Privacy policy
Last updated 16 October 2026
Chatji (chatji.ai) is software that businesses use to talk to their customers on WhatsApp. It is operated by Chatji("we", "us"). This policy explains what data we handle, why, and the choices you have.
Who is responsible for what
- Businesses that use Chatji (our customers) decide which of their customers they message and why. For their customers' data they are the data fiduciary / controller, and we process that data on their behalf and on their instructions.
- For our own account holders (people who sign in to Chatji) we are responsible for the data described below.
Data we handle
- Account data: your email address, name of your business, your role, sign-in records. Sign-in uses one-time codes sent by email; we keep only a hashed form of each code and session.
- WhatsApp data of a business's customers: phone number, WhatsApp profile name, messages exchanged with the business (text and descriptions of media), delivery status, opt-in or opt-out (STOP/START), and, when the chat began from a Click-to-WhatsApp ad, the ad id, its text and the click id Meta provides.
- Data from systems a business connects: for example order number, items, total, payment method and tracking link from Shopify or WooCommerce; booking or payment details sent through our events API; Razorpay payment link status.
- Connection credentials: WhatsApp access tokens, Shopify tokens, Razorpay keys and webhook secrets. These are stored encrypted (AES-256-GCM) and never shown again in the app.
- Information a business gives its AI agent: the business description, prices, policies and hours it enters.
- Technical data: server logs (for example request time and errors) kept for security and troubleshooting.
How we use it
- To provide the service: receive and send WhatsApp messages, show them in the business's inbox, run the automations and broadcasts the business sets up, and create payment links it asks for.
- To answer customers with the AI agent, when the business switches it on: the recent conversation and the business's own information are sent to the AI provider to draft a reply. The AI is told not to make up facts and to hand over to the business when unsure.
- To report Click-to-WhatsApp ad results to Meta, when the business switches this on: the event type (for example Purchase), its value and Meta's click id. No message content or phone number is sent for this.
- To keep the service secure, prevent abuse, and meet legal obligations.
We do not sell personal data and do not use a business's customer data for advertising of our own.
Service providers we use
- Meta Platforms (WhatsApp Business Platform / Cloud API): to send and receive WhatsApp messages, and the Facebook login used to connect a WhatsApp number.
- Vercel (application hosting) and Supabase (database). Both run in the Tokyo, Japan region.
- Resend: to email sign-in codes.
- OpenAI or Anthropic: to draft AI replies, only for businesses that switch the AI agent on.
- Services a business chooses to connect, such as Shopify, WooCommerce and Razorpay.
Data may therefore be processed outside India. We share only what each provider needs to do its job.
Cookies
We use one cookie to keep you signed in. We do not use advertising or analytics cookies. The page for connecting a WhatsApp number loads Meta's Facebook SDK, which may set Meta's own cookies when you use it.
How long we keep data
We keep data while the business's Chatji account is active, so its inbox and history keep working. When a business closes its account or asks us to delete data, we delete it within 30 days, except where the law requires us to keep it longer. Copies in backups are removed as those backups expire.
Your choices and rights
- Customers of a business can reply STOP to stop marketing messages from that business, and START to allow them again.
- To access, correct or delete your data, contact the business you were talking to, or write to us at support@chatji.ai. See Data deletion for the steps.
- You may also complain to the data protection authority where you live, for example the Data Protection Board of India.
Security
Connections use HTTPS. Credentials are encrypted at rest. Access to a business's data in Chatji is limited to that business's team members. Webhooks from Meta, Shopify, WooCommerce and Razorpay are checked with their signatures before they are accepted.
Children
Chatji is a service for businesses and is not meant for children.
Changes and contact
If we change this policy we will update the date above, and tell account holders about important changes. Questions: support@chatji.ai.