← RightCurve WhatsApp for Frappe CRM
Privacy policy — RightCurve WhatsApp for Frappe CRM
RIGHTCURVE LLP, Singapore · Effective 17 September 2026
This notice describes the RightCurve WhatsApp for Frappe CRM pilot. The service has been tested with local stand-ins, but has not yet processed a live client's Meta or Frappe data. We will review this notice against the live setup before accepting client connections.
1. Who we are
RIGHTCURVE LLP ("RightCurve", "we") is a Singapore limited liability partnership developing a connection between a client's WhatsApp Business account and its Frappe CRM site. The client decides how it uses conversations with its customers. RightCurve handles the connection and relays messages on the client's behalf.
2. Data we process, and why
- Client administrator details — organisation name and administrator email entered on the onboarding page. Purpose: identify the client and its connection.
- Meta assets and grant — the Meta business id and name, WhatsApp Business Account (WABA) id and name, phone number id, display phone number, verified name and quality rating that the client authorised through Meta Embedded Signup, and the access token Meta issues for that grant. Purpose: verify what was authorised, configure the client's Frappe CRM, and act on the client's behalf towards Meta. The token is stored only in encrypted form and is never shown to the client, written to the client's Frappe site, or written to logs.
- Frappe connection — the client's Frappe site URL and the name of the WhatsApp account record created there. The Frappe API key/secret the client supplies is used once to write that configuration and is not stored.
- Message events in transit — WhatsApp messages and delivery statuses sent by Meta to RightCurve are checked and forwarded to the client's Frappe site. The pilot database stores event identifiers and delivery status for duplicate detection, not message bodies. Operational logs may contain account identifiers, errors and connection activity.
- Outbound requests — messages and template operations the client's Frappe site sends through the RightCurve proxy are forwarded to Meta and not stored.
3. Legal basis and sharing
We use this data to provide and support the connection requested by the client. The service communicates with Meta's WhatsApp Business Platform and the client's Frappe CRM site. Hosting and infrastructure providers may process data needed to run the service. We do not sell message data or use it for advertising.
4. Retention and deletion
Grant and connection records are needed while a connection is active. Revoking a grant in RightCurve stops the pilot from using it, but does not itself erase the stored record. An operator can remove a client's records after verifying a deletion request. Event identifiers and operational logs also need a retention process before live use; no automatic deletion period is in place yet. We will retain personal data only while it is needed for a business or legal purpose and establish the operating schedule before accepting live clients. See data deletion instructions.
5. Security
The pilot encrypts Meta grant tokens at rest and stores client proxy keys as salted hashes. It checks Meta's signature on incoming webhooks. The planned live service requires HTTPS and restricted operator access; those deployment controls have not yet been verified.
6. Your rights and contact
For questions or requests about RightCurve's records, email rightcurve.sg@gmail.com. Include enough information for us to identify the connection, but do not send passwords or access tokens. Customers seeking access to or correction of messages held in a business's Frappe CRM should contact that business. We will verify requests and respond in line with applicable Singapore data protection requirements.
7. Changes
We will post changes to this page and update the effective date.