Privacy Policy

Privacy Policy

Effective date: 24 August 2026
Last updated: 24 August 2026

1. Who we are

This Privacy Policy is issued by Teajar ("Teajar", "we", "us", "our"), the company behind the Teajar business management platform and the products described below.

 

 

Company

Teajar

Website

https://teajar.io

Address

3915 Lone Pine Rd, Apt 303, West Bloomfield, Michigan 48323, United States

Email

[email protected]

Phone

+972 56-929-6501

We are committed to protecting personal information. This policy explains what we collect, why, who we share it with, how long we keep it, and how you can have it erased.

2. What Teajar is, and what this policy covers

Teajar is a business management platform. Businesses use it to run their day-to-day operations: accounting and financial records, customers and suppliers, invoicing, documents, and team collaboration. Customer messaging is one part of that platform — not the whole of it.

This policy applies to all of the following, together the "Services":

  • The Siteteajar.io and its subdomains: marketing pages, contact and demo-request forms, and account sign-up.

  • The Platform — the Teajar business management and accounting application that registered customers sign in to use.

  • Teajar Phone Portal — a module of the Platform. It is a shared team inbox that lets a business's authorized staff receive and answer customer messages in one place instead of on a personal phone. Messaging channels are pluggable; today the Portal connects to the WhatsApp Business Platform operated by Meta Platforms, Inc. ("Meta"), and it also handles messages, notes, and tasks that never leave Teajar. It is registered on the Meta Developer Platform under App ID 1041746678800834.

Where a section applies to only one of these, it says so. By using the Services you agree to this policy. If you do not agree, please do not use them.

3. The two roles we act in

Your rights, and our obligations, depend on which of these applies.

a) Teajar as controller. When you visit the Site, request a demo, create a Teajar account, or contact our support team, Teajar decides why and how your data is processed. We are the controller of that data.

b) Teajar as processor, on behalf of a business. When a business subscribes to Teajar and uses the Platform — including Teajar Phone Portal — to serve its own customers, that business is the controller of the data it puts into, or receives through, Teajar. Teajar processes that data only on that business's documented instructions, to provide the Services to it. This includes messages exchanged between that business and its customers.

If you are an end customer who messaged a business through a WhatsApp number that business connected to Teajar, the business you contacted is your first point of contact for privacy requests. We will always help, and we will act on any valid request we can verify — see section 12.

4. Information we collect

 

4.1 Site visitors

  • Contact details you submit — name, email address, phone number, company name, and anything you write in a contact or demo-request form.

  • Usage data — IP address, browser type, operating system, pages visited, referring page, and diagnostic data.

  • Cookies and similar technologies — see section 10.

 

4.2 Platform users (our business customers and their staff)

  • Account details — name, email address, phone number, company name, role, and login credentials. Where a user signs in with Google, we receive the name and email address associated with that Google account and nothing else.

  • Business data you enter — the accounting entries, customer and supplier records, invoices, documents, and figures you or your team add in the course of using the Platform.

  • Service data — sign-in history, activity and audit logs, device and session information, and support correspondence. We use these to secure accounts and to help you when you contact us.

  • Session data — an encrypted, HTTP-only session cookie issued after sign-in.

 

4.3 Teajar Phone Portal — end customers who message a business

When a person messages a business's connected WhatsApp business number, the Portal receives and stores, on that business's behalf:

  • The sender's WhatsApp identifier and phone number, and the WhatsApp profile name if one is set.

  • Message content — the text of messages exchanged with that business number.

  • Attached media — images, documents, audio, video, and other files sent in either direction.

  • Message metadata — timestamps, direction (inbound or outbound), delivery and read status, and the WhatsApp message identifier.

  • Operational data added by the business's staff — internal notes, tags, conversation status, and assignment to a team member. Internal notes are visible only to that business's staff and are never sent to the customer.

We do not collect any data from a person's WhatsApp account beyond what that person sends to the business, plus the profile name and phone number WhatsApp supplies with the message.

4.4 Channel connection data

When a business connects a messaging channel, we store the credentials and identifiers needed to operate it — for WhatsApp, the WhatsApp Business Account ID, phone number ID, and access token. Tokens are encrypted at rest and are used only to send and receive that business's messages.

5. How we use information

We use information to:

  • Provide, operate, secure, and maintain the Services.

  • Create and manage accounts, authenticate users, and enforce role-based access.

  • Deliver the accounting, records, invoicing, and collaboration features a customer subscribes to.

  • Receive, route, read, and answer customer messages in the Portal, and keep a conversation history so any authorized colleague can continue a request without the customer having to repeat themselves.

  • Respond to enquiries, support requests, and correspondence.

  • Detect, prevent, and investigate fraud, abuse, and security incidents, and meet legal obligations.

  • Understand aggregate usage in order to improve and troubleshoot the Services.

  • Send marketing communications about Teajar, where you have opted in and only until you opt out.

We do not sell personal data. We do not use message content or contact data for advertising, ad targeting, profiling, credit scoring, or training generalized artificial-intelligence models. We do not use one customer's data for the benefit of another customer.

6. Legal bases for processing

Where the GDPR or a comparable law applies, we rely on:

  • Contract — to provide the Services you or your employer signed up for.

  • Legitimate interests — to secure the Services, prevent abuse, and improve them, balanced against your rights.

  • Consent — for optional cookies and marketing email. You may withdraw consent at any time.

  • Legal obligation — to keep tax, accounting, and other records the law requires.

Where Teajar acts as a processor (section 3b), the legal basis is determined by the business that is the controller.

7. Teajar Phone Portal and the WhatsApp Business Platform

Message delivery for the WhatsApp channel is provided by Meta through the official WhatsApp Business Cloud API. Teajar receives message data from Meta solely in order to operate the Portal for the business that connected the number.

Teajar's use and transfer of information received from Meta APIs adheres to the Meta Platform Terms, the WhatsApp Business Messaging Policy, and the WhatsApp Business Solution Terms. In particular:

  • We access only the data necessary to operate the Portal for the connected business.

  • We do not sell, license, or transfer Platform Data to any third party for that third party's own purposes, and we do not use it for advertising or to build user profiles.

  • We do not combine Platform Data with data from other sources for any purpose other than providing the Service to the connected business.

  • We keep Platform Data only as long as needed for that purpose, and delete it on request.

Your use of WhatsApp itself is separately governed by Meta's terms and the WhatsApp Privacy Policy. Data held by Meta on its own systems, including the copy of a conversation in your own WhatsApp app, is outside our control.

Teajar is not affiliated with, endorsed by, or sponsored by Meta. WhatsApp and Meta are trademarks of Meta Platforms, Inc.

8. Sharing your information

We do not sell personal data and we do not share it except as follows:

  • Sub-processors — vetted vendors who process data only on our instructions and only to deliver the Services: cloud hosting and server infrastructure, managed database and object storage, error monitoring, and transactional email. They are bound by written confidentiality and data-protection terms.

  • Meta — as the operator of the WhatsApp Business Platform through which WhatsApp messages are delivered.

  • The controller business — where we act as a processor, the business whose account the data belongs to.

  • Legal compliance — where required by law, or in response to a valid request from a court, regulator, or public authority. We assess every such request and disclose only what is legally required.

  • Business transfers — in a merger, acquisition, or asset sale, data may transfer as part of the transaction. We will notify you before your data becomes subject to a different privacy policy.

A current list of sub-processors is available on request from [email protected].

9. How we protect your information

We apply technical and organizational measures appropriate to the risk:

  • All traffic is served over encrypted connections (HTTPS/TLS).

  • Access is restricted to authenticated users and scoped by role; each business's data is isolated from every other business's data and every query is scoped to the account it belongs to.

  • Credentials and channel access tokens are encrypted at rest.

  • Data is held in an access-controlled database, and media in access-controlled object storage; neither is publicly reachable.

  • Administrative access is limited to the minimum number of staff who need it, and is logged.

  • We take regular backups and have a documented restore procedure.

No method of transmission or storage is completely secure. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant authority as the law requires.

10. Cookies and similar technologies

The Site uses cookies to keep you signed in, remember preferences, measure aggregate traffic, and improve content. You can configure your browser to refuse cookies or alert you when one is set; some features may then not work.

The Platform and the Portal use a strictly necessary, encrypted, HTTP-only session cookie for authentication. It is not used for tracking or advertising.

11. Data retention

We keep personal data only as long as it is needed for the purposes in this policy:

  • Account data — for as long as the account is active, and after closure only where the law requires us to retain it.

  • Business and accounting records — for the retention period the applicable tax and commercial law requires.

  • Conversation history, including WhatsApp messages and media — for as long as the controlling business needs it for customer service and reasonable business records, or until deletion is requested.

  • Logs and usage data — for a limited period needed for security and troubleshooting.

  • Marketing contacts — until you unsubscribe.

When data is no longer needed, or on a valid deletion request, it is permanently erased from our live systems, and from backups on the normal backup-rotation cycle.

12. Data deletion

You may ask us to erase your personal data at any time, whichever Teajar service you used. There is no charge, and we will not ask for more information than we need to find your records.

Full step-by-step instructions are on our Data Deletion page.

In short: email [email protected] with the subject "Data deletion request", and tell us which of these applies.

  • A Teajar account — email us from the registered address. We close the account and erase the personal data associated with it, except records the law requires us to keep.

  • A website enquiry or mailing list — email us from the address you used to contact us.

  • WhatsApp or other messages you sent to a business using Teajar — email us from, or quoting, the phone number you messaged from. The contact record is permanently deleted together with all associated messages, media, internal notes, tags, and conversation history. Where the data belongs to one of our business customers, we forward the request to that business and act on its instruction, and in any case within the deadline below.

Deletion is irreversible. We confirm it to you in writing, normally within 30 days.

Deletion removes data from Teajar's systems. Data held by Meta on WhatsApp's own systems is governed by Meta's policies and is outside our control.

13. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you, and know how it is used.

  • Have inaccurate data corrected.

  • Have your data erased.

  • Object to or restrict processing.

  • Withdraw consent where processing is based on consent, without affecting prior processing.

  • Receive a copy of your data in a portable, machine-readable format.

  • Not be subject to a decision based solely on automated processing that significantly affects you. We do not make such decisions.

  • Lodge a complaint with your data protection authority.

Email [email protected] to exercise any of these. We respond within 30 days. We do not discriminate against anyone for exercising their privacy rights.

14. Children's privacy

The Services are business tools and are not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, email [email protected] and we will delete it.

15. International data transfers

Teajar operates internationally, and information may be processed in countries other than your own, including the United States. Where data is transferred out of the EEA, the UK, or another region with transfer restrictions, we rely on an appropriate safeguard such as the European Commission's Standard Contractual Clauses, and we take steps to ensure the data remains protected consistently with this policy.

16. Links to other sites

The Services may link to sites Teajar does not operate. We are not responsible for their privacy practices, and we recommend you read the privacy policy of any site you visit.

17. Changes to this policy

We may update this policy from time to time. Changes are posted on this page with a new effective date and take effect when posted. If a change is material, we will give notice through the Services or by email before it takes effect. Please review this page periodically.

18. Contact us

Questions about this policy or our data practices:

Teajar
3915 Lone Pine Rd, Apt 303, West Bloomfield, Michigan 48323, United States
Email: [email protected]
Phone: +972 56-929-6501
Web: https://teajar.io

Related pages: Terms and Conditions · Data Deletion · العربية