BrandlyPro← Back to site

Privacy Policy

BrandlyPro · Last updated 2026-07-29

Draft — not in forceThis document is a working scaffold. It has not been reviewed by a lawyer and is not a binding statement of BrandlyPro’s practices. Highlighted values still need to be decided. Do not submit this URL for Meta App Review, and do not rely on it, until this notice is removed.

1. Who we are

BrandlyPro (“we”, “us”) provides software that connects a business to the WhatsApp Business Platform. You can reach us at neeraj@brandlypro.com or +91 77018 22010.

Registered address: [ registered address, exactly as on the GST certificate ]. Grievance officer for DPDP purposes: [ name and email ].

2. Two different roles

This distinction decides which rights apply to whom, so it comes first.

  • For our customers’ account data — the people who sign up and use the software — we are the controller. We decide what is collected and why.
  • For the WhatsApp messages our customers send and receive — including the phone numbers and message content of the people they talk to — we are a processor. The customer is the controller. We handle that data only to run the service on their instruction.

If you are a member of the public who messaged a business using our software, your request should go to that business. If you contact us instead, we will pass it on. [ Confirm this routing with counsel — some regimes require a direct response ].

3. What we collect

Account data (we are the controller)

  • Name, email address, and password credentials for each user profile.
  • Business account details, team membership, and invitations.
  • WhatsApp Business Account and phone number identifiers issued by Meta, plus access tokens for the numbers you connect.
  • Product usage and onboarding events, used to measure activation.
  • Billing records. [ Describe exactly what the payment processor returns to us and what we store ].

Customer message data (we are a processor)

  • Contacts: phone number, name, email, tags, notes, and any custom fields the customer defines.
  • Conversations and messages, including message content, media references, delivery and read status, and reactions.
  • Broadcasts, templates, automations, flows, and their execution logs.
  • Pipelines and deals, where the customer uses them.

We do not sell personal data, and we do not use message content to train machine-learning models. [ If AI reply features process message content through a third-party model, that must be disclosed here explicitly, naming the provider ].

4. Where data is stored

Application data is stored in a managed PostgreSQL database hosted by Supabase in the ap-southeast-2 (Sydney, Australia) region. If you are in India, this means your data is transferred and stored outside India. [ Confirm this is acceptable under the DPDP Act for your customer base, or plan a migration to an Indian region — this is a decision, not a wording choice ].

Access tokens for connected WhatsApp accounts are encrypted at rest. Tenant data is separated by row-level security policies so one customer account cannot read another’s rows.

5. Who else processes data

ProcessorPurposeLocation
Meta PlatformsWhatsApp Business Platform — message deliveryPer Meta’s terms
SupabaseDatabase, authentication, file storageap-southeast-2
[ Payment processor ]Subscription billing[ region ]
[ Email / any analytics or error-tracking provider ][ purpose ][ region ]

Note that message charges are billed to the customer by Meta directly. We do not process message payments and therefore hold no card data for them.

6. How long we keep it

[ Set a retention period for each category: account data after closure, message history, automation and delivery logs, billing records (Indian tax law generally requires 8 years), and backups ]. State the period, not “as long as necessary” — regulators increasingly reject that phrasing.

7. Your rights

Under the Digital Personal Data Protection Act, 2023, you may request access to your personal data, correction of it, erasure, and you may nominate someone to exercise these rights on your behalf. Write to neeraj@brandlypro.com.

[ State the response window you commit to, and the grievance-redressal escalation path the DPDP Act requires ].[ If you serve customers in the EU or UK, add the GDPR lawful bases and the right to lodge a complaint with a supervisory authority ].

8. Deleting your data

The account owner can delete the account from Settings → Delete account. The account is locked immediately and the data is permanently deleted 30 days later; within that window it can still be restored on request. Full instructions, including what we cannot delete for you, are on the data deletion page. [ Describe the encrypted-backup window after the 30-day purge — check the Supabase project’s actual backup schedule ].

[ Meta App Review requires a dedicated data-deletion instructions URL — add /data-deletion and link it here ].

9. Cookies

We set cookies required to keep you signed in and to remember interface preferences such as theme. We do not use advertising cookies. [ If any analytics tool is added, list it here and add a consent mechanism ].

10. Changes

We will update the date at the top of this page when this policy changes. [ Commit to a notice period for material changes ].

11. Contact

Questions about this policy: neeraj@brandlypro.com.

© 2026 BrandlyProPrivacy · Terms · Refunds · Delete my data · neeraj@brandlypro.com