1. Overview & Data Architecture #
TGCPilot ("we", "our", or "us") provides a collaborative WhatsApp CRM and broadcast automation platform designed for teams. This Privacy Policy governs how personal and workspace data is processed across our software, infrastructure, APIs, and client-facing interfaces. Each workspace operates in strict multi-tenant isolation with encryption and strict data boundary controls.
2. Information We Collect #
To operate the platform and deliver Meta WhatsApp Cloud API services, we collect and process the following categories of information:
- Account & Billing Data: Name, business email address, billing contacts, payment profile records, and subscription history.
- WhatsApp Connection & Token Metadata: Meta WhatsApp Business Account (WABA) credentials, phone number IDs, access tokens, and webhook routing configurations.
- Conversations & Contact Data: End-user phone numbers, contact profile fields, tags, message contents, media attachments, and internal team notes created within tenant workspaces.
- Technical & Telemetry Data: IP addresses, user agent header data, activity logs, API rate limiting metrics, and authentication audit logs.
3. How We Use Information #
We use the collected information exclusively to provide, maintain, and optimize TGCPilot services. Specifically: (a) routing WhatsApp inbound and outbound messages through Meta Cloud API; (b) managing team roles, permissions, and conversation assignments; (c) executing automated chatbot flows and campaign broadcasts; (d) detecting fraud, rate limit abuse, and unauthorized workspace access; and (e) satisfying legal, tax, and regulatory requirements.
4. Meta WhatsApp Business API Integration #
TGCPilot connects directly to Meta WhatsApp Cloud API endpoints. When your workspace sends or receives messages, metadata and message payloads are transmitted securely via Meta infrastructure. TGCPilot complies with Meta Developer Policies and WhatsApp Business Terms. We do not use your customer data or WhatsApp conversation transcripts for training general artificial intelligence models or selling to third-party ad networks.
5. Workspace Isolation & Security Controls #
We employ multi-layer security measures, including AES-256 encryption at rest for sensitive access tokens and database records, TLS 1.3 encryption in transit for all network traffic, automated tenant boundary scoping on every request, role-based access control (RBAC), and session rate-limiting.
6. Data Retention & 30-Day Erasure Policy #
Data is retained for the duration of your active workspace subscription. In accordance with GDPR, CCPA, and Saudi PDPL guidelines, workspace owners may request total data erasure at any time. Upon confirmed erasure request, customer records, contact profiles, and chat transcripts are permanently erased or tombstoned across active databases within 30 days. Statutory tax and billing records are retained as required by applicable laws.
7. Data Sharing & Third-Party Processors #
We do not sell personal data. We share data only with authorized sub-processors necessary to operate TGCPilot: (a) Meta Platforms Inc. (WhatsApp API execution); (b) Cloud Infrastructure & Hosting Providers (secure server hosting and database clusters); and (c) Payment Gateways (secure subscription payment handling). All sub-processors are bound by strict data protection agreements.
8. User Rights & Data Protection Controls #
Depending on your jurisdiction, you have the right to access, rectify, export, or erase your personal data, restrict processing, and withdraw consent. Workspace administrators can export contact databases and request tenant erasure directly via workspace settings or by contacting our Data Protection Officer.
10. Contact Us & DPO Inquiries #
If you have questions regarding this Privacy Policy, data protection practices, or wish to exercise your legal rights, please contact our Data Protection Officer at privacy@tgcpilot.com or via our support channel.