Let's Tok Privacy Policy
This policy covers the Let's Tok website-to-WhatsApp customer messaging service only. The Letstok AI video and social publishing products are covered by a separate policy.
Version 1.0 · 2026-08-17
1. Who we are
Let's Tok is operated by Letstok. In this policy “we” and “Letstok” mean the operator of the service, “you” or “the business” means the business that subscribes to Let's Tok, and “visitor” or “end customer” means a person who messages that business through WhatsApp.
2. Our role: we process, you control
This distinction determines everything below. For the messages exchanged between a business and its customers, the business is the data controller and Letstok is a data processor acting on the business's documented instructions. We do not decide why those conversations happen or what is said in them.
For the business's own account data — the people who sign in, billing records, support requests — Letstok is the controller.
Letstok never sends messages under its own identity. Conversations open against the business's own WhatsApp Business Account and phone number, and end customers are messaging that business, not us.
3. What we process
- Business account data: the WhatsApp phone number used to sign in — which is the account identity — plus name, role, a billing email address, and audit records of actions taken in the shared inbox.
- Authentication data: one-time codes we send to that number, stored hashed and short-lived, together with delivery and verification attempts, sign-in times, device and browser information and IP addresses. We keep these to operate sign-in and to detect account takeover.
- Billing data: subscription tier, invoices and payment status. Card details are handled by our payment processor and are never stored by us.
- WhatsApp connection data: the business's WhatsApp Business Account ID, phone number ID, display name and the access token issued by Meta, held encrypted.
- Conversation data: messages sent and received through the connected number, including text, media the customer chooses to send, timestamps, delivery status, the end customer's WhatsApp phone number and profile name, and which page of the business's website the conversation started from.
- Configuration data: welcome menus, routing rules, departments, templates and widget settings.
- Technical data: server logs, IP addresses and error traces, used to operate and secure the service.
4. Where the data comes from
- Directly from the business when it signs up and configures the service.
- From Meta, through the official WhatsApp Business Platform, when the business connects its account and when messages are delivered to us by webhook.
- From the end customer, when they choose to send a message to the business.
- From the business's public website, if the business enables automatic website reading so that answers can reference its own published information.
5. Why we process it
- To deliver the service: route incoming messages, send the business's configured replies, and present conversations in its shared inbox.
- To provide the automated welcome and support-routing workflow the business has configured.
- To deliver leads and notifications where the business has enabled email, webhook or CRM delivery.
- To meter usage against the business's plan and to bill it.
- To secure the service, prevent abuse and comply with legal obligations.
6. What we do not do
- We do not sell personal data.
- We do not use one business's conversation data to serve another business.
- We do not use end-customer message content to train general-purpose AI models.
- We do not message a business's customers on our own initiative.
7. Subprocessors
We use a small number of providers to run the service. Each is bound by contract to appropriate confidentiality and security obligations.
| Provider | Purpose |
|---|---|
| Meta Platforms (WhatsApp Business Platform) | Message delivery to and from WhatsApp. Governed by the business's own agreement with Meta. |
| Cloud hosting and database provider | Running the service and storing data. |
| Payment processor | Subscription billing. Card data never reaches us. |
| Email delivery provider | Transactional email and lead notifications. |
| AI model provider | Only if the business enables the optional AI answering layer. Off by default. |
8. How long we keep it
| Data | Retention |
|---|---|
| Conversation content and media | 24 months from the last message, or a shorter period configured by the business, or until deletion is requested. |
| Business account and configuration | For the life of the account, then 90 days after closure. |
| Billing records | As required by applicable tax and accounting law. |
| Authentication codes | Deleted or expired within minutes. Sign-in and device records: 12 months. |
| Technical logs | Up to 12 months. |
| WhatsApp access tokens | Deleted immediately on disconnection. |
9. Security
- WhatsApp access tokens are encrypted at rest with managed keys and are never exposed to a browser, returned by an API or written to logs.
- The public identifier embedded in the website widget identifies a widget configuration only. It grants no access to messages and carries no token or account identifier.
- Every query is scoped to a single business at the data-access layer, so one business's data cannot be reached from another's session.
- Access by Letstok staff is limited to what is needed for support and is logged.
- Data in transit is encrypted with TLS. Incoming webhooks from Meta are cryptographically verified before processing.
10. Rights of end customers
Because the business is the controller of its conversations, an end customer should direct requests to access, correct or delete their data to the business they messaged. If a request reaches us first, we will pass it to the relevant business and assist that business in responding.
An end customer can stop receiving messages at any time by telling the business, and can block the number in WhatsApp. Opt-outs are recorded against the conversation.
11. Rights of the business
- Export: request a machine-readable export of conversations and configuration at any time.
- Deletion: request deletion of all conversation data; we complete it within 30 days, except where law requires retention.
- Disconnection: disconnect the WhatsApp Business Account from the settings screen at any time. The account, the number and the customer relationships remain the business's own.
- Instructions: we process conversation data only as instructed by the business and as needed to run the service.
12. International transfers
The service is operated from Israel and hosted on cloud infrastructure that may process data in other jurisdictions. Where personal data of individuals in the European Economic Area is involved, transfers rely on an appropriate safeguard such as the European Commission's standard contractual clauses. A data processing agreement is available to subscribing businesses on request.
13. Changes to this policy
We will notify subscribing businesses by email before a material change takes effect, and the version number and date at the top of this page will be updated. Continued use after the effective date constitutes acceptance.
Contact
Questions about this policy, or a data request: contact@letstok.com. A data processing agreement is available to subscribing businesses on request.