Privacy Policy

Last updated: 7 June 2026

Casia Growth Lab Ltd. ("Casia Lab", "we", "us") operates ChatLedger, a software platform that helps small businesses manage WhatsApp customer conversations, quotes, payments, and orders. This Privacy Policy explains what data we handle, why, and the rights you have over it. It applies to both the business owners who sign up for ChatLedger (our "Customers") and the people those businesses message through ChatLedger ("End Users").

ChatLedger is provided globally. This policy is written to align with applicable data protection laws in the jurisdictions where our Customers and End Users live — including the EU/EEA (GDPR), UK (UK GDPR), Nigeria (NDPA 2023), the United Arab Emirates (UAE PDPL), and equivalent regimes elsewhere — and with the WhatsApp Business Solution requirements set by Meta Platforms Ireland Ltd.

1. Who we are and how to reach us

ChatLedger is a product of Casia Growth Lab Ltd. ("Casia Lab"), a software company incorporated in Nigeria. We build tools for businesses worldwide that operate on WhatsApp ( casialab.com).

You can reach our data protection team at chatledger@casialab.com. Our registered address is published on our website footer.

2. Data we collect from Customers (the businesses using ChatLedger)

  • Account identifiers — your name, phone number, email address.
  • Business profile — business name, address, default currency, billing tier.
  • Authentication data — one-time codes sent to your phone or email.
  • Staff records — names, roles, contact details of staff you add.
  • Payment information — bank account details and payment-provider account references (Stripe or, where you opt for a regional alternative, Paystack), processed for the purpose of routing customer payments to you. We do not store card numbers.
  • Usage data — logs of actions taken in the product (messages sent, quotes created, login times) to operate, secure, and improve the service.

3. Data we handle on behalf of Customers (about their End Users)

When a Customer uses ChatLedger, the platform processes data about the End Users that the Customer messages. In this context, the Customer is the data controller and ChatLedger is a data processor acting on the Customer's instructions. This data includes:

  • End User WhatsApp phone numbers and display names provided by Meta.
  • Message content sent to and from the Customer (including any media attachments).
  • Customer-assigned tags, notes, location, segment, and order history.
  • Payment references and transaction outcomes.
  • Delivery details voluntarily provided (addresses, ETAs, proof images).

Neither ChatLedger nor Casia Growth Lab Ltd. uses End User data for our own marketing, profiling, or any purpose beyond providing the service to the Customer.

4. Why we process this data

  • To operate the inbox, quote, payment, and order workflows the Customer signed up for.
  • To authenticate Customers and protect their accounts.
  • To send transactional notifications (payment confirmations, dispatch updates) on the Customer's behalf.
  • To meet our legal, tax, and accounting obligations.
  • To analyse aggregate usage and improve the product. We do not sell personal data.

5. Sub-processors we use

We rely on the following third parties to deliver the service. Each is bound by data protection agreements that restrict their use of the data to providing services to us.

  • Meta Platforms Ireland Ltd. — WhatsApp Business Platform; transports messages between Customers and their End Users. Meta's own privacy practices apply to message routing.
  • Supabase Inc. (USA) — managed Postgres database, file storage, and authentication.
  • Railway Corp. (USA) — application hosting.
  • Stripe, Inc. (USA / Ireland) — primary payment processor for card payments, payouts, and platform billing. Used only when a Customer enables payments or subscribes to a paid plan.
  • Paystack Payments Ltd. (Nigeria / USA) — regional payment processor offered as an alternative to Stripe in markets where Paystack is preferred (currently Nigeria, Ghana, Kenya, South Africa). Used only when a Customer selects Paystack.
  • Zoho Corporation (ZeptoMail, India/USA) — transactional email delivery (sign-in links, account notifications, deletion confirmations).
  • Anthropic PBC (USA) — large-language-model inference for the AI Support feature. When a Customer enables AI Support, the customer's structured knowledge (business description, products, policies) and the most recent ~20 messages from the active conversation are sent to Anthropic to generate a reply. Anthropic does not train on this data and retains it only for the duration required to deliver the response and standard abuse-prevention logs (30 days). Used only when AI Support is on.
  • PostHog Inc. (USA) — product analytics. Tracks how Customers use ChatLedger (events like "reply_sent", "quote_created") so we can improve the product. Identified by an opaque user id and tenant id. We do not send End User personal data to PostHog.

If we add or change a sub-processor, we update this section and bump the "last updated" date above. Material changes are also notified to Customers in-product.

6. AI Support

AI Support is an optional feature that drafts or sends automated replies on the Customer's behalf. When a Customer enables it:

  • The Customer's configured knowledge (business description, products, policies, FAQ) is sent to Anthropic on each reply.
  • The most recent ~20 messages from the active conversation are sent to Anthropic to give the model context. End User phone numbers, display names, and any other personal data the End User shared in the conversation may be included.
  • Anthropic returns a draft or sent reply. We log a summary of the run (decision, model used, token counts, confidence) for billing and quality review; the full prompt is not retained.
  • The Customer can turn AI Support off at any time, pause it on a single conversation, or restrict it to specific hours. When off, no data is sent to Anthropic.

If you are an End User and you do not want your conversation with a Customer to be processed by AI Support, ask the Customer to disable it for your conversation or contact us at chatledger@casialab.com.

7. Cross-border transfers

ChatLedger operates globally, and our sub-processors are located in multiple jurisdictions (the United States, Ireland, India, Nigeria, and elsewhere). When data is transferred across borders, we rely on the data subject's consent (given through use of the service), our legitimate interest in operating the service, and the contractual safeguards we have with each sub-processor — including Standard Contractual Clauses where required by EU/UK GDPR and equivalent mechanisms under NDPA, UAE PDPL, and other applicable regimes.

8. How long we keep data

  • Active account data — for as long as the Customer maintains an active subscription.
  • Message and order history — retained while the account is active so the Customer can search their history.
  • Authentication logs — 90 days.
  • After cancellation — Customer and End User data is deleted within 30 days, except where we are legally required to retain it under applicable tax, accounting, or anti-fraud law in the relevant jurisdiction (typically 5–10 years for financial records).
  • Backups — encrypted backups may persist up to a further 35 days before being overwritten.

9. Your rights

Depending on where you live, you have data protection rights under GDPR, UK GDPR, NDPA, UAE PDPL, and other applicable laws. Wherever you are, we honour the following:

  • access the personal data we hold about you;
  • request correction of inaccurate data;
  • request deletion of your data, subject to our legal retention obligations;
  • object to or restrict certain processing;
  • request a portable copy of your data;
  • withdraw consent at any time, where processing is based on consent.

To exercise any of these rights, contact chatledger@casialab.com. For End Users, please contact the Customer business that messaged you first; if they cannot resolve your request, write to us directly.

Step-by-step deletion instructions, including the in-app self-serve flow and the retention timeline, are on our data deletion page.

10. Security

We use TLS for all network traffic, encrypt data at rest in our database, isolate tenants' data at the row level, and require strong authentication for all staff accessing production systems. We do not guarantee security against every possible threat, but we work to limit and quickly respond to incidents.

11. Cookies

We use a small number of strictly necessary cookies to keep you signed in and remember your acting-staff identity in dev mode. We do not use third-party advertising or tracking cookies.

12. Children

ChatLedger is not intended for use by anyone under 18. We do not knowingly collect data from minors. If you believe we have, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the product evolves or laws change. Material changes will be communicated to Customers via in-product notification and email at least 14 days before they take effect.

14. Complaints

Write to us first at chatledger@casialab.com — we'll try to resolve any concern directly. You also have the right to complain to your local data protection authority, including but not limited to:

  • EU/EEA — your country's national supervisory authority.
  • United Kingdom — the Information Commissioner's Office (ICO).
  • Nigeria — the Nigeria Data Protection Commission (NDPC), ndpc.gov.ng.
  • United Arab Emirates — the UAE Data Office (federal) or the equivalent free-zone authority (e.g., DIFC Commissioner of Data Protection, ADGM Office of Data Protection).
  • Other jurisdictions — the regulator with authority over your residence or the data controller.
Privacy Policy — ChatLedger