Effective Date: July 2026 | Last Updated: July 2026
1 Introduction & Scope
The Pitch Point ("The Pitch Point", "we", "us", or "our") is committed to protecting your privacy and handling personal information responsibly, lawfully and transparently. This Privacy Policy explains how we collect, use, disclose, store and safeguard information when you visit our website, contact us, or use our services — including digital marketing, performance marketing, web development, graphic designing, and our WhatsApp Business Cloud API platform and messaging solutions.
The Pitch Point is a registered Meta Tech Provider (WhatsApp Business Solution Provider) and provides access to the WhatsApp Business Cloud API to businesses ("Clients"). This Policy applies to our website visitors, our Clients, and to end users who communicate with our Clients through WhatsApp using our platform ("End Users").
By using our website, platform or services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please discontinue use of our website and services.
2 Our Role: Data Controller and Data Processor
- As a Data Controller (Data Fiduciary): When we collect information directly from website visitors, enquiry forms, marketing activities and our own Clients for account creation, onboarding, billing and support, we determine the purpose and means of processing.
- As a Data Processor (Data Processor / Sub-Processor): When our Clients use our platform to send and receive WhatsApp messages, the Client is the Data Controller of their End User data. We process that data strictly on the Client's documented instructions, solely to deliver the messaging service, and never for our own independent purposes.
- Client Responsibility: Our Clients are responsible for obtaining valid, informed opt-in consent from their End Users, for the lawful basis of their messaging, and for maintaining their own privacy notice. We do not control, and are not responsible for, the content of Client messages or Client data practices.
3 Information We Collect
- Personal Information: Name, business name, email address, phone number, WhatsApp number, billing and GST details, designation, address, and any other details you voluntarily share through forms, email, calls, or onboarding documents.
- Account & Verification Data: Information required for WhatsApp Business Account (WABA) creation and Meta Business Verification, such as business legal name, display name, business category, website, business documents, and Facebook Business Manager ID.
- Usage Data: IP address, device and browser type, operating system, pages visited, referring URLs, time spent on pages, dashboard activity logs and other diagnostic statistics.
- Message & Communication Data: Where you contact a business through WhatsApp using our platform, we process the WhatsApp phone number, WhatsApp profile name, message content, attached media, template names, delivery/read status, timestamps and message metadata.
- Payment Information: Transaction records and invoices. Card and banking credentials are collected and processed directly by our PCI-DSS compliant payment gateway partners; we do not store full card details on our servers.
- Cookies & Tracking Technologies: Cookies, pixels and similar technologies used to operate the website, remember preferences and measure performance, as described in Section 15.
4 WhatsApp Business Cloud API & Meta Platforms
Our WhatsApp messaging services are built on the WhatsApp Business Cloud API, hosted and operated by Meta Platforms, Inc. and WhatsApp LLC ("Meta"). When a message is sent or received through our platform, it is transmitted through Meta's infrastructure.
- Meta as a Processor: Meta processes WhatsApp message data in accordance with the WhatsApp Business Terms of Service, the WhatsApp Business Data Processing Terms and Meta's own privacy practices. Please review Meta's policies at whatsapp.com/legal and business.whatsapp.com/policy.
- Encryption: WhatsApp messages are protected in transit. Messages sent using the Cloud API are encrypted between the End User's device and Meta's servers, and between Meta's servers and our platform over TLS.
- Meta Retention: Meta does not retain message content on the Cloud API after successful delivery, other than for a limited period required to attempt delivery or as described in Meta's documentation.
- Policy Compliance: We and our Clients are required to comply with the WhatsApp Business Messaging Policy, the WhatsApp Commerce Policy and Meta Platform Terms. Prohibited, deceptive, unsolicited or non-consented messaging is not permitted and may result in immediate suspension.
- No Advertising Use: We do not use WhatsApp End User data for advertising or ad targeting, we do not sell it, and we do not build user profiles or enrich third-party datasets with it.
- No Independent Reuse: WhatsApp data obtained on behalf of a Client is not used to train unrelated systems, is not shared with other Clients, and is not repurposed beyond delivering the service the Client has instructed.
5 Opt-In, Consent & Opt-Out for WhatsApp Messaging
We only support WhatsApp messaging to users who have provided prior, explicit and verifiable opt-in consent, in line with Meta's opt-in requirements.
- Valid Opt-In: Consent must be collected through a clear channel — website form, checkbox, IVR, in-store form, app, missed call, click-to-WhatsApp ad or a WhatsApp message initiated by the End User — stating the business name and that WhatsApp messages will be received.
- Proof of Consent: Clients must maintain records of opt-in (source, timestamp and scope) and produce them on request by us or by Meta.
- Opt-Out: End Users can stop receiving messages at any time by replying STOP, UNSUBSCRIBE or OPT OUT, by using the in-message opt-out button, by blocking the business on WhatsApp, or by writing to us at info@thepitchpoint.com. Opt-out requests are honoured promptly and the number is suppressed from further promotional messaging.
- No Unsolicited Messaging: Purchased, scraped, rented or harvested phone number lists are strictly prohibited on our platform.
6 How We Use Your Information
- To Provide Services: To deliver, operate and support our digital marketing, performance marketing, web development, graphic designing and WhatsApp Business Cloud API services, including message routing, delivery and reporting.
- Account Management: To create and verify WhatsApp Business Accounts, manage display names, submit message templates and administer your dashboard access.
- Billing: To process payments, issue invoices, apply conversation-based pricing and manage credits.
- Support & Communication: To respond to enquiries, provide technical assistance and send service, transactional and administrative notices.
- Improvement & Analytics: To analyse aggregated, de-identified usage data to improve reliability, performance and user experience.
- Security & Abuse Prevention: To detect, investigate and prevent spam, fraud, policy violations and unauthorised access.
- Marketing: To send promotional information about our own services, only where you have consented, and always with an opt-out.
- Legal Compliance: To comply with applicable law, tax and accounting requirements, lawful requests from authorities, and to establish or defend legal claims.
7 Legal Basis for Processing
- Consent: For WhatsApp messaging, marketing communications and non-essential cookies.
- Performance of a Contract: To deliver the services you or your organisation have engaged us for.
- Legitimate Interests: To secure our platform, prevent abuse, and improve our services, balanced against your rights.
- Legal Obligation: To meet statutory, regulatory, tax and law-enforcement requirements.
We process personal data in accordance with the Digital Personal Data Protection Act, 2023 (India), the Information Technology Act, 2000 and its rules, and — where applicable to users in those regions — the EU/UK GDPR.
8 Sharing Your Information
We do not sell, rent or trade your personal information. We share information only in the following circumstances:
- Meta Platforms, Inc. / WhatsApp LLC: To transmit and receive messages through the WhatsApp Business Cloud API and to manage WhatsApp Business Accounts.
- Our Clients: Where you message a business using our platform, your message content and WhatsApp profile details are made available to that business, which acts as the controller of that conversation.
- Sub-Processors and Service Providers: Cloud hosting, data storage, CRM, analytics, communication and payment providers who act on our instructions under written confidentiality and data protection obligations.
- Professional Advisors: Auditors, accountants and lawyers bound by professional confidentiality.
- Business Transfers: In connection with a merger, acquisition, restructuring or sale of assets, subject to this Policy continuing to apply.
- Legal Requirements: Where disclosure is required by law, court order, subpoena or a valid governmental or regulatory request, or to protect our rights, safety or property.
9 Data Retention
- Message Data: Retained only for as long as necessary to deliver the service and provide conversation history to the Client, or as instructed by the Client. Clients may request deletion at any time.
- Account & Billing Records: Retained for the duration of the engagement and thereafter for the period required under Indian tax, accounting and statutory laws.
- Enquiry & Marketing Data: Retained until you withdraw consent or request deletion.
- Logs: Technical and security logs are retained for a limited period for troubleshooting, audit and abuse prevention, and are then deleted or anonymised.
- Deletion on Termination: On termination of a Client account, Client and End User data is deleted or returned within a reasonable period, unless retention is required by law.
10 International Data Transfers
Our service providers, including Meta, may store and process data on servers located outside India. Where personal data is transferred across borders, we take reasonable steps to ensure it remains protected by appropriate safeguards, such as contractual data protection terms with the receiving party, and we transfer data only to jurisdictions permitted under applicable law.
11 Data Security
We implement administrative, technical and physical safeguards designed to protect personal information, including TLS/HTTPS encryption in transit, encryption at rest for sensitive data, role-based access controls, least-privilege access for staff, secure API key and token management, firewalls, activity logging and periodic security reviews.
No method of transmission over the internet or electronic storage is completely secure. While we work to protect your information, we cannot guarantee absolute security, and you share information with us at your own risk. You are responsible for keeping your account credentials and API keys confidential.
12 Data Breach Notification
In the event of a personal data breach, we will investigate promptly, take steps to contain and remediate it, and notify affected Clients, affected individuals and the relevant supervisory authority — including the Data Protection Board of India, where applicable — without undue delay and within the timelines prescribed by law. Where we act as a processor, we will notify the relevant Client so that they can meet their own notification obligations.
13 Your Rights
- Access: You may request confirmation of whether we process your personal data and a summary of that data.
- Correction: You may request correction of inaccurate, incomplete or outdated information.
- Erasure: You may request deletion of your personal data, subject to our legal and contractual retention obligations.
- Withdraw Consent: You may withdraw consent at any time, including opting out of WhatsApp messages by replying STOP. Withdrawal does not affect processing carried out before withdrawal.
- Data Portability & Objection: Where applicable law provides these rights, you may request a copy of your data in a portable format or object to certain processing.
- Nominate: Under the DPDP Act, 2023 you may nominate another individual to exercise your rights in the event of your death or incapacity.
- Grievance Redressal: You may raise a complaint with our Grievance Officer (Section 18) and, if unsatisfied, escalate to the relevant data protection authority.
To exercise any right, write to us at info@thepitchpoint.com. We may need to verify your identity before acting, and we will respond within the timelines required by applicable law. If your data is held by us on behalf of a Client, we will refer your request to that Client and assist them in responding.
14 Children's Privacy
Our website and services are intended for businesses and individuals aged 18 years and above. We do not knowingly collect personal data from children. WhatsApp requires users to meet its own minimum age requirements. If we become aware that we have collected data from a child without verifiable parental consent, we will delete it promptly.
15 Cookies & Tracking Technologies
We use cookies and similar technologies to keep the website functioning, remember your preferences, measure traffic and evaluate campaign performance. Essential cookies are required for the site to work. Analytics and advertising cookies, including those set by third parties such as Meta Pixel and Google Analytics, are used only where permitted. You can control or delete cookies through your browser settings, though disabling some cookies may affect site functionality.
16 Third-Party Links & Services
Our website and platform may contain links to third-party websites or integrate third-party tools. We are not responsible for the privacy practices or content of those third parties. We encourage you to read their privacy policies before providing them with personal information.
17 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements or Meta platform policies. Any changes will be posted on this page with a revised effective date. Where changes are material, we will provide additional notice by email or through the platform. Continued use of our services after an update constitutes acceptance of the revised Policy.
18 Grievance Officer & Contact Us
If you have questions, concerns or complaints about this Privacy Policy, our data practices, or wish to exercise your rights, please contact our Grievance Officer, appointed in accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023:
We aim to acknowledge grievances within 24 hours and resolve them within the timelines prescribed by applicable law.