Privacy Policy
We are committed to protecting your privacy and handling your personal data transparently and responsibly.
Effective date: February 13, 2026 · Last updated: August 7, 2026
Important Notice
Please read this Privacy Policy carefully before using our services. By accessing or using Cincht, you acknowledge that you have read, understood, and agree to be bound by this policy. If you do not agree with any part of this Privacy Policy, you must not use our service.
1. What This Policy Covers
This Privacy Policy applies to the Cincht WhatsApp Business Platform ("Service"), operated by Cincht Inc. ("Cincht", "we", "us", or "our"). It covers our website, web applications, APIs, and all related services. It explains:
- What personal information we collect from you and why
- How we use, store, and share that information
- Our role as a data controller (for account and billing data) and a data processor (for WhatsApp messaging data you manage on our platform)
- Your rights regarding your personal data
- Our practices regarding cookies and similar technologies
This policy does not apply to third-party services — including Meta Platforms, Inc. (WhatsApp), Stripe, Paystack, Flutterwave, or other integrations — that you connect to the Service. Those services have their own privacy policies which we encourage you to review.
Cincht is a registered WhatsApp Business Solution Provider (BSP) and acts as a technology intermediary between Meta's WhatsApp Business API and businesses that use our platform. As such, we are subject to Meta's Business Policy, Data Policy, and WhatsApp Business Policy, in addition to applicable data protection laws.
2. Information We Collect
2.1 Account Information (Data Controller)
When you sign up or use the Service as a business customer, we collect data for which we act as the data controller:
- Account credentials (name, email address, password)
- Business profile (company name, address, industry, website, VAT/tax number)
- Phone number associated with your WhatsApp Business Account (WABA)
- Billing and payment details (processed via third-party providers; we do not store card numbers)
- Communications with our support team
2.2 Automatically Collected Platform Data
- Usage data (features accessed, session duration, page navigation, clicks)
- Device and browser metadata (IP address, browser type and version, operating system, device identifiers)
- Log data (access timestamps, API calls, errors encountered)
- Cookies and similar tracking technologies (see Section 12)
2.3 WhatsApp Messaging Data (Data Processor)
When you use Cincht to send or receive WhatsApp messages on behalf of your business, we process the following data as your data processor — meaning this data is yours, and we act only on your documented instructions:
- Message content (text, images, documents, templates, interactive replies)
- Contact information of your end users (WhatsApp phone numbers, display names, profile pictures)
- Message delivery metadata (status updates: sent, delivered, read, failed; timestamps)
- Conversation history, labels, notes, and assignment data
- Broadcast campaign data and contact segmentation lists
- Automation flow triggers, conditions, and outcomes
Your end users' personal data processed through WhatsApp is subject to Meta's Privacy Policy in addition to your own privacy commitments to those users. You are responsible for ensuring you have lawful basis and appropriate consent to message your contacts via WhatsApp Business API.
2.4 Data You Provide for Platform Tools
- Message templates submitted for Meta's pre-approval process
- Contact import files (CSV, spreadsheets) for campaigns
- Webhook configurations and API keys for your integrations
- Chatbot flows, AI prompts, and knowledge base content
3. Legal Basis for Processing
For individuals in the European Economic Area (EEA), United Kingdom, or other jurisdictions that require a documented legal basis for data processing, we process your personal data on the following grounds:
- Performance of a ContractProcessing your account information, managing your subscription, and providing the core platform functionality. This is the primary basis for all data we process as data controller.
- Legitimate InterestsSecurity monitoring, fraud prevention, platform improvement, analytics (where anonymised), and ensuring the integrity of our service. We balance these interests against your rights and freedoms.
- Legal ObligationCompliance with applicable laws (tax, anti-money laundering, court orders), Meta's Business Policy requirements, and regulatory mandates.
- ConsentMarketing communications and non-essential cookies. You may withdraw consent at any time. For WhatsApp messaging data we process as your data processor, consent is governed by your own data processing agreements with your end users.
4. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provision, operate, maintain, and improve the platform and all its features
- WhatsApp API Operations: To route messages, manage your WABA credentials, process template submissions to Meta, and handle webhook events from WhatsApp
- Billing: To process subscription payments, issue invoices, manage wallet top-ups, and pass through Meta's per-conversation charges
- Support & Communications: To respond to support tickets, send service alerts, security notices, and product updates
- Safety & Compliance: To detect, prevent, and address fraud, spam, abuse, policy violations, and security incidents — including compliance with Meta's policies as a BSP
- Platform Analytics: To understand aggregate usage patterns and improve user experience (using anonymised or aggregated data where possible)
- Legal Compliance: To comply with applicable laws, respond to lawful requests from authorities, and enforce our terms
- Marketing: To send promotional content and product news where you have opted in (always with an unsubscribe option)
We do not use WhatsApp messaging data processed on your behalf (Section 2.3) for our own marketing, analytics, or product development. That data is used exclusively to provide the Service to you.
5. WhatsApp & Meta Data Processing
5.1 Our Role as a WhatsApp Business Solution Provider
Cincht is an authorised WhatsApp Business Solution Provider (BSP) through Meta's official partner programme. In this capacity:
- We access the WhatsApp Business API on behalf of our customers under Meta's BSP programme agreement
- All message traffic passes through Meta's infrastructure; Cincht provides the management layer on top
- We are bound by Meta's Data Policy, Business Policy, and WhatsApp Business Policy as conditions of our BSP status
- Meta's Privacy Policy governs how Meta processes data on its own systems — we cannot control or override Meta's data practices
5.2 Data Processing Agreement
When you use Cincht to process WhatsApp messaging data that contains personal data of your end users, Cincht acts as your data processor and you are the data controller. Our Data Processing Agreement (DPA), which governs this relationship, is incorporated into our Terms of Service. For enterprise contracts, a separately executed DPA is available on request at privacy@cincht.com.
5.3 Your Obligations to Your End Users
As the data controller for your customers' WhatsApp conversations, you are responsible for:
- Obtaining valid, informed consent from your end users before sending them WhatsApp messages
- Maintaining an opt-in record for each contact you message via the platform
- Providing your end users with a clear and accessible privacy notice covering your WhatsApp communications
- Honouring opt-out and deletion requests from your end users promptly
- Ensuring all messages comply with Meta's Messaging Policy and your local laws
5.4 Meta as Sub-Processor
By using the WhatsApp Business API through Cincht, you authorise Cincht to engage Meta Platforms, Inc. as a sub-processor for message delivery, template approval, and related API services. Meta's data processing activities are governed by Meta's Business Tools Data Processing Terms and Meta's Data Policy, which are independent of Cincht's obligations under this Policy.
5.5 Phone Number Lookup Tool
If you use our WhatsApp number validation tool (/validate), any phone number you submit is sent to the WhatsApp Business API to check registration status. We log lookup requests (IP address, timestamp, number format — not the exact number) for rate-limiting purposes only. Lookup results are not stored beyond the session.
7. Data Retention
We retain your data only for as long as necessary for the purposes set out in this Policy, or as required by law.
| Data Type | Retention Period |
|---|---|
| Account & profile data | Duration of account + 30 days after deletion |
| Billing & invoice records | 7 years (legal/tax obligation) |
| WhatsApp message history | 12 months rolling (configurable per plan) |
| Broadcast campaign data | 12 months after campaign end |
| Contact lists & CRM data | Until deleted by you or account deletion |
| API access logs | 90 days |
| Security & audit logs | 12 months |
| Support ticket content | 3 years |
| Cookies (session) | Session end |
| Cookies (analytics) | Up to 13 months |
Upon account termination, we will retain your data for 30 days to allow for recovery or data export requests, after which all data is securely deleted unless a longer retention period is required by applicable law.
8. Data Security
We implement industry-standard technical and organisational measures to protect your personal information. These include:
- TLS 1.3 encryption for all data in transit between your browser, our servers, and the WhatsApp API
- AES-256 encryption for sensitive data at rest (including WhatsApp access tokens and API credentials)
- Role-based access controls (RBAC) ensuring your workspace data is accessible only to your authorised team members and Cincht engineers with a documented need
- Multi-factor authentication (MFA) available and recommended for all accounts
- Regular third-party penetration testing and vulnerability assessments
- 24/7 automated security monitoring, anomaly detection, and incident response procedures
- Geographically redundant, SOC 2-compliant data centre infrastructure
No method of transmission over the internet is 100% secure. While we employ best-in-class security, we encourage you to use a strong, unique password and enable two-factor authentication on your account.
In the event of a data breach that is likely to result in risk to your rights or freedoms, we will notify affected users and, where required by law (e.g., GDPR Article 33), the relevant supervisory authority within 72 hours of becoming aware.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@cincht.com. We will respond within 30 days (or within 1 month under GDPR). We may ask you to verify your identity before fulfilling any request.
- Access (Art. 15 GDPR)Request a copy of the personal data we hold about you, including how it is processed and with whom it is shared.
- Rectification (Art. 16)Correct inaccurate or incomplete personal data. You can update most account information directly in your settings.
- Erasure (Art. 17)Request deletion of your personal data (the 'right to be forgotten'), subject to our legal retention obligations (e.g., billing records).
- Data Portability (Art. 20)Receive your data in a structured, machine-readable format (JSON or CSV). Use the export tool in your account settings or submit a request.
- Objection (Art. 21)Object to processing based on legitimate interests, including direct marketing. We will stop processing unless we have compelling legitimate grounds.
- Restriction (Art. 18)Request that we restrict processing of your data in certain circumstances, such as while a dispute is being resolved.
- Withdraw ConsentWhere processing is based on consent, withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
- Lodge a ComplaintFile a complaint with your local supervisory authority (e.g., the ICO in the UK, or your EEA national DPA).
Note for WhatsApp end users: If you are an end user who received messages from a business using Cincht, your personal data is controlled by that business, not Cincht. Please contact the business directly to exercise your data rights. Cincht processes that data only as their processor.
10. California Residents — CCPA Notice
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights. This section supplements the rest of this Privacy Policy.
Categories of Personal Information Collected
In the past 12 months, we have collected the following categories (as defined by the CCPA):
- Identifiers (name, email, IP address, account IDs)
- Commercial information (subscription plan, billing history)
- Internet or other electronic network activity (usage data, log data)
- Professional or employment-related information (company name, job role)
- Inferences drawn from the above (account health, feature usage patterns)
Your CCPA Rights
- Right to Know: Request disclosure of the categories and specific pieces of personal information collected about you
- Right to Delete: Request deletion of personal information, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt Out of Sale/Sharing: We do not sell or share personal information for cross-context behavioural advertising
- Right to Limit Use of Sensitive PI: We do not use sensitive personal information for purposes other than providing the Service
- Right of Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
To submit a CCPA request, contact us at privacy@cincht.com with "CCPA Request" in the subject line. We will respond within 45 days, with a possible 45-day extension where reasonably necessary.
11. International Data Transfers
Cincht operates globally and your personal data may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have data protection laws that differ from those in your jurisdiction.
Where we transfer data from the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreements (IDTAs) where applicable
- Transfer Impact Assessments (TIAs) for high-risk transfers
- Adequacy decisions issued by the European Commission
A copy of the applicable transfer mechanism can be provided on request at privacy@cincht.com.
13. Children's Privacy
Cincht is a business-to-business platform not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that a child under 18 has provided personal data, we will take prompt steps to delete that information.
If you believe we have inadvertently collected information from a minor, please contact us immediately at privacy@cincht.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements (including Meta's BSP programme requirements), or for other operational reasons. When we make material changes, we will:
- Post the updated policy on this page with a new "Last updated" date
- Notify account holders by email at least 14 days before material changes take effect
- Where required by law, seek renewed consent for changes that materially affect how we process personal data
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of any changes constitutes acceptance of the updated policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices — including requests to exercise your data rights or inquiries about our BSP data processing obligations — please reach out to our Privacy team:
Privacy Email: privacy@cincht.com
Data Protection Officer: dpo@cincht.com
Website: cincht.com/contact
Address: Cincht Inc., San Francisco, CA, USA
We aim to respond to all privacy enquiries within 5 business days, and to complete data subject requests within 30 days (or as required by applicable law).
