1. About this Privacy Policy
WayConnect provides business communication, customer relationship management, campaign, automation, analytics, developer, file-management, billing, and workforce-management services. This Privacy Policy applies when you visit a WayConnect website, create or use a WayConnect account, join a customer workspace, interact with support, or otherwise use a service that links to this Policy (collectively, the “Services”).
In this Policy, “WayConnect”, “we”, “us”, and “our” mean the WayConnect supplier identified in the applicable Order Form, invoice, or checkout record. “Customer” means the organisation that controls a workspace. “Authorised User” means a person permitted by a Customer to use that workspace. “Customer Content” means data that a Customer or Authorised User submits to, receives through, generates in, or connects with the Services.
This Policy does not replace the privacy notice of a Customer that uses WayConnect to communicate with contacts, manage leads, process employee information, recruit candidates, or operate other business workflows. Those individuals should normally direct requests about Customer Content to the relevant Customer.
2. Our data-protection roles
When WayConnect acts for its own purposes
WayConnect generally acts as a controller or business for website, account-registration, authentication, billing, product-usage, security, support, and direct business-relationship information. We determine why and how this information is processed for the purposes described in this Policy.
When WayConnect acts for a Customer
For Customer Content—such as contacts, leads, messages, employee records, attendance entries, payroll inputs, candidate records, and workspace files—WayConnect generally acts as a processor or service provider and follows the Customer's documented instructions, the Services configuration, and the applicable agreement.
The Customer is responsible for providing required notices, establishing a lawful basis, collecting valid consent where needed, configuring permissions and retention, responding to individuals, and ensuring that its use of the Services complies with employment, communications, privacy, consumer-protection, and sector-specific laws.
3. Personal data we process
The information processed depends on the Services selected, the Customer's configuration, the integrations enabled, and the information users choose to provide.
Account, identity, and workspace information
- Name, display name, work email, phone number, profile image, job role, organisation, brand, workspace membership, language, timezone, and preferences.
- Password hashes, one-time authentication records, Google sign-in identifiers, session identifiers, invitation records, account status, role assignments, and permission settings.
- Workspace, brand, location, department, team, and business-profile details supplied by administrators.
Customer, lead, and communication data
- Contact and lead names, phone numbers, email addresses, tags, custom fields, sources, consent or opt-out status, assignments, notes, follow-ups, and activity history.
- Inbound and outbound message content, template variables, attachments and media references, channel and participant identifiers, delivery/read status, timestamps, failure information, chatbot sessions, campaign audience details, and conversation assignments.
- WhatsApp, Instagram, Messenger, Meta Lead Ads, Google Ads lead forms, inbound email, developer API, webhook, Google Sheets, and Microsoft Excel data when the relevant connection is enabled.
Workforce and people-operations data
- Employee identity and contact data, employee code, photograph, date of birth, gender, nationality, marital status, blood group, home address and coordinates, family and emergency-contact information.
- Employment details such as department, designation, manager, work location, joining and confirmation dates, contract type, salary, pay frequency, leave policy, skills, availability, permissions, and employment notes.
- Attendance, shift, leave, geofence, punch location, accuracy and device data; payroll calculations and tax identifiers; expense claims, receipts and reimbursement details; assets and device allocations; visitor records; policies; and operational events.
- Recruitment data such as candidate contact details, resumes or attachments, source, job application, stage history, interview notes, assessment information, and hiring decisions.
- Identity, address, education, employment, bank, tax, medical, background-check, and other employee documents uploaded by a Customer. These records may contain sensitive personal data, and access is controlled by Customer-assigned permissions.
Billing and transaction information
- Legal or business name, billing email, billing address, country, tax registration identifiers, plan, billing cycle, add-ons, invoices, tax amounts, payment status, and transaction references.
- Razorpay order, payment, customer, plan, subscription, mandate status, payment-method type, renewal and cancellation references. Full card, bank-account, or UPI credentials are handled by the payment provider and are not intended to be stored by WayConnect.
- Prepaid wallet balance, top-ups, message and AI usage charges, categories, refunds or reversals, adjustments, and associated ledger entries.
Files, integrations, and developer data
- Uploaded files, file names, types, sizes, storage keys, folder structure, document associations, and access metadata.
- Integration configuration, connected account or asset identifiers, OAuth grants and tokens, sync status, field mappings, event payloads, webhook endpoints, API keys, idempotency records, and delivery logs.
- AI prompts and contextual inputs selected by a user, recent conversation content used to draft a reply, configured public knowledge-page extracts, generated results, model and token usage, provider response identifiers, and billing metadata.
Device, usage, and security data
- IP address, user agent, browser and operating-system details, device identifiers and fingerprint, application version, request identifiers, login history, feature interactions, error and diagnostic information.
- Security events, access grants, audit history, rate-limit records, authentication method, approximate country inferred from trusted network headers for pricing, and actions taken in a workspace.
- Push-subscription endpoint and device information when browser or app notifications are enabled.
4. How we receive personal data
- Directly from you when you register, sign in, complete onboarding, buy a plan, submit a form, upload a file, configure a workflow, contact us, or use the Services.
- From the Customer that creates your account, imports records, assigns a role, or otherwise submits Customer Content.
- From contacts, message recipients, employees, candidates, visitors, or other individuals who interact with a Customer through a connected channel or business process.
- From enabled providers and integrations, including Meta services, Google, Microsoft, Razorpay, email providers, connected APIs, webhooks, and customer-configured data sources.
- Automatically from browsers, devices, servers, cookies, local browser storage, logs, and security systems when the Services are accessed.
5. Google API Services and Google user data
Google connections are optional and are initiated only when an Authorised User chooses Google Sign-In or connects Google Sheets. WayConnect's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google data we access
- For Google Sign-In, basic identity information such as the Google account identifier, name, email address, and profile image, used to create or authenticate the relevant WayConnect account.
- For Google Sheets, the connected account email and read-only Google Drive metadata for spreadsheet files, including file identifiers, names, modified times, and links, so the user can find and select a spreadsheet.
- Read-only metadata and cell content from the spreadsheet and worksheet selected by the user, including worksheet titles, headers, rows, and field values required for preview, mapping, import, and scheduled lead synchronisation.
- OAuth grant information, granted scopes, and tokens required to maintain the authorised connection. WayConnect does not receive or store the user's Google password.
How we use Google data
- Authenticate the user when Google Sign-In is selected and associate the verified Google identity with the correct WayConnect account.
- Display available spreadsheet files, let the user select a worksheet and map its columns, import selected rows as leads into the Customer's CRM workspace, and periodically read new or changed rows while the connection remains active.
- Operate, secure, troubleshoot, and audit the user-requested Google connection. Google user data is not used for unrelated product features.
Storage, protection, retention, and user control
- WayConnect may store the connected account email, granted scopes, selected spreadsheet and worksheet configuration, field mappings, synchronisation metadata, imported CRM records, and an encrypted OAuth refresh token. Short-lived access tokens may be held temporarily while an authorised request is processed.
- Access is limited through workspace permissions and security controls. WayConnect personnel do not read Google user data except with the user's affirmative permission for specific support, when necessary for security, or where required by law.
- Google connection data is retained only while needed to provide the authorised feature, satisfy Customer instructions, protect the Services, or meet legal obligations. Users may revoke WayConnect access through their Google Account; workspace administrators may delete imported CRM records under product controls or request deletion at support@wayconnect.co. Residual copies may remain temporarily in protected backups until normal deletion cycles complete.
Sharing and prohibited uses
- Google user data is made available only to authorised users in the Customer workspace and to service providers needed to host, operate, secure, or support the requested feature, subject to appropriate safeguards. It may also be disclosed when required by law or as otherwise permitted by the Google API Services User Data Policy.
- WayConnect does not sell Google user data, transfer it to data brokers or information resellers, use it for advertising or retargeting, use it for credit or lending decisions, or use it to develop, improve, or train generalised or non-personalised artificial-intelligence or machine-learning models.
- The Google Sheets connection is read-only. WayConnect does not edit or delete files in the user's Google Drive.
6. Why we process personal data
Providing and administering the Services
- Create accounts and workspaces, authenticate users, apply permissions, connect channels, route conversations, send authorised messages, run campaigns, manage contacts and leads, operate workforce tools, store files, and provide requested integrations.
- Process subscriptions, verify payments, calculate applicable taxes and usage, maintain wallet and invoice records, administer renewals, and apply plan entitlements.
- Provide support, respond to requests, deliver essential operational communications, and maintain Customer-requested configurations.
Security, integrity, and compliance
- Detect, investigate, prevent, and respond to fraud, abuse, unlawful activity, account compromise, policy violations, delivery failures, and security incidents.
- Maintain auditability, enforce agreements and usage limits, protect rights and safety, comply with lawful requests, and meet accounting, tax, recordkeeping, and legal obligations.
Improvement and communication
- Monitor reliability and performance, troubleshoot issues, understand feature usage, improve workflows, and develop new functionality.
- Send product, service, billing, security, and policy notices. Promotional communications are sent only where permitted, and recipients can use the provided opt-out method.
Applicable legal bases
Where a legal basis is required, we rely as appropriate on performance of a contract, steps requested before entering a contract, compliance with legal obligations, legitimate interests that are not overridden by individual rights, consent, and other grounds available under applicable law. The Customer determines the legal basis for Customer Content it instructs us to process.
7. Customer Content and individual requests
Customers control what Customer Content is submitted, which users can access it, which integrations receive it, how workflows use it, and when records are archived or deleted. WayConnect does not independently decide the business purpose for a Customer's message, employee record, payroll calculation, candidate evaluation, or contact list.
If your data was provided to WayConnect by a Customer—for example, because you received a message, applied for a role, or are managed as an employee—please contact that Customer first. We will assist the Customer with verified requests as required by the applicable agreement and law.
Customers must not submit sensitive or regulated information unless their use is lawful, necessary, appropriately secured, and supported by the selected Services and agreement. Users should never place passwords, one-time passcodes, complete payment credentials, private access tokens, or unrelated sensitive information in support requests or AI prompts.
8. AI-assisted features
When an Authorised User chooses an AI-assisted feature, WayConnect may send the prompt, selected workspace context, recent conversation content, and an extract from a configured public knowledge page to the configured AI provider, currently through an OpenAI-compatible response service. This processing occurs to generate the requested template, campaign plan, chatbot flow, or suggested inbox reply.
Generated results are returned for user review and may be stored in encrypted form with model, usage, cost, and provider-response metadata. AI output may be incomplete or inaccurate and should be reviewed before it is used or sent. Customers should configure AI access and input data consistently with their privacy duties and provider terms.
10. Third-party services and links
Connected services are independently operated and have their own terms and privacy practices. A Customer's administrator decides whether to enable an integration and is responsible for reviewing its permissions. WayConnect receives and sends only the data needed for the configured connection, but the third party controls its own subsequent processing.
The Services may link to third-party websites. A link does not mean that WayConnect controls or endorses that site's privacy practices. Review the applicable third-party notice before providing data or authorising access.
11. International data transfers
WayConnect, its service providers, connected platforms, and Customer-authorised recipients may process data in countries other than the country where an individual is located. Those countries may have different data-protection laws.
Where required, transfers are supported by an applicable adequacy decision, standard contractual clauses, a data-processing agreement, contractual and technical safeguards, consent, or another lawful transfer mechanism. Customers requiring specific residency or transfer commitments should ensure that they are recorded in an Order Form or Data Processing Addendum before submitting affected data.
12. Retention and deletion
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, Customer instructions, the active service relationship, security, dispute resolution, and legal, tax, accounting, and regulatory requirements. Retention also depends on the data category, workspace settings, plan, and applicable agreement.
- Authentication states, one-time passcodes, temporary signup sessions, and similar security records are short-lived and expire according to configured security periods.
- Meta webhook event records are configured to expire after a limited troubleshooting period, currently 30 days by default. Developer API logs and developer events are also retained for 30 days by default, while developer idempotency records are short-lived.
- Workspace activity logs may be retained for up to 730 days to provide audit, security, and accountability history.
- Billing profiles, invoices, subscriptions, wallet ledgers, and payment references may be retained for the period required for tax, accounting, fraud prevention, and legal recordkeeping, including after cancellation.
- Customer Content remains subject to Customer instructions and product deletion or archive controls. Deleted data may persist temporarily in protected backups or provider systems until normal overwrite and deletion cycles complete.
- We may retain a minimal record where necessary to document a request, preserve an opt-out, prevent fraud, establish or defend legal claims, or comply with law.
13. Security and access controls
WayConnect uses administrative, technical, and organisational controls designed for the nature of the Services and the information processed. Controls reflected in the platform include role- and workspace-scoped permissions, credential hashing, encryption for supported message and credential records, rotating sessions, rate limiting, signed temporary file links, webhook-signature verification, audit and security events, and restricted support access.
No online service can guarantee absolute security. Customers must assign least-privilege roles, protect accounts and connected services, maintain accurate users, review integrations, secure exported files, and promptly report suspected compromise. If you believe personal data or an account is at risk, contact us without sending passwords, full card details, or secret keys.
15. Your privacy rights
Depending on where you live and the context in which data is processed, you may have rights to know or access personal data, obtain a copy, correct or complete inaccurate data, request deletion, restrict processing, object to certain processing, withdraw consent, request portability, opt out of direct marketing, or lodge a complaint with a competent authority. Applicable law may provide additional rights, including grievance-redressal or nomination rights.
Rights are not absolute. A request may be limited where identity cannot be verified, WayConnect processes the data only for a Customer, another person's rights would be affected, or retention is required by law, security, fraud prevention, contract, or legal claims.
How to submit a request
Send the request to support@wayconnect.co from the email associated with the account and state the relevant workspace, your relationship to it, the right you want to exercise, and the data involved. Do not include passwords, one-time passcodes, full payment details, or unnecessary identity documents. We may request proportionate information to verify identity and authority.
Customer-controlled data
For contact, lead, employee, candidate, visitor, or other Customer Content, contact the relevant Customer first. If we receive a request relating to Customer-controlled data, we may refer it to that Customer and assist as required.
16. Regional privacy information
India
Where Indian data-protection law applies, WayConnect and Customers will process digital personal data for lawful purposes and provide notices, consent choices, security safeguards, access, correction, erasure, grievance handling, and other rights to the extent required by applicable law and its effective rules.
European Economic Area, United Kingdom, and Switzerland
Individuals may have the rights and legal bases described above, including a right to complain to their local supervisory authority. Customers may request a Data Processing Addendum addressing processor obligations, subprocessors, security measures, assistance, deletion, and recognised transfer safeguards.
United States
Residents of certain states may have rights to know, access, correct, delete, or obtain a portable copy of personal information and to opt out of certain sales, sharing, targeted advertising, or profiling. WayConnect does not sell personal data or use Customer Content for cross-context behavioural advertising. We will not discriminate against a person for exercising an applicable privacy right.
17. Service and marketing communications
We may send essential account, security, billing, transaction, policy, and operational messages while an account or business relationship is active. These notices are necessary to administer the Services and may not offer an unsubscribe option.
Where permitted, we may separately send product education, event, or promotional messages. You can opt out using the unsubscribe method in the communication or by submitting a request. An opt-out does not stop essential service messages or communications a Customer independently sends through its own workspace.
18. Children
The Services are business products and are not directed to children. Individuals must be legally capable of using the Services or be authorised through a Customer's lawful employment, education, or business process. Customers must not use WayConnect to collect children's data unless they have a valid legal basis, provide required notices, obtain any required parental or guardian authorisation, and use appropriate safeguards.
If you believe a child provided personal data directly to WayConnect without appropriate authorisation, contact us with enough information to locate the record.
19. Data Processing Addendum
Customers may request a Data Processing Addendum where WayConnect processes Customer Content on their behalf. The DPA may address documented instructions, confidentiality, subprocessors, security controls, breach assistance, individual-rights assistance, audits, return or deletion, and international transfer mechanisms.
A signed Order Form, DPA, or negotiated agreement takes precedence over this public Policy to the extent it expressly provides different terms for the same subject.
20. Changes, questions, and complaints
We may update this Policy when the Services, providers, legal requirements, or processing practices change. The current version and effective date will remain available on this page. If a change materially affects existing account data, we will provide additional notice through the website, workspace, email, or another appropriate channel before or when the change takes effect, as required.
Questions, complaints, privacy requests, and requests for the applicable grievance or data-protection contact may be sent to support@wayconnect.co. Include the relevant workspace and enough detail to route the request, but do not send passwords, one-time passcodes, complete card or bank details, API secrets, or unrelated sensitive records.
