Privacy Policy
Last updated: July 18, 2026
Wazza ("Wazza", "we", "us") provides a no-code platform that lets businesses build automated WhatsApp conversations, manage a team inbox, and send broadcasts using the official WhatsApp Business Platform by Meta. This policy explains what data we collect, why we collect it, how we protect it, and the choices you have. It applies to our website (wazza.co.il), the Wazza application, and the services around them (together, the "Service").
1. Data we collect
Account data. When you create an account we collect your name, email address, and a password (stored only as a salted hash). If you sign in with Facebook we do not receive or store your Facebook password.
Data received from Meta Platforms. When you connect Facebook or WhatsApp we receive, through Meta's official APIs:
- From Facebook Login for Business: your app-scoped Facebook user ID and, where available, your name. We use these solely to create and authenticate your Wazza account.
- From the WhatsApp Business Platform: your WhatsApp Business Account (WABA) ID, phone number ID, display phone number, verified business name, and the access tokens required to operate your number on your behalf.
- Messages. Message content and metadata exchanged between your WhatsApp Business number and your customers, delivered to us by Meta's webhooks so we can power your inbox, bots, and analytics.
Usage and technical data. Standard log data (IP address, browser type, pages viewed) and cookies needed to keep you signed in.
Billing data. Payments are processed by our payment provider; we do not store full card numbers.
2. How we use data
- To provide, operate, and secure the Service.
- To power the features you configure: chatbots, team inbox, broadcasts, templates, and analytics.
- To communicate with you about your account (verification emails, security notices, service updates).
- To comply with legal obligations and enforce our Terms of Service.
We do not sell personal data, and we do not use your customers' message content for advertising. Data received from Meta's platforms is used only to provide the Service to you, in accordance with the Meta Platform Terms and the WhatsApp Business Terms of Service.
3. How data is stored and protected
- WhatsApp and Facebook access tokens are encrypted at rest (AES-256-GCM) and are never exposed to browsers or third parties.
- Passwords are stored as salted bcrypt hashes; we never store them in plain text.
- All traffic between your browser, our servers, and Meta's APIs is encrypted in transit (TLS).
- Webhook traffic from Meta is verified with cryptographic signatures before it is processed.
- Access to production data is restricted to authorized personnel who need it to operate the Service.
4. Sharing and sub-processors
We share data only with service providers that help us run the Service - cloud hosting and databases, object storage for media files, payment processing, email delivery, and AI processing for features you explicitly invoke (for example, the AI bot builder). These providers process data on our instructions. We also exchange data with Meta Platforms as required to operate Facebook Login and the WhatsApp Business Platform. We may disclose data if required by law.
5. Data retention
We keep your data for as long as your account is active. When your account is deleted, associated personal data - including data received from Meta platforms, conversation history, and encrypted tokens - is deleted or irreversibly anonymized within 30 days, except where a longer retention period is required by law (for example, billing records).
6. Your rights and data deletion
You may access, correct, export, or delete your personal data. Businesses on Wazza can also delete individual customer contacts and their conversation history from within the product, and export contact data for GDPR requests.
To request deletion of your data, use any of the following:
- In the product: Settings → your account → delete account, or contact us from the email address on your account.
- By email: send a deletion request to privacy@wazza.co.il. We confirm completion within 30 days.
- If you used Facebook Login: you can also remove Wazza from your Facebook settings (Settings & privacy → Settings → Apps and websites → Wazza → Remove). Removing the app revokes our access; to have the data we already hold deleted as well, contact us as described above and we will delete it within 30 days.
Full step-by-step instructions are also available on our data deletion page.
7. Cookies
We use strictly necessary cookies to keep you signed in (session cookies) and to protect against cross-site request forgery. We do not use third-party advertising cookies on the Service.
8. Children
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children.
9. International transfers
Our infrastructure providers may process data in the European Union, the United States, and Israel. Where data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses provided by our sub-processors.
10. Changes to this policy
We may update this policy from time to time. Material changes will be announced on this page with an updated "Last updated" date, and where appropriate by email.
11. Contact
Wazza Ltd · Israel · privacy@wazza.co.il