Privacy Policy
Last updated July 21, 2026
Placeholder — pending legal review
This document uses templated language adapted from a standard SaaS legal template. It is provided for transparency and product-review purposes and is not final or binding legal text. A lawyer-reviewed version will replace it before it takes effect.
1. Overview and our role
This Privacy Policy explains how Relay collects, uses and shares information when you use our WhatsApp CRM service. It covers both the information we handle as a controller (for our own account, billing and product-improvement purposes) and the end-customer data we process as a processor on behalf of our customers.
Controller vs processor
For the personal data of our own users — account holders, team members and prospects — Relay acts as a data controller. For the WhatsApp messages and contact details our customers exchange with their end-customers, Relay acts as a data processor: our customer is the controller, and we process that data only on their documented instructions. Our processing of end-customer data is governed by our Data Processing Addendum.
2. Information we collect
Account and profile data
Name, email address, password (stored hashed by our authentication provider), organization/account details, team membership and role, and preferences.
WhatsApp messages and contacts (processed on our customers’ behalf)
When you connect a WhatsApp Business number, we receive and store the messages you send and receive, the phone numbers and WhatsApp profile names of the contacts you communicate with, message media, and delivery/read status. This data belongs to our customer and is processed on their behalf.
Billing data
Subscription, plan and payment information is handled by our payment processor (Stripe). We do not store full card numbers; we retain limited billing metadata such as plan, status and invoices.
Usage and metering data
Product usage, feature metering (e.g. message and broadcast counts), device/browser information and log data used for security, troubleshooting and billing.
Cookies and analytics
We use strictly necessary cookies for authentication and session management, and may use limited analytics to understand product usage. See “Cookies” below.
3. How we use information and legal bases
We use information to provide, secure and improve the Service, to authenticate users, to process payments, to send transactional communications, to provide support, to meter usage, and to comply with legal obligations. Depending on your jurisdiction, our legal bases include performance of a contract, our legitimate interests in operating and securing the Service, your consent (where required, e.g. for certain analytics), and compliance with legal obligations.
4. Sub-processors and sharing
We share data with the following categories of service providers who process it on our behalf under appropriate contractual safeguards:
- Supabase — Managed Postgres database, authentication and file storage — the primary system of record. (United States / EU).
- Meta Platforms (WhatsApp Business Cloud API) — Sending and receiving WhatsApp messages on your behalf via the official WhatsApp Business Platform. (United States / global).
- Stripe — Subscription billing and payment processing. (United States).
- Email delivery provider — Transactional email (invitations, notifications, password resets). (United States / EU).
- AI model providers (bring-your-own — e.g. OpenAI, Anthropic) — Generating reply drafts and running the optional AI assistant, using an API key you supply. Only engaged when you enable AI features. (United States).
We do not sell personal data. We may disclose information where required by law or to protect our rights, users or the public.
5. Data retention
We retain account and message data for as long as your account is active and as needed to provide the Service. When you delete data or close your account, we delete or anonymize the associated data within a commercially reasonable period, except where we must retain limited records to comply with legal, tax or security obligations.
6. International transfers
Our providers may process data in the United States and other countries. Where personal data is transferred across borders, we rely on appropriate safeguards such as Standard Contractual Clauses. [Specific transfer mechanisms — to be confirmed on legal review.]
7. Your rights, export and erasure
Depending on your location, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Account holders can export and delete data directly from within the product; for end-customer data, requests should be directed to the relevant customer (the controller), and we will assist them as their processor.
Export and delete your data from your account:
To exercise a right or ask a question, contact privacy@relay.app. You may also have the right to lodge a complaint with your local data-protection authority.
8. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit (HTTPS/TLS), encryption of WhatsApp access tokens at rest using AES-256-GCM, row-level security (RLS) enforcing strict tenant isolation on our database, role-based access controls, and signed/verified webhooks. No method of transmission or storage is completely secure, but we work to protect your information.
10. Contact and data protection
For privacy questions, or to reach our data-protection contact, email privacy@relay.app. For a description of how WhatsApp/Meta data flows through the Service, see our data-handling page.