All data collected, stored and accessed by Cloud API is controlled and monitored to ensure proper usage and maintain the high level of privacy expected from a WhatsApp client.
Information about the businesses, including their phone numbers, business address, contacts, type, etc. is maintained by Meta and the Business Manager product and complies with the terms of service set by Meta. Cloud API relies on Business Manager and other Meta systems to identify any access to Cloud API on behalf of the business.
Messages sent or received through Cloud API are only accessed by Cloud API, no other part of Meta can use this information. Messages have a maximum retention period of 30 days in order to provide the base features and functionality of the Cloud API service; for example, retransmissions. After 30 days, these features and functionality are no longer available.
Cloud API does not rely on any information about the user (customer/consumer) the business is communicating with other than the phone number used to identify the account. This information is used to deliver the messages through the WhatsApp client code. User phone numbers are used as sources or destinations for individual messages; as such they are deleted when messages are deleted. No other part of Meta has access to this information.
Like the On-Premise client, the WhatsApp client code used by Cloud API collects messaging information about the business as required by WhatsApp. This is information used by WhatsApp to detect malicious activity. No message content is shared or sent to WhatsApp at any time and no WhatsApp employee has access to any message content.
Cloud API Data | System | Available to rest of Meta | Available to WhatsApp |
---|---|---|---|
Message content | Cloud API | No | No |
Consumer phone number | Cloud API | No | Yes |
Non-identifiable statistics | Cloud API | Yes | Yes |
Integrity signals - per business | WhatsApp Client | No | Yes |
Business Information | Business Manager | Yes | Yes |
Billing - per business | Yes | Yes |