Privacy Policy
This policy explains what personal data Resalian collects, why, and what we do with it. Resalian is operated by Tech Serenity IT (registered company name, Commercial Registration No. commercial registration number, registered address).
On this page
1. Who we are
Resalian is a business messaging platform operated by Tech Serenity IT. It lets businesses send campaigns and hold conversations with their customers over the WhatsApp Business Platform, and — in future releases — over other Meta channels including Facebook and Instagram.
For questions about this policy, contact [email protected].
2. What we collect
Account and identity data
- Your name and email address
- A cryptographic hash of your password — we never store the password itself and cannot recover it
- Your workspace name and role (owner, admin or member)
- Session records, including the time a session was last active
Configuration you provide
- Your WhatsApp Business Account details and phone number IDs
- Access tokens for the Meta APIs, stored encrypted (see Security)
- API keys you create — stored only as a hash, shown in full once at creation
- Message templates, campaign settings, segment definitions and sending preferences
Usage and technical data
- Request logs including timestamps, endpoints called, response status and API key used, for security, debugging and rate limiting
- Counts of messages sent, delivered, read and failed, for reporting and billing
- Errors returned to us by Meta in the course of delivering your messages
What we do not collect
- We do not use third-party advertising or analytics trackers on our dashboard.
- We do not sell personal data to anyone, ever, in any form.
- We do not read your customer conversations except where strictly necessary to investigate a fault you have reported to us, or where we are legally compelled.
3. Why we use it
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing the service — sending your messages, running your campaigns | Account, configuration, message data | Performance of our contract with you |
| Authenticating you and keeping accounts secure | Credentials, session and request logs | Contract; our legitimate interest in preventing unauthorised access |
| Rate limiting and abuse prevention | API key usage counters, request logs | Legitimate interest in platform stability and in protecting other customers |
| Billing and account administration | Account details, message volume counts | Contract; legal obligation to keep financial records |
| Support you have asked for | Whatever is relevant to the issue reported | Contract; your consent where we need to look at message content |
| Complying with law and with Meta's platform requirements | As required | Legal obligation |
4. Your customers' data
When you upload a contact list or send a campaign, the personal data of your customers is processed by us on your behalf and on your instructions. You decide who is messaged and what they are told; we provide the mechanism.
You are responsible for:
- Having a lawful basis to message every person on your list, including valid opt-in where marketing rules require it
- Honouring opt-out requests — Resalian detects and applies replies such as STOP automatically, but the underlying obligation remains yours
- Giving your own customers the privacy information they are entitled to
- Not uploading special category data (health, religion, biometrics and similar) into contact attributes
Resalian offers settings that let you minimise or entirely avoid storing your customer list with us, including erasing recipient numbers as soon as a campaign finishes and keeping your list on your own servers. These are described in the Data Protection Rules.
5. Data obtained through Meta platforms
Resalian is a technology provider integrated with the WhatsApp Business Platform, and will extend to Facebook and Instagram. When you connect your Meta assets to Resalian, we obtain data through Meta's APIs — "Platform Data" under Meta's Platform Terms.
What we obtain
- Your WhatsApp Business Account ID and phone number IDs
- The display name, verification state and quality rating Meta reports for your number
- Your message templates and their approval status
- Access tokens you authorise, stored encrypted
- Message delivery receipts and inbound messages sent to your number
What we do with it — and what we never do
We use Platform Data solely to provide the service you have asked for: sending your messages, showing your conversations, and reporting on delivery.
- We do not sell, licence or rent Platform Data.
- We do not use it for advertising, ad targeting or audience building of our own.
- We do not use it to train machine learning or AI models.
- We do not combine or co-mingle it across customers. Every query is scoped to a single workspace, and per-workspace hashing means one customer's data cannot be correlated with another's.
- We do not transfer it to data brokers, or to any party outside the recipients listed in section 6.
Deletion and retention of Platform Data
We keep Platform Data only as long as needed to provide the service. When you disconnect a number, its access token is destroyed immediately. When you close your account or ask us to, Platform Data is deleted within 30 days. Full instructions, including how to revoke our access at Meta, are on the Data Deletion Instructions page.
Our handling of Platform Data is also governed by Meta's Platform Terms and Developer Policies. Where those impose a stricter obligation than this policy, the stricter obligation applies.
6. Who we share it with
We share personal data only with the following categories of recipient.
| Recipient | Purpose | What they receive |
|---|---|---|
| Meta Platforms (WhatsApp Business Platform) | Actually delivering your messages, and in future Facebook and Instagram campaigns | Recipient phone numbers and message content, as required to deliver them |
| Cloudflare, Inc. | Hosting, database, queueing and network security for the entire platform | All data processed by the service, as our infrastructure provider |
| Payment processor | Processing subscription payments, where online payment is used | Billing contact details and transaction data. We do not currently operate an online payment processor — billing is by direct invoice. If we introduce one, we will name it here and give notice before any data reaches it. Card details would in any case go directly to the processor and never be held by us. |
| Professional advisers and authorities | Legal, accounting or regulatory obligations | Only what is legally required |
If Tech Serenity IT is ever party to a merger, acquisition or sale of assets, personal data may transfer to the acquiring entity. We will tell you before that happens and before any change to how your data is handled.
7. Where data is stored, and cross-border transfers
Resalian runs on Cloudflare's global network. Application data is held in Cloudflare D1, and requests may be served from Cloudflare locations worldwide. We will confirm the current primary storage region for your workspace on request. Delivering a WhatsApp message necessarily transfers the recipient's number and message content to Meta, which operates internationally.
This means personal data processed through Resalian is transferred outside Oman. We say so plainly because it is unavoidable in a platform of this kind: there is no configuration in which WhatsApp messages are delivered without Meta receiving them, and no version of this service that runs only on infrastructure inside Oman.
Oman's Personal Data Protection Law (Royal Decree No. 6/2022) and its Executive Regulations impose conditions on transferring personal data outside the Sultanate. Where you are established in Oman and use Resalian to message customers, you are the controller making that transfer, and meeting those conditions — including obtaining any consent or approval required — is your obligation. We support you by:
- disclosing, in this policy and in the Data Protection Rules, exactly which parties receive data and for what;
- relying on the contractual safeguards our providers offer, including standard contractual clauses in our agreements with Cloudflare and Meta;
- offering storage modes that reduce or eliminate what we hold at all — including one in which your customer list never leaves your own systems.
If you are established outside Oman, your own local transfer rules apply instead of or in addition to Oman's, and the same disclosure is provided to help you meet them.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and workspace records | For as long as your account is open, then 90 days after closure |
| Message history and conversations | Until you delete it, or automatically on the retention schedule you configure — as short as one hour |
| Campaign recipient lists | Until you delete them, or erased automatically at the end of each campaign if you have chosen that setting |
| Opt-out records | Kept indefinitely as one-way hashes. We cannot honour an unsubscribe we have deleted, so these deliberately outlive everything else. |
| Request and security logs | 90 days |
| Billing and financial records | As required by Omani tax and commercial law, currently 10 years |
When a retention period expires, phone numbers and message content are irreversibly replaced with hashes or removed. Aggregate counts — how many messages were delivered in a month — survive, because they contain no personal data.
9. How we protect it
These are the specific measures in place, not a general assurance.
- Encryption in transit. All connections use HTTPS/TLS. Our API refuses plaintext.
- Encrypted credentials. WhatsApp access tokens are encrypted at rest with AES-256-GCM. The encryption key is held in a secret store, never in the database.
- Passwords. Stored as PBKDF2-SHA256 derivations with a per-user salt and 100,000 iterations. Comparisons are constant-time.
- API keys. Stored only as SHA-256 hashes. A leaked database does not yield working keys.
- Phone number hashing. Where numbers are reduced to hashes, we use a keyed HMAC rather than a plain digest — the space of phone numbers is small enough to brute-force otherwise, and the key never resides in the database.
- Webhook verification. Every inbound message from Meta is verified against an HMAC signature before we act on it.
- Environment separation. Test and live credentials are isolated; a key issued for testing cannot reach your production number.
- Rate limiting. Per-key request limits protect against runaway integrations and abuse.
- Least privilege. Access to production data by our staff is limited to what is necessary to operate and support the service.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to affected people, we will notify the relevant supervisory authority and affected customers without undue delay and within any statutory deadline.
10. Your rights
Under Oman's Personal Data Protection Law (Royal Decree No. 6/2022), and under any other data protection law applicable to you, you have the right to access your personal data; to have inaccurate data corrected; to request deletion; to restrict or object to certain processing; to receive your data in a portable format; and to withdraw consent where processing relies on it.
Exercise any of these by writing to [email protected]. We will respond within 30 days. We may ask you to verify your identity first — a request to hand over personal data is exactly the request an attacker would make.
If you are a customer of one of our users — that is, you
received a WhatsApp message sent through Resalian — we process your data on
that business's instructions and cannot action your request directly. Contact
the business that messaged you. If you cannot identify them, write to us and we
will forward your request to them. To stop receiving messages immediately,
reply STOP to the conversation; that is applied automatically and
permanently.
11. Cookies and local storage
We use the minimum required to make the dashboard work.
| Name | Type | Purpose | Duration |
|---|---|---|---|
rsess |
Cookie, httpOnly and secure | Keeps you signed in. Strictly necessary — the dashboard cannot function without it. | 30 days |
resalian.environment |
Local storage | Remembers whether you are viewing test or live data | Until cleared |
theme |
Local storage | Remembers your light or dark preference | Until cleared |
We set no advertising cookies and run no third-party analytics on the dashboard. Because every item above is strictly necessary or a stored preference you set yourself, no consent banner is required.
12. Children
Resalian is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child's data has reached us, write to [email protected] and we will delete it.
13. Changes to this policy
We will update this policy as the product changes — notably when Facebook and Instagram channels launch, which will extend the categories of data shared with Meta. Material changes will be notified by email and in the dashboard at least 30 days before they take effect. The date at the top always reflects the current version.
14. Contact and complaints
Tech Serenity IT
registered company name
registered address
Privacy: [email protected]
General: [email protected]
If you are unhappy with how we have handled your data, please raise it with us first — we would rather fix it. You also have the right to complain to the relevant data protection authority, which in Oman is the Ministry of Transport, Communications and Information Technology (MTCIT).