Privacy Policy

Effective date: July 21, 2026 · Last updated: July 21, 2026

Expansio Marketing ("we", "us", or "our") operates Expansio Tech, a software platform that lets businesses manage WhatsApp Business conversations, run automation, send broadcast campaigns, and integrate messaging into their own systems, built on the WhatsApp Business Platform provided by Meta Platforms, Inc. ("Meta"). This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights available to you.

This policy applies to visitors of expansio.site, to businesses that register a workspace on Expansio Tech ("Customers"), to individual users Customers invite to their workspace ("Agents"), and, where relevant, to the end customers a Customer communicates with over WhatsApp ("Contacts"). By using Expansio Tech, you agree to the collection and use of information as described here.

1. Information we collect

Account information. When you or your business sign up, we collect your name, email address, and a hashed password (or, if you use Google Sign-In, the profile information Google shares with us for authentication). We also record your workspace name and role (owner, admin, or agent).

WhatsApp conversation data.Once a Customer connects a WhatsApp Business Account, Expansio Tech processes the phone numbers, contact names, message content, media attachments, delivery/read status, and timestamps exchanged between the Customer and their Contacts via the WhatsApp Business Platform, so that the Customer's team can view and reply to those conversations from a shared inbox.

Connection credentials.To send and receive messages on a Customer's behalf, we store their WhatsApp Business Account ID, phone number ID, and API access token. Access tokens are encrypted at rest (AES-256-GCM) and are never displayed in the dashboard after they're entered.

Business configuration data. Contact lists, custom contact fields, tags, message templates, broadcast campaigns, automation rules, and chatbot flows that a Customer creates while using the Service.

Payment information. Subscription billing is handled by our payment processor, Razorpay. We store the resulting subscription status, plan, and billing cycle, but we never receive or store full card, UPI, or bank account numbers — those are handled directly by Razorpay under its own privacy policy.

API keys and webhooks. If a Customer generates an API key or registers a webhook endpoint to integrate Expansio Tech with their own systems, we store a hashed version of the key and the webhook URL and secret they provide.

Technical and usage data. IP address (used for rate-limiting and security purposes), browser/device information, log timestamps, and pages visited on expansio.site.

Cookies.We use a strictly necessary session cookie to keep you logged in. We don't use advertising or cross-site tracking cookies.

2. How we use information

We use the information above only to operate and improve the Service, specifically to:

  • authenticate users and maintain workspace access control,
  • send and receive WhatsApp messages on behalf of the connected Customer,
  • display conversations in the Customer's shared team inbox in real time,
  • run the automation, broadcast, and AI-assisted reply features a Customer explicitly configures,
  • enforce plan limits, process subscription billing, and prevent abuse,
  • send transactional emails (account activation, password reset),
  • maintain, secure, debug, and improve the reliability of the Service.

We do not sell personal data or conversation content, and we do not use Customer or Contact data to train third-party AI models. Where a Customer enables the optional AI fallback bot using their own OpenAI API key, message content needed to generate a reply is sent to OpenAI under the Customer's own OpenAI account and its terms — we do not separately retain that content for AI training.

3. How we share information

We share information only in the following circumstances:

  • Meta / WhatsApp Business Platform— message data flows to and from Meta's servers as an inherent part of sending and receiving WhatsApp messages. Meta processes this data under its own WhatsApp Business Platform terms and Privacy Policy.
  • Razorpay — for processing subscription payments.
  • Resend — our transactional email provider, used to deliver account-activation and password-reset emails.
  • Infrastructure providers — hosting, database, and object-storage providers strictly necessary to run the Service, bound by confidentiality and data processing obligations.
  • Destinations a Customer configures themselves— if a Customer sets up outbound webhooks or connects Expansio Tech's API to their own CRM or tools, the data they choose to send flows to the destinations theyconfigure. We don't control, and aren't responsible for, what a Customer does with their own integrations.
  • Legal requirements — if required to comply with a legal obligation, enforce our Terms of Service, or protect the rights, property, or safety of Expansio Tech, our users, or the public.

We do not sell personal information to third parties, and we do not share it for third-party advertising.

4. Data retention

Conversation, contact, and account data is retained for as long as the Customer's workspace is active. A Customer can delete individual contacts or conversations, or their entire account, at any time from within the dashboard. Deleted data is removed from primary storage within 30 days, except where we're required to retain records for legal, accounting, tax, or fraud-prevention purposes, in which case it is retained only as long as necessary for that purpose.

5. Security

Access tokens, API keys, and webhook secrets are encrypted at rest using AES-256-GCM. All traffic to and from the platform is encrypted in transit via HTTPS/TLS. Passwords are hashed and never stored in plain text. Access to production systems and customer data is restricted to what's necessary to operate and support the Service. We take reasonable technical and organizational measures to protect your information, but no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

6. International data transfers

Expansio Tech is operated from India, and our infrastructure may be located in India or other countries. Where we or our sub-processors (such as Meta, Razorpay, or our hosting providers) transfer personal data across borders, we rely on those providers' own compliance mechanisms and contractual safeguards for such transfers.

7. Your rights and choices

Depending on your location, you may have rights under applicable data protection law (including India's Digital Personal Data Protection Act, 2023, or the EU/UK GDPR) to access, correct, export, restrict, object to, or delete your personal data, and to withdraw consent where processing is based on consent. A Customer can exercise most of these rights directly from the Expansio Tech dashboard (editing or deleting contacts, conversations, or the account). For any request we can't fulfil directly in-product, or if you're a Contact who wants to exercise a right over data a Customer has processed about you, contact us at expansio.marketing@gmail.com — we'll respond within a reasonable time and, where the request concerns a Customer's data, may direct you to that Customer as the party who controls it.

8. Children's privacy

Expansio Tech is a business tool and is not directed to, and should not be used by, individuals under the age of 18. We do not knowingly collect personal information from children.

9. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to our practices or for legal, operational, or regulatory reasons. We'll update the "Last updated" date above, and where changes are material we'll take reasonable steps to notify Customers (such as by email or an in-app notice).

10. Contact us

Expansio Marketing
Picnic Spot Road, Lucknow, Uttar Pradesh 226016, India
Email: expansio.marketing@gmail.com