Privacy Policy
This policy explains what data Grostify Connect processes, why, who it is shared with and what rights you have. It includes a technical appendix on the processing of WhatsApp Business Platform messaging data, because that is what the product does.
Last updated: October 3, 2026
1. Data controller
The controller of the data collected through connect.grostify.com and the Grostify Connect service is Grostify LLC, a limited liability company organized in the State of Wyoming, United States (Wyoming Secretary of State, filing ID 2025-001731973), with its address at 1021 E Lincolnway 8776, Cheyenne, WY 82001, United States.
Grostify LLC has completed Meta Platforms, Inc. business verification and operates on the WhatsApp Business Platform. For any privacy question write to privacy@grostify.com.
2. What Grostify Connect is and our role
Grostify Connect is infrastructure that software companies, agencies and developers (our customers) use to connect the WhatsApp Business accounts of their own end customers and to expose their products to AI assistants through the MCP protocol.
For the data of WhatsApp users who message a connected business, that business is the controller and Grostify acts as a processor on its behalf, following its instructions. Meta Platforms, Inc. and its affiliates process that data independently under their own policies.
For the data of people who create a Connect account, visit the site or write to us, Grostify is the controller.
3. What data we process
Account data
Name, work email, company, hashed password, language and preferences, access logs and billing information when you subscribe to a plan.
Connected WhatsApp Business account data
Identifiers of the Meta portfolio, the WhatsApp Business account (WABA ID), the phone numbers (phone number ID) and the app, business display name, verification status, number quality, messaging limits, message templates and their approval status, and the access tokens Meta issues to operate the account.
Messaging data
The events Meta delivers via webhook: message identifiers, sender and recipient phone numbers, timestamp, message type, delivery and read status, errors, and the message content when the connected business uses Connect to receive or send it. Retention details are in the technical appendix.
Consent data
A record of each contact's opt-in: number, date, source (QR, link, form, conversation) and authorized message category, so the connected business can prove the consent that the WhatsApp messaging policy requires.
Technical and usage data
IP address, device and browser type, pages visited, API calls with their metadata (endpoint, latency, response code), and cookies required for the site and session to work.
4. Why we use the data
- To provide the service: connect accounts, deliver and send messages, manage templates, expose MCP tools and show Meta's cost per account.
- Security: validate webhook signatures, detect abuse, protect number quality and comply with Meta's policies.
- Compliance: keep the proof of consent and the audit logs our customers need.
- Support and communication: answer your requests and notify you of changes to the service or to Meta's rules.
- Product improvement, with aggregated or pseudonymized data.
- Legal, tax and accounting obligations.
5. Legal basis
Performance of the contract with you or your company, our legitimate interest in running a secure service and improving it, your consent where we ask for it explicitly, and compliance with legal obligations. Where we act as processor, the legal basis is determined by the connected business as controller.
6. Who we share data with
We do not sell personal data. We share data with:
- Meta Platforms, Inc. and its affiliates, because WhatsApp messaging is delivered through their platform. Meta bills the connected business directly for messages and processes data under its privacy policy and the WhatsApp Business Platform terms.
- Providers acting as processors on our behalf: cloud hosting and compute, databases, transactional email, monitoring and support, all under contracts that require them to protect the information.
- AI model providers, only when the connected business enables an agent and only with the data needed to answer.
- Authorities, where a legal obligation requires it.
7. International transfers
Grostify operates from the United States and serves customers in Latin America, Europe and other regions. Data may be processed outside your country. Where applicable law requires it, we use standard contractual clauses or other recognized safeguards.
8. Retention
- Account data: while the account is active and up to 12 months after it is closed, unless a legal obligation requires longer.
- Identifiers and tokens of connected WhatsApp accounts: while the connection is active. On disconnection or account deletion, tokens are revoked with Meta and deleted.
- Message content: 30 days from receipt or sending by default. The connected business can set a shorter period or disable content storage.
- Messaging metadata and audit logs: 13 months, for support, billing disputes and compliance.
- Consent records: while the contact remains active and 3 years afterwards, to be able to prove it.
- Backups: overwritten within 90 days at most.
9. Security
We encrypt access tokens at rest, validate the HMAC-SHA256 signature of every webhook before processing it, apply role and account based access control, log access and keep systems updated. No system is infallible. If we detect a breach that affects you, we will notify you as applicable law requires.
10. Your rights
You can access, rectify, delete, restrict or object to the processing of your data, and request portability, by writing to privacy@grostify.com. If you are an end user of a connected business, address your request to that business and, if you write to us, we will forward it. You can lodge a complaint with your country's data protection authority.
To delete a connected WhatsApp Business account and all its data, see the data deletion page on connect.grostify.com, which describes the three available paths, including the automatic one when you remove Grostify's app from Meta.
11. Cookies
We use strictly necessary cookies for session, security and remembering the language. If we add analytics, we will ask for consent first and you will be able to manage it from the site.
12. Minors
Connect is a service for companies and professionals. It is not directed at people under 18 and we do not knowingly collect their data.
13. Changes to this policy
We will publish any change on this page with the update date. If the change is material, we will notify account holders by email.
Technical appendix: processing of messaging data, gateways and webhooks
A. Account connection (Embedded Signup)
Linking uses Meta's Embedded Signup flow. The end customer signs in to Meta, picks or creates their portfolio and WhatsApp Business account and grants Grostify's app the whatsapp_business_management and whatsapp_business_messaging permissions. Meta returns a code that our server exchanges for a business token. That token is encrypted at rest, never exposed to the browser and revoked with Meta when the account is disconnected.
If the business connects a number it already uses in the WhatsApp Business app (coexistence), it keeps using the app and Meta sends Connect a copy of the messages the business writes from it from that point on. Connect does not import the chat history from before the connection or the phone's contact list.
B. Webhooks
Meta delivers events to a Grostify endpoint. Before processing any event we validate the X-Hub-Signature-256 header with the app secret using HMAC-SHA256 and constant-time comparison. Events without a valid signature are rejected and not stored. Valid events are deduplicated by message id, queued and acknowledged to Meta in under one second.
C. What we keep from each event
Always: account, number, message and template identifiers, timestamp, event type, status and error codes. Message content only if the connected business has storage enabled, and for the period in section 8. Media files are downloaded from Meta on demand and not kept unless explicitly configured.
D. Sending messages and cost
Messages go out through Meta's Cloud API with the connected business's token. For each send we record the identifier, the pricing category Meta assigns and the delivery status, so the business sees Meta's cost at cost and separate from Grostify's fee.
E. MCP servers
When a customer publishes an MCP server with Connect, third-party AI assistants access tools defined by the customer through OAuth 2.1 with short-lived tokens and per-tool scopes. Tools are read-only by default. We log each call (who, which tool, when, result) in an audit trail the customer can export. We do not use conversations to train models.
F. Data Deletion Callback
When a user removes Grostify's app from Meta, Meta sends a signed request (signed_request) to our deletion endpoint. We verify the signature, record the request, generate a confirmation code and return to Meta the URL where the status can be checked. Deletion completes within the period stated on the data deletion page.