Privacy Policy
This policy explains what personal data we collect, why we collect it, who we share it with, and the choices and rights you have. It covers the eZage platform and the business messaging services we provide through the WhatsApp Business Platform.
Last updated: 14 September 2026
EZAGE TECHNOLOGIES PRIVATE LIMITED, Kolkata, India
1. Who we are
EZAGE TECHNOLOGIES PRIVATE LIMITED ("eZage", "we", "us") is a company registered in India, with its place of business in Kolkata, West Bengal. We operate the eZage platform at ezage.ai, which includes a marketplace connecting brands, creators and professionals, and a business messaging product that lets our business customers communicate with their own customers over WhatsApp.
We are a Meta Tech Provider. That means we build and operate software on the WhatsApp Business Platform on behalf of businesses that use our product.
2. The two roles we play
Our responsibilities under data protection law depend on whose data we are handling, so it is important to be clear about the distinction:
- As a data fiduciary (controller), we decide how we handle the personal data of the people who sign up for eZage — our own account holders. This covers your name, email, phone number, business details, billing records and how you use the product.
- As a data processor, we handle the personal data our business customers send through our product — including the phone numbers and message content of the people they message on WhatsApp. We process that data only on their instructions, to deliver the service they have asked for. Our business customer is the controller of that data, not us.
If you received a WhatsApp message from a business that uses eZage and you want your data corrected or deleted, the fastest route is usually to contact that business directly, because they control it. You can also contact us and we will forward your request to them and assist.
3. Information we collect
Information you give us when you create an account
- Identity and contact details — name, username, email address, phone number, profile photo, date of birth and gender where you provide them.
- Business details — company name, business category, website and the information you publish on your public profile or listings.
- Authentication data — a hashed password, or an identifier from Google, LinkedIn or Instagram if you choose to sign in with those services.
- Payout details — bank account or UPI information, where you sell through the marketplace and need to be paid.
WhatsApp Business Platform data
- Your WhatsApp Business Account (WABA) identifier, the business phone numbers you connect, their display names, verification status and quality rating.
- Access tokens issued by Meta that allow us to send and receive messages on your behalf. These are encrypted at rest and are never displayed back to you or shared with other customers.
- Message templates you create and their review status.
Data processed on behalf of our business customers
- Contact lists our customers upload or sync, which typically contain names and phone numbers of their own customers.
- The content of messages sent and received through the platform, including text, media and template variables.
- Delivery metadata — timestamps, delivery and read receipts, failure reasons and the WhatsApp message identifier.
Information collected automatically
- Technical data such as IP address, browser and device type, and pages viewed.
- Usage data such as messages sent, API calls made and features used, which we use for billing, rate limiting and abuse prevention.
- Cookies and similar technologies used to keep you signed in and to remember your preferences.
We do not collect or store full payment card details. Card and UPI payments are handled directly by our payment gateways.
4. How we use information
- To create and administer your account and authenticate you.
- To deliver the service — sending and receiving WhatsApp messages, managing templates, running campaigns and reporting on delivery.
- To bill you, meter usage against your plan and enforce rate limits.
- To provide support and respond to your enquiries.
- To keep the platform secure — detecting fraud, abuse, spam and violations of the WhatsApp Business Messaging Policy.
- To improve the product, using aggregated or de-identified usage data.
- To send you service communications about outages, billing or material changes. Marketing emails are sent only with your consent and you can opt out at any time.
- To comply with legal obligations and to establish, exercise or defend legal claims.
We do not sell personal data. We do not use the content of our customers' WhatsApp messages to train machine learning models or for our own advertising.
5. Legal bases for processing
Where Indian law applies, we process personal data on the basis of your consent, or because processing is necessary for a legitimate use permitted under the Digital Personal Data Protection Act, 2023. Where the EU or UK GDPR applies, we rely on performance of a contract, legitimate interests (operating and securing the service), consent (marketing and certain cookies), and compliance with a legal obligation.
6. Sharing your information
Meta Platforms
To deliver WhatsApp messages we transmit message content, recipient phone numbers and related metadata to Meta Platforms, Inc. and its affiliates, which operate the WhatsApp Business Platform. Meta's handling of that data is governed by its own terms and privacy policies. We only transmit what is necessary to send the messages you or our business customers have instructed us to send.
Service providers
We use a small number of vendors to run the platform. They act on our instructions, are bound by confidentiality, and may only use the data to provide their service to us:
- Cloud hosting and database providers, for application hosting and data storage.
- Cloudinary and Firebase, for image and file storage.
- Cashfree and PhonePe, for payment processing.
- Email and notification providers, for transactional email.
- Google, LinkedIn and Instagram, where you choose to sign in or connect those accounts.
Other disclosures
- To our business customers, where we process data on their behalf.
- To law enforcement or regulators, where we are legally required to do so.
- To a buyer or successor in the event of a merger, acquisition or sale of assets, subject to this policy continuing to apply.
7. Messaging rules and consent
Businesses using eZage to message people over WhatsApp must obtain valid opt-in from each recipient before messaging them, as required by the WhatsApp Business Messaging Policy. Our customers are responsible for obtaining and keeping records of that consent, for honouring opt-out requests promptly, and for the content they send.
If you receive an unwanted message sent through our platform, you can reply STOP to the business, or contact us at ez.ezage@gmail.com and we will investigate. We may suspend or terminate accounts that repeatedly message people without consent.
8. How long we keep data
- Account data — for as long as your account is active, and for up to 90 days after closure, unless a longer period is required by law.
- Message content and delivery logs — retained for the period set out in your plan so you can view history and reporting, and deleted or anonymised after that. Business customers may request earlier deletion.
- Billing and tax records — retained for up to 8 years, as required under Indian law.
- Access tokens — deleted immediately when you disconnect a WhatsApp Business Account.
- Security and audit logs — typically retained up to 12 months.
9. How we protect data
- Data is transmitted over encrypted connections (TLS).
- Meta access tokens and comparable credentials are encrypted at rest using AES-256-GCM, and are never returned through our API or interface.
- Access to production systems is restricted to personnel who need it, and is authenticated.
- Each workspace's data is logically separated, so one customer cannot access another customer's messages, contacts or credentials.
- API access uses per-workspace keys that are stored hashed, can be scoped, and can be revoked at any time.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant authority as required by law.
10. International transfers
We are based in India and our vendors, including Meta, may process data outside India, including in the United States and the European Union. Where we transfer personal data internationally we rely on appropriate safeguards, such as standard contractual clauses, and we transfer only what is necessary to provide the service.
11. Your rights
Subject to applicable law, you have the right to access the personal data we hold about you, to have inaccurate data corrected, to have your data erased, to withdraw consent where we rely on it, to receive a copy of your data in a portable format, and to nominate another person to exercise these rights on your behalf in the event of death or incapacity.
To exercise any of these rights, email ez.ezage@gmail.com. We respond within 30 days. If you are not satisfied with our response you may complain to the Data Protection Board of India, or to your local supervisory authority.
12. Deleting your data
You can request deletion of your account and associated data at any time. Full instructions, including what is deleted and what we are required to retain, are on our data deletion page.
13. Children
The eZage platform is not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. If we make a material change we will notify account holders by email or through the platform before it takes effect. The date at the top of this page shows when it was last revised.