This Privacy Policy explains how TRooInbound (“TRooInbound”, “we”, “us”) collects, uses, shares, and protects information through the WhatsApp Connector for HubSpot (the “Service”), a HubSpot Marketplace app that connects a business’s WhatsApp Business Account to their HubSpot CRM using the official WhatsApp Business Platform. It applies to HubSpot portal admins and users who install or use the Service (“Customers”) and, where relevant, to the Customer’s own end contacts who exchange WhatsApp messages through it (“End Users”).
1. Information We Collect
From HubSpot (via OAuth, when a Customer installs the app)
- HubSpot portal ID and account/user identifiers used to authenticate Customers.
- Contact records (name, phone number, email, and other properties relevant to messaging and opt-in status) needed to send and log WhatsApp messages.
- Deal information (e.g., deal stage and related properties), used for payment-link messages and deal-stage-triggered message templates.
- Marketing/workflow contact lists used to run bulk WhatsApp sends.
We request only the HubSpot scopes each feature actually uses, and access is authorized and can be revoked by the Customer at any time from their HubSpot account.
From the WhatsApp Business Platform (Meta)
- The Customer’s WhatsApp Business Account ID, phone number ID, and an access token scoped to that WhatsApp Business Account, obtained through Meta’s Embedded Signup flow.
- WhatsApp message content and metadata (sender/recipient number, timestamps, delivery/read status, template usage), including any media attachments (images, documents), needed to send, receive, and display conversations inside HubSpot.
- Opt-in and opt-out status of End Users (including “STOP” requests).
TRooInbound operates as a Meta Tech Provider on a single Meta app; Customers connect their own WhatsApp Business Account and never share Meta app credentials with us.
From Stripe
- Your subscription to the Service itself is billed through TRooInbound’s own Stripe account: Stripe processes your card details directly, and we store only your Stripe customer/subscription ID and subscription status.
- If a Customer connects payments, a Stripe Connect (Standard) account ID and an access token scoped to that connected account, obtained via Stripe OAuth.
- Payment/checkout session status needed to confirm a payment and trigger a WhatsApp confirmation message. We never receive or store card numbers; Stripe’s hosted Checkout handles that directly in both cases above.
Generated automatically
- Audit logs of admin and system actions taken within the Service.
- Webhook event records from HubSpot, Meta, and Stripe, used for processing and troubleshooting delivery.
2. How We Use Information
- Sending and receiving WhatsApp messages on behalf of the Customer.
- Syncing WhatsApp conversations to the HubSpot Contact Timeline and triggering HubSpot workflows, including Custom Behavioral Events when a WhatsApp message is received (available on HubSpot Data Hub Pro/Enterprise).
- Running Customer-initiated bulk sends and payment-link messages.
- Storing WhatsApp message media (images, documents) in the Customer’s HubSpot File Manager so it can be attached to tickets, tasks, or deals created from an inbound message.
- Sending operational notifications, such as a failed payment-link send, to a Customer’s active users by email.
- Enforcing per-Customer plan limits, billing, and subscription status.
- Security, fraud prevention, and troubleshooting.
We do not sell personal information.
3. Who We Share Information With
Data is shared only with the sub-processors needed to run the Service, and only to the extent each integration requires:
- Meta / WhatsApp Business Platform — to deliver and receive WhatsApp messages.
- HubSpot — to read/write the CRM data a Customer has authorized.
- Stripe — to process payments through a Customer’s own connected account.
- Amazon Web Services (AWS) — to host and run the Service and store data securely.
Each Customer’s data is logically isolated from every other Customer’s data; the Service is multi-tenant but strictly partitioned at the data-access layer. We do not share data across Customers, and we disclose information to law enforcement only when legally required.
TRooInbound support and operations staff may access a Customer’s account to provide support, including a time-boxed (30-minute) session that mirrors that Customer’s own access. Every such session is logged in our audit trail.
4. Data Retention
- WhatsApp message content and metadata are retained for up to 24 months, after which they are automatically purged.
- Webhook event records are retained for up to 90 days.
- One-time verification codes are purged shortly after they expire.
- WhatsApp message media uploaded to a Customer’s HubSpot File Manager expires after 3 months, independent of the periods above, per HubSpot’s own file storage settings.
When a Customer uninstalls the Service, or when HubSpot notifies us that a contact has been deleted for privacy reasons, the corresponding message history and mappings are deleted or anonymized. Customers can also request deletion of their data at any time by contacting us (see Section 8).
5. Data Security
- Data in transit is encrypted (HTTPS/TLS).
- Access tokens and OAuth refresh tokens (HubSpot, Meta, and Stripe) are encrypted at rest.
- Inbound webhooks from HubSpot, Meta, and Stripe are verified using each provider’s signature scheme before being processed.
- Access to Customer data is restricted to what each Customer’s own tenant is authorized to see.
6. Your Rights and Choices
- End Users can opt out of WhatsApp messages at any time by replying “STOP”, which we honor across all future sends.
- Customers can revoke HubSpot access from their HubSpot account, disconnect their WhatsApp Business Account or Stripe account from the Service, or request export or deletion of their data.
- Depending on applicable law (including GDPR), individuals may have rights to access, correct, or delete their personal information, or to object to or restrict certain processing. Requests can be sent to the contact in Section 8.
7. International Data Transfers
The Service is hosted on cloud infrastructure that may process data outside the country where a Customer or End User is located. Where required by law, we rely on appropriate safeguards for such transfers.
8. Contact Us
Questions about this Privacy Policy, or requests relating to your data, can be sent to hello@trooinbound.com.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the effective date above.