Legal · Privacy

Privacy Policy

This policy explains what data Wonkka processes, why we process it, and the choices available to people and businesses that use the platform.

Last updated:

On this page

Scope and roles

This policy applies to Wonkka’s public website, accounts, and workspaces, including WhatsApp conversations, AI-assisted operations, bookings, classes, orders, memberships, access, payments, billing, and analytics.

When a business uses Wonkka to communicate with its customers, that business decides why and how customer data is used, and Wonkka processes it to provide the service. Wonkka determines the processing needed to manage accounts, billing, security, support, and its own compliance obligations.

Data we collect

Depending on the features used, we may process the following categories:

  • Account and identity data, such as name, email, password hash, protected verification codes, sessions, invitations, membership, and workspace role.
  • Workspace and operational data, such as location, modules, schedules, availability, services, products, professionals, resources, customers, bookings, classes, orders, memberships, access checks, check-ins, and notifications.
  • Content and metadata needed to operate WhatsApp, the AI assistant, and operational notifications, including text, audio, images, PDFs, derived transcripts and visual summaries, phone numbers, business-scoped user identifiers, profile names, delivery status, opt-outs, and human handoffs.
  • Wonkka billing and business-payment data, such as plan, usage, amounts, references, deadlines, status, refunds, connected-account identifiers, and CBUs, CVUs, or aliases used in configuration or assigned to memberships. Integration credentials are encrypted; Wonkka does not store full card details or payer banking credentials.
  • Technical, operational, and security data, such as IP address, device, browser, sessions, access dates, logs, traces, API and webhook events, errors, and signals used to prevent abuse or fraud.

Where data comes from

We receive data from people who create an account; authorized workspace members; customers who interact with the business; and connected integrations, including Kapso, Meta, WhatsApp, Mercado Pago, and Cresium. We also receive API and webhook events to synchronize messages, assets, subscriptions, and payments.

How we use data

We use data only when needed for purposes such as:

  • Creating and managing accounts, workspaces, locations, teams, customers, and operations.
  • Sending and receiving messages; transcribing audio; interpreting images and PDFs in context; running AI-assisted responses; executing authorized actions; and handing conversations to the team.
  • Managing plans and trials, measuring usage, creating payment requests, reconciling charges and refunds, and maintaining recurring subscriptions.
  • Answering questions, resolving incidents, and communicating important service changes.
  • Authenticating users, protecting the platform, and detecting fraud, abuse, or policy violations.
  • Analyzing performance and improving Wonkka, preferably with aggregated or deidentified information. Wonkka does not use conversation content to train AI models.

Providers and recipients

We do not sell personal data. We share it when necessary with providers that support the service or when required by law. These providers may include:

  • Kapso, to connect phone numbers, transport WhatsApp messages and operational notifications, host the conversation inbox, and deliver signed webhook events.
  • Meta and WhatsApp, as the messaging platform, WABA authority, and decision maker for channel approvals, policies, and quality.
  • OpenAI, to generate responses and process text, audio, images and PDFs when the assistant is active. Data sent to its API is not used to train models by default; retention depends on the service, configured controls and the provider’s obligations.
  • DeepSeek, when configured as the primary or fallback provider, to process conversation context and generate responses or proposed actions.
  • TypeSafe, when enabled, to interpret requests, classify intent and select or summarize information from messages and business context.
  • Cloudflare, to run and protect the application, deliver content, process queues and scheduled tasks, maintain temporary assistant conversation state and record technical operating information.
  • Cloudflare D1, to host the platform's account and operational data.
  • Resend, to send transactional email related to an account.
  • PostHog, to measure site and dashboard usage and assistant performance in aggregate. It receives internal identifiers, metrics and usage events; it does not receive conversation content, phone numbers or the names of each business's customers. We honor the browser's "Do Not Track" signal.
  • Mercado Pago, for the business's Wonkka subscription and, when connected by the workspace, to authorize its account, host checkouts, manage payments or subscriptions, and report their status.
  • Cresium, when connected by the workspace, to create payment orders, process and reconcile transfers, and report collection status.

Retention

We retain data while an account is active and for as long as reasonably necessary to provide the service, maintain operational records, resolve disputes, prevent fraud, and meet legal, tax, or accounting obligations.

Encrypted WhatsApp webhooks expire after 30 days, and their content is removed sooner when successfully processed. The assistant’s working state expires after 7 days of inactivity. Wonkka processes audio, images and PDFs without keeping its own permanent copy of those files; message content and derived transcripts or summaries are purged after 90 days. Technical payloads expire after 7 days. Purging runs through periodic tasks; minimal operational, security and compliance records and provider retention may follow other timelines.

Security and international transfers

We apply reasonable technical and organizational measures, including role-based controls, workspace isolation, protected access codes, webhook validation, and encryption of sensitive tokens and credentials. No system can guarantee absolute security.

Our providers may process data in other countries. Where required, we use available contracts and safeguards to protect those transfers under applicable law.

Your rights

Depending on applicable law, you may request:

  • Access to your personal data and an explanation of its processing.
  • Correction or updating of inaccurate information.
  • Deletion when there is no valid reason to retain the data.
  • Objection to or restriction of certain processing.
  • A portable copy where this right applies.
  • Withdrawal of consent without affecting processing before withdrawal.

Children

Wonkka is intended for businesses and people with legal capacity to contract. We do not knowingly collect children's data through their own accounts. Businesses using Wonkka for services aimed at minors must obtain the authorizations required by law.

Changes to this policy

We may update this policy to reflect legal, technical, or service changes. We will publish the current version on this page and, when a change is material, provide notice through a reasonable channel.

Privacy questions

Write from the email associated with your account and identify your workspace and the right you want to exercise. If you are a customer of a business using Wonkka, include its name and the WhatsApp number, email, or identifier you used in the interaction.

Contact Wonkka