Privacy Policy

Last Updated: May 16, 2026

This Privacy Policy describes how MsgOrb ("we," "us," or "our"), accessible at msgorb.com, collects, uses, and shares your personal information when you use our WhatsApp automation Software as a Service (SaaS) platform and our international calling services, and the choices you have associated with that data.

Our Role as a Technology Provider

MsgOrb acts as a technology service provider to businesses that use our platform to send WhatsApp messages to their own customers. In this capacity:

  • MsgOrb is a data processor, not a data controller, for message content sent through our platform
  • The businesses using MsgOrb are the data controllers for their customers' data
  • MsgOrb does not use WhatsApp message content for any purpose other than delivering the service requested by the business
  • MsgOrb does not claim ownership of any message content, contact lists, or customer data processed through our platform
  • Message content is not used for advertising, profiling, or any secondary purpose

Information We Collect

When you register for an account or use our services, we collect the following personal information directly from you: First and last name, Email address, Phone number, Address, City, State, and ZIP code. We do not collect information using advertising trackers, analytics tools, or remarketing technologies.

Information Collected Automatically

  • IP addresses collected for security and abuse prevention
  • User agent strings and browser information collected for compatibility
  • Server access logs retained for 30 days for security monitoring

These are operational necessities, not tracking or analytics.

How We Use Your Information

We use the collected information to: create and manage your account, provide and maintain our services (including WhatsApp automation and international voice calling), process your payments and manage billing, communicate with you regarding updates and support, and facilitate the connection of your WhatsApp Business account via Meta's Embedded Signup.

Legal Basis for Processing (GDPR)

Our legal basis for processing your information includes:

  • Contractual necessity: processing required to deliver the service you signed up for
  • Legal obligation: processing required to comply with applicable laws
  • Legitimate interests: security monitoring, fraud prevention, platform improvement

Third-Party Services

We do not sell your personal information. We share your information only with: Stripe (payment processing), Supabase (authentication and database), Resend (transactional emails), strictly vetted telecommunications partners (solely for routing international voice calls), and Meta (WhatsApp Business integration). Your use of WhatsApp messaging via our platform is also subject to Meta's Privacy Policy.

Data Security

We implement industry-standard security measures to protect your data and your customers' data from unauthorized access, loss, or misuse:

  • Encryption in Transit: All data transmitted between our platform, your browser, and third-party partners (such as Meta's WhatsApp network) is encrypted using TLS 1.2 or higher (including TLS 1.3).
  • Encryption at Rest: All database storage (including backups) is encrypted at rest using industry-standard AES-256 encryption.
  • Access Control: We enforce strict, role-based access control (RBAC). Only authorized personnel who require access to perform their duties can interact with sensitive systems. We do not read, process, or store the contents of your messages except as strictly necessary for transmission.
  • Infrastructure Certifications: We host our infrastructure with leading cloud providers (like Supabase and Google Cloud/AWS) that hold internationally recognized security certifications, including SOC 2 Type II and ISO 27001.
  • Regular Audits: Our platform undergoes regular automated vulnerability scanning and security reviews to identify and mitigate potential threats.

Data Retention

We retain your personal account information only as long as your account is active or as necessary to fulfill the purposes set out in this policy and required by law. Message transmission logs and metadata are retained temporarily (e.g., up to 30 days) for operational troubleshooting, after which they are securely deleted. Message content is not retained longer than strictly necessary to complete delivery to the Meta network.

User Rights and Data Deletion

You have the right to access, correct, restrict processing of, or request the deletion of your personal information. To request complete deletion of your account and associated data, please contact us at privacy@msgorb.com. We will process your deletion request within 30 days. If you are an end-customer of a business using MsgOrb, please contact that business directly to exercise your data rights.

California Privacy Rights

California residents may request disclosure of data collected and shared. We do not sell personal information to third parties. Contact privacy@msgorb.com to make a California privacy request.

Cookies

We use only essential cookies necessary to keep you logged in and ensure platform security. We do not use advertising or tracking cookies.

Children's Privacy

Our services are not intended for anyone under the age of 13. We do not knowingly collect data from children under 13.

Meta WhatsApp Business API Compliance

MsgOrb complies with Meta's WhatsApp Business API terms and policies. We do not use WhatsApp user data to target advertisements, build user profiles, or for any purpose beyond providing the automation service requested. Message delivery data is processed in accordance with Meta's platform policies.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by posting the new policy on this page and updating the Last Updated date.

Contact Us

Email: privacy@msgorb.com