Privacy Policy
WA FollowUp Manager stores data needed to authenticate users, enforce subscription limits, manage contacts, schedule follow-ups, connect supported providers, process payments, and record operational logs.
Data Collected
The system may store names, email addresses, password hashes, verification records, Google account identifiers, contact names and phone numbers, notes, tags, consent status, consent source, consent date, consent wording, form version, non-reversible IP hashes, browser information, opt-out reason and date, suppression records, sender configuration, webhook identifiers, message templates, queue schedules, provider responses, technical and security audit logs, plan status, invoices, payment references, payment status, and billing phone numbers.
Sensitive Data and Exports
Features such as contact management, exports, support tickets, and transaction history can involve personal or business-sensitive information. Exported files may include names, email addresses, phone numbers, notes, tags, consent data, and transaction references. Users are responsible for handling those exports securely and limiting access to authorized people only.
Users should avoid storing unnecessary sensitive data and should not upload special-category, regulated, or confidential information unless they have independently confirmed a lawful basis and appropriate safeguards. Remoxus cannot control what happens after a user downloads, copies, forwards, or stores exported data outside the application.
Payment Data
Checkout requests are sent to the payment gateway. WA FollowUp Manager stores transaction references, invoice numbers, amounts, statuses, payment URLs, and provider responses needed to activate or audit a subscription. Card, bank, or payment-account credentials are handled by the payment provider and are not intended to be stored by this application.
Use of Data
Data is used to provide the service, verify accounts, enforce plan limits, schedule messages, communicate with WhatsApp providers, receive webhook status updates, prevent abuse, provide support, process subscription access, and maintain security and reliability.
Contact Consent and Suppression
Only import contacts who have given permission to receive WhatsApp communication. The user is responsible for lawful collection, use, retention, and deletion of contact data. The application may require an import declaration and record consent source, date, evidence, wording, form version, and technical verification data.
STOP, unsubscribe, manual do-not-contact, and equivalent requests may create a durable suppression record. Suppression records are retained separately from ordinary contact records to prevent accidental re-import and repeat messaging. A number should be released only after renewed, documented consent.
Our Role and Data Processing Agreement
Remoxus may act as a controller for account, security, billing, and direct service data. For contact lists, campaign content, and messages controlled by the user, Remoxus generally processes data on the user’s instructions. Additional terms are in the Data Processing Agreement.
Third Parties
Data may be transmitted to services selected by the user or operator, including Meta/WhatsApp, OpenWA, Twilio, custom gateways, Google, email providers, the payment gateway, hosting companies, network operators, and security services. Their own terms and privacy policies apply. Provider categories and purposes are listed on the Subprocessors page.
Independent Product Notice
WA FollowUp Manager is an independent software product by Remoxus and is not affiliated with, endorsed by, authorized by, or sponsored by WhatsApp, Meta, or their affiliates. If you connect a third-party API or platform, the handling of personal data by that provider is governed by that provider’s own terms and privacy policy.
User Controller Responsibility
For uploaded contacts and campaign content, the user is generally the party responsible for deciding why and how personal data is processed. Users must ensure that they have an appropriate legal basis, provide any required notices, and honor deletion, correction, and opt-out requests in accordance with applicable law.
Sub Accounts and Managed Workspaces
When an account owner sends a sub-account invitation, we process the invited email address, invitation token, status, creation time, 24-hour expiry time, acceptance or rejection time, owner identity, and the user account linked to the invitation. After acceptance, the invited manager can select the owner’s workspace and process operational data on the owner’s behalf.
The owner and manager can disconnect the relationship through Settings. The application verifies accepted access on each request, so a disconnected manager can no longer select or use the owner’s workspace. Limited invitation, disconnection, and security-audit records may be retained for account security, dispute handling, fraud prevention, and compliance.
Managed access does not share the owner’s password or expose owner-only billing and account credential controls. Owners should review active access regularly and revoke access that is no longer needed.
Security
Passwords are stored as hashes. Supported provider credentials are encrypted at rest by the application when server cryptography is available. The service also uses session protections, CSRF controls, rate limiting, audit records, suppression enforcement, and administrator two-factor authentication features. Access tokens, exported spreadsheets, support attachments, and API credentials must still be protected with HTTPS, restricted hosting access, device security, and appropriate server permissions. No internet-connected service can guarantee absolute security. See the Security & Incident Policy.
Your Requests and Choices
Verified requests for access, correction, export, deletion, withdrawal of consent, objection, or reporting unauthorized use of a number can be submitted through the Privacy Request page. Identity verification may be required before data is disclosed or deleted.
Retention and Deletion
Users or administrators can delete supported records from the dashboard. Routine operational logs, temporary exports, and older WhatsApp reply/chat records may be removed after the configured retention period, generally up to 3 months. Essential invoice details and limited accounting, fraud-prevention, dispute, chargeback, or legal records may be retained longer. Where possible, unnecessary payment response data, payment URLs, and billing phone details are removed or anonymized while the essential transaction record is retained.
Inactive Account Lifecycle
If an account has no meaningful activity for 24 consecutive months, it may be scheduled for deletion. Meaningful activity includes login, an active paid subscription, active automations, recent API or webhook use, and unresolved billing or support matters.
The system is designed to send notices approximately 90, 30, and 7 days before the inactivity date. At 24 months, the account enters a 30-day recovery period. Logging in or otherwise creating meaningful activity during a notice or recovery period cancels the deletion schedule.
After the recovery period, operational account data may be permanently deleted, including contacts, phone numbers, messages, campaigns, templates, sender credentials, support content, newsletter queues, and uploaded files. A minimal deletion audit containing non-reversible hashes and limited anonymized transaction records may be retained where required for accounting, fraud prevention, security, legal claims, or compliance.
Deleted data may remain temporarily in encrypted or access-restricted backups until those backups expire under the hosting backup cycle. If a backup is restored, the deletion list must be reapplied so deleted accounts are not returned to normal service.
Platform and Account Risk
WhatsApp, Meta, gateways, payment processors, hosting services, and other third parties may change rules, reject messages, disconnect sessions, restrict accounts, or suffer outages. Remoxus does not control those services and does not guarantee continued availability of a number, device, account, session, template, API, or payment channel.