Whisper360

Privacy Policy

Effective 19 August 2026 · Updated 30 September 2026

Whisper360 ("Whisper360", "we", "us") is a customer-operations platform: a shared team inbox, CRM, AI assistance and voice tools for businesses, available at whisper360.io, operated by Whispa Konnect Ltd (RC 1846500), a company registered in Nigeria with its place of business in Lagos. This policy explains what information we collect, how we use it, and the choices you have. It applies to the whisper360.io website and the Whisper360 application.

The two kinds of data we handle

Account and workspace data — information about you and your business: your name, email address, sign-in credentials, workspace profile (business name, industry, region, what you sell), team members you invite, and the channels you connect. For this data, Whispa Konnect Ltd, trading as Whisper360, is the data controller.

Customer conversation data — messages, attachments, contact details and call recordings that flow through the channels a workspace connects (WhatsApp, email mailboxes, Facebook Messenger, Instagram, website chat and calls, and phone). This data belongs to the workspace that connected the channel; Whisper360 processes it on that workspace's behalf and on its instructions. If you are a customer of a business that uses Whisper360, contact that business about your data — Whispa Konnect Ltd, trading as Whisper360, acts as their processor.

What we collect

When you create an account: your name, email address, and a password (stored only as a salted hash) — or, if you sign up with Google, the identity Google shares with us (see the Google section below). Your workspace setup answers (business name, industry, region, offerings) are stored to configure your workspace and to ground AI features in your business context.

When you use the product: the conversations, contacts, notes, tickets and settings your team creates or imports; technical logs (IP address, browser type, timestamps, error reports) kept for security and reliability; and a session cookie that keeps you signed in. The public website also loads Google Tag Manager for measurement tags.

When a workspace connects a channel: the credentials or tokens needed to operate that channel (encrypted at rest), and the messages that channel delivers to or sends from the workspace.

Google user data

Sign in with Google: if you create your account with Google, we receive your name, email address and basic profile from Google to create and authenticate your Whisper360 account. We do not receive or store your Google password.

Gmail mailboxes: connecting Gmail is separate from signing in to Whisper360. When you choose Connect with Google, Google asks you to authorise mailbox access. Whisper360 stores an encrypted authorisation token, not your Google password. It reads email addresses, sender and recipient details, subjects, message bodies, thread headers and attachments to display incoming email in your workspace, preserve reply context and send replies from the connected mailbox. The current sync checks unread inbox messages from the connection date; it does not import your entire mailbox history. Synced messages and attachments are stored in the workspace and are available to members according to their access permissions. The Gmail API connection uses the gmail.modify permission to receive mail, send replies and mark successfully imported messages as read. Older mail-protocol connections use the https://mail.google.com/ permission until reconnected with the narrower permission. Whisper360 does not offer permanent deletion of messages from Gmail.

Whisper360's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain words: we do not use Google user data for advertising; we do not sell it; we do not use Gmail data to develop, improve or train generalised AI or machine-learning models; and no human at Whisper360 reads it except with the workspace's permission, when required for security or abuse investigation, to comply with law, or as part of aggregated, anonymised internal operations.

You can disconnect a Gmail mailbox at any time from Settings → Channels, and you can revoke Whisper360's access from your Google Account at myaccount.google.com/permissions. Disconnecting stops all further access; synced copies inside the workspace inbox can be deleted by the workspace.

How we use information

To run the service: delivering and routing conversations, enforcing roles and permissions, measuring response times against the service levels a workspace configures, and keeping the platform secure and reliable.

AI features: when a workspace enables them, AI features draft replies, summarise conversations or answer questions using the workspace's conversations and knowledge, which can include connected Gmail messages. Relevant content is sent to the AI model provider configured for the workspace to produce the requested response. Depending on the workspace's configuration, a reply may require team review or may be sent by an enabled automated agent. Google mailbox data must not be used to develop, improve or train generalised AI or machine-learning models.

We do not sell personal information, and we do not use the content of your conversations for advertising.

Who we share data with

Subprocessors that host and power the service: cloud infrastructure (DigitalOcean), web hosting and CDN (Vercel), transactional email delivery (Resend), real-time calls (LiveKit), and — only when the corresponding feature is used — messaging platforms (Meta for WhatsApp, Messenger and Instagram; Google for sign-in and Gmail; Microsoft for Outlook) and AI model providers (such as Anthropic or OpenAI, or a provider key the workspace brings itself).

We share data with authorities only when legally required, and we will tell the affected workspace unless the law prevents it. If Whisper360 is ever part of a merger or acquisition, this policy continues to apply to previously collected data.

Retention and deletion

Account and workspace data is kept while the workspace is active. Conversation data is kept for the workspace until the workspace deletes it or disconnects the channel and asks for its removal.

When an account or workspace is closed, or when you email us a deletion request, we delete the associated personal data within 30 days, after which it also ages out of encrypted backups. Some minimal records (for example invoices, where they exist) may be retained where the law requires it.

Security

All traffic is encrypted in transit (TLS). Channel credentials and tokens are encrypted at rest. Every workspace's data is isolated from other workspaces at the database layer, access inside the team is governed by roles, and passwords are stored only as salted hashes. No internet service can promise perfect security, but if we learn of a breach affecting your data we will notify you without undue delay.

Your rights

You can access and update your account and workspace data in Settings, and you can ask us — at the email below — to export or delete your personal data, or to answer any question about this policy. Depending on where you live, you may have statutory rights to access, correct, delete, or object to processing of your personal data; we honour such requests regardless of where you are.

If you are an end customer of a business using Whisper360, direct requests to that business; we support them in fulfilling it.

Children

Whisper360 is a business tool and is not directed at children under 16. We do not knowingly collect personal data from children.

Changes and contact

We will post any changes to this policy on this page and, for material changes, notify workspaces in the product or by email. Questions and requests: hello@whispakonnect.com.