Skip to content

Last updated 30 September 2026

Privacy Policy

This policy explains what information MeloHello collects through this website, why we collect it, and what we do with it. It covers the website and the MeloHello platform together, and we have tried to write it in plain language rather than legal boilerplate.

Who we are

MeloHello is operated by [registered entity name to be confirmed], [registered office address to be confirmed]. We are the organisation responsible for the personal data described in this policy, except where we say we are acting as a processor for a business that uses the platform.

Two different roles appear in this policy, and it is worth keeping them apart. For our own website, accounts, billing and support, we decide how data is used and we are the controller. For the customer data a business puts into the platform, that business decides and we are the processor, acting on their instructions. Their privacy notice governs that data, and our Data Processing Agreement sets out what we owe them.

Information you give us

When you submit the form on this site we collect the details you enter: your name, business name, phone or WhatsApp number, email address, business type, your current WhatsApp setup, approximate message volume, what you want help with, and any notes about your workflow.

We use this to reply to your enquiry and to work out what your setup would involve. We do not sell it, and we do not add you to a marketing list you did not ask for.

Information collected automatically

When you visit this site we collect some information without you entering it. This is ordinary web-server and security telemetry, and we collect it because a website cannot be operated or protected without it.

  • Technical data: your IP address, the browser and version you are using, your operating system, the device type and screen size, and your language setting.
  • Request data: the pages you visited, the time and date of each request, how long the page took to load, and the page you arrived from.
  • Diagnostic and security data: error records, and records of requests that were blocked because they looked abusive.
  • Stored preferences: data kept in your browser so the site behaves consistently between visits, such as whether you have dismissed a banner.

Cookies and similar technology

A cookie is a small file a site stores in your browser. We use them in the narrow way this site requires: to keep the site working, to remember preferences you have set, and to protect forms against automated abuse. We do not use cookies to build a profile of you across other websites, and we do not sell advertising space on this site.

You can block or delete cookies in your browser settings. Blocking the ones needed for security and form protection may stop parts of this site from working, and we would rather tell you that than have you discover it.

Information created when you use the platform

Once your business is onboarded, the platform processes business data on your behalf — customer conversations, contact records, workflow events, assignments and reports.

In that context you are the controller of your business data and we act as a processor: we handle it to provide the service to you, under your instructions, and not for our own purposes.

Information we receive from other sources

We receive some information about your business from the services you connect, rather than from you directly. Which services applies depends on how you configure things, and it can include:

  • WhatsApp and Meta: the business account, phone number, display name and quality signals that the WhatsApp Business Platform maintains, and the delivery status of messages sent through it.
  • Payment gateways: confirmation that a payment succeeded or failed, and the reference needed to reconcile it. We do not receive your customers’ full card details.
  • SMS and AI providers: delivery status, and error information where a message or a request could not be handled.

Why we are allowed to use it

We do not use your customers’ conversation content for our own marketing, and we do not use it to train models for our own product development.

What we use it forWhat it coversWhy we are allowed to
Providing the platform to your businessAccount data, workflow data, customer conversations on your behalfTo perform our contract with you. For your business data we act on your instructions as your processor.
Replying to an enquiry you submitThe details you enter in the form on this siteYour consent, given when you submit the form — and our need to respond to a request you made.
Keeping the service secure and free of abuseTechnical and diagnostic data, access recordsTo keep the service we promised you secure and available.
Support you ask forAccount data and relevant conversation dataTo perform our contract with you.
Billing, tax and accountingAccount, subscription and invoice dataA legal obligation we are subject to.
Improving the platformAggregated usage statistics that identify no oneOur need to improve what we offer, applied only to data that no longer identifies anyone.

Third-party services

MeloHello connects to services operated by other companies, and those companies process data under their own terms and privacy policies. Our Sub-processors page names each of them, says what it processes for us, and describes where the processing happens.

  • WhatsApp / Meta — for message delivery. Conversation and messaging charges are billed by Meta, not by us.
  • Payment gateways — if you take payments through a connected workflow.
  • SMS providers — if you send SMS alongside WhatsApp.
  • AI providers — if you enable AI-assisted replies.
  • Hosting and infrastructure providers — where the platform runs and data is stored.

What we do not do

  • We do not sell your personal information.
  • We do not use your business conversation data to market to your customers.
  • We do not claim security certifications we do not hold.
  • We do not use your business data to train models for our own product development.

How long we keep it

Enquiry details are kept for as long as needed to follow up and then for a reasonable period afterwards for our records.

Platform data is kept for the duration of your subscription, and for a limited period after it ends so that you can export it. We delete it when you ask, when it is no longer needed for the purpose it was given to us for, when your account closes, or when the law requires it — in each case as soon as reasonably possible and within one hundred and twenty days, unless a legal requirement obliges us to keep it longer. Invoices and tax records are kept for the period Indian law requires.

Message data is partly outside our control: Meta retains message data for a maximum of thirty days for delivery and retransmission, and we cannot shorten that period by contract.

Sending data outside India

Some of the services we use process data outside India, and the WhatsApp Business Platform operates from Meta’s data centres. Where your data is transferred outside India we rely on the transfer mechanisms available under applicable law, and we require the same confidentiality and security obligations from the recipient that we owe you.

Our Sub-processors page records where each provider processes data, so you can see this without asking.

Your rights

You have the right to ask us what personal information we hold about you, to ask for a copy, to ask for corrections, to ask us to delete it, to withdraw consent you previously gave, and to ask us to send a copy of data you gave us to another service.

Where we act as a processor for a business, the request should normally go to that business, because it is the controller of that data and we act on its instructions. We will help it respond. We will also tell you if your request is one we must refer on rather than answer directly.

We do not charge for a reasonable request, and we do not make you justify exercising a right. If we cannot do what you have asked, we will tell you why rather than ignore it.

How to ask us to delete your data

Email hello@melohello.com with the subject line "Data deletion request" and tell us: the name and email address or phone number the data relates to; whether you are the business that owns the account or one of its customers; and which part you want deleted, or that you want everything deleted.

What happens next: we acknowledge your request, confirm we have found the data you mean, and then delete it. We will tell you when it is done. If some of it has to be kept — an invoice we are legally required to retain, for example — we will tell you what we kept and why rather than deleting some of it and saying nothing.

You do not need an account with us to make this request, and you do not need to give a reason.

Security

We use encryption in transit and at rest, secure authentication with multi-factor authentication for administrative access, role-based access on a least-privilege basis, tenant-separated data storage, protected API access, secret management for credentials, and verified webhook handling. We test the platform for security weaknesses at least once a year and keep dependencies patched.

No system is perfectly secure. If a breach affects your data, we will tell you without undue delay and within seventy-two hours of becoming aware of it, tell you what we know at that point, and keep you updated. We will not play it down.

Children

This site and the platform are built for businesses and are not intended for use by anyone under eighteen. We do not knowingly collect information from children, and we do not run behavioural advertising or tracking aimed at children.

If your business messages people who may be children, obtaining any consent that applies is your responsibility as the controller of that data. Tell us if you need help configuring a workflow that handles that.

Grievance officer and complaints

If you are unhappy with how we have handled your data or a request, write to our grievance officer, [grievance officer name to be confirmed], at hello@melohello.com. We will acknowledge your complaint and tell you what we are doing about it.

If we cannot resolve it, you can take it to the Data Protection Board of India where Indian law applies, or to the supervisory authority in your own country where a different law applies. We would rather hear from you first, but you are not required to.

Changes to this policy

If we make a material change, we will update the date at the top of this page and, where the change is significant, tell customers directly. We will not quietly widen what we do with your data and leave you to notice.

Questions about this policy? Write to hello@melohello.com.