Privacy Policy
Last updated: 26 August 2026
In short
- We do not sell personal data, and we do not use your WhatsApp conversations to train AI models or for advertising.
- Message content passes through Meta because delivery runs on the WhatsApp Business Platform — that is unavoidable, not optional sharing.
- AI-assisted replies (OpenAI) are off by default and only see conversation text if you turn that feature on.
- Closed accounts are deleted or anonymised within 90 days, except records we must keep for tax and accounting law.
Who we are
Wovara CRM (“Wovara”, “we”, “us”) is a customer-messaging platform that lets businesses manage WhatsApp conversations with their own customers. The service is operated by Go4Lead. You can reach us at grow@go4lead.com.
This policy covers two different groups of people, and it is important to keep them apart:
- Our customers — the businesses that sign up for a Wovara CRM account and use it to talk to their own customers.
- End users — the people those businesses message on WhatsApp. For this data we act as a processor on the business’s behalf; the business, not Wovara, decides what is sent and to whom.
Information we collect
Account information
When a business creates an account we collect a name, work email address, password (stored only as a salted hash — never in readable form), company name, and workspace identifier.
WhatsApp Business connection
When a business connects its WhatsApp Business Account we receive and store the WhatsApp Business Account ID, phone number ID, display phone number, and an access token issued by Meta. Access tokens are encrypted at rest using AES-256-GCM and are never displayed back in full through the interface or our API.
Messages and contacts
To provide a shared inbox, campaigns and automation, we store the contacts a business adds or imports (phone number, name, email, and any custom fields the business chooses to add) and the WhatsApp messages exchanged with them, including message content, media references, timestamps and delivery status.
Billing information
Payments are processed by Razorpay and Stripe. Card details are entered directly with those providers and never reach our servers. We retain transaction identifiers, amounts and invoice records for accounting and tax purposes.
Technical information
We record standard server logs (IP address, browser user agent, timestamps, requested endpoints) and application error reports, which we use for security, debugging and abuse prevention.
How we use information
- To operate the service — delivering messages, syncing status, running campaigns and automations.
- To authenticate users and secure accounts, including optional two-factor authentication.
- To calculate usage, apply per-message charges and produce invoices and statements.
- To provide support when a customer contacts us.
- To detect, investigate and prevent fraud, abuse and violations of our terms.
- To meet legal, tax and regulatory obligations.
We do not sell personal data. We do not use the content of our customers’ WhatsApp conversations to train machine-learning models, and we do not use it for advertising.
Sub-processors and third parties
We share data with a limited set of providers, only as needed to run the service:
- Meta Platforms — the WhatsApp Business Cloud API delivers all messages; message content necessarily passes through Meta.
- Amazon Web Services — hosting and data storage.
- Razorpay and Stripe — payment processing.
- OpenAI — only if a business enables AI-assisted replies. When enabled, the relevant conversation text is sent to OpenAI to generate a response. This feature is off by default.
- Sentry — application error monitoring.
- Email delivery providers — for transactional email such as password resets and invoices.
If a business connects an optional integration (for example HubSpot or Shopify), data is also shared with that provider under the business’s own instruction and their privacy policy applies to what they do with it.
Data retention
We keep account and message data for as long as the account is active. After an account is closed, data is deleted or irreversibly anonymised within 90 days, except where we are required to retain records longer for legal, tax or accounting reasons — invoices and transaction records, for example, are typically retained for the statutory period.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email grow@go4lead.com.
If you are an end user who received a WhatsApp message from a business using Wovara CRM, your relationship is with that business. We will pass your request on to them, and you can stop receiving messages at any time by replying to opt out or blocking the number in WhatsApp.
Security
All traffic is encrypted in transit with TLS. WhatsApp access tokens and other sensitive credentials are encrypted at rest with AES-256-GCM. Access to production systems is restricted, and each business’s data is isolated by tenant so one customer cannot read another’s data. No system is perfectly secure, but we work to protect data using measures appropriate to its sensitivity.
International transfers
We operate primarily from India and our infrastructure is hosted in the Asia-Pacific region. Some sub-processors listed above operate in other countries, so data may be transferred internationally and protected under the safeguards those providers offer.
Children
Wovara CRM is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes to this policy
We may update this policy as the service evolves. If a change materially affects how we handle personal data, we will notify account holders by email or in the application before it takes effect.
Contact
Questions about this policy or how we handle data: grow@go4lead.com.