Last updated 2026-05-02
Privacy Policy
initiate.click (“we”, “our”, or “the service”) is a revenue operating system for WhatsApp-first businesses. This policy explains what data we collect, why, and what control you have over it.
What we collect
Account data: workspace name, email address, and team-member emails for the purpose of authentication and access control.
Operational data: connected Meta Ads, WhatsApp transport, attribution clicks, leads, conversations, ad performance, and credit ledger entries.
Technical data: IP address, user-agent, request timestamps, and error traces collected through standard server logs.
How we use it
To provide the product: attributing ad spend to revenue, syncing WhatsApp conversations, surfacing leaks and recommendations.
To improve service quality: aggregated, anonymized analytics on feature usage and reliability.
To communicate operational events: connector outages, billing receipts, and security notices.
How we share it
We do not sell your data. We do not share your data with advertising platforms.
We use sub-processors to operate the service: Supabase (auth + database), Neon (Postgres), Cloudflare (routing + storage), Upstash (queues), Resend (transactional email), and OpenAI (AI suggestions). Each is bound by a data-processing agreement and processes data only on our instruction.
We disclose data when legally required (subpoena, court order) or to protect against fraud or security threats.
Data retention
Operational data is retained for the lifetime of your account. On account deletion, personal data is removed within 30 days; aggregated, non-identifying analytics may be retained.
Backups are retained for 30 days for disaster-recovery purposes.
Your rights
You can access, export, correct, or delete your data at any time from Settings → Account, or by emailing privacy@initiate.click.
EU/UK users have the rights under GDPR/UK-GDPR, including the right to object, the right to restrict processing, and the right to lodge a complaint with a supervisory authority.
Security
Data is encrypted in transit (TLS 1.2+) and at rest (provider-managed AES-256). Access is restricted to authenticated team members under least-privilege controls.
We do not store payment-card details — payment processing is handled by our PCI-compliant payment processor.
Contact
Questions about this policy or your data? Email privacy@initiate.click.