Legal
Privacy Policy
Last updated: 4 October 2026
This policy explains what data Vancely, a product of Bytevancer, handles, why, and the choices you have.
Our privacy promise
Our policy is to store as little as possible. We built Vancely so that the conversations you and your customers have stay yours:
- We never store message content. WhatsApp messages travel over encrypted connections, are kept only until they are delivered and are then erased; website chats are erased when the chat ends.
- Nothing people tell you is saved without consent. The details people type in (such as their name, email address or answers to your bot) and chat transcripts are saved only when you turn the feature on and the person agrees in the chat. Without both, they are not kept.
- Only what we need to run the service. To deliver messages, prevent abuse and bill you, we keep minimal records: your account and billing details; for each message the phone number, the name shown on WhatsApp, its type, status and time; and each recipient's opt-in or STOP record. Message records are deleted after 90 days.
- No selling, no advertising. We never sell personal data or use the people you talk to for our own marketing.
Data about you (our customer)
- Account details: business name, your name, email address and a hashed password.
- Billing records: plans, invoices, payment method and payment reference you give us.
- Technical data: IP addresses, API key usage and logs we need to secure and operate the service.
Data you process through the service
When you connect a number, we process the messages you send and receive through it: phone numbers, names shown on WhatsApp, message text, media and delivery status, plus the consent and opt-out records the service keeps for each recipient. For this data you are the controller and we act as your processor: we use it only to deliver the service to you.
- The WhatsApp session for each connected number is stored on our servers so the number stays linked. Logging the number out removes it.
- We do not store message content. Text, captions, locations and files exist on our servers only while they are on their way, encrypted, and are erased as soon as they are delivered: outbound content once WhatsApp accepts the message, inbound content once your webhook receives it (or, if your endpoint keeps failing, when we stop retrying after a few hours).
- Inbound files are kept encrypted until a few minutes after their first complete download through the API, and never longer than 24 hours.
- Bot flows keep a contact's answers encrypted in memory only while the conversation is running (at most about an hour after the last message), then hand them to your webhook and erase them. Reminders a flow schedules keep their text encrypted until they are sent (at most 30 days), then it is erased.
- Saved responses are opt-in. A business can choose to keep the answers one of its flows collects (for example a name, email or project details) as a form in its dashboard. This is off by default, the business must confirm it asks for consent, and answers are saved only for contacts who agree in the chat. They are stored encrypted, deleted automatically after the period the business sets (at most a year) or when it deletes them, and are never used by us. Chat messages themselves are still not stored.
- Website chat. When a business adds our chat widget to its website, visitors' messages pass through our servers encrypted and are deleted when the chat ends (or after it has been idle for a while). The visitor's browser keeps its own copy of the conversation. A name or email the visitor enters before chatting is kept encrypted only while their chat session is valid. If the business uses chat webhooks, the text, name and email in them are kept encrypted until its endpoint receives them (or we stop retrying), then erased. If the visitor agrees to a saved transcript (below), their messages and name are kept until that transcript's retention ends.
- Chat transcripts are opt-in. A business can turn on transcripts for its chat widget after confirming it understands what is kept. The chat then asks each visitor whether to save a copy; only if the visitor answers Yes are the messages from that moment on stored, encrypted, and deleted automatically after the period the business sets (at most what its plan allows) or when it deletes them. Visitors who answer No, or are never asked, have nothing saved.
- What we keep is metadata: phone numbers, names shown on WhatsApp, message type, status and timestamps.
How we use data
- To provide, secure and support the service, and to enforce the Acceptable Use Policy (for example, detecting broadcasts).
- To bill you and to send service emails such as password resets, invoices and important notices.
- We do not sell personal data and do not use your recipients' data for our own marketing.
Sharing
We share data only with providers that help us run the service (listed on our Sub-processors page), with WhatsApp as needed to deliver your messages, and with authorities when the law requires it.
Retention
Account and billing records are kept while your account is open and afterwards as long as the law requires. Message content is not kept (see above). Message metadata is kept for 90 days and webhook delivery logs for 30 days. When an account is closed, the remaining message data and WhatsApp sessions are deleted within a reasonable period.
Security
API keys are stored hashed, webhook secrets are encrypted, connections use HTTPS, and access to production systems is restricted. No system is perfectly secure; tell us immediately if you believe your account was compromised. More detail is in our Security overview.
Your choices
You can update your profile in the dashboard and ask us for a copy of your data, a correction or deletion. Recipients who no longer want messages can reply STOP, and should contact the business that messaged them for other requests.
Your rights
Depending on where you live (for example under the GDPR in the EU and UK, or the CCPA in California), you have the right to:
- Access the personal data we hold about you and get a copy of it.
- Correct data that is wrong or incomplete.
- Delete your data, unless we must keep it by law (for example invoices).
- Portability: receive the data you gave us in a common, machine-readable format.
- Object to or restrict how we use your data, and withdraw any consent you gave.
- Not be treated differently for using these rights. We do not sell personal data or share it for advertising.
To make a request, email support@bytevancer.com from the address on your account. We may ask you to confirm your identity and will reply within the time the law requires. You can also complain to your local data protection authority.
If a business messaged you through Vancely, that business controls your data: send your request to it. If you contact us instead, we will pass it on and help the business answer it.
International transfers
We serve customers worldwide, so data may be processed in a country other than your own, including where our servers are hosted. Where the law requires it, such as for transfers from the EEA, the UK or Switzerland, we protect those transfers with appropriate safeguards, such as the European Commission's Standard Contractual Clauses described in our Data Processing Addendum.
Children
Vancely is a service for businesses. Account holders must be 18 or older (see our Terms), and the service is not meant for children. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
Related policies
- Cookie Policy: the few cookies and browser storage the service uses.
- Data Processing Addendum: our commitments when we process data for you.
- Sub-processors: the providers that help us run the service.
- Security overview: how we protect the service and your data.
Contact
Privacy questions: support@bytevancer.com.