Privacy Policy
KaushalStack Technologies · Last updated 14 September 2026
Draft under review. Payments are in test mode and no charges are made while this notice is shown; the final policy will be published before live payments begin.
Whose data this is
A linked WhatsApp account belongs to a person — usually an employee or founder of the organisation that pays for the Service, or a business number the organisation owns. The contacts, groups and messages it holds are that person's, and the people in them — family, friends, clients, a doctor — are the data principals: they have not signed up to anything and cannot be asked by us. Linking therefore mirrors personal data of people who never consented. We limit what we do with it accordingly: metadata-only scoring, no sending, no sharing between members, no advertising, and deletion on request. The organisation and the member decide whether that is appropriate for a given number; we recommend company-owned business numbers for that reason.
What we collect
- Organisation data: name, address, owner email, billing details and GSTIN, and sign-in records.
- Linked-account data: for each linked WhatsApp account, the contact list, group rosters, chat list and message records (sender, time, direction, length, and the text where the plan includes topic tagging) mirrored from the device history, plus the device credentials WhatsApp issues to a linked device.
- Derived data: relationship strength scores computed from message metadata only; topic tags with the quote they were taken from; and, on plans with semantic search, numerical embeddings of contact profiles.
- Message text leaving this server: on plans with semantic search, a contact's profile sent to the embedding provider includes the contact's name, topics and short samples of recent message text (capped per contact); on plans with AI topic extraction, the messages being tagged are sent to the AI provider for that request. Starter plans send no message text anywhere.
- Payment data: transaction identifiers and invoices from Razorpay. Card, UPI and bank details never reach us.
- Technical data: server logs with IP addresses and request paths, kept for security and troubleshooting.
How we use it
Only to provide, secure, support and bill the Service. We never send WhatsApp messages, never contact anyone in a linked account's network, and do not sell or share personal data. Semantic search sends contact profiles — name, topics, and short samples of that contact's messages — to an embedding provider (currently OpenAI) through a stateless relay that stores nothing; topic extraction, where enabled, sends the specific messages being tagged to an AI provider for that request only. Nothing is used to train models. Members are told which of these applies to their plan before they scan.
Who inside an organisation sees what
- A member sees only their own network.
- The organisation owner sees who has linked an account, sync status and how much has synced — never a member's contacts, scores or messages, and no aggregate of them. Introductions are brokered: a teammate is told only that someone has a strong connection, and the member who has it decides whether to reveal a name.
- KaushalStack Technologies's operators can see organisation status, counts and billing; access to a member's network for support requires that member's consent and is logged.
How we protect it
- Every record derived from a linked account carries that account's id, and the database client enforces the boundary: one account cannot query another's rows.
- All traffic is encrypted in transit; device credentials are stored per account in a private directory on encrypted disks in India.
- The Service is read-only by construction: the code contains no path that sends a WhatsApp message.
Retention, unlinking and deletion
We keep an organisation's data while it exists. A member can unlink their WhatsApp at any time (from WhatsApp's Linked Devices screen or from their Account page), which stops all further reading; they can also delete their mirrored data from the Account page. When an organisation is closed, a recovery archive is kept for 24 hours and then deleted, except records we must keep by law (invoices).
Your rights and contact
Members can see, export and delete their own mirrored data in the Service. People who appear in someone else's network may write to admin@kaushalstack.com to ask what is held about them; because that data belongs to the linked account's organisation, we forward the request to that organisation and act on its instructions, or on a lawful request. Data-protection questions and breach notifications go to the same address.