LEGAL · PRIVACY

Privacy Policy

This policy explains how RelayCore processes information while providing secure messaging infrastructure to connected business applications.

Last updated: August 25, 2026

1. Who we are

RelayCore is an independently operated software service that connects authorized business applications to the WhatsApp Business Platform. RelayCore acts as infrastructure: it authenticates webhook events, routes them to the appropriate connected application and submits authorized message requests to Meta.

Privacy questions and data requests can be sent to privacy@relaycore.tech.

2. Information we process

Administrator identity

For restricted administration access, we may receive the administrator’s name, email address, profile image and authentication identifiers from Google.

Business integration information

We process application names and identifiers, WhatsApp Business Account identifiers, phone-number identifiers, display phone numbers, encrypted access tokens, webhook destinations and application credentials.

Messaging and webhook information

Webhook payloads and outbound message requests may include phone numbers, names, message content, message identifiers, media metadata, delivery statuses and timestamps. RelayCore processes this information only to route, deliver, retry, secure and audit the requested integration.

Operational records

We keep records of administrative actions, authentication events, API-key use, delivery attempts, failures and relevant technical timestamps needed to secure and operate the service.

3. How we use information

  • Provide, maintain and troubleshoot the messaging gateway.
  • Authenticate Meta, administrators and connected applications.
  • Route each webhook only to its authorized destination.
  • Send messages requested by authorized connected applications.
  • Prevent abuse, investigate incidents and maintain audit records.
  • Comply with applicable legal and regulatory obligations.

RelayCore does not sell personal information and does not use message content for advertising or independent marketing.

4. Roles and lawful processing

For customer communications, the connected business generally determines why and how the information is used, and RelayCore processes it to provide the requested infrastructure. Each connected business is responsible for its own privacy notices, lawful basis, customer permissions and WhatsApp policy compliance.

Depending on context and applicable law, processing is based on performance of a service agreement, legitimate interests in providing and securing the service, compliance with law, or consent managed by the connected business.

5. Service providers and disclosures

Information may be processed by providers necessary to operate RelayCore:

  • Meta, for the WhatsApp Business Platform and related business services.
  • Vercel, for application hosting, delivery and platform security.
  • Prisma Postgres and its infrastructure providers, for database hosting.
  • Google, for restricted administrator authentication.
  • The connected business application authorized for the relevant number.

We may also disclose information when required by law, to protect rights or safety, or during a legitimate business reorganization subject to appropriate safeguards.

6. Retention and deletion

Integration credentials are retained while an application or number remains connected. Delivery, message and audit records are retained only as reasonably necessary for routing, retry, security, troubleshooting and legal obligations. Residual copies may remain temporarily in protected backups before routine expiry.

Instructions for requesting deletion are available on our Data Deletion page.

7. Security

RelayCore uses transport encryption, encrypted Meta access tokens, signed webhook verification, tenant-aware routing, restricted administrator access, revocable application keys and audit logging. No system can guarantee absolute security, but we review and improve safeguards proportionate to the service.

8. International processing

Infrastructure and service providers may process information in countries other than the individual’s country. Where required, the responsible parties must use appropriate contractual or legal safeguards for these transfers.

9. Your rights

Depending on applicable law, individuals may have rights to access, correct, delete, restrict or object to processing, request portability, or withdraw consent. Customers should normally contact the business they communicated with first. Requests sent to RelayCore will be verified and coordinated with that business when necessary.

10. Children

RelayCore is business infrastructure and is not directed to children. Connected businesses must not use the service to collect children’s information without the permissions and safeguards required by applicable law.

11. Changes to this policy

We may update this policy as the service or law changes. The current version and its effective date will always be published at this URL.