Data Processing Terms
Last updated: 9/21/2026
1. Roles
You are the controller of the customer data in your WhatsApp Business account. Sharikat acts as your processor and only processes that data on your documented instructions — given by connecting an account and by the consent you accept when you create your workspace.
2. What we process
For every inbound WhatsApp message that originates from an instant-messaging ad we store: a one-way hash of the customer phone number and WhatsApp id, the country prefix, message timestamps and count, the ad referral identifiers supplied by the platform (click id, campaign, ad group, ad), and the delivery result of each conversion we report.
We do not store message bodies, media, contact names or address books, and we never use your data to train models or to build audiences of our own.
3. What is shared with ad platforms
To attribute a conversation we report events to the ad platform you connected: TikTok Events API / Business Messaging and, where connected, the Meta Conversions API. Each event contains the click identifier, event name, timestamp, and — when you keep hashed identifier sharing enabled — a one-way hashed phone number or WhatsApp id used solely for matching. Message content is never sent.
4. Sub-processors
Hosting and database (Lovable Cloud / Supabase), Meta Platforms for the WhatsApp Business Platform, and TikTok for Business for conversion reporting. We will inform you before adding a new sub-processor that processes conversation data.
5. Retention and deletion
Attribution records are retained while your workspace is active so reporting windows and reconciliation can complete, and are deleted within 30 days of workspace deletion or on written request. Disconnecting an integration stops all further processing for that integration immediately.
6. Security
Data is encrypted in transit over HTTPS and at rest by our hosting provider. Access tokens are stored server-side only and are never exposed to the browser. Every workspace is isolated by row-level access rules so one workspace can never read another's data.
7. Your rights and instructions
You can withdraw data-sharing consent at any time in Workspace → Data & privacy, which pauses all reporting, and you can request export or deletion of your workspace data by contacting us. We assist you with data-subject requests you receive from your customers.