Effective 12 August 2026

Privacy Policy

How Quibly Tech collects, uses, stores and deletes information when a business connects its WhatsApp Business Account to Quibly.

1. Who we are

Quibly Tech ("Quibly", "we", "us") operates Quibly, a software platform that lets a business connect its WhatsApp Business Account to an AI assistant that reads incoming customer messages and helps the business reply, qualify leads, and manage bookings.

We are registered in India and act as a technology provider on the WhatsApp Business Platform (Cloud API), operated by Meta Platforms, Inc.

Legal entityQuibly Tech
Registered addressK501, Green Valley Apartments, Plot 18, Sector 22, Dwarka, New Delhi, South West Delhi, Delhi 110077
Udyam / MSMEUDYAM-DL-10-0027919
Shop & Establishment2026074250
Privacy contactprivacy@quiblytech.in
Telephone+91 78383 63463

2. Our role and yours

There are two kinds of people whose information passes through Quibly, and our responsibilities differ for each.

Business customers

The business that signs up for Quibly and connects its WhatsApp Business Account. For their account data we are the data fiduciary (controller) — we decide what we collect and why.

WhatsApp users who message that business

End customers who send a WhatsApp message to a Quibly-connected business number. For their messages we are a data processor acting on the business's instructions. The business is the controller of that conversation; we handle it on their behalf and do not use it for our own purposes.

If you messaged a business on WhatsApp and want your data removed, contact that business directly — they control it. You can also write to us at privacy@quiblytech.in and we will pass the request on and act on their instruction.

3. Information we collect

a. Business account information

  • Name, email address and phone number of the person signing up
  • Business name, category, address, operating hours and service details you provide
  • Login credentials (passwords are stored only as salted hashes — never in plain text)

b. WhatsApp connection information

  • Your WhatsApp Business Account (WABA) ID and business phone number ID
  • Display name and verification status of the connected number
  • Access tokens issued by Meta that authorise Quibly to send and receive messages on your behalf, stored encrypted at rest

c. Message content and metadata

When a WhatsApp user messages your connected number, Meta delivers that event to Quibly. We receive and store:

  • The message body — text, and for media messages the caption and a reference to the media
  • The sender's WhatsApp phone number and WhatsApp profile name
  • Message identifiers, timestamps, and delivery/read status of replies
  • Replies generated or sent through Quibly

d. Technical and usage information

  • Server logs — IP address, request paths, timestamps, error traces
  • Product usage — features accessed, conversations handled, message volumes

We do not collect payment card details. We do not run advertising trackers or sell data to anyone, ever.

4. WhatsApp Business app coexistence

Quibly supports Meta's coexistence mode, which lets a business keep using the WhatsApp Business app on a phone while the same number is also connected to the Cloud API through Quibly. This is optional and only happens if you choose it during onboarding.

When you enable coexistence, Meta synchronises additional data from your WhatsApp Business app to Quibly. You are consenting to that synchronisation. Specifically we may receive:

What syncsWhy
Contact list from your WhatsApp Business appSo Quibly recognises returning customers and does not treat them as new enquiries
Message history — up to six months of past conversationsSo the assistant has context on prior conversations and does not ask a customer something they have already answered
Message echoes — copies of messages you send from the WhatsApp Business app by handSo Quibly does not duplicate or contradict a reply you have already sent yourself

This historical data is stored on the same terms as all other message content described in this policy, and is deleted on the same schedule. If you disconnect coexistence, we stop receiving new syncs; previously synced history is deleted when you delete your account or on request.

Important for coexistence users: synced history may contain conversations with people who never interacted with Quibly directly. We process that data solely to provide the service to you, never for our own purposes, and never to train models available to anyone else.

5. Automated processing and AI

Quibly's core function is automated. Message content is sent to third-party large-language-model providers to generate suggested or automatic replies. Currently those providers are:

  • OpenAI — reply generation and text analysis
  • Google (Gemini) — reply generation and content assistance

We use these providers under their enterprise/API terms, which prohibit using submitted content to train their general-purpose models. We do not send them your access tokens or login credentials — only the conversation content needed to produce a reply.

Automated replies can be wrong. Quibly is an assistant, not a substitute for human judgement, and you remain responsible for what is sent from your number. Where a decision could materially affect a customer, review it before it goes out.

6. How we use information

  • To deliver the service — receive messages, generate replies, send them via the WhatsApp Business Platform
  • To authenticate you and keep your account secure
  • To maintain conversation context so the assistant behaves sensibly across a conversation
  • To provide dashboards, reporting and analytics to you about your own account
  • To diagnose faults, monitor reliability and prevent abuse
  • To meet legal obligations and enforce our terms

We do not use your messages or your customers' messages for advertising, for resale, or to train models offered to third parties.

7. Who we share it with

RecipientPurpose
Meta Platforms, Inc.Message delivery over the WhatsApp Business Platform. Meta's own handling is governed by Meta's terms and privacy policy.
OpenAIGenerating replies and analysing message text
GoogleGenerating replies (Gemini) and content assistance
Hosting and infrastructure providersRunning our servers and databases
Law enforcement or regulatorsOnly where legally compelled, and only to the extent required

We do not sell personal data. We do not share it with data brokers or advertising networks.

8. Meta platform terms

Because Quibly integrates with the WhatsApp Business Platform, our handling of data obtained through Meta's APIs is additionally governed by Meta's Platform Terms and Developer Policies. Where those terms are stricter than this policy, they prevail. That includes limits on how long we may retain platform data and an obligation to delete it on request or when it is no longer needed for the purpose it was obtained.

9. Retention

DataRetained for
Business account and profileWhile your account is active
Conversation content and metadataUp to 24 months from the message date, unless you ask for shorter
Coexistence-synced historySame as conversation content
Access tokensUntil you disconnect WhatsApp or the token is revoked
Server and audit logsUp to 12 months
Records we must keep by lawAs long as the law requires

When you close your account we delete or irreversibly anonymise your data within 30 days, except where retention is legally required.

10. Security

  • All traffic to and from Quibly is encrypted in transit over HTTPS/TLS
  • Access tokens and two-step verification PINs are encrypted at rest
  • Passwords are stored as salted hashes only
  • Every inbound webhook from Meta is verified using an HMAC-SHA256 signature before it is processed
  • Access to production systems is restricted and logged
  • Each business's data is logically separated by tenant and never mixed across accounts

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by law, without undue delay.

11. Where data is stored

Quibly's servers are located in India. Where a WhatsApp Business Account is eligible, we set Meta's data localisation region to India (IN) so that message data is stored locally by Meta as well.

Some of our sub-processors — notably Meta, OpenAI and Google — operate globally and may process data outside India. Where that happens, we rely on the contractual protections in those providers' enterprise terms.

12. Your rights

Under India's Digital Personal Data Protection Act, 2023 and other applicable law, you may:

  • Ask what personal data we hold about you and get a copy
  • Ask us to correct data that is wrong or incomplete
  • Ask us to delete your data
  • Withdraw a consent you previously gave, including consent to coexistence synchronisation
  • Nominate someone to exercise these rights on your behalf
  • Raise a grievance with us, and escalate to the Data Protection Board of India if unresolved

Write to privacy@quiblytech.in. We respond within 30 days and may need to verify your identity first.

13. Deleting your data

Full instructions, including what is deleted and how long it takes, are on our Data Deletion page.

14. Children

Quibly is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, write to privacy@quiblytech.in and we will delete it.

15. Changes

We may update this policy as the product or the law changes. The effective date at the top always reflects the current version. For material changes affecting how we use your data, we will notify account holders by email at least 14 days before the change takes effect.

16. Contact us

Grievance Officer — Quibly Tech

K501, Green Valley Apartments, Plot 18, Sector 22, Dwarka
New Delhi, South West Delhi, Delhi 110077
Email: privacy@quiblytech.in
Phone: +91 78383 63463