Last updated: October 4, 2026
This policy describes the information processed through CloudSend, a WhatsApp messaging service for businesses. It is a product privacy explanation, not a legal certification. The business using CloudSend decides whom to contact and is responsible for its customer-data practices and any required notices, permissions or consent.
Who operates the service
Operator / legal business name: Vayutron
Privacy contact: tejatravi.8087@gmail.com
CloudSend platform information
To operate the service, CloudSend processes account names, email addresses, WhatsApp phone numbers supplied during signup, password hashes and session information; tenant/business names, team-size selections and membership roles; support or privacy correspondence sent through configured channels; and technical information needed to operate, secure and troubleshoot the application. Passwords are stored as salted hashes. The application uses an essential session cookie for sign-in. Signup phone numbers are recorded as unverified while a verification provider is not configured.
Customer-provided business and customer information
Businesses may provide or generate information in their CloudSend workspace, including:
- WhatsApp Business account and connection details, such as WABA and phone-number identifiers, display details, connection status and encrypted access credentials.
- Contacts, such as phone numbers, names, email addresses, labels and other imported fields provided by the business.
- Campaign names, recipient snapshots, selected template names/languages, personalization values, scheduling and campaign status.
- Message metadata, including recipient number, message ID, message type, send time, delivery/read/failure status and relevant error information. Message payloads may be stored as part of campaign processing and outgoing chat records.
- Chat records available through the connected WhatsApp integration. Incoming message text is processed to handle opt-outs and, where enabled, agent auto replies; CloudSend stores inbound chat records for supported Cloud API connections.
- Suppression and opt-out records, including phone number, source and time, so that the business can avoid future campaign sends to those records.
- Whether agent auto replies are enabled for a connection. For enabled auto replies, incoming text and a short, in-memory conversation context may be sent to the configured AI provider to generate a response.
- Subscription plan and payment-request information, including selected plan, displayed amount and currency, request and review status, approval dates and subscription start and expiry. Payment receipt screenshots are shared by the customer directly with the configured CloudSend WhatsApp Business number; they are not uploaded to CloudSend's application database. WhatsApp may process those attachments under its own policies.
Businesses control the customer data they upload and are responsible for ensuring it is accurate and appropriate for their use of the service. Uploaded spreadsheet files are processed to prepare contacts or campaign recipients and are not retained as campaign files by the queue.
Purposes and third-party services
CloudSend processes information to authenticate users, manage tenants and WhatsApp connections, import and manage contacts, prepare and send messages requested by a business, process provider webhooks, maintain suppression records, display reports and chats, provide configured auto replies, administer plan-payment requests and subscriptions, and secure and troubleshoot the service.
- Meta / WhatsApp: WhatsApp account and connection information, recipient information, message content and delivery events are exchanged with Meta/WhatsApp to provide connection, messaging and webhook features. Meta handles information under its own policies and terms.
- Neon / PostgreSQL: Application records are stored in the PostgreSQL database configured by the operator, which may be hosted by Neon. The database provider processes data under its own terms.
- AI providers: If agent auto replies are enabled and configured, the deployment uses the provider selected by its operator (Google Gemini or OpenAI). Incoming text and limited in-memory reply context may be sent to that provider. Provider choice and data handling are subject to the operator's configuration and that provider's terms and privacy information. If no provider is configured, reply generation may fail.
CloudSend's source supports these integrations; actual third-party processing depends on deployment configuration and enabled features. CloudSend does not sell customer contact data.
Storage, security and retention
Records are stored in PostgreSQL. WhatsApp credentials are encrypted by the application and passwords are stored as salted hashes. These measures reduce risk but do not guarantee absolute security. The operator controls database hosting, access, backups, logs and deployment security.
Information is retained while needed to provide the service, preserve campaign and opt-out history, maintain security, or address legal or operational obligations. CloudSend does not currently provide self-service account deletion. Account administrators may request account/data deletion from the operator using the privacy contact above. Disconnecting a WhatsApp number does not automatically delete campaign, contact, chat or suppression records. Database backups may retain information according to the configured provider's backup lifecycle.
A person contacted by a CloudSend customer should contact that business to request access, correction or removal of the business-held information. The business can review its CloudSend contacts and suppression records. For a CloudSend account or privacy request, contact the operator using the details above.
Customer responsibilities
Businesses are responsible for their customer notices, lawful basis and permissions, WhatsApp/Meta policy compliance, contact accuracy, honoring opt-outs, and deciding whether to enable or review automatically generated replies. A suppression feature helps prevent campaign messages to listed numbers but does not itself guarantee compliance with any law or policy.
Updates and privacy contact
This policy may be updated as the service or its data practices change. The latest version will be published here. For privacy questions or requests, contact the operator using the configured privacy contact above. If no contact is configured, ask the CloudSend administrator to provide a valid privacy contact.