Privacy Policy & Data Disclosure
Effective Date: [REQUIRED OWNER DECISION: Set WWA_LEGAL_EFFECTIVE_DATE]
1. Introduction
WooCommerce WhatsApp Revenue Automation (WWA) ("we", "our", or "the Platform") operates a commercial website platform and provides WordPress plugin software. This Privacy Policy details the data collected, processed, transmitted, and retained when using our website, customer portal, licensing REST API, and WWA plugin.
Platform Business Operator: [REQUIRED OWNER DECISION: Set WWA_LEGAL_ENTITY_NAME in environment]
Contact Email: [REQUIRED OWNER DECISION: Set WWA_LEGAL_CONTACT_EMAIL in environment]
Registered Address: [REQUIRED OWNER DECISION: Set WWA_BUSINESS_ADDRESS in environment]
2. Information Collected on the Commercial Platform
When you create an account, purchase WWA Pro, or manage licenses on our website (/account), we process:
- Customer Account Data: Name, email address, password hash, registration timestamp.
- Order & Billing Data: Stripe Customer ID, Stripe Checkout Session ID, Payment Intent ID, Order Number, Total Amount, Currency, Payment Status. Note: Raw credit card numbers are processed directly by Stripe and are never stored on our servers.
- Licensing Data: Encrypted license key hashes, activation token hashes, registered domain URLs, WordPress version, WooCommerce version, PHP version, activation timestamps.
3. Information Processed by WWA Plugin in Your WordPress Store
When installed on your WooCommerce store, WWA processes merchant and customer data to deliver automated WhatsApp messaging:
- WhatsApp Credentials: Phone Number ID, WABA ID, and System User Access Tokens stored encrypted in your local WordPress database.
- Shopper & Order Data: Customer phone numbers (E.164 format), order totals, item names, cart session tokens, order statuses.
- Message Logs: Template names, recipient phone numbers, dispatch timestamps, delivery status callbacks.
4. Third-Party Data Processors
WWA integrates directly with two primary third-party processors to fulfill services:
Meta / WhatsApp Cloud API
WhatsApp messages are dispatched directly via Meta\'s Graph API (graph.facebook.com). Meta processes phone numbers and approved message template parameters under Meta\'s WhatsApp Business Terms.
Stripe Payment Infrastructure
Commercial payments, checkout sessions, and recurring subscriptions are processed by Stripe. Stripe handles card data securely under PCI-DSS Level 1 compliance.
5. Data Retention & Erasure
On the commercial platform, account and licensing records are retained while your commercial subscription is active or as required for tax compliance.
In WordPress, WWA integrates with the native WordPress Privacy Exporter & Eraser tools (PrivacyIntegration). Merchants can export or erase stored customer WhatsApp logs and cart tracking data upon request.
Specific retention periods for commercial logs and audit trails require business configuration by the platform owner.
6. Security Safeguards
We implement technical and organizational security controls across our platform:
- Strict HTTPS enforcement for all public and API endpoints.
- Stripe HMAC SHA-256 webhook signature validation.
- Prepared SQL statements and Laravel Eloquent ORM to prevent SQL injection.
- Encrypted licensing tokens and secure time-limited signed download URLs.
7. Privacy Inquiries
For privacy inquiries, account data export requests, or license data questions, contact our support team at [REQUIRED OWNER DECISION: Set WWA_LEGAL_CONTACT_EMAIL] or via our Support Portal.