We use account, company and WhatsApp connection information to provide and secure the service. We do not sell personal information or use WhatsApp customer data for unrelated advertising.
Scope and operator
This Privacy Policy applies to the Revault WhatsApp API platform, websites, dashboards, APIs and related support services operated under the Revault brand (collectively, the “Service”). It covers company administrators, team members, developers and other people who access the Service.
Companies using Revault remain responsible for the messages they send, their contact lists, their lawful basis for messaging and the privacy notices they provide to their customers. For customer messaging data, Revault generally acts on the company’s instructions to provide the requested service.
Information we collect
Account and identity information
We process email addresses, names, one-time sign-in verification records, session information, team membership, roles and account status.
Company information
We process company name, business email, website, country, industry, plan, seat allocation, approval status and administrator records.
WhatsApp connection and service information
When a company connects WhatsApp, we may process WhatsApp Business Account identifiers, phone-number identifiers, display phone number, verified business name, number quality status, template information, webhook events and Meta authorization information.
API and operational information
We process API-key identifiers and hashes, message identifiers, sender or recipient numbers, message type, delivery status, error codes, timestamps, audit events, IP-derived security signals and technical logs. The current Service records operational message metadata and does not provide a long-term archive of message bodies.
How we use information
- Provide email sign-in, company registration and account administration.
- Approve companies, enforce assigned seats, plans, message allowances and security limits.
- Connect authorized WhatsApp business assets and deliver requested API messages.
- Receive delivery, quality, template and account webhook updates.
- Prevent fraud, spam, unauthorized access and misuse.
- Maintain audit records, troubleshoot failures and improve reliability.
- Respond to support, legal, privacy and data-deletion requests.
- Comply with applicable law and enforce our Terms.
WhatsApp and Meta data
The Service connects to the official WhatsApp Business Platform operated by Meta. A company authorizes the connection through Meta’s tools and remains responsible for its WhatsApp Business Account, message recipients, templates, payment arrangements and compliance with Meta and WhatsApp requirements.
We process WhatsApp user data only as needed to provide the Service on behalf of the connected company, to maintain security, or to comply with legal and platform obligations. Meta separately processes information under its own terms and privacy policies.
Security
We use safeguards designed for the sensitivity of the Service, including HTTPS, restricted administrative access, hashed API keys and sessions, one-time-code expiry, webhook signature verification, request limits, audit records and secret storage outside the public source code.
No internet service can guarantee absolute security. Workspace owners must protect their email accounts, API keys, Meta credentials and authorized devices, and must notify us promptly of suspected compromise.
Retention and deletion
We retain information for as long as needed to provide the Service, secure accounts, resolve disputes, meet contractual or platform requirements and comply with law. One-time codes expire after a short period, while security, audit, transaction and compliance records may be kept longer.
When a verified deletion request is approved, we delete or de-identify information that is no longer required. Limited records may be retained where necessary for fraud prevention, security, financial reporting, legal claims or obligations imposed by law or the WhatsApp Business Platform. See our Data Deletion Instructions.
Your choices and rights
Depending on applicable law and your relationship with the workspace owner, you may request access, correction, export, restriction, objection or deletion of your personal information. You may also disconnect a WhatsApp business integration through Meta’s settings.
Send privacy requests to bamitaleolaoluwa@gmail.com. We may need to verify your identity and authority before acting. If your account belongs to a customer company, we may direct the request to that company as the workspace controller.
The Service is intended for business users who are at least 18 years old and is not directed to children.
International processing
Revault, Meta and our service providers may process information in countries other than the country where it was collected. Where required, we use contractual, organizational or other safeguards intended to protect information during international processing.
Changes and contact
We may update this policy as the Service, law or platform requirements change. We will post the revised policy here and update the effective date. Material changes may also be communicated through the Service or by email.
Questions, complaints and privacy requests may be sent to bamitaleolaoluwa@gmail.com.