Legal

Privacy Policy

We are committed to protecting your privacy and handling your personal data transparently and responsibly.

Effective date: February 13, 2026 ·  Last updated: August 7, 2026

Important Notice

Please read this Privacy Policy carefully before using our services. By accessing or using Cincht, you acknowledge that you have read, understood, and agree to be bound by this policy. If you do not agree with any part of this Privacy Policy, you must not use our service.

1. What This Policy Covers

This Privacy Policy applies to the Cincht WhatsApp Business Platform ("Service"), operated by Cincht Inc. ("Cincht", "we", "us", or "our"). It covers our website, web applications, APIs, and all related services. It explains:

  • What personal information we collect from you and why
  • How we use, store, and share that information
  • Our role as a data controller (for account and billing data) and a data processor (for WhatsApp messaging data you manage on our platform)
  • Your rights regarding your personal data
  • Our practices regarding cookies and similar technologies

This policy does not apply to third-party services — including Meta Platforms, Inc. (WhatsApp), Stripe, Paystack, Flutterwave, or other integrations — that you connect to the Service. Those services have their own privacy policies which we encourage you to review.

Cincht is a registered WhatsApp Business Solution Provider (BSP) and acts as a technology intermediary between Meta's WhatsApp Business API and businesses that use our platform. As such, we are subject to Meta's Business Policy, Data Policy, and WhatsApp Business Policy, in addition to applicable data protection laws.


2. Information We Collect

2.1 Account Information (Data Controller)

When you sign up or use the Service as a business customer, we collect data for which we act as the data controller:

  • Account credentials (name, email address, password)
  • Business profile (company name, address, industry, website, VAT/tax number)
  • Phone number associated with your WhatsApp Business Account (WABA)
  • Billing and payment details (processed via third-party providers; we do not store card numbers)
  • Communications with our support team

2.2 Automatically Collected Platform Data

  • Usage data (features accessed, session duration, page navigation, clicks)
  • Device and browser metadata (IP address, browser type and version, operating system, device identifiers)
  • Log data (access timestamps, API calls, errors encountered)
  • Cookies and similar tracking technologies (see Section 12)

2.3 WhatsApp Messaging Data (Data Processor)

When you use Cincht to send or receive WhatsApp messages on behalf of your business, we process the following data as your data processor — meaning this data is yours, and we act only on your documented instructions:

  • Message content (text, images, documents, templates, interactive replies)
  • Contact information of your end users (WhatsApp phone numbers, display names, profile pictures)
  • Message delivery metadata (status updates: sent, delivered, read, failed; timestamps)
  • Conversation history, labels, notes, and assignment data
  • Broadcast campaign data and contact segmentation lists
  • Automation flow triggers, conditions, and outcomes

Your end users' personal data processed through WhatsApp is subject to Meta's Privacy Policy in addition to your own privacy commitments to those users. You are responsible for ensuring you have lawful basis and appropriate consent to message your contacts via WhatsApp Business API.

2.4 Data You Provide for Platform Tools

  • Message templates submitted for Meta's pre-approval process
  • Contact import files (CSV, spreadsheets) for campaigns
  • Webhook configurations and API keys for your integrations
  • Chatbot flows, AI prompts, and knowledge base content


4. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provision, operate, maintain, and improve the platform and all its features
  • WhatsApp API Operations: To route messages, manage your WABA credentials, process template submissions to Meta, and handle webhook events from WhatsApp
  • Billing: To process subscription payments, issue invoices, manage wallet top-ups, and pass through Meta's per-conversation charges
  • Support & Communications: To respond to support tickets, send service alerts, security notices, and product updates
  • Safety & Compliance: To detect, prevent, and address fraud, spam, abuse, policy violations, and security incidents — including compliance with Meta's policies as a BSP
  • Platform Analytics: To understand aggregate usage patterns and improve user experience (using anonymised or aggregated data where possible)
  • Legal Compliance: To comply with applicable laws, respond to lawful requests from authorities, and enforce our terms
  • Marketing: To send promotional content and product news where you have opted in (always with an unsubscribe option)

We do not use WhatsApp messaging data processed on your behalf (Section 2.3) for our own marketing, analytics, or product development. That data is used exclusively to provide the Service to you.


5. WhatsApp & Meta Data Processing

5.1 Our Role as a WhatsApp Business Solution Provider

Cincht is an authorised WhatsApp Business Solution Provider (BSP) through Meta's official partner programme. In this capacity:

  • We access the WhatsApp Business API on behalf of our customers under Meta's BSP programme agreement
  • All message traffic passes through Meta's infrastructure; Cincht provides the management layer on top
  • We are bound by Meta's Data Policy, Business Policy, and WhatsApp Business Policy as conditions of our BSP status
  • Meta's Privacy Policy governs how Meta processes data on its own systems — we cannot control or override Meta's data practices

5.2 Data Processing Agreement

When you use Cincht to process WhatsApp messaging data that contains personal data of your end users, Cincht acts as your data processor and you are the data controller. Our Data Processing Agreement (DPA), which governs this relationship, is incorporated into our Terms of Service. For enterprise contracts, a separately executed DPA is available on request at privacy@cincht.com.

5.3 Your Obligations to Your End Users

As the data controller for your customers' WhatsApp conversations, you are responsible for:

  • Obtaining valid, informed consent from your end users before sending them WhatsApp messages
  • Maintaining an opt-in record for each contact you message via the platform
  • Providing your end users with a clear and accessible privacy notice covering your WhatsApp communications
  • Honouring opt-out and deletion requests from your end users promptly
  • Ensuring all messages comply with Meta's Messaging Policy and your local laws

5.4 Meta as Sub-Processor

By using the WhatsApp Business API through Cincht, you authorise Cincht to engage Meta Platforms, Inc. as a sub-processor for message delivery, template approval, and related API services. Meta's data processing activities are governed by Meta's Business Tools Data Processing Terms and Meta's Data Policy, which are independent of Cincht's obligations under this Policy.

5.5 Phone Number Lookup Tool

If you use our WhatsApp number validation tool (/validate), any phone number you submit is sent to the WhatsApp Business API to check registration status. We log lookup requests (IP address, timestamp, number format — not the exact number) for rate-limiting purposes only. Lookup results are not stored beyond the session.


6. Data Sharing & Disclosure

We do not sell your personal information. We may share your information only in the following limited circumstances:

  • Meta Platforms, Inc.As required for WhatsApp Business API access, message delivery, template management, and BSP programme compliance. Meta is an authorised sub-processor. See Section 5.
  • Infrastructure & Hosting ProvidersCloud hosting (e.g., AWS, Vercel), database, and CDN providers necessary to operate the Service. These providers are bound by data processing agreements and may not use your data for their own purposes.
  • Payment ProcessorsStripe, Paystack, and Flutterwave process payment transactions on our behalf. They are PCI-DSS compliant and operate under their own privacy policies.
  • Analytics & MonitoringAnonymised or aggregated usage metrics may be shared with analytics providers to improve the Service. No personally identifiable messaging data is used for this purpose.
  • Legal AuthoritiesWhen required by applicable law, regulation, court order, or to protect the rights and safety of Cincht, our users, or the public. We will notify you where legally permitted to do so.
  • Business TransfersIn connection with a merger, acquisition, financing due diligence, or sale of business assets, subject to appropriate confidentiality protections.
  • With Your ConsentIn any other circumstance where you have explicitly authorised the disclosure.

7. Data Retention

We retain your data only for as long as necessary for the purposes set out in this Policy, or as required by law.

Data TypeRetention Period
Account & profile dataDuration of account + 30 days after deletion
Billing & invoice records7 years (legal/tax obligation)
WhatsApp message history12 months rolling (configurable per plan)
Broadcast campaign data12 months after campaign end
Contact lists & CRM dataUntil deleted by you or account deletion
API access logs90 days
Security & audit logs12 months
Support ticket content3 years
Cookies (session)Session end
Cookies (analytics)Up to 13 months

Upon account termination, we will retain your data for 30 days to allow for recovery or data export requests, after which all data is securely deleted unless a longer retention period is required by applicable law.


8. Data Security

We implement industry-standard technical and organisational measures to protect your personal information. These include:

  • TLS 1.3 encryption for all data in transit between your browser, our servers, and the WhatsApp API
  • AES-256 encryption for sensitive data at rest (including WhatsApp access tokens and API credentials)
  • Role-based access controls (RBAC) ensuring your workspace data is accessible only to your authorised team members and Cincht engineers with a documented need
  • Multi-factor authentication (MFA) available and recommended for all accounts
  • Regular third-party penetration testing and vulnerability assessments
  • 24/7 automated security monitoring, anomaly detection, and incident response procedures
  • Geographically redundant, SOC 2-compliant data centre infrastructure

No method of transmission over the internet is 100% secure. While we employ best-in-class security, we encourage you to use a strong, unique password and enable two-factor authentication on your account.

In the event of a data breach that is likely to result in risk to your rights or freedoms, we will notify affected users and, where required by law (e.g., GDPR Article 33), the relevant supervisory authority within 72 hours of becoming aware.


9. Your Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@cincht.com. We will respond within 30 days (or within 1 month under GDPR). We may ask you to verify your identity before fulfilling any request.

  • Access (Art. 15 GDPR)Request a copy of the personal data we hold about you, including how it is processed and with whom it is shared.
  • Rectification (Art. 16)Correct inaccurate or incomplete personal data. You can update most account information directly in your settings.
  • Erasure (Art. 17)Request deletion of your personal data (the 'right to be forgotten'), subject to our legal retention obligations (e.g., billing records).
  • Data Portability (Art. 20)Receive your data in a structured, machine-readable format (JSON or CSV). Use the export tool in your account settings or submit a request.
  • Objection (Art. 21)Object to processing based on legitimate interests, including direct marketing. We will stop processing unless we have compelling legitimate grounds.
  • Restriction (Art. 18)Request that we restrict processing of your data in certain circumstances, such as while a dispute is being resolved.
  • Withdraw ConsentWhere processing is based on consent, withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
  • Lodge a ComplaintFile a complaint with your local supervisory authority (e.g., the ICO in the UK, or your EEA national DPA).

Note for WhatsApp end users: If you are an end user who received messages from a business using Cincht, your personal data is controlled by that business, not Cincht. Please contact the business directly to exercise your data rights. Cincht processes that data only as their processor.


10. California Residents — CCPA Notice

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights. This section supplements the rest of this Privacy Policy.

Categories of Personal Information Collected

In the past 12 months, we have collected the following categories (as defined by the CCPA):

  • Identifiers (name, email, IP address, account IDs)
  • Commercial information (subscription plan, billing history)
  • Internet or other electronic network activity (usage data, log data)
  • Professional or employment-related information (company name, job role)
  • Inferences drawn from the above (account health, feature usage patterns)

Your CCPA Rights

  • Right to Know: Request disclosure of the categories and specific pieces of personal information collected about you
  • Right to Delete: Request deletion of personal information, subject to certain exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioural advertising
  • Right to Limit Use of Sensitive PI: We do not use sensitive personal information for purposes other than providing the Service
  • Right of Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

To submit a CCPA request, contact us at privacy@cincht.com with "CCPA Request" in the subject line. We will respond within 45 days, with a possible 45-day extension where reasonably necessary.


11. International Data Transfers

Cincht operates globally and your personal data may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from those in your jurisdiction.

Where we transfer data from the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreements (IDTAs) where applicable
  • Transfer Impact Assessments (TIAs) for high-risk transfers
  • Adequacy decisions issued by the European Commission

A copy of the applicable transfer mechanism can be provided on request at privacy@cincht.com.


12. Cookies

We use cookies and similar tracking technologies to operate the Service, analyse platform usage, and personalise your experience. We use the following categories of cookies:

  • Strictly Necessary: Essential to authenticate users, maintain sessions, and prevent fraud. Cannot be disabled.
  • Functional: Remember your preferences (language, dark mode, sidebar state). Disabled without meaningful impact to core features.
  • Analytics: Aggregate usage statistics to improve the platform. We use anonymised data only.
  • Marketing: Track visits from advertising campaigns. Used only with your explicit consent.

You can manage cookie preferences through your browser settings or our cookie consent banner. For full details, see our Cookie Policy.


13. Children's Privacy

Cincht is a business-to-business platform not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that a child under 18 has provided personal data, we will take prompt steps to delete that information.

If you believe we have inadvertently collected information from a minor, please contact us immediately at privacy@cincht.com.


14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements (including Meta's BSP programme requirements), or for other operational reasons. When we make material changes, we will:

  • Post the updated policy on this page with a new "Last updated" date
  • Notify account holders by email at least 14 days before material changes take effect
  • Where required by law, seek renewed consent for changes that materially affect how we process personal data

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of any changes constitutes acceptance of the updated policy.


15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices — including requests to exercise your data rights or inquiries about our BSP data processing obligations — please reach out to our Privacy team:

Privacy Email: privacy@cincht.com

Data Protection Officer: dpo@cincht.com

Website: cincht.com/contact

Address: Cincht Inc., San Francisco, CA, USA

We aim to respond to all privacy enquiries within 5 business days, and to complete data subject requests within 30 days (or as required by applicable law).