Google Play Data Safety & Deletion Policy
Verified Policy ComplianceMessegy adheres strictly to Google Play Developer Policies and global privacy regulations (GDPR, CCPA, IT Act). This page outlines how users can delete their accounts, what data is permanently erased, what data is retained for legal/tax compliance, and the exact retention timelines.
1. Overview & Your Privacy Rights
At Messegy, we respect your data ownership and privacy. If you choose to discontinue using Messegy, you have the right to request the complete deletion of your account and associated personal and business data. Whether you use our Web Dashboard or our Mobile App, you can initiate account deletion through automated self-service or by submitting a manual request to our support team.
2. How to Request Account Deletion
We offer two convenient ways to request account and data deletion:
Instant In-App Deletion
- Log in to your Messegy Account on the Web Dashboard or Mobile App.
- Go to Settings > Account & Security.
- Scroll down to the Danger Zone section.
- Click on "Delete Account".
- Confirm your deletion request with your account password or OTP.
⚡ Account access is revoked immediately upon confirmation.
Support Assisted Request
If you are unable to access your account, send an email to our dedicated data support team:
⏱️ Manual requests are verified and processed within 7 to 14 business days.
3. Data Permanently Deleted Upon Request
When your account deletion is processed, the following data is permanently purged from our active databases and servers and cannot be recovered:
User Profile & Account Info
Full name, login email address, hashed passwords, profile photo, phone number, and user settings.
Messages & Campaign Logs
WhatsApp conversation logs, broadcast campaign history, template drafts, auto-replies, and media attachments.
Contacts & Customer Databases
Uploaded phone books, customer lists, tags, custom attributes, and audience segmentation data.
API Keys & Integrations
Generated API tokens, webhook subscriptions, connected e-commerce credentials (Shopify/WooCommerce), and OAuth tokens.
4. Data Retained & Retention Timelines
In strict compliance with statutory regulations, financial compliance mandates, and platform security standards, certain limited records are retained for specified periods before final disposal:
What is retained: Invoices, payment transaction receipts, subscription billing logs, tax registration numbers (GST/VAT), and billing addresses.
Purpose & Statutory Basis: Required by applicable tax laws, corporate accounting standards, financial audits, and anti-money laundering regulations. Note: Messegy never stores credit card details directly; payments are processed securely via PCI-DSS compliant gateways.
What is retained: Anonymized server access logs, IP addresses linked to critical security events, rate-limiting counters, and security anomaly records.
Purpose & Operational Basis: Essential for preventing platform abuse, protecting system infrastructure, mitigating cybersecurity attacks, and investigating suspicious activities.
What is retained: Communication logs or account details subject to ongoing legal disputes, law enforcement inquiries, or court subpoenas.
Purpose & Legal Basis: Maintained solely to fulfill valid legal proceedings, statutory compliance mandates, or judicial orders.
5. Data Handling & Retention Summary Table
Quick overview of data categories, handling status, retention timelines, and legal/business justifications:
| Data Category | Handling Status | Retention Window | Purpose / Basis |
|---|---|---|---|
| Profile & User Credentials | Permanently Deleted | Purged within 7–14 days | Account cancellation |
| Messages, Broadcasts & Media | Permanently Deleted | Purged within 7–14 days | User privacy protection |
| Contact Lists & Audiences | Permanently Deleted | Purged within 7–14 days | User data ownership |
| API Keys & Webhooks | Revoked & Purged | Immediate to 7 days | Security & access revocation |
| Billing & Tax Invoices | Retained | 7 Years | Statutory tax & accounting laws |
| Security & Server Audit Logs | Retained (Anonymized) | 90 to 180 Days | Fraud prevention & system safety |
| Disaster Recovery Snapshots | Overwritten | Up to 30 Days | Automated rolling backup cycle |
6. Account Deletion Lifecycle & Timeline
When an account deletion request is submitted, data flows through the following structured lifecycle:
Immediate (Day 0)
- Account login disabled
- Active sessions terminated
- API keys & webhooks deactivated
- WhatsApp API triggers paused
Days 1 to 14
- Primary DB records purged
- Message logs & media deleted
- Uploaded contact lists erased
- Team access revoked
Up to 30 Days
- Encrypted backup rotation cycles
- Snapshot data overwritten
- Full deletion cycle completed
7. Revoking Third-Party & Meta Access
Messegy integrates with Meta (WhatsApp Business Cloud API). Upon account deletion, Messegy automatically revokes system tokens. However, you can also manually disconnect Messegy from your Meta Business Manager:
- Go to Meta Business Suite / Business Manager.
- Navigate to Business Settings > System Users or Connected Apps.
- Find Messegy and click Remove / Revoke Access.
Have Questions About Account Deletion?
Our Privacy & Data Security Team is here to help. Contact us if you have any questions regarding your data safety, privacy rights, or deletion request status.