GO Inbox Privacy Policy
Last updated: 5 October 2026
This policy explains how we process personal data in the GO Inbox service: which data we receive, where it comes from, what we use it for, who we share it with, how long we keep it and how you can ask for your data to be deleted. The gno-cy.com website itself has a separate privacy policy.
- Who we are
- What GO Inbox is
- Who decides what
- What data we process
- Where the data comes from
- What we use the data for
- What we never do
- Service providers
- Where the data is
- How long we keep data
- Security
- Your rights
- Data deletion
- Children
- Changes
1. Who we are
GO Inbox is developed and operated by GAVANİ & ÖZKOÇ DIGITAL SOLUTIONS LTD. ("G&O", "we"), a software company based in Nicosia (North Cyprus).
- Address: Şht. Ecvet Yusuf Cad. Öztek Apt. No:19/2, Yenişehir, Nicosia (Lefkoşa), North Cyprus
- E-mail: support@gno-cy.com
- Phone: +90 533 886 00 09
2. What GO Inbox is
GO Inbox is a WhatsApp inbox for businesses in North Cyprus. A business connects its WhatsApp Business number to GO Inbox through Meta's official signup window. Its team then sees incoming WhatsApp messages from customers on one screen, replies to them and manages message templates approved by Meta.
GO Inbox runs on the WhatsApp Business Platform (Cloud API) operated by Meta. Our app at Meta is called "GO Inbox", App ID 1121288680429180.
3. Who decides what
- Data of the business's customers: the business that uses GO Inbox decides about its conversations with its own customers and about their data (name, phone number, messages). G&O processes this data only on the business's behalf, to provide the service and following the business's instructions.
- Account data of business users: G&O is responsible for the GO Inbox account data of the business's staff (name, e-mail, sign-in data) and for the technical records we keep to secure the service.
If you wrote to a business on WhatsApp, that business is your first point of contact about your data. If you write to us, we handle your request together with that business.
4. What data we process
- Business and staff accounts: the business name; each staff member's name, e-mail address, language preference and role (owner, admin, agent); sign-in data. With Google sign-in, the name, e-mail address and profile photo link that Google shares are kept by the sign-in service. Passwords are not stored in readable form and we cannot see them.
- Business and WhatsApp account details: the business, WhatsApp Business account and phone number IDs given by Meta; the display phone number, the business name verified by Meta, the number's quality rating and connection status; the access token given by Meta and the number's two-step verification PIN. The access token and the PIN are kept on the server only, encrypted.
- Contacts (the business's customers): WhatsApp profile name, username if any, phone number and the business-scoped user ID that Meta assigns.
- Messages: the content of incoming and outgoing messages (text, photo captions, button and list replies, reactions, the text and variables of a sent template); the message time; which staff member sent it; delivery statuses (sent, delivered, read, failed) and error codes; pricing information reported by Meta; a reference to the message being replied to; if the customer wrote from a Meta ad, the ad's source details (ad ID, link, headline); the unread count and who last read the conversation; a note when the customer writes a word such as "STOP" or "DUR". Photos and other media files are not downloaded or stored at present; only the file ID and type given by Meta are recorded.
- Message templates: template name, language, category, content and sample values; Meta's review result (approved, rejected and the reason) and quality score.
- Technical records: server logs written by our app (account, business and message IDs and error details; phone numbers, names and message contents are not written); records that Google's infrastructure keeps automatically for each request (IP address, browser details, time); the IP address and browser details that the sign-in service (Firebase Authentication) records for security; app error logs (the error message with any digits masked, technical error details, the page path, the user ID); counters that limit abuse; the sign-up limit uses the IP address only in hashed form.
- In your browser: your sign-in session and your theme preference are kept in the browser's own storage so that you stay signed in. GO Inbox uses no advertising or tracking cookies.
5. Where the data comes from
- From the business: the business name, and the account details it selects in Meta's signup window when it connects its WhatsApp number.
- From staff: the name and e-mail they enter when opening an account (or the name and e-mail Google shares with Google sign-in), the messages they write and the templates they create.
- From the business's customers: the messages and profile details passed to us through the WhatsApp Business Platform operated by Meta when they write to the business on WhatsApp.
- From Meta: details of the WhatsApp account and number, message delivery statuses, template review results and account notifications.
6. What we use the data for
- To receive and show customer messages, send the customer a read receipt when a staff member opens the conversation, deliver the business's replies to the customer and apply WhatsApp's 24-hour rule.
- To create message templates, submit them to Meta for review and show their status.
- To open accounts, let staff sign in and make sure each business sees only its own data.
- Security: to prevent abuse and to find and fix errors.
- Support: to solve a problem when the business asks us for help. G&O staff access a business's data only for support, fixing errors or legal duties, and only as much as needed.
- Legal duties: to keep records the law requires and to answer lawful requests from competent authorities.
7. What we never do
- We do not sell or rent data.
- We do not use data for advertising, profiling or marketing, and we do not share it with advertising networks.
- We do not use data from the Meta platform (messages, contact and account details) for any purpose other than providing the GO Inbox service.
- We do not share one business's data with another business.
- We do not message customers on our own initiative; messages sent from GO Inbox are sent by the business's staff.
- We do not share data with anyone other than those listed on this page.
8. Service providers
We work only with these providers to run GO Inbox:
- Meta Platforms (WhatsApp Business Platform): WhatsApp messages are sent and received through Meta's infrastructure. When a number is connected, Meta's signup window and the Facebook JavaScript SDK are loaded into the browser from Meta. Meta processes this data under its own terms and privacy policy.
- Google (Google Cloud and Firebase): hosting, database, server functions and sign-in (Firebase Authentication). Google provides these services on our behalf under its own data processing terms. The app also loads its fonts from Google Fonts; this passes your browser's IP address to Google, which processes it under its own privacy policy.
Apart from these, we share data only where the law requires it, in answer to lawful requests from competent authorities.
9. Where the data is
- Messages, contacts, templates and business records are stored and processed in Google Cloud data centres in the European Union.
- Staff sign-in data (e-mail, name, the password in unreadable form, IP address and browser details) is processed by Firebase Authentication. Google runs this service from data centres in the United States.
- While WhatsApp messages are delivered, Meta processes them on its own infrastructure under its own terms; this may include servers outside the EU.
10. How long we keep data
- Data is kept for as long as the business uses GO Inbox.
- When the account is closed, or when we receive a deletion request, the data is deleted within 30 days. Records the law requires us to keep longer are kept only for that period and only for that purpose. Deleted data is then also removed from Google's backup systems through Google's own deletion process, within 180 days at the latest.
- When a WhatsApp number is disconnected, that number's access token is deleted immediately. So that the number can be reconnected with the same PIN, its two-step verification PIN stays stored, encrypted, until the account is closed or deletion is requested. Past conversations remain until the business asks for them to be deleted or the account is closed.
- Technical records are short-lived: error logs are deleted automatically after 30 days and the technical index used to match message statuses after 45 days; server logs are usually deleted within 30 days; the sign-in service keeps IP addresses for a few weeks; abuse counters expire on their own shortly after.
11. Security
- All connections are encrypted (HTTPS/TLS). Google also stores the data in its database encrypted.
- Each business sees only its own data; this is checked both on the server and in the database rules.
- Access tokens and PINs given by Meta are kept on the server only, encrypted; they are never sent to the browser and never written to logs.
- When a number is connected, we never see your Facebook password; you sign in inside Meta's own window.
- Every notification from Meta is accepted only after its signature has been verified.
- Opening an account requires a confirmed e-mail address, and there are limits against abuse. Phone numbers are not written to server logs or web addresses.
No system is perfect. If we become aware of a security incident affecting data, we will inform the affected businesses without delay.
12. Your rights
To the extent the applicable data protection law grants them, you have the right to access the data about you, to ask for it to be corrected or deleted or for its processing to be restricted, to object to its processing and to receive a copy of your data.
To make a request, write to support@gno-cy.com; we reply within 30 days at the latest. We may ask for extra information to confirm that the request is yours. If you are a customer of a business, you can also send your request directly to that business; we handle requests we receive together with the business concerned. You also have the right to complain to the competent data protection authority.
13. Data deletion
How to request deletion
- Send an e-mail to support@gno-cy.com with the subject line "GO Inbox veri silme / data deletion".
- Tell us who you are and what you want deleted: as a business, the business name and the connected WhatsApp number; for a staff account, the account's e-mail address; as a customer who wrote to a business on WhatsApp, the name of that business and your own WhatsApp number.
- We may ask for a short check that the request is yours (for example, a reply from the registered e-mail address).
- After that check, we delete the data within 30 days at the latest and confirm the deletion by e-mail.
What is deleted
- For a business account: the business record, staff accounts, connected WhatsApp account records, access tokens and PINs, conversations, messages, contacts and template records.
- For a customer: the conversations, messages and contact details relating to that person. The business concerned is informed.
- Records the law requires us to keep longer are deleted when that period ends.
Good to know
Deleting from GO Inbox does not delete records Meta keeps in its own systems, or the copies of messages in WhatsApp on the customer's phone; those are subject to Meta's and WhatsApp's own rules. Message templates also exist in the WhatsApp account at Meta; the business can delete them in WhatsApp Manager. Removing deleted data completely from Google's backup systems can take up to 180 days.
You can disconnect at any time
A business can disconnect its WhatsApp number in GO Inbox at any time under WhatsApp Account › Disconnect; the access token is deleted immediately and no new messages are received from that number. The business can also remove GO Inbox's access in Meta Business Settings; Meta then notifies us and the number automatically changes to "Disconnected" in GO Inbox. Disconnecting does not delete past data; to delete it, follow the steps above.
14. Children
GO Inbox is a tool for businesses and is not intended for use by anyone under 18. Only people aged 18 or over may open a staff account. If you believe data of someone under 18 has reached us, write to us; we will review it together with the business concerned and delete it.
15. Changes
We update this policy when needed; the current version is always published on this page with the date of the last update at the top. We inform businesses of important changes by e-mail or in the app before they take effect. Before new features that process data differently from today go live, this policy will be updated.
Questions: support@gno-cy.com