; API-level data non-retention; encryption
Payment Processor (Razorpay) Billing name, email, payment details Process subscription payments PCI DSS Level 1; Razorpay Privacy Policy
Cloud Infrastructure All Service data (encrypted) Host and operate the platform SOC 2 Type II; encryption at rest; DPA
Analytics (Aggregated) Anonymized, aggregated usage data only Service improvement; performance monitoring No PII shared; aggregation and anonymization
Legal / Government As required by valid legal process Comply with law; protect rights Only upon valid court order or legal obligation

Business Transfers: In the event of a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, personal data may be transferred as part of the transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.

8 Sub-Processors

We use the following sub-processors to deliver our Service. Each has a Data Processing Agreement (DPA) in place:

Sub-ProcessorServiceLocationData Processed
Meta Platforms, Inc.WhatsApp Cloud APIUnited States / GlobalMessages, phone numbers
OpenAI, Inc.AI response generationUnited StatesConversation context
Razorpay Software Pvt. Ltd.Payment processingIndiaBilling data
MongoDB, Inc.Database hostingConfigurable regionAll application data (encrypted)

We will notify Business Users of any material changes to our sub-processor list at least 30 days in advance via email.

9 International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. When we transfer personal data internationally, we ensure appropriate safeguards are in place:

10 Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required by law.

Data TypeRetention PeriodAfter Expiry
Account data Duration of active account + 90 days after closure Permanently deleted
Customer messages & conversations 12 months from date of message Automatically purged
Order & payment data 12 months after order completion/cancellation (or as required by tax law) Automatically purged
AI training data Duration of active account + 30 days Permanently deleted
Log & analytics data 12 months Automatically purged
Billing records As required by applicable tax law (typically 5–7 years) Deleted after legal obligation expires
Support communications 24 months Automatically purged

Early Deletion: You may request deletion of your data at any time (see Section 12). We will process deletion requests within 30 days. Certain data may be retained longer where required by law (e.g., tax records, fraud prevention records).

Account Deletion: When you delete your ChatOrbit account, we will delete or anonymize all associated personal data and customer data within 30 days, except data we are legally required to retain.

11 Data Security

We implement industry-standard technical and organizational measures to protect your data:

11.1 Technical Measures

11.2 Organizational Measures

No Guarantee of Absolute Security: While we implement strong security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. In the event of a data breach, we will notify you in accordance with applicable law (see Section 20).

12 Your Rights (All Jurisdictions)

Regardless of where you are located, we provide the following rights to all users:

Right to Access

Request a copy of all personal data we hold about you in a structured, machine-readable format (CSV or JSON).

Right to Correction

Request correction of inaccurate or incomplete personal data. We will update records promptly.

Right to Deletion

Request permanent deletion of your personal data and all associated customer data. Processed within 30 days.

Right to Data Portability

Receive your data in a machine-readable format (CSV/JSON) for transfer to another service.

Right to Restrict Processing

Request that we temporarily stop processing your personal data while a dispute or request is being resolved.

Right to Withdraw Consent

Withdraw consent for any processing based on consent at any time, without affecting prior processing.

Right to Object

Object to processing based on legitimate interests. We will cease processing unless we have compelling grounds.

Right to Non-Discrimination

Exercising your privacy rights will never result in discriminatory treatment, different pricing, or reduced service quality.

How to Exercise Your Rights

Submit requests via any of the following methods:

We will acknowledge your request within 72 hours and fulfill it within 30 days. If we need more time (up to 60 additional days for complex requests), we will notify you with an explanation.

We may verify your identity before processing requests to protect your data from unauthorized access.

13 GDPR-Specific Rights (EEA/UK)

If you are located in the European Economic Area (EEA) or the United Kingdom, the following additional rights apply under the General Data Protection Regulation (GDPR) and UK GDPR:

14 CCPA/CPRA Rights (California)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

Categories of Personal Information Collected (per CCPA):

Do Not Sell or Share My Personal Information: ChatOrbit does not sell or share (as defined by CCPA/CPRA) personal information. This applies to all users, not just California residents.

To submit a CCPA request, email hirenchheta123@gmail.com with the subject line "CCPA Request". We will respond within 45 days.

15 India DPDPA Rights

If you are located in India, the following rights apply under the Digital Personal Data Protection Act, 2023 (DPDPA):

DPDPA Compliance: ChatOrbit processes personal data of Indian Data Principals only with valid consent or for legitimate uses as defined under the DPDPA. We maintain appropriate security safeguards as required under Section 8 of the Act and will notify the Data Protection Board of India and affected Data Principals in the event of a personal data breach.

16 Meta Platform Data Deletion

In compliance with Meta Platform Terms and Developer Policies, we provide the following data deletion mechanisms:

16.1 Data Deletion Request Callback

ChatOrbit implements Meta's Data Deletion Request Callback. When a user requests deletion of their data from Facebook/Meta:

16.2 Manual Data Deletion

You can also request data deletion at any time by:

16.3 Scope of Deletion

Upon receiving a valid deletion request, we delete:

Data retained for legal obligations (tax records, fraud prevention logs) will be deleted when the retention obligation expires.

17 Cookies and Tracking Technologies

17.1 Cookies We Use

Cookie TypePurposeDurationRequired?
Essential / Strictly Necessary Authentication, session management, security (CSRF protection) Session / 24 hours Yes — Service cannot function without these
Functional / Preferences Remember language preferences, theme selection (dark/light mode), dashboard settings 12 months No — but opt-out may degrade experience
Analytics (if enabled) Aggregated, anonymized usage statistics to improve Service performance 12 months No — opt-in only; requires consent

17.2 What We Do NOT Use

17.3 Managing Cookies

You can manage cookie preferences through your browser settings. Most browsers allow you to block or delete cookies. Note that blocking essential cookies will prevent you from using the Service.

18 Children's Privacy

ChatOrbit is a business-to-business (B2B) service designed for use by businesses and professionals. Our Service is NOT directed at individuals under the age of 18 (or the applicable age of majority in your jurisdiction).

This policy is consistent with the requirements of the U.S. Children's Online Privacy Protection Act (COPPA), India's DPDPA provisions on children's data, and GDPR Article 8.

19 Third-Party Links

Our Service may contain links to third-party websites, services, or applications that are not operated by us. These include, but are not limited to, Meta/WhatsApp, Razorpay, and OpenAI.

20 Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

21 Grievance Officer (India)

In compliance with India's Digital Personal Data Protection Act, 2023 (Section 13) and Information Technology Act, 2000, we have appointed a Grievance Officer:

Grievance Officer
Name: Hiren Chheta
Email: hirenchheta123@gmail.com
Response Time: Within 30 days of receiving a grievance

If you are unsatisfied with our response, you may file a complaint with the Data Protection Board of India.

22 Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

We encourage you to review this Policy periodically.

23 Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, your personal data, or our data practices, please contact us:

PurposeContact
General Privacy Inquiries hirenchheta123@gmail.com
Data Deletion Requests hirenchheta123@gmail.com (Subject: "Data Deletion Request")
GDPR / CCPA / DPDPA Rights Requests hirenchheta123@gmail.com (Subject: "[Law] Request")
Grievance Officer (India) hirenchheta123@gmail.com
General Support hirenchheta123@gmail.com
Company ChatOrbit (operated by Hiren Chheta), India
Response Times: We acknowledge all privacy-related requests within 72 hours and fulfill them within 30 days. For CCPA requests, the response period is 45 days. Complex requests may take up to 90 days with prior notification.