Privacy Policy
Data processed in the Suppliping service, the purposes of processing, our retention approach, and ways to submit a request.
Last updated: September 1, 20261. Data controller and contact details
This policy explains the data processing practices of the business identified below that operates the Suppliping panel. A business that uses the panel for its own supplier communication processes must separately assess its role and obligations under applicable law with respect to the personal data it processes.
2. Categories of data processed
- Administrator account: name, email address, password hash, session records, and sign-in security records.
- Private-pilot access request: company and contact name, business email, phone, country, estimated supplier and message volume, and an optional note. A short-lived HMAC fingerprint is stored instead of the raw IP address to limit abuse.
- Contact and support request: optional company name, contact name, business email, optional phone number, request category, subject, description, tracking reference, request status, and timestamps. A short-lived HMAC fingerprint is stored instead of the raw IP address to limit abuse.
- Supplier directory: company/contact name, phone number, region, category, tags, notes, status, and the source and time of communication consent.
- Message records: the template used, destination number and company snapshot, sending time, Meta message ID, and sent, delivered, read, replied, or failed status.
- Incoming WhatsApp events: sender number, text or media ID, time received, and related webhook information.
- Operational data: schedules, queue and worker runs, error codes, configuration states, and timestamps used for auditing.
- Security and access logs from the hosting infrastructure. The application is not designed to store unnecessary raw access tokens or secrets in the database.
3. Why do we process data?
- To authenticate the panel account and prevent unauthorized access.
- To assess the business and use-case fit of a private-pilot request, contact the applicant, and limit duplicate or abusive requests.
- To record and securely track sales, access, technical support, privacy, and data-deletion requests and contact the requester.
- To manage the supplier directory and communication consent status.
- To schedule approved WhatsApp templates, submit them to the Meta Cloud API, and report the results.
- To record incoming replies and act on opt-out requests such as “DUR” or “İPTAL.”
- To investigate failures, duplicate sendings, misuse, and security incidents, and to support backups and service continuity.
The business using the panel is responsible for identifying an appropriate legal basis for each processing activity and for providing required notices and obtaining any required consent. This page is not legal advice or a guarantee of regulatory compliance.
4. Sharing and service providers
Data required to send messages and receive their statuses is transferred to Meta Platforms’ WhatsApp Business Platform. Hosting, domain, backup, and monitoring providers may process data only to the extent necessary to operate the service. Information may be disclosed to authorized public authorities only when required by a valid legal obligation.
If Meta or a hosting provider uses infrastructure in other countries, applicable international data transfer requirements must be assessed separately.
5. Retention, security, and deletion
Data is retained for as long as necessary for the purpose of the service and applicable legal obligations. This version does not apply one automatic retention period to every record; the operator should establish a written retention and disposal schedule by data category. Deleted records may remain in encrypted backups for a limited period until the ordinary backup cycle is completed.
Public-form rate-limit fingerprints are removed during the next automatic cleanup after the active window expires. Access and support request details should not be retained longer than needed for assessment, resolution, and necessary follow-up communication.
The application keeps access tokens in server environment secrets, sets session cookies as HTTP-only, and verifies Meta webhook signatures. No technical measure can guarantee absolute security.
6. Your rights and how to submit a request
You may send requests available under applicable law—such as asking whether your data is processed, requesting information, correction or deletion, or objecting to processing—to the contact address above. Identity and the request’s connection to the relevant person may be verified without requesting excessive information.
For general contact or support, use the Contact and Support page. For the steps required to submit a full deletion request, see the Data Deletion Instructions page.
7. Changes
This policy may be updated if the service’s data flows or providers change. The current text and last-updated date will always be published at this URL.