Privacy Policy

Last updated: 2026-09-28

Solina ("we", "us") operates Solina CRM – a business CRM with lead management, a dialer, and sending and receiving WhatsApp, SMS and email messages. This policy explains what data we process, why, who we share it with, how long we keep it and how to delete it.

Address: 4 Ema Tauber, Herzliya 4631704, Israel

1. Roles

Businesses that use the service ("Business Customers") decide which data about their own customers is stored and why – they are the controllers of that data. We process it on their behalf and only on their instructions. For the account data of the people who use the service itself (name, email, phone) we are the controller.

2. Data we process

  • Account data: name, email, phone, role and permissions, and a hashed password.
  • Contacts and leads the business adds or that come from inquiries: name, phone, email, source, status, notes, tasks and deals.
  • Communications: content and metadata of WhatsApp, SMS and email messages sent and received, and phone-call details (time, duration, outcome, and a recording – only if the business enabled recording).
  • Consent and opt-outs: marketing consent status and unsubscribe requests, so they are honoured on every channel.
  • Technical data: access and security logs, an audit trail of actions, and the IP address at sign-in.

3. Data from Meta and the WhatsApp Business Platform

When a business connects WhatsApp through Meta's Embedded Signup, we receive and store:

  • The WhatsApp Business Account (WABA) and business phone-number identifiers, display name, quality rating and messaging limit.
  • A business access token – encrypted at rest (AES-256-GCM) and used only for actions the business requested.
  • Message templates the business created and their approval status at Meta.
  • Inbound and outbound messages, delivery/read statuses and account updates that Meta sends to our webhook.

We use this data only to let the business send and receive messages, manage its templates and phone numbers, and show its conversations – that is, the whatsapp_business_messaging and whatsapp_business_management permissions. We do not sell data obtained from Meta, do not use it for advertising or profiling, and do not transfer it to third parties other than the service providers in section 5 for operating the service.

4. How we use data

  • To provide the service: lead management, dialing, sending and receiving messages, reports and automations the business configured.
  • Security, abuse prevention and enforcing consent and opt-outs.
  • Support and operations. AI features (if the business enabled them) process only data the user may see and are not used to train models.

5. Sharing with service providers

  • Meta Platforms (WhatsApp Business Platform / Cloud API) – sending and receiving WhatsApp messages.
  • Telnyx – phone calls and SMS. Resend – email.
  • Vercel – hosting. Neon – database (PostgreSQL). Anthropic – AI features, only if enabled.

We disclose data to authorities only when required by law.

6. Retention

Data is kept while the business account is active. The business can set shorter retention for messages and logs. After a deletion request, data is deleted within 30 days (see section 8). Backups are purged in their normal cycle.

7. Security

Encrypted transport (TLS), tokens and secrets encrypted at rest, database-level isolation between businesses (Row-Level Security), role-based permissions and an audit trail.

8. Data deletion

  • Business owner: Settings → Account → "Delete business and all data". The WhatsApp connection is disconnected and tokens are erased immediately; everything else is permanently deleted after 14 days (cancellable until then).
  • Any user: Settings → Account → "Delete my user" – personal details are erased; the business's records remain without identifying you.
  • Removing the app from Facebook disconnects it and erases its token. A separate Facebook data deletion request also erases connection identifiers and linked signup records. Confirmation receipts are retained for up to 90 days with a fingerprint instead of the original user identifier.
  • Customers of a business that uses the service should contact that business; we help it fulfil the request.

Details and request status: Data Deletion.

9. Your rights

You may request access to, correction, deletion or restriction of your data. Contact: contact@solina.co.il.

10. Children

The service is for businesses and is not directed to children under 16.

11. Changes and contact

Any change to this policy will be published here. Questions: contact@solina.co.il.