Privacy Policy
Tarabot Connect — a WhatsApp Business messaging module operated by Tarabot Technology Solutions.
Tarabot Technology Solutions ("Tarabot", "we", "us", "our") is a Jordan-based technology company building digital infrastructure for humanitarian and non-profit organizations. Tarabot Connect is our WhatsApp Business messaging module: it lets client organizations send and receive WhatsApp messages, manage message templates, and track delivery statuses through the official WhatsApp Business Platform (WhatsApp Cloud API), using data Meta classifies as Platform Data.
This policy explains what Platform Data and related account data we process through Tarabot Connect, why, how we protect it, and how you can request its deletion.
What data we collect
- Account and organization information — the client organization's name and the staff accounts authorized to use the dashboard.
- WhatsApp Business Account (WABA) IDs and Phone Number IDs — identifiers for the connected WhatsApp Business Account and sending number, assigned by Meta.
- Message templates — template names, languages, categories, body text, and Meta's approval status for each template.
- Message content and metadata — the text of messages sent and received, sender/recipient WhatsApp numbers, timestamps, and Meta message IDs.
- Webhook events and delivery statuses — inbound message events and status callbacks (sent, delivered, read, failed) that Meta pushes to our webhook endpoint.
- Technical logs — request/response logs needed to operate and troubleshoot the integration (e.g. API call outcomes, error codes).
- Access tokens — Meta system-user access tokens used to authenticate API calls, stored server-side only (see "How we protect it" below).
Why we process it
We use Platform Data to enable client organizations to send and receive WhatsApp messages with their beneficiaries, customers, and stakeholders; manage those conversations from one dashboard; and generate basic service-delivery records (message status, timestamps) needed for accountability and reporting. Platform Data is used only to route messages, display conversation history to the client's authorized staff, and operate the messaging service itself.
We do not sell Platform Data, and we do not use it for advertising or any purpose unrelated to providing the messaging service the client organization requested.
How we protect it
- All WhatsApp Cloud API calls are made server-side only — access tokens and app secrets are never sent to, or readable from, the browser/frontend.
- Per-client access tokens in the production multi-tenant platform are encrypted at rest (AES-256-GCM).
- Inbound webhook requests are verified against Meta's
X-Hub-Signature-256header (HMAC-SHA256, constant-time comparison) before any data is accepted or processed. - Access to Platform Data is restricted to authorized Tarabot personnel and the client organization's own authorized staff — no other client or third party can view another organization's data.
Who may access it — service providers / subprocessors
We use the following categories of infrastructure providers to operate Tarabot Connect:
- Meta Platforms, Inc. — WhatsApp Business Platform / Cloud API itself.
- Cloud hosting / tunneling infrastructure — used to run the backend and receive webhook callbacks over HTTPS. Exact provider(s) depend on the deployment (see the Data Handling document); during App Review demo testing this may include ngrok, Inc. for HTTPS tunneling.
We do not share Platform Data with any other third party, and we do not permit subprocessors to use Platform Data for their own purposes.
Data retention & deletion
Platform Data is retained only as long as needed to provide the service and to satisfy the client organization's own retention requirements. See our Data Deletion page for how to request deletion, what is deleted, and how a Meta/WhatsApp connection is disconnected.
Contact
Questions about this policy or requests regarding your data: info@tarabot.info
Tarabot Technology Solutions · Zahran St., 7th Circle, Amman, Jordan
Last updated: 19 July 2026