RecoverPay · Legal

Privacy Policy

Last updated: September 2026

1. Information We Collect

We collect information you provide directly to us when you create an account, set up a workspace, or contact us — including your name, email address, phone number, and business details.

We also collect usage data to provide and improve the Service, including session activity, message delivery status, campaign performance metrics, and lead pipeline activity within your workspace.

RecoverPay offers two ways to connect a WhatsApp number. Each collects slightly different data:

  • WhatsApp Business Cloud API (Meta): when you authorise this connection, we receive your business profile, phone number, approved message templates, and message delivery and read status from Meta as part of the official API integration.
  • QR-code linked device: when you scan the QR code from WhatsApp's Linked Devices menu on your phone — the same way you would link WhatsApp Web or WhatsApp Desktop — RecoverPay receives the messages, contact names, and delivery receipts needed to send and track your follow-ups through that session. Your existing chat history, group chats, and media are never accessed.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve RecoverPay services
  • Send and receive WhatsApp messages on your behalf through whichever connection method you have authorised
  • Manage your lead pipeline, campaign sequences, team members, and workspace settings
  • Generate AI-powered follow-up message suggestions when you request them (see Section 5)
  • Respond to enquiries submitted through our contact form, email, or WhatsApp
  • Monitor usage, enforce plan quotas, and prevent abuse or unauthorised access
  • Send you important account and service notifications

3. WhatsApp Contact Import

RecoverPay includes a feature that lets you import contact names and phone numbers from your own connected WhatsApp account directly into your lead pipeline. This feature is designed with your privacy as a first principle:

  • Only contact names and phone numbers are read. No message history, group chats, status updates, or media files are accessed, imported, or stored by this feature.
  • End-to-end encrypted throughout. The contact sync operates over the same end-to-end encrypted WhatsApp session used for messaging. Data travels directly between your connected WhatsApp account and your workspace's database without being routed through or stored by any third-party service.
  • Stays inside your workspace. Imported contacts are stored in your organisation's isolated workspace only. They are never shared with other RecoverPay customers, third-party marketers, or any external service.
  • You are in control. You can delete any imported lead from your workspace at any time from the Leads page. Disconnecting a WhatsApp channel immediately stops any further contact syncing for that number.

We only read what is necessary to help you manage your leads. Nothing else.

4. Your WhatsApp Conversations

RecoverPay only stores and displays conversations that are initiated through our platform — the follow-up messages your campaigns send, and the replies your leads send back through that same channel.

We do not fetch, import, or display your existing WhatsApp chat history. Connecting a number — whether by QR code or the WhatsApp Business API — does not give RecoverPay access to conversations, groups, or contacts that existed before the connection, or that happen outside RecoverPay's platform. Only the ongoing conversations created through RecoverPay appear in your dashboard and inbox.

5. AI & LLM Features

RecoverPay uses large language model (LLM) technology to provide AI-powered message rewriting and an on-site chat assistant. We take a data-minimal approach to both:

  • AI follow-up rewrites (dashboard): when you request an AI rewrite of a follow-up message, a small amount of context — the lead's name, a brief snippet of the recent conversation, and basic campaign details — is sent to our third-party AI provider. This data is processed in-flight only. It is not stored, logged, or used to train any AI model, in accordance with our data processing agreements with the provider. AI-generated suggestions are proposals only — you review and approve every message before it is sent.
  • AI chat assistant (marketing website): the on-site chat assistant answers product questions using a knowledge base built from RecoverPay's public documentation. No user account data, lead data, or workspace data is used by this assistant.

Your conversation data is never used to train AI models, fine-tune algorithms, or improve any model beyond your own session.

6. Data Sharing

We do not sell your personal information. We share data only in the following limited circumstances:

  • Meta Platforms, Inc.: when you use the WhatsApp Business Cloud API connection, messages are routed through Meta's infrastructure as required by that API integration. QR-linked connections do not use Meta's Business API and are not subject to Meta's API data terms.
  • AI providers: a minimal, anonymisable subset of conversation context is sent to our AI provider solely to generate message rewrite suggestions, as described in Section 5 above.
  • Service providers: we work with trusted hosting, infrastructure, and operational vendors who assist in running the platform. All vendors are bound by strict confidentiality agreements and are permitted to use your data only as needed to provide their service to us.
  • Legal requirements: we may disclose information if required by law, court order, or to protect the rights, property, or safety of RecoverPay, our users, or the public.

7. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption in transit using TLS for all API and real-time communication
  • Encryption at rest for sensitive credentials including WhatsApp access tokens
  • Role-based access control within workspaces so team members only see data they are authorised to access
  • WhatsApp access tokens are stored encrypted server-side and are never exposed in client-facing API responses
  • Regular security reviews of our infrastructure, dependencies, and access controls

While we take security seriously, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to use strong, unique passwords and to enable two-factor authentication where available.

8. Data Retention

We retain your data for as long as your workspace is active and as needed to provide the Service. Specifically:

  • Account and workspace data (profile, team members, settings) is retained for the lifetime of your workspace.
  • Lead and campaign data is retained for the lifetime of your workspace and is available for export at any time from the Leads and Campaigns pages.
  • WhatsApp message logs (sent follow-ups and received replies) are retained within your workspace for up to 12 months, after which they may be archived or deleted.
  • After account termination, your workspace data is retained for 30 days to allow you to export your data or request its return. After this 30-day window, all data is permanently and irreversibly deleted from our systems.
  • AI rewrite context is never retained beyond the in-flight request (see Section 5).

You may request early deletion of your data at any time by contacting us at contact@recoverpay.cloud.

9. Your Rights

Depending on your location, you may have rights under applicable data protection law (e.g. GDPR, Pakistan PDPA, UAE PDPL) including:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request that we correct inaccurate or incomplete data.
  • Deletion: request that we delete your personal data (“right to be forgotten”), subject to our legal obligations.
  • Data portability: request your data in a structured, machine-readable format.
  • Objection or restriction: object to or request restriction of certain processing activities.

To exercise any of these rights, contact us at contact@recoverpay.cloud with “Privacy Request” in the subject line. You may also disconnect your WhatsApp account and delete your workspace at any time from your dashboard settings.

10. Cookies

We use essential cookies and browser storage to maintain your authenticated session, remember your active workspace, and store your UI preferences (such as dark mode). These are strictly necessary for the Service to function and cannot be disabled while you are logged in.

We do not use advertising cookies, third-party tracking pixels, or behavioural profiling cookies. We do not sell cookie data or share it with advertisers.

11. Contact Us

If you have questions about this Privacy Policy, want to exercise your data rights, or have a privacy concern, please contact us at contact@recoverpay.cloud. Include “Privacy” in the subject line so we can prioritise your request. We aim to respond within 5 business days.

AI
RecoverPay AI
Ask us anything