Privacy Policy

Last Updated: September 14, 2026

1. Introduction

Welcome to Convia(also referred to as “Convia Platform”, “we”, “our”, or “us”). We provide a multi-tenant WhatsApp customer relationship management (CRM) platform, commerce integrations, automated messaging workflows, and team communication services.

This Privacy Policy explains how we collect, use, store, disclose, and safeguard information when you use our website, mobile/web applications, and services (collectively, the “Service”), particularly when integrating with Meta Platforms, Inc. services including the Meta Graph API, WhatsApp Cloud API, and WhatsApp Business Platform.

2. Information We Collect

We collect information to provide and improve our CRM services effectively:

A. Information You Provide to Us

  • Account Information: Name, business email address, phone number, password, company name, billing details.
  • Meta / WhatsApp Business Credentials: WhatsApp Business Account (WABA) ID, Phone Number ID, App ID, Meta System User Access Tokens (securely encrypted at rest), and WhatsApp Template messages.
  • CRM & Contact Data: Customer contact lists, phone numbers, customer attributes, notes, tags, and conversation labels that you or your authorized team upload or receive.

B. Information Processed via Meta / WhatsApp API

  • Message Content & Metadata: Incoming and outgoing WhatsApp text messages, media attachments (images, documents, audio, video), message status indicators (sent, delivered, read, failed), and timestamps received via Meta Webhooks.
  • Customer Identifiers: WhatsApp phone numbers (E.164 formatted), display names, profile identifiers provided by Meta webhooks.

C. Technical & Usage Data

  • Log Information: IP addresses, browser type, operating system, access timestamps, API request logs, and error telemetry.

3. How We Use Your Information

We process collected data exclusively for legitimate business and service delivery purposes, including:

  • Providing the CRM & Messaging Platform: Transmitting, receiving, routing, and displaying WhatsApp messages between your business and your end-customers.
  • Automations & Workflows: Executing automated messaging workflows, interactive reply bots, and message broadcasting as configured by you.
  • Multi-Tenant Isolation: Ensuring strict tenant separation so that customer records and credentials are isolated using tenant-level identifiers (Row Level Security).
  • Template & Media Management: Syncing WhatsApp message templates and processing media attachments with Meta APIs.
  • AI & Copilot Assistance: Providing context-aware message drafts, summaries, and suggestions when requested by authorized operators within your tenant.
  • Security & Compliance: Verifying Meta webhook signatures (X-Hub-Signature-256), authenticating API requests, detecting fraudulent activity, and ensuring system reliability.

4. Information Sharing & Disclosure

We do not sell, rent, or trade your personal data or your customers' messaging data to third parties or advertisers.

We only share information with third parties under the following conditions:

  • Meta Platforms, Inc.: Data transmitted through WhatsApp messaging is processed in accordance with Meta's WhatsApp Business Platform terms and APIs.
  • Infrastructure & Service Providers: Cloud infrastructure, database hosting (e.g., Supabase / PostgreSQL), secure storage, and authentication providers acting under strict data protection agreements.
  • Legal & Regulatory Compliance: If required by law, subpoena, court order, or to protect the rights, safety, or property of our users or the public.

5. Data Security and Storage

We implement industry-standard security measures to safeguard your information:

  • Encryption in Transit & at Rest: All data transmitted over the internet uses TLS/HTTPS encryption. Sensitive credentials such as Meta access tokens and webhook secrets are encrypted at rest.
  • Tenant Isolation: Strict Row Level Security (RLS) policies isolate tenant data at the database layer.
  • Webhook Signature Verification: All inbound Meta webhooks are cryptographically validated using HMAC SHA-256 signatures before processing.

6. Data Retention and User Data Deletion Instructions

We retain personal data only for as long as necessary to provide our CRM services or as required by applicable laws and regulations.

How to Request User Data Deletion (Meta Data Deletion Callback / Request)

In accordance with Meta Platform policies, users have the right to request the deletion of their personal data processed by our application:

  1. Self-Service: Workspace administrators can delete contacts, chat histories, or disconnect their Meta / WhatsApp Business Account directly within the Dashboard settings.
  2. Written Request: Send an email to privacy@convia.app or support@convia.app with the subject line “Data Deletion Request”, providing your registered email and workspace identifier.
  3. Processing Timeline: We will acknowledge your request within 48 hours and permanently delete or anonymize your stored data from our active databases within 30 days.

7. Your Privacy Rights (GDPR & CCPA)

Depending on your jurisdiction, you have the following rights regarding your data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete information.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data.
  • Right to Restriction / Objection: Object to or restrict certain processing of your data.
  • Right to Data Portability: Request export of your data in a structured, machine-readable format.

8. Children's Privacy

Our Service is intended solely for business users and is not directed to individuals under the age of 16. We do not knowingly collect personal information from children.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When changes are made, we will update the “Last Updated” date at the top of this page. Significant changes will be communicated via email or through the platform interface.

10. Contact Us

If you have questions, comments, or requests regarding this Privacy Policy or our data handling practices, please contact us at:

Convia Data Protection Officer

Email: privacy@convia.app

Support: support@convia.app

← Back to Home© 2026 Convia Platform