Skip to content
ONPADDocs

Docs / Workspace

Data and privacy

What ONPAD stores, who can see it, how credentials are protected, and how to get your data out.

View as Markdown

What ONPAD stores

For your workspace: contacts, conversations and their messages, templates, campaigns and their results, automations, AI Agent settings, team members, and logs of activity and API requests.

Messages are stored so the inbox works — a shared inbox that forgets yesterday is not an inbox.

Who can see it

Your team, according to their roles. An agent sees conversations; only the owner sees billing. See Team and roles.

Workspaces are separate. Nothing is shared between them. A contact in one does not appear in another, even with the same phone number and the same owner.

ONPAD staff can access workspace data only where support requires it, and such access is logged.

Credentials

The access token Meta issues when you connect WhatsApp is stored encrypted. It is used to send and receive on your behalf and for nothing else.

Your Facebook password is never seen by ONPAD. The connection runs through Meta's own Embedded Signup — you sign in to Meta, and Meta hands ONPAD a token.

API keys are stored as a hash, not as the key. That is why the full key is shown only once: ONPAD genuinely cannot show it again.

What belongs to you

Your WhatsApp Business Account is yours. It lives in your own Meta Business Manager. If you leave ONPAD, the account and the number stay with you — you disconnect ONPAD and connect something else.

Your contacts and conversations are yours. Export contacts as CSV whenever you want.

ONPAD is software you use, not a place your WhatsApp presence is locked inside.

Meta also has the data

Every message goes through Meta's WhatsApp Business Cloud API, so Meta has it too, under its own terms. That is true of every WhatsApp Business platform — it is how the official API works.

Meta's data handling is Meta's, and no platform can change it.

Getting your data out

Contacts — export as CSV from Contacts at any time.

Everything else, or a full copy, or deletion of an account and its data: email support@onpad.in from the owner's address. Requests from any other address are not actioned, because that is how accounts get taken.

Deleting a workspace

Deleting removes the workspace and its data. Before you do:

  1. Export your contacts. They are not recoverable afterwards.
  2. Disconnect at Meta's end too, if you are leaving entirely — deleting the ONPAD workspace does not delete your WhatsApp Business Account, which is correct, because that account is yours.

Good habits

Remove people the day they leave. An unwatched account is the one that gets misused.

One API key per integration. Revoking one then does not break the others.

Never put an API key in browser code or a public repository. Anyone holding it can message your customers from your number.

Do not ask customers for card numbers, passwords or ID numbers over WhatsApp. Meta rejects templates that do, and it trains your customers to be phished.

Next

Still stuck?

Ask ONPAD, the assistant inside your workspace, can answer questions about your own data — how a specific campaign performed, why one message failed, what your limits are right now.

Ask ONPAD in your workspaceEmail support@onpad.in