Privacy Policy

1. Who We Are and What This Policy Covers

This Privacy Policy explains how Advance Link for Design and Programming of Special Software ("Advancelink", "we", "us", "our") collects, uses, stores, shares and deletes personal data in connection with the Advancelink platform available at https://advancelink.net.

Advancelink is a software-as-a-service platform that allows business customers ("merchants") to manage their own WhatsApp Business Account ("WABA") through the official WhatsApp Business Platform (Meta Cloud API). Merchants connect a WABA that they already own in Meta Business Manager, either by supplying a Meta System User access token or by authorising the connection through Facebook OAuth. Advancelink does not create WhatsApp Business Accounts on a merchant's behalf.

This policy applies to our website, our merchant dashboard, our agent and administrator interfaces, and our public API. It does not apply to WhatsApp itself, to Meta Platforms' own products, or to the independent privacy practices of any merchant that uses our platform to communicate with its own customers.

2. Our Two Roles: Controller and Processor

It is important to distinguish two different categories of data, because our responsibilities differ for each.

If you are an end customer who has exchanged WhatsApp messages with a business that uses Advancelink, the business you messaged is responsible for that conversation and for answering your privacy requests. Please contact that business directly. If you contact us instead, we will forward your request to the relevant merchant where we are able to identify them.

3. Categories of Data We Collect

a. Merchant account data (we are controller)

b. Meta and WhatsApp credentials supplied by the merchant

c. End-customer conversation data (the merchant is controller)

d. Product, catalogue and order data (the merchant is controller)

e. Technical and operational data

f. Payment data

4. How WhatsApp and Meta Data Is Obtained, Used and Stored

A merchant grants Advancelink access to its WABA in one of two ways: by pasting a Meta System User access token generated in the merchant's own Meta Business Manager, or by completing a Facebook OAuth authorisation flow. In both cases the merchant is the owner of the WABA and controls the scope of access granted.

We use the resulting credentials only to operate the features the merchant has asked for: sending and receiving messages, sending approved message templates, reading and synchronising message template and product catalogue data, reading the messaging limit tier and quality rating that Meta reports for the connected phone number so the merchant can see the health of its own number, and refreshing tokens that are close to expiry so the connection does not break. Inbound messages are received through a webhook registered with Meta; each inbound request is signature-verified before it is processed.

Message content, media files, catalogue records and delivery statuses are stored in our platform database and on our server filesystem so that the merchant's inbox, chatbot flows, campaign reports and agent workflows can function. Access tokens are stored so that scheduled and automated features continue to work without the merchant re-authenticating each time.

Use of the WhatsApp Business Platform is additionally governed by Meta's own terms and policies, including the WhatsApp Business Messaging Policy, the WhatsApp Business Terms of Service and the Meta Privacy Policy. Merchants and their end customers are subject to those terms in addition to this policy, and Meta processes message traffic under its own privacy terms independently of Advancelink.

5. Purposes and Legal Bases for Processing

Merchants are responsible for having a valid legal basis, and for obtaining any opt-in required by Meta's policies and by applicable law, before messaging their own customers through the platform.

6. Sharing and Sub-processors

We do not sell personal data, and we do not share it for advertising or profiling purposes. We disclose data only in the following circumstances:

Each of these providers processes the data it receives under its own terms and privacy policy, which we do not control.

7. Cookies, Browser Storage, Analytics and Tracking

a. Essential session and authentication storage. To sign in to the merchant dashboard, the agent interface or the administrator panel, the platform stores a signed session token (a JSON Web Token) and related interface preferences in your browser's local storage. This storage is strictly necessary — without it you cannot stay signed in and the dashboard cannot function. Clearing your browser storage, or signing out, removes it. We do not use it to track you across other websites.

b. Website analytics. Our public website supports an optional Google Analytics tag, which a platform administrator can enable or disable from the admin panel. When it is enabled, pages on advancelink.net load a script from googletagmanager.com operated by Google LLC. Google Analytics sets its own cookies and/or browser identifiers and receives data about your visit, including the pages you view, the date and time, referring page, approximate location derived from your IP address, and browser and device characteristics. That data is processed by Google under Google's own privacy terms, and we cannot control Google's independent use of it.

c. Current status. As at the "Last updated" date of this policy, no analytics tag is configured on advancelink.net and no analytics cookies are set by our pages. If we enable analytics, the description in paragraph (b) applies from that moment, and this section is the disclosure of that processing. You can in any case block or delete cookies through your browser settings, or use Google's opt-out tools; blocking analytics cookies does not affect your ability to use the dashboard, whereas blocking the essential storage in paragraph (a) does.

d. No advertising or cross-site tracking. We do not run advertising pixels, retargeting tags or cross-site tracking on the platform, and we do not use end-customer WhatsApp conversation data for any analytics or advertising purpose.

8. Data Retention

We keep personal data only for as long as it is needed for the purpose it was collected for. The following periods apply:

How deletion works in practice. Deleting a chat or a contact from the dashboard removes the corresponding message, chat and contact records from our database. Media files that were previously downloaded to the server filesystem are removed by the full purge routine — that is, when a matched Meta data-deletion request is processed or when we delete an account following a verified request. If you need media files removed sooner, email advancelink@advancelink.net and we will run the purge for the account concerned.

9. Your Rights, Account Closure and Deletion

Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, objection to processing, and a copy of data you provided to us. The following concrete mechanisms exist:

Our response times. We acknowledge privacy and deletion requests within 5 business days of receipt, and complete verified access, correction and deletion requests within 30 days. This matches the 30-day window shown on the deletion status page returned to Meta. If a request is unusually complex and we need longer, we will tell you within the initial 30 days, explain why, and give you a revised date. We may ask for information to verify your identity or your authority over the account before acting, and the clock runs from the point that verification is complete.

Where Advancelink acts as a processor, a request from an end customer will normally be passed to the merchant who controls that conversation data, and the merchant will decide the outcome.

10. Security

We take measures that are reasonable for a platform of this type. Access to the merchant dashboard, agent interface and administrator panel requires authentication with a signed session token, and each request is re-validated against the account record so that disabling or removing an account takes effect immediately. Roles are separated — platform administrator, merchant owner and agent sub-account — and agents can only reach conversations that have been assigned to them. Passwords are stored as one-way hashes and are never stored or displayed in plain text. The website and the platform are served over HTTPS, and plain HTTP requests are redirected to HTTPS. Inbound Meta webhook requests are signature-verified before processing, and OAuth callbacks are verified against a signed state value. Meta API activity is written to an internal log table that we can review when investigating a fault, a support ticket or a suspected incident.

We do not claim any certification, audit or standard that we have not obtained, and we do not operate continuous automated security monitoring or alerting. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Merchants are responsible for protecting their own login credentials, for managing the agent accounts they create, and for the security of any third-party destination they configure.

11. Security Incidents and Personal Data Breaches

If we become aware of, or reasonably suspect, a security incident affecting personal data held on the platform, we will investigate without undue delay and take reasonable steps to contain the incident, to restore normal operation and to prevent a recurrence.

12. International Transfers

Advancelink is established in the State of Kuwait, and the platform is operated from server infrastructure that may be located outside your country of residence. In addition, message traffic is necessarily transmitted to and from Meta Platforms, payments are handled by processors that operate internationally, and — where website analytics is enabled — analytics data is processed by Google. As a result, personal data may be transferred to, stored in and processed in jurisdictions whose data protection laws differ from those of your own. Each of these providers processes the data it receives under its own published terms and privacy policy. Where a transfer takes place, we take steps to ensure the data continues to be protected in a manner consistent with this policy and with applicable law.

13. Children's Data

Advancelink is a business-to-business service. It is not directed at children, and we do not knowingly permit anyone under the age of 18 to create an account or to use the platform. If we become aware that we have collected personal data from a person under 18 without appropriate authority, we will delete it. If you believe a minor has provided us with personal data, please contact advancelink@advancelink.net.

14. Changes to This Policy

We may update this policy to reflect changes in the platform, in our service providers, or in applicable law or Meta platform requirements. The current version is always published at https://advancelink.net with the "Last updated" date shown below, and that date is the authoritative indication that something has changed. Where a change materially affects how we handle personal data, we will also email the address registered on each active account. Continued use of the platform after an update takes effect constitutes acceptance of the revised policy.

15. Contact for Privacy Requests

For any privacy question, data access request, correction or deletion request, write to us at:

We acknowledge privacy requests within 5 business days and complete verified requests within 30 days, as set out in section 9. We may need to verify your identity, or your authority to act for an account, before we can act on a request.

16. Governing Law

This Privacy Policy and any dispute arising out of or in connection with it are governed by the laws of the State of Kuwait, and the courts of the State of Kuwait shall have jurisdiction, without prejudice to any mandatory rights you may have under the law of your own country of residence.

Last updated: 14 August 2026