Privacy Policy

Last updated: 23 July 2026

1. Who we are

SISPL ("we", "us") operates the SISPL WhatsApp Panel, a multi-tenant platform that helps businesses connect their own WhatsApp Business number to manage team inboxes, send broadcast campaigns, and use AI-assisted auto-chat. This policy explains what data we process and why. For any question, contact us at loukesh@gmail.com.

2. Data we collect

  • Account data: name, email, organization details, and hashed passwords for users who register.
  • WhatsApp Business data: when a client connects their number, we process the WhatsApp Business Account and phone-number identifiers, message templates, and access tokens (stored encrypted) needed to send and receive messages on their behalf.
  • Message data: inbound and outbound WhatsApp messages, contact phone numbers, delivery/read statuses, and campaign records, used to operate the inbox and reporting features.
  • Billing data: wallet balances, credit purchases, and payment references processed through our payment provider (Razorpay). We do not store card details.
  • Technical data: log data and basic usage metrics required to run and secure the service.

3. How we use data

We use data solely to provide the service: authenticating users, sending and receiving WhatsApp messages on behalf of the connected business, generating AI-assisted replies (only when the account has enabled it and has prepaid credit), processing payments, and providing usage reporting. We do not sell personal data.

4. WhatsApp and Meta

The platform uses the WhatsApp Business Platform (Cloud API) provided by Meta. Message delivery is subject to Meta's and WhatsApp's own terms and policies. Access tokens obtained through Meta's Embedded Signup are stored encrypted and used only to operate the connected account.

5. Data sharing

We share data only with the sub-processors required to run the service — Meta (WhatsApp message delivery), Razorpay (payments), and our AI provider (Anthropic, for generating auto-replies) — and only to the extent needed to perform those functions. Each processes data under its own terms.

6. Data retention & deletion

We retain data for as long as an account is active. You may request access to or deletion of your data at any time — see our Data Deletion Instructions or email loukesh@gmail.com.

7. Security

Access tokens and sensitive secrets are encrypted at rest (AES-256-GCM). Access is restricted to the account's own organization. We take reasonable technical and organizational measures to protect data, though no system is completely secure.

8. Changes

We may update this policy from time to time. Material changes will be reflected on this page with an updated date.