Privacy Policy
What we collect, why we collect it, and what rights you have over it — written to be read without a lawyer.
Last updated:
Fasla Cloud (fasla.cloud) is a platform businesses use to run their customer conversations on WhatsApp. This policy covers the website and the application at https://app.fasla.cloud.
There are two kinds of data here, and the distinction matters because your rights differ by kind: your own data as an account holder, and your customers’ data, which passes through us on your instructions.
Who you are contracting with
- Legal name
- Fasla Cloud
1. Who is responsible for what
For your own account data — your name, your email, your subscription — we are the **controller**, because we decide why we hold it.
For your contacts and their conversations, **you** are the controller and we are a **processor** acting on your instructions. We do not decide who you message or what you keep; you do, and we carry it out.
If one of your customers wants to know what you hold about them, or asks you to delete it, that request goes to you — not to us. We help you carry it out; we do not answer on your behalf.
2. What we collect
- Your account
- Name, email, job title, country, any phone numbers you add, profile photo, and your company name and website if you provide them.
- Your workspace
- Workspace name, team members and their roles, subscription status, and settings such as timezone.
- Your customers
- Phone numbers, names, the tags and custom fields you add, and the text and media of conversations passing through the platform.
- Connection credentials
- Access tokens and keys for the WhatsApp channels you connect. These are stored **encrypted** and are never shown again in any interface after you save them.
- Technical data
- Error and usage logs needed to run the service and diagnose failures. No advertising trackers and no marketing profiles.
3. Why we collect it
We do not sell your data or your customers’ data to anyone, and we do not use the content of your conversations to train any models.
- To make the service work: without a phone number there is no message, and without an access token there is no WhatsApp connection.
- To secure your account: sign-in, roles and permissions, and phone-number verification.
- To answer you when you contact support.
- To comply with applicable law or with Meta’s terms where we are required to.
4. Our relationship with Meta and WhatsApp
The platform integrates with Meta's WhatsApp Business Platform. When you connect a number through the Cloud API, messages pass through Meta's servers and are subject to Meta's terms and privacy policies in addition to this document.
Billing for messages happens between you and Meta directly. We are not a party to it and we do not see your payment details at Meta.
Our access to and use of any information obtained through Meta APIs complies with the Meta Platform Terms and the WhatsApp Business Terms.
5. Who else can access your data
We rely on a small number of providers to run the service. Each has access only to the minimum its role requires:
- Supabase
- Database, authentication and file storage. Your account data and conversations are stored there.
- Meta Platforms
- Delivery of WhatsApp messages through the Cloud API.
- Our hosting provider
- Running the application itself.
There is no advertising network and no third-party analytics. If that ever changes, this document will be updated before the change takes effect.
6. How we protect it
No system is completely secure. If a breach affects your data, we will notify you without undue delay with what we know about its scope.
- Every workspace is isolated from every other at the database level (Row Level Security), not merely in application code.
- Access tokens and connection keys are stored encrypted with AES-GCM and are never returned to the browser after saving.
- Permissions are enforced on the server. Hiding a button in the interface has never counted as security here.
- Verification codes are stored as keyed hashes, never as digits, and are bounded by an attempt cap and an expiry.
7. How long we keep it
We keep your account data and conversations for as long as the account is active. When you request deletion, the account is frozen immediately and permanently erased within 14 days.
We may keep a minimal record — that an account was deleted, and when — where required by law or to establish or defend a legal claim. That record contains no conversation content.
The full request procedure, the timeline and the steps are on the Data deletion page.
8. Your rights
To exercise any of these, write to fasla.cloud@gmail.com from the email address on your account.
- See the data associated with your account, and edit most of it yourself in Settings.
- Request a copy of your data.
- Request correction of anything inaccurate.
- Request deletion of your account and its data — the procedure is on the Data deletion page.
- Withdraw consent by ceasing to use the service and requesting deletion.
9. Not a service for children
Fasla Cloud is a business tool, is not directed at anyone under 18, and we do not knowingly collect data from anyone in that age group. If we learn that an account was created by a minor, we will close it and delete its data.
10. Changes to this policy
We may update this document as the product develops. The date of the last revision is shown above. If a change materially affects your rights, we will tell you in the app or by email before it takes effect.
Questions about this document?
Write to us and we'll reply within support hours. If your question is about your own data, send it from the email address on your account so we can confirm it's you.