Privacy Policy — Ignitra Reach
Last updated: 19 July 2026
Ignitra Reach ("Ignitra Reach", "the Service", "we", "us", "our") is a WhatsApp business-messaging platform operated by Ignitra Labs. This Privacy Policy explains what personal data we collect, how we use it, the legal bases we rely on, and the rights available to you. It is written to meet the requirements of India's Digital Personal Data Protection Act, 2023 (DPDP Act) and Meta's WhatsApp Business Platform data policies.
1. Who we are
Ignitra Reach is a product of Ignitra Labs.
- Registered business name: Ignitra Labs
- Udyam Registration No.: UDYAM-GJ-05-0090811
- Registered address: LIG, Plot No. 16, Street No. 2, Shastri Nagar, Bhavnagar, Gujarat 364003, India
- Contact email: ignitralabs@gmail.com
- Grievance / Data Protection contact: Ignitra Labs (ignitralabs@gmail.com)
We act as a Data Fiduciary for the account information of our business customers, and as a Data Processor for the contact/recipient data that our business customers upload and message.
2. Who this policy covers
- Our customers— the businesses and their staff who sign up to use Ignitra Reach ("Tenant Users").
- Message recipients — the end customers of our business customers, whose phone numbers and message data are processed through the Service.
If you are a message recipient, the business that messaged you is the primary party responsible for how your data is used; Ignitra Reach processes that data on their instructions.
3. What data we collect
3.1 Account data (Tenant Users)
- Name, email address, and mobile number of the account owner and staff users.
- Business name and details provided at signup.
- Authentication data (passwords are stored only as salted, hashed values — never in plain text).
- Wallet and billing records. Payments are processed by our payment provider (Razorpay); we do not store your full card or bank details.
3.2 WhatsApp connection data
- Your WhatsApp Business Account (WABA) identifiers and phone number details, provided by Meta when you connect your number.
- Access tokens issued by Meta to operate your number. These are encrypted at rest (AES-256-GCM) and are never displayed or logged.
- Message templates synced from your WhatsApp account.
3.3 Recipient and messaging data
- Recipient phone numbers and the contents of the template messages you send.
- Message delivery status (sent, delivered, read, failed) reported by Meta.
- Records of opt-outs, which we enforce so opted-out recipients are not contacted again.
3.4 Technical data
- Log data such as IP address, timestamps, and request identifiers, used for security, fraud prevention, and debugging. We mask phone numbers in our logs.
We do not sell personal data, and we do not use the contents of your messages for advertising or profiling.
4. How and why we use your data
| Purpose | Data used | Legal basis (DPDP Act) |
|---|---|---|
| Provide the Service (send messages, show delivery status, manage your wallet) | Account, WhatsApp, messaging data | Performance of the service you requested |
| Bill you and maintain the credit ledger | Account, wallet/billing data | Performance of the service; legal record-keeping |
| Secure the platform, prevent fraud and abuse | Technical/log data | Legitimate use for security |
| Comply with Meta's WhatsApp Business Platform policies | WhatsApp, messaging data | Legal / contractual obligation |
| Support and communicate with you | Account data | Performance of the service |
Where the DPDP Act requires consent, we obtain it at the point of collection and you may withdraw it at any time (see Section 8).
5. Consent for messaging recipients
Our business customers are contractually requiredto obtain valid consent from their recipients before messaging them through Ignitra Reach, in line with the DPDP Act and WhatsApp's Business Messaging Policy. Ignitra Reach provides and enforces opt-out handling, but responsibility for lawful consent to message a recipient rests with the business customer sending the message.
6. How we share data
- Meta Platforms — to deliver your messages through the WhatsApp Business Cloud API, governed by Meta's own privacy policy.
- Razorpay — to process wallet top-up payments, governed by its own privacy policy.
- Infrastructure providers — hosting and database services, bound by confidentiality and data-protection terms.
- Legal/regulatory authorities — where required by law.
We do not share your data with third parties for their own marketing.
7. Data retention
- Account and billing records are retained while your account is active and for the period required by law and tax record-keeping.
- Messaging records and delivery status are retained for 12 months to support reconciliation, support, and dispute resolution, then deleted or anonymised.
- Encrypted Meta access tokens are deleted when you disconnect your number.
8. Your rights
Under the DPDP Act, you have the right to access, correct, and erase your personal data; to withdraw consent; to grievance redressal; and to nominate another person to exercise your rights. To exercise any right, contact us at ignitralabs@gmail.com. We respond within the timelines required by law, and you may escalate an unresolved complaint to the Data Protection Board of India.
9. Security
We protect your data with industry-standard measures, including encryption of sensitive credentials at rest (AES-256-GCM), encrypted transport (HTTPS), hashed passwords, tenant isolation, access controls, and audit logging. We will notify you and the relevant authority of a reportable data breach as required by law.
10. Children's data
Ignitra Reach is a business tool, not directed at children, and we do not knowingly collect children's personal data.
11. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date reflects the latest revision; material changes are communicated to account owners by email or in-app notice.
12. Contact us
Ignitra Labs — Ignitra Reach
ignitralabs@gmail.com
LIG, Plot No. 16, Street No. 2, Shastri Nagar, Bhavnagar, Gujarat 364003, India