Privacy Policy

Last updated: 21 July 2026

1. Introduction

This Privacy Policy explains how Filarity (“Filarity”, “we”, “us”, the “Platform”) collects, uses, shares and protects information when a business (“you”, the “Business”) uses our billing, inventory, GST-invoicing and customer-messaging software. This Policy applies to Business account data and to the customer data a Business enters, imports, or syncs into the Platform (for example, via Shopify). It is written for a business-to-business software product - our direct users are businesses, not individual consumers.

2. Roles: Who Controls the Data

Data-protection law (including GDPR and India’s Digital Personal Data Protection Act, 2023) distinguishes between a Data Controller (who decides why and how personal data is processed) and a Data Processor (who processes data on the Controller’s instructions).

  • The Business is the Data Controllerfor its own customers’ personal data (names, phone numbers, addresses, purchase history, and any data synced from the Business’s own Shopify or other connected store). The Business decides whose data to enter, what to message them about, and whether it has a lawful basis and consent to do so.
  • We are a Data Processor / Technology Service Providerwith respect to that customer data. We store it, run the software that generates invoices and reports, and - only where the Business actively enables it - relay the Business’s messages through WhatsApp Business Platform on the Business’s instructions. We do not decide who a Business messages or what a Business says to its customers, and we do not use Business customer data for our own purposes (see Section 4).
  • We are the Data Controller only for Business account data - the information about the Business itself as our direct customer (owner name, login email, subscription and billing records, support communications, and platform usage logs).

3. Information We Collect

3.1 Business Account Data (we are the Controller)

  • Business/owner name, login email, password (stored as a salted hash, never in plain text).
  • Subscription plan, trial status, and payment records for the Platform’s own fees.
  • Staff accounts created by the Business owner and their assigned permissions.
  • Support requests and correspondence with us.

3.2 Customer Data the Business Enters or Syncs (Business is the Controller)

  • Name - printed on invoices (“Bill To”) and used to personalize messages the Business chooses to send.
  • Phone number - saved to the Business’s customer book; used only to share invoices/receipts and, where the Business enables messaging, to send the messages the Business authors (Section 5).
  • Email address - collected only if the Business adds it, for invoice delivery or the Business’s own email campaigns sent from the Business’s own mailbox.
  • Address - printed on invoices for billing/shipping.
  • Order and transaction data - items purchased, amounts, GST, payment status, and purchase history, required to generate tax invoices and reports.
  • Supplier data - for Businesses using the purchasing module: supplier name, phone, GSTIN, and payables.

We do not use this customer data for advertising, profiling, or automated decision-making, and we do not sell it. It is used only to run the software the Business has configured.

3.3 Data From Connected Third-Party Platforms

Shopify.Where a Business connects its Shopify store, we access product, inventory, order, and order-customer data through Shopify’s Admin API solely to import the catalog, keep stock levels synchronized in both directions, and convert Shopify orders into GST invoices inside the Business’s account. Access tokens are encrypted at rest. Disconnecting the store immediately stops all further access, and no further Shopify data is read.

Amazon (where enabled).Where a Business connects an Amazon Seller account, we access order and inventory data through Amazon’s Selling Partner API for the same purpose - converting orders into invoices and keeping stock consistent - and for no other purpose. This integration is only activated for Businesses that explicitly connect it.

3.4 Automatically Collected Data

Standard technical logs (IP address, browser type, timestamps, pages visited) for security, fraud prevention, and diagnosing errors. We do not use third-party advertising trackers or cookies on this platform.

4. How We Use Information

  • To operate the software: generate invoices, track stock and purchases, run reports, and maintain the customer/supplier ledgers a Business configures.
  • To relay messages a Business composes and chooses to send, through the channel(s) the Business enables (Section 5).
  • To provide customer support to the Business.
  • To secure the Platform, prevent fraud and abuse, and enforce this Policy and our Terms of Service.
  • To maintain an internal activity log of changes made within a Business account, for the Business owner’s own audit purposes.
  • To improve the Platform in aggregate, non-identifying ways (e.g. which features are used) - never by reading or analysing the content of a Business’s customer messages.

5. WhatsApp Business Platform and Meta Platforms, Inc.

We use the WhatsApp Business Platform, provided by Meta Platforms, Inc. (“Meta”), as a technology enabler that lets a Business communicate with its own customers from its own WhatsApp number. In this relationship:

We do not initiate, send, or determine recipients of any messages. All messages are initiated solely by the Business using its own WhatsApp Business account.

  • We act only as a technology provider, not as the sender.Every message sent through the Platform is authored, initiated, and sent under the instruction of the Business, using the Business’s own WhatsApp number and (where applicable) the Business’s own connected Meta/WhatsApp Business Account. We do not decide, generate, or select who receives a message, and we do not send any message on our own initiative.
  • Two categories of messages are supported, and the Business is responsible for correctly categorising and formatting them per Meta’s policies:
    1. Transactional messages - invoices, payment confirmations, order/shipping updates sent to a specific customer about their own transaction.
    2. Marketing messages - offers and promotions, which Meta requires to be sent using pre-approved message templates and only to recipients who have opted in.
  • Data shared with Meta.To deliver a message, the recipient’s phone number and the message content composed by the Business are transmitted to Meta’s WhatsApp Business Platform for routing and delivery. Meta processes this data under its own Business Terms of Service, WhatsApp Business Messaging Policy, and Data Processing Terms for Platform Technology Providers, which govern how Meta handles data on our (and the Business’s) behalf.
  • Where a Business connects its own WhatsApp Business Accountto the Platform (via Meta’s Embedded Signup), the resulting access credentials are encrypted at rest and used exclusively to send the messages that Business initiates. Disconnecting immediately revokes our access.
  • Throughput limits. Bulk sends through the WhatsApp Business API are capped at a fixed daily volume per Business, enforced on our servers, to prevent spam-scale sending regardless of the limits Meta separately applies to a number based on its messaging tier and quality rating.
  • Quality-signal restrictions.We may restrict, pause, or disable a Business’s messaging capabilities based on complaint rates, recipient blocks or reports, high failure rates, or Meta quality-rating signals associated with the Business’s number.
  • Send logs. Every send attempt (sent, failed, or held back by a limit) is logged with its outcome, giving the Business - and us - an audit trail of messaging activity for abuse review.
  • For click-to-chat style messaging (opening the Business’s own WhatsApp app with a pre-filled message), no data passes through our servers to Meta at all - the message is composed on the Platform and sent directly from the Business’s own device and number.

We do not sell, rent, or use customer data for advertising, profiling, or marketing purposes of our own.

6. Consent and Opt-In Requirements

The Business must obtain explicit, verifiable, and auditable opt-in consent from each recipient before sending any marketing or non-transactional message via WhatsApp or any other messaging channel, and must provide a clear and functional opt-out mechanism in every applicable communication. Specifically, the Business must:

  1. Only message individuals who have provided their contact information for the purpose of receiving business communications (e.g. by purchasing, enquiring, or explicitly subscribing).
  2. For marketing messages, obtain clear opt-in consent before the first message and keep a record of how and when consent was obtained.
  3. Honour any opt-out or “STOP” request immediately and permanently.
  4. Never purchase, scrape, or otherwise use contact lists that were not obtained directly and lawfully by the Business.

Recipients must be able to withdraw consent at any time, and the Business must honour opt-out requests immediately.

6.1 What the Business must record

For every recipient, before any marketing message, the Business must record in the Platform: the date consent was given, the source (e.g. in-store, WhatsApp, website checkout, phone call), and the exact consent wording shown to or agreed by the customer. Every customer record starts as not opted in by default - including customers created automatically from billing, imports, or e-commerce sync. The Platform is designed to offer only recipients with a consent record as a messaging audience on any channel, and for messages delivered through our servers (the WhatsApp Business API), to re-verify the consent record and the absence of an opt-out server-side at send time.

6.2 Automated opt-out enforcement

Where a Business connects the WhatsApp Business API, inbound replies containing common opt-out keywords (such as “STOP”, “unsubscribe”, or “cancel”) are detected automatically by our systems and immediately mark that customer as opted out - independent of any action by the Business. That customer is automatically excluded from all future campaigns. Opt-out requests phrased in other languages or wordings may not be detected automatically; the Business remains obliged to honour any opt-out request received by any means, and can mark a customer as opted out manually at any time from the customer record.

6.3 We do not verify consent

We do not independently verify the truth, accuracy, or legal sufficiency of any consent record entered by a Business. The consent-recording feature is a tool to help the Business document consent it has already obtained - it is not proof of consent, and responsibility for lawfully obtaining that consent remains entirely with the Business, as Data Controller.

We do not permit, and will not knowingly facilitate, unsolicited messaging. Accounts found sending messages without consent will be actioned under Section 7 and our Terms of Service.

7. Anti-Spam and Prohibited Use

The following are strictly prohibited on the Platform, on any channel:

  • Sending unsolicited marketing messages to individuals who have not opted in.
  • Harassment, threats, hate speech, or abusive content directed at any recipient.
  • Messaging content that violates Meta’s WhatsApp Business Messaging Policy or Commerce Policy, including prohibited goods/services, deceptive claims, or illegal content.
  • Impersonation, phishing, or attempting to collect sensitive personal or financial information from recipients under false pretences.
  • Any use that would cause Meta, or any other integrated platform, to suspend or flag our platform-level access.

This is enforced with real, automated controls, not policy alone: a required consent record before any send, automated STOP/opt-out handling, and a daily send-volume cap, all described in Section 6. We additionally monitor for abuse signals (spam complaints relayed by Meta, unusual sending volume, high failure rates) and reserve the right to suspend messaging features or the account under Section 8 of our Terms of Service.

8. How We Share Information

We do not sell personal data. We share data only as follows:

  • Meta Platforms, Inc. - to deliver WhatsApp messages the Business initiates (Section 5).
  • Shopify, Inc. and Amazon - to sync catalog, inventory and orders, only for Businesses that connect those integrations.
  • Infrastructure sub-processors - our database provider and application hosting provider, who store and process data on our behalf under their own security commitments, strictly to run the Platform.
  • Legal requirements - where required to comply with a valid legal process, or to protect the rights, safety, or property of the Platform, our users, or the public.

9. Data Retention

  • Business and customer data is retained for as long as the Business account remains active.
  • A Business can export a full backup of its data at any time (Settings → Data → Download Backup).
  • A Business can permanently delete its account at any time (Settings → Data → Delete Account). This immediately and irreversibly erases all invoices, products, customers, suppliers, staff logins, activity logs, and connected-platform tokens. Nothing is retained after deletion, other than what we are legally required to keep (e.g. for tax or dispute-resolution purposes, retained only as long as legally necessary).
  • Message content sent via WhatsApp is retained by Meta according to Meta’s own data retention practices, independent of our Platform.

10. Data Security

  • All data in transit is encrypted (HTTPS/TLS).
  • The database is encrypted at rest, with encrypted backups.
  • Third-party access tokens (Shopify, Amazon, WhatsApp) are additionally encrypted at the application level before storage.
  • Passwords are hashed with bcrypt; never stored or logged in plain text.
  • Access within a Business account is role-based - staff see only what the owner permits.
  • Changes to business-critical data are recorded in an activity log for the owner’s review.

11. Your Rights and Choices

A Business, and - through the Business - its customers, may exercise the following rights over personal data we hold as a processor:

  • Access - request a copy of the data held.
  • Correction - update inaccurate data (directly editable within the Platform for most fields).
  • Deletion - delete specific customer/supplier records, or the entire account, at any time.
  • Portability - export data as a spreadsheet at any time.
  • Objection/Opt-out - a customer of a Business who wishes to stop receiving messages should contact that Business directly (as the Data Controller); we will assist a Business in honouring such requests promptly.

Requests relating to Business account data directly (rather than a Business’s own customers) can be sent to the contact in Section 15.

12. Cross-Border Data Transfer

Our infrastructure providers may process and store data in data centres located outside your country, including outside India. Where this occurs, we require our infrastructure and platform sub-processors to maintain security and confidentiality protections consistent with this Policy.

13. Children’s Data

The Platform is intended for use by businesses and is not directed at children. We do not knowingly collect personal data about children through the Platform.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date above. Continued use of the Platform after an update constitutes acceptance of the revised Policy.

15. Grievance Officer / Contact

For privacy questions, data requests, or grievances relating to this Policy, contact Filarity’s Grievance Officer at: melbinkuriakos@gmail.com. We aim to acknowledge grievances within 48 hours and resolve them within 30 days. See also our Terms of Service.