Fynchat

How do we protect your data?

An explanation of the security and privacy measures we apply to protect your account and your customers.

The security and data-isolation page

Data isolation (Multi-tenancy)

Each customer account in Fynchat is fully isolated from every other one at the technical level:

  • Every database query is automatically filtered by your account
  • It is impossible for a user in company A to reach company B's data by tampering with the URL or the API
  • We test this isolation automatically with every update

Encryption

Type Standard
Data in transit TLS 1.3
Data in the database AES-256 encryption at rest
Passwords bcrypt with salt
Tokens / Access keys Encrypted in the database + never shown in logs

Access

  • Your account is protected by a strong password + email confirmation
  • You'll be able to enable 2FA soon (in development)
  • We log every sign-in with IP and time
  • If we detect suspicious activity, we terminate the session immediately and send you an alert

Backups

  • Daily at midnight (UTC)
  • Encrypted + stored in a separate location
  • 30-day retention for backups
  • Recovery: less than 4 hours (RTO), less than one hour of data loss (RPO)

What we log (Logs)

We log only the necessary information:

  • ✅ Sign-in and sign-out events
  • ✅ Account settings changes
  • ✅ Campaign sends
  • ✅ System errors

We do not log:

  • ❌ Passwords
  • ❌ Message content (except to display it in the inbox)
  • ❌ Credit card information (we use specialized payment gateways)

Compliance

  • 🇸🇦 Saudi Personal Data Protection Law (PDPL) — compliant
  • 🇪🇺 GDPR — compliant (for customers who have European customers)
  • 🌍 Meta Data Use Policy — adherent

Review:

Data sharing

We do not sell your data to anyone. We share it only with:

Party Why
Meta (WhatsApp) To send messages via the official API
AWS For hosting and sending emails
Government authorities Only under a valid court order

Your rights

Under the PDPL and GDPR, you have the right to:

  1. Access your data → request it at [email protected]
  2. Correction → via account settings
  3. Deletion → request full deletion of your account
  4. Portability → we export your data in JSON / CSV format

We commit to responding within 30 days.

Reporting a breach

If you notice anything suspicious (an unfamiliar sign-in, unusual messages, etc.):

  1. Change your password immediately
  2. Report it to [email protected]
  3. We will investigate and respond within 4 hours

Bug Bounty

We value security researchers. If you discover a vulnerability, report it via:

  • 📧 [email protected]
  • We handle it confidentially and offer rewards ranging from SAR 500–10,000 depending on the severity of the vulnerability

Quick links