TickReply
PrivacyTermsData deletion

Privacy Policy

Effective 26 July 2026

TickReply is operated by Sampoorna Digi Branding Private Limited(“we”, “us”). This policy explains what personal data we handle when you use tickreply.in, why we handle it, who else receives it, and what you can ask us to do with it.

1. Two different roles

This distinction determines who is answerable for what, so it comes first.

  • For our customers’ own data — the account you create, your team members, your billing records — we are the data fiduciary (controller). This policy governs that data.
  • For the people your business messages on WhatsApp — your contacts and the conversations you have with them — you are the fiduciary and we are a data processor acting on your instructions. We do not decide what you send, who you send it to, or how long you keep it. Your own privacy notice governs that relationship, and you are responsible for having a lawful basis to message those people.

2. What we collect

Account and workspace data

  • Name, email address and password hash of each user.
  • Workspace name, role assignments and team invitations.
  • Sign-in session cookies, which are required for the service to function.

WhatsApp Business data

  • Your WhatsApp Business Account ID, phone number IDs, display numbers, quality rating and messaging tier.
  • Access tokens issued by Meta, which we store encrypted at rest with AES-256-GCM.
  • Contacts you import or that message you: phone number, name, tags, attributes and consent status.
  • Message content in both directions, delivery and read receipts, and the message identifiers Meta returns.

Usage and billing data

  • Message and AI-token counts used for metering, plus the resulting credit ledger.
  • Subscription status and payment references from Razorpay. We never see card details.
  • Server logs containing IP address, timestamp and request path, kept for security.

3. Why we handle it

PurposeBasis
Delivering the service you signed up for — sending and receiving messages, running your flows and campaignsPerformance of our contract with you
Metering usage and taking paymentPerformance of contract; legal obligation to keep tax records
Optional AI features you switch onYour instruction, given by enabling them
Security, fraud prevention and abuse investigationOur legitimate interest in a safe service
Service notices about outages, billing or policy changesPerformance of contract

We do not sell personal data. We do not use your message content or your contacts to advertise to anyone, and we do not use it to train AI models.

4. Who else receives data

We use the following processors. Each receives only what it needs for the stated purpose.

RecipientWhyWhere
Meta Platforms (WhatsApp Business Platform)Delivers and receives every WhatsApp message. Message content, phone numbers and delivery receipts pass through Meta by necessity — it is the messaging channel.United States and Ireland
Anthropic (Claude)Powers optional AI features: intent detection, suggested and automatic replies, and message rewriting. Conversation text is sent only when a workspace enables these features, and is not used to train models.United States
RazorpayProcesses subscription and top-up payments. Card and bank details are entered on Razorpay's systems and are never received or stored by us.India
Hostinger InternationalHosts the application servers and databases.India

We may also disclose data where the law requires it, or to establish or defend legal claims. If we are ever acquired, data transfers with the business and this policy continues to apply until replaced by one no less protective.

5. International transfers

Our servers are in India. Meta and Anthropic process data outside India, as noted above. Where data leaves India we rely on contractual protections with those providers.

6. How long we keep it

  • Conversations, contacts and campaign records: for as long as your workspace is active. You can delete individual contacts and their message history at any time from within the product.
  • After you close your account: we delete workspace data within 30 days, except where we must keep records longer.
  • Invoices and payment records: retained as long as Indian tax law requires, currently eight years.
  • Server logs: 30 days.
  • Backups: deleted data persists in encrypted backups for up to 30 days before those rotate out.

7. Security

  • All traffic is served over TLS.
  • Meta access tokens are encrypted at rest with AES-256-GCM.
  • Passwords are stored as bcrypt hashes and are never recoverable in plain text.
  • Every record is scoped to a workspace, and access within a workspace is limited by role.
  • Databases are not exposed to the public internet.

No system is perfectly secure. If a breach affects your data we will notify you and the Data Protection Board of India as the law requires.

8. Your rights

Under the Digital Personal Data Protection Act, 2023 you may ask us to give you a copy of your data, correct it, erase it, or nominate someone to exercise these rights if you cannot. Write to privacy@tickreply.in and we will respond within 30 days. See Data deletion for how to erase data immediately yourself.

If you are one of our customers’ contacts rather than a customer, please contact that business directly — they control that data and we can only act on their instructions. If you do not know who to contact, write to us and we will route your request.

9. Children

TickReplyis a business tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child’s data has reached us, tell us and we will delete it.

10. Changes

We will post any change here and update the effective date. If a change materially affects your rights we will email account owners before it takes effect.

11. Contact

Sampoorna Digi Branding Private Limited
Hyderabad, Telangana, India
privacy@tickreply.in

Sampoorna Digi Branding Private Limited · Hyderabad, Telangana, India