Privacy Policy
Last updated: September 14, 2026
In short
At WAIA Connect we don't keep your customers' conversations. WhatsApp message content is not stored: it travels when needed and is deleted once delivery is confirmed. What stays with us is the detail of your transactions and usage and the log of the emails we send you.
To run the service we also keep traffic metadata (who and when, never the text) and your account and connection data. None of that is the content of a conversation. The details of all this are below.
Who we are
WAIA Connect is a product of ZZIA, the software brand of Consulta Automática (owner: Mariano Porcile, Córdoba, Argentina), which connects WhatsApp Business numbers to its customers' systems using Meta's official API (Cloud API and Coexistence). We operate under the app IAutoresponder (Meta App ID 1488010632180493) and are a Meta-verified technology provider. The infrastructure runs on servers located in Argentina.
This policy is the product-specific one and prevails on what it covers; the owner's general framework is the ZZIA privacy policy, published at zzia.info.
It explains what data we process and what we do NOT store. We describe what the system actually does.
The invariant that defines us: we don't store your message content
We do not persist the content of WhatsApp messages. It's a product principle from day one, not a setting. A message body travels when needed —when sending it to Meta, or when forwarding an inbound message to your endpoint— but it is not stored: it lives ephemerally while being processed and is deleted once delivery is confirmed.
What we do keep for each message is metadata: who (identifiers, not the body), when, the direction (inbound/outbound), the type, the status (sent/delivered/read/failed) and which connection it belongs to. Never the text, image or document.
What data we process
Your account data: name, email and profile picture provided by your Google sign-in.
Your connection data: the WhatsApp phone number, Meta identifiers (WABA, phone number id) and access tokens, which are stored encrypted (AES-256-GCM), never in plaintext.
Traffic metadata: as described above (no content). Recipient numbers, when a Meta restriction requires recording them, are stored hashed (SHA-256 with a per-account salt), not in the clear.
Usage and billing: message counters per period and the payment records of whichever processor you chose (MercadoPago or Polar).
How long we keep it
Message metadata: kept for up to 30 days, then purged.
Aggregated usage data (daily counters) and payment evidence: kept while the relationship is active and for as long as needed to meet accounting and legal obligations.
Ephemeral payloads (a message in the outbound queue, an event pending delivery to your endpoint): deleted once delivery is confirmed or retries are exhausted.
When you cancel your account, sending and active processing stop. Traffic metadata follows its retention period (max. 30 days); aggregated usage data and payment evidence are kept for the applicable accounting and legal obligations. You can request early deletion of anything we are not required to keep by writing to us.
Who we share data with (third parties)
We use a small set of providers to run the service, only what's necessary:
Meta (WhatsApp Cloud API): the messaging channel. Message content passes through Meta by the nature of the service.
MercadoPago: processes payments in Argentine pesos. We never see or store your card details — MercadoPago handles them directly.
Polar: processes payments in US dollars as merchant of record (it invoices and settles the applicable taxes). We never see or store your card details — Polar handles them directly. You choose which of the two to use when you subscribe.
Resend: sends our transactional emails (operational notices).
Google: provides sign-in. We do not publish or sell your data to third parties for advertising.
When you visit this site
We count how many times each page is opened and how many times each file is downloaded (the n8n workflows, the API contract, the documentation). We measure it ourselves, on our own server, and we store exactly four things: which page, when, which site the link came from, and which campaign —if the link carried one—.
In this log we store nothing that identifies you. Not your IP address (not even hashed or truncated), not which browser you use, not a device fingerprint, not an identifier that would let us recognise you across visits. From the referrer we keep only the site (for example google.com), never the full address of the page you were on.
The consequence is deliberate: this log cannot tell whether two visits are the same person, and we don't want it to. That's why we count visits, not visitors. The only thing that carries from one visit to the next are the functional cookies described below, and all they carry is which kind of route you arrived by —a value shared by everyone who arrives the same way, not an identifier of yours—: if you later create an account, that route is stored alongside it. If you never create an account, nothing of yours remains.
We use no third-party analytics —no Google Analytics or equivalent—: nobody but us sees your visit, and there is not a single line of tracking JavaScript on these pages.
Cookies: this site uses no tracking or advertising cookies. It does use up to three first-party, functional cookies. The first remembers which campaign brought you, if you arrived through a campaign link. The second remembers what kind of channel you arrived by —a search engine, an AI assistant, a social network, another site, or no referrer— without storing which site exactly. Both last 30 days and serve to recognise the origin if you create an account later. The third is set only if you arrived through a campaign link, lasts one day, and exists so the same visit is not counted twice.
None of the three carries personal data and none is shared with anyone. And the first two cannot recognise you across visits: they store a value shared by everyone arriving through the same campaign or the same kind of channel, so they cannot tell two people apart. The third does recognise your browser, and only within the same day: that is exactly what it exists for —not counting you twice— and it expires after 24 hours.
This visit log is kept for 180 days and is then deleted automatically.
If a reseller brought you
If you opened your account through a reseller (a commercial partner who promotes Connect), that reseller sees only: that your account exists, its name, the plan, the status and since when you've been a customer. They never see your WhatsApp numbers, your message content, your connections or your consumption. That separation is a system rule, not a setting.
Your number is yours
You own your WhatsApp Business Account (WABA) and your number. If you stop using Connect, your number stays yours and you can connect it to another provider. We don't hold it hostage or block it.
Security
Tokens and secrets are stored encrypted (AES-256-GCM). All traffic goes over HTTPS. Each account is isolated from the others at the data level.
Your rights and how to exercise them
You can access your account data from the panel, cancel your account (which stops processing), and unsubscribe from our emails via the link in each email or from the panel.
To access, rectify or delete your data, or for any question about it, write to us at hola@waiaconnect.com. You can also direct the request to the owner at mporcile@gmail.com, the address Consulta Automática registers for these requests at zzia.info. It's the same owner behind both sites.
Changes to this policy
If we change this policy we update the date above and, if the change is material, we notify you via the panel or email.
⚠ This is an operational, honest text describing how the service works; it is not legal advice and does not replace review by a lawyer. If in doubt, write to us at hola@waiaconnect.com.