BVFX Digify Messaging Privacy Policy
Business identity: BVFX Digify Messaging. Support and data requests: bvfx96@gmail.com.
Last updated: October 2, 2026
What this software does
BVFX Digify Messaging is a WhatsApp messaging SaaS sandbox and integration tool for business accounts. It manages business onboarding, contacts and consent, message templates, scheduled campaigns, delivery reports, webhook status updates, incoming WhatsApp replies, and sandbox wallet records. Live WhatsApp sending is gated by server configuration and real billing is disabled in the current build unless explicitly enabled in a future approved production setup.
Data we store and why
- Business and account details: business name, owner name, owner email, mobile number, account status, invitation records, user email, user name, and password hash. This is used to create business tenants, authenticate users, manage admin access, and suspend or activate accounts.
- Contacts and consent records: contact name, phone number, tenant ID, and consent state such as verified, missing, or opted out. This is used to decide who may receive WhatsApp messages and to suppress opted-out contacts at send time.
- Templates, campaigns, schedules, and jobs: template name, language, category, body, approval state, campaign name, scheduled time, recipients JSON, job status, attempts, lock time, and errors. This is used to queue and recover scheduled sends, prevent duplicate sends, and show campaign history.
- Messages, delivery reports, and incoming replies: outbound and inbound direction, contact name or ID when available, provider message ID, message text, status such as submitted, delivered, read, failed, received, or ambiguous, timestamps, and campaign ID. This is used for delivery reports, shared inbox display, reconciliation, and duplicate webhook protection.
- Provider connections and webhook events: tenant ID, provider name, WhatsApp Phone Number ID, WABA ID, display number, connection status, provider event IDs, event type, and received time. This is used to route signed Meta webhook events to the correct tenant and avoid processing duplicate events.
- Sandbox billing data: test ledger entries for credits, reservations, settlements, and refunds. These are non-production test records and are not live payment transactions.
Data shared with Meta WhatsApp Cloud API
When live WhatsApp sending is intentionally enabled, the software sends Meta the recipient WhatsApp phone number, approved template name, template language, and template parameters required by the approved template. Meta returns provider message IDs and later sends webhook events for message status and inbound replies. The webhook receiver validates Meta signatures using the app secret before processing POST requests. Inbound replies from WhatsApp may include the sender phone number, provider message ID, message text, and status metadata. The software does not send sandbox wallet records, passwords, password hashes, or business-user login credentials to Meta.
Credential security
Meta access tokens, app secrets, webhook verify tokens, and encryption keys are configured server-side in environment variables or the local .env file. The repository ignores .env and credential files so they are not committed. The app avoids printing secrets in normal setup and diagnostic commands. The current local build stores provider connection metadata in SQLite; production secret-manager storage is still a required hardening step before operating this as a production multi-tenant service.
Retention and deletion
SQLite records are retained until an administrator deletes or updates the business data, the local database is removed as part of an approved cleanup, or BVFX Digify Messaging processes a deletion request. There is no automatic retention purge in the current build. Provider webhook event IDs are retained to prevent duplicate processing. If a business asks us to delete data, we will review the tenant records, contacts, messages, reports, provider connection metadata, and sandbox billing records associated with that business and remove or anonymize them where legally and operationally permitted.
Your choices and deletion requests
Business owners can request access, correction, export, or deletion of business/account data, contact records, consent records, messages, delivery reports, and incoming replies by emailing bvfx96@gmail.com. Include the business name, owner email, WhatsApp phone number involved, and the request type. We may need to verify account ownership before acting on a request.
Contact
BVFX Digify Messaging
Support and privacy requests: bvfx96@gmail.com