Privacy Policy
Introduction
This Privacy Policy explains how RBAG WORLD Inbox API collects, uses, stores, and protects information when you use the login system, WhatsApp Cloud API connection, RBAG WORLD Auto Connect, webhook, inbox, media upload, and support features.
Information We Collect
We collect only information needed to operate the account, connect WhatsApp services, keep messages available in the cloud inbox, secure the service, and provide support.
Account Information
Account access is verified against the configured account source. This can include login identifier, account name, account status, expiry date, and other account fields required to decide whether access is active.
WhatsApp Business Connection Data
When you connect WhatsApp, we may store authorized connection details required for WhatsApp Cloud API operation, including access status, selected connection method, encrypted tokens where applicable, webhook status, and related setup metadata.
Meta Embedded Signup Data
For RBAG WORLD Auto Connect, Meta Embedded Signup may return information needed to complete the connection, validate it, and keep the account linked. This may include signup session information, authorization code result, connection status, and Meta API response summaries without exposing secrets publicly.
Business Portfolio Information
The customer remains the owner of their Facebook account, Meta Business Portfolio, WhatsApp Business Account, and WhatsApp phone number. The website stores only the identifiers and connection details that the customer authorizes for the service to send, receive, and manage WhatsApp messages.
WABA ID
We may store the WhatsApp Business Account ID connected to your account so that messages and webhook events are routed to the correct customer account.
Phone Number ID
We may store the WhatsApp Phone Number ID so that outbound messages are sent from the correct connected WhatsApp number and incoming webhook events are matched correctly.
Connected Phone Number Information
We may store the display phone number, verified name, phone status, quality or health details returned by Meta, and the selected default number for the connected account.
Message and Webhook Data
Messages, contacts, timestamps, WhatsApp message IDs, delivery statuses, unread state, webhook payload summaries, and related media metadata may be stored so the cloud inbox works after refresh, logout, login, or use on multiple devices.
Login and Session Information
We use secure sessions and security checks to keep logged-in accounts protected. We may store session state, rate-limit data, CSRF tokens, and access checks needed to protect restricted pages.
Uploaded Files
Images, videos, audio, voice recordings, and documents sent or received through the inbox may be stored or proxied in protected server storage so they remain available in the conversation history.
Technical and Security Logs
We may keep technical logs for errors, webhook processing, API failures, security checks, and troubleshooting. Sensitive values such as tokens, passwords, private keys, and app secrets should not be intentionally exposed in public pages, JavaScript, or user-facing error messages.
How We Use Information
- To verify account access and account status.
- To connect and maintain WhatsApp Cloud API access.
- To send, receive, display, and store WhatsApp conversations.
- To process webhooks, delivery statuses, media, and message history.
- To troubleshoot errors, improve reliability, and protect the service.
How We Store Information
Connection records, message records, and media metadata are stored in the server-side database and protected storage. Sensitive connection values are intended to remain server-side and not be exposed in frontend JavaScript.
Data Security
We use server-side configuration, encrypted storage for supported secret values, protected sessions, CSRF protection, rate limiting, and restricted access checks. No security method is perfect, but the system is designed to avoid exposing sensitive credentials in public frontend output.
Data Sharing
We do not sell customer data. Information may be shared only when necessary with Meta, WhatsApp, Google services configured for account verification, hosting infrastructure, or support systems required to operate this service.
Meta and WhatsApp Services
WhatsApp messaging and Meta Embedded Signup are provided by Meta. Your use of WhatsApp Cloud API and Meta services is also subject to Meta and WhatsApp terms, platform rules, and privacy practices.
Third-Party Services
The service may use Hostinger or similar hosting, Meta Graph API, WhatsApp Cloud API, Google account verification services, and browser/device services such as camera or microphone permission when you use media features.
Google Sheets or Google Service Account Usage
If Google Service Account login verification is configured, it is used server-side to read the authorized account sheet for login, status, expiry, and related access fields. The browser should not directly receive the Google Service Account credential file.
Cookies and Sessions
We use cookies and session data to keep users logged in, verify secure requests, and protect account access. Disabling cookies may prevent login or restricted pages from working correctly.
Data Retention
Account, connection, message, media, and log data may be retained while the account is active or as needed for service operation, troubleshooting, legal, security, or backup purposes unless deletion is requested and approved where applicable.
User Choices
You may disconnect WhatsApp access from the available setup or auto-connect controls where enabled. You may also contact support for help with account access, data review, or deletion requests.
Account Disconnection
Disconnecting WhatsApp access stops the active connection method from being used by this website. Historical inbox data may remain stored unless deletion is requested or removed through an authorized process.
Data Deletion Request
To request deletion of account data, WhatsApp connection data, or stored conversation data, contact support through the WhatsApp support link below and include the account email or login identifier. We may verify account ownership before processing deletion.
User Rights
Depending on your location, you may have rights to request access, correction, deletion, or restriction of your personal data. Contact support to make a request.
Children's Privacy
This service is intended for business use and is not directed to children. Children should not create accounts or connect WhatsApp business assets through this service.
International Processing
Your information may be processed on servers or by providers located outside your country. By using the service, you understand that service providers may process data where their infrastructure operates.
Policy Updates
We may update this Privacy Policy when the service, legal requirements, or connected providers change. The updated date at the top will show the latest version.
Contact Information
For privacy, support, account disconnection, or data deletion requests, contact the service owner through the support WhatsApp link.