Legal
Privacy policy
Coocall · phone, WhatsApp, leads, and billing
This notice explains how Code24x7 Private Limited (“we”) handles personal information on this website and in the Coocall workspace. It is separate from the terms of use. It covers the business that opens an account, people invited into that workspace, people who request a demo call, and people that business calls or messages.
Coocall is provided by Code24x7 Private Limited, CIN U72900BR2021PTC050449, GSTIN 10AAJCC2786R1Z6. Registered office: House No-6, M/S Code24x7 Private Limited, Near Baji Pul, Banjaria, Sundarpur, Sakra, Muzaffarpur, Bihar, 843102, India. These pages were last updated on 28 September 2026. Questions go to support@coocall.ai.
Our role
For account, login, billing, and demo-call data, we decide why the data is used. Under the Digital Personal Data Protection Act, 2023, that makes us the Data Fiduciary for that data.
For your customers’ call audio, transcripts, WhatsApp messages, and leads, you decide why the data is collected. We process it on your instructions to run the workspace. You are the Data Fiduciary for that customer data, and we are the Data Processor. You must have a lawful reason to contact them, tell them what you will do with the call or message, and honour their choices.
The operational duties of that Act commence in phases. Until they are fully in force, we also follow the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, where those rules still apply to this service.
What we collect, and why
- Account. Name, email, a bcrypt hash of the password, optional authenticator secret and hashed backup codes, workspace name, and the role of each person you invite. Used to create the workspace, sign people in, and limit what each role can see.
- Google sign-in. If you choose it, we receive the name and email Google shares for the openid, email, and profile scopes. Used only to sign you in.
- Cookies. A sign-in cookie on this site, and a short-lived cookie while Google sign-in finishes. We do not set advertising cookies and we do not sell cookie data.
- Demo call. The phone number you type on the public site, and the recording and transcript of that call if the call connects. Used only to place the demonstration you asked for.
- Phone calls you run. Numbers, time, outcome, the job brief and script you wrote, the transcript, and the recording. Used to place or answer the call, show it in the workspace, and count connected talk-time against the plan.
- Calling preferences. Numbers you mark Do Not Call, and inbound follow-up memory until you remove it in Settings. Used so later dials skip a blocked number and so an inbound caller can be recognised until you clear that memory.
- WhatsApp. The business token Meta issues for Embedded Signup, stored encrypted; message content and media; customer phone numbers and profile names; contacts you import or that sync from the WhatsApp Business app; templates and Meta’s status, quality, and category updates; quality, display name, and messaging-limit events; and marketing opt-out or opt-in choices, including STOP. Used to show the inbox, send messages you or your automations request, honour opt-outs, and show usage.
- Leads. Fields you type, upload, or receive from a webhook, and, if you connect Meta Lead Ads, the form answers Meta sends, which can include a name, phone number, and email. Used to store the lead and to call or message them when you ask.
- Billing. Plan, usage, payment status, and any GSTIN and billing address you save. Razorpay collects the card, UPI, or net-banking details. We do not store the full card number or UPI handle.
- Support. The message you send us and the workspace email it relates to. Used to answer that request.
WhatsApp and Meta
You connect WhatsApp through Meta’s Embedded Signup. You remain the owner of the WhatsApp account. Meta bills WhatsApp conversation charges to the payment method on your Meta account. We keep the business token only so we can act on that account until you disconnect.
Message content and media are stored so your team can read the thread and so automations you turn on can run. Media stays in a private store and is not published on this website. We do not sell WhatsApp conversations. We do not use them to advertise to those people for ourselves, and we do not use your customers’ calls or WhatsApp threads to train a model that we offer to other businesses.
Disconnecting WhatsApp in the workspace deletes our copy of the token and asks Meta to stop webhooks for that account. Data Meta holds is governed by Meta’s own terms. Meta’s Cloud API also keeps message data on Meta’s side for a limited period described in Meta’s data-privacy documentation.
Who else processes information
We share personal information only as needed to provide the feature you use:
- Meta, for WhatsApp delivery, templates, Embedded Signup, and Lead Ads you connect.
- The telephone carrier configured for the call, such as Twilio, Plivo, or Vobiz.
- The speech and language providers configured for the employee, such as Deepgram, OpenAI, Google, or ElevenLabs. They receive the audio and text required for that call.
- Razorpay, for subscription payments.
- Google, when you use Google sign-in.
- The hosting and database operators that run this deployment.
- A webhook address you configure. We send only the events you enable, to the URL you enter.
Some of these providers process data outside India. The Digital Personal Data Protection Act allows a transfer except to a country the Government of India restricts. If a restriction applies to a provider we use, we stop that transfer.
How long we keep it
Account data, recordings, transcripts, leads, WhatsApp messages, media, and contacts stay for the life of the workspace. Raw WhatsApp webhook payloads are deleted about 14 days after they are processed. Failed payloads are deleted after about 30 days. Messages and contacts already saved in the inbox remain.
After a verified deletion request, or after the workspace is closed, we delete that workspace’s customer content from the live service. Billing and tax records are kept for the period the Central Goods and Services Tax Act requires, generally six years from the due date of the annual return for that year, and longer if an authority requires it. A carrier may delete its own copy of a recording on the carrier’s schedule while our copy remains, or the other way around.
Security and breaches
Passwords and authenticator backup codes are stored as hashes. WhatsApp tokens and phone-registration PINs are stored encrypted. Meta webhook calls are checked with a signature before they are accepted. A person signed in to one workspace cannot read another workspace’s calls, messages, or leads.
If a breach of personal data is likely to affect people, we will tell the affected workspace owner. When the duty under the Digital Personal Data Protection Act is in force, we will also notify the Data Protection Board of India and the affected people in the manner that Act requires.
Your choices
- You can stop a demo by not submitting the form, and you can ignore or end the call.
- You can disconnect WhatsApp, remove a lead, clear follow-up memory, and edit Do Not Call entries.
- A person who receives a marketing WhatsApp message can reply STOP. The workspace then stops marketing templates to that number.
- Withdrawing consent for the workspace itself is done by asking us to close it. We will not make withdrawal harder than opening the account.
- You may ask for a copy of the personal information we hold about your workspace, and for a correction if it is wrong.
Access, correction, and deletion
You can ask us to export or delete personal information. A statement that deletion is possible is not the whole of the process. Use the steps below. The same steps are published at /data-deletion, which is the data-deletion instructions URL for our Meta app.
- Email support@coocall.ai from the workspace email, or use the Contact page. Subject: “Data deletion” or “Data export”.
- Include the workspace email, whether you want an export or deletion, and whether a WhatsApp or Meta account is connected. If you are the person who was called or messaged, name the business and the phone number they used.
- We may ask you to confirm you control that email or that phone number before we delete anything.
- For a workspace you own, we then delete the account, call recordings and transcripts, leads, WhatsApp messages, media, and contacts, and we disconnect the stored Meta token. Billing and tax records stay for the period the law requires.
- If you only want the Meta connection removed, disconnect WhatsApp under Connect WhatsApp, or say that in the email. We delete the token and ask Meta to stop webhooks. Your WhatsApp account in Meta Business Suite remains yours.
- If a business using Coocall called or messaged you, contact that business first. They control the campaign and the inbox. If you write to us, we will forward the request to the workspace that holds the record, or delete the record where we are the party holding it.
- We complete a verified request within 30 days and email you when it is done. Meta, your carrier, Razorpay, and Google keep their own copies under their policies. Deleting data here does not delete those copies.
Children
The workspace is for businesses. We do not knowingly open an account for anyone under 18. If a child’s information was stored as a customer of a business using Coocall, that business should delete it or ask us to delete it.
Grievances
Grievance Officer: Neeraj Goswami. Write to support@coocall.ai. Use the subject “Grievance” and include the workspace email, what happened, and any Razorpay payment id.
We acknowledge a complaint within 48 hours and aim to resolve a consumer complaint within one month of receiving it. A privacy or deletion request is completed within 30 days after we have verified the requester, and in any case within 90 days, except for records the law requires Code24x7 Private Limited to keep.
These timelines follow the Consumer Protection (E-Commerce) Rules, 2020, and the grievance practice in the Digital Personal Data Protection Act, 2023. Mandatory rights under the law of India still apply where a contract cannot remove them.
Changes
When this notice changes, we update the date at the top and publish the new text on this page. If a change affects how we use customer call or WhatsApp content, we also describe that change on this page before we rely on it.
Privacy · Terms · Refunds · Data deletion · Contact