[{"data":1,"prerenderedAt":536},["ShallowReactive",2],{"navigation":3,"\u002Fblog\u002Fwhatsapp-privacy-message-rules-why-the-thread-beats-the-policy-page":156,"\u002Fblog\u002Fwhatsapp-privacy-message-rules-why-the-thread-beats-the-policy-page-surround":530},[4,23,41,60,78,90,108,137],{"title":5,"path":6,"stem":7,"children":8,"icon":22},"Getting Started","\u002Fdocs\u002Fgetting-started","docs\u002F1.getting-started\u002F1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Quick Start","\u002Fdocs\u002Fgetting-started\u002Fquick-start","docs\u002F1.getting-started\u002F2.quick-start","i-lucide-zap",{"title":18,"path":19,"stem":20,"icon":21},"Connect WhatsApp Phone Numbers","\u002Fdocs\u002Fgetting-started\u002Fconnect-whatsapp","docs\u002F1.getting-started\u002F3.connect-whatsapp","i-lucide-phone","i-lucide-rocket",{"title":24,"path":25,"stem":26,"children":27,"icon":30},"Team Inbox","\u002Fdocs\u002Finbox","docs\u002F2.inbox\u002F1.index",[28,31,36],{"title":29,"path":25,"stem":26,"icon":30},"Shared Inbox","i-lucide-inbox",{"title":32,"path":33,"stem":34,"icon":35},"Rich Messaging","\u002Fdocs\u002Finbox\u002Frich-messaging","docs\u002F2.inbox\u002F2.rich-messaging","i-lucide-message-square",{"title":37,"path":38,"stem":39,"icon":40},"Contact Details","\u002Fdocs\u002Finbox\u002Fcontact-details","docs\u002F2.inbox\u002F3.contact-details","i-lucide-user-check",{"title":42,"path":43,"stem":44,"children":45,"icon":59},"Messaging","\u002Fdocs\u002Fmessaging","docs\u002F3.messaging\u002F1.index",[46,49,54],{"title":47,"path":43,"stem":44,"icon":48},"Single Message","i-lucide-send",{"title":50,"path":51,"stem":52,"icon":53},"Broadcast","\u002Fdocs\u002Fmessaging\u002Fbroadcast-campaigns","docs\u002F3.messaging\u002F2.broadcast-campaigns","i-lucide-megaphone",{"title":55,"path":56,"stem":57,"icon":58},"Campaign History","\u002Fdocs\u002Fmessaging\u002Fcampaign-history","docs\u002F3.messaging\u002F3.campaign-history","i-lucide-bar-chart","i-lucide-message-circle",{"title":61,"path":62,"stem":63,"children":64,"icon":77},"Contacts","\u002Fdocs\u002Fcontacts","docs\u002F4.contacts\u002F1.index",[65,67,72],{"title":10,"path":62,"stem":63,"icon":66},"i-lucide-book-user",{"title":68,"path":69,"stem":70,"icon":71},"Contact Lists","\u002Fdocs\u002Fcontacts\u002Flists-segmentation","docs\u002F4.contacts\u002F2.lists-segmentation","i-lucide-list-filter",{"title":73,"path":74,"stem":75,"icon":76},"Bulk Import","\u002Fdocs\u002Fcontacts\u002Fimporting-contacts","docs\u002F4.contacts\u002F3.importing-contacts","i-lucide-file-spreadsheet","i-lucide-users",{"title":79,"path":80,"stem":81,"children":82,"icon":84},"Templates","\u002Fdocs\u002Ftemplates","docs\u002F5.templates\u002F1.index",[83,85],{"title":10,"path":80,"stem":81,"icon":84},"i-lucide-file-text",{"title":86,"path":87,"stem":88,"icon":89},"Template Syncing","\u002Fdocs\u002Ftemplates\u002Fsyncing-managing-templates","docs\u002F5.templates\u002F2.syncing-managing-templates","i-lucide-refresh-cw",{"title":91,"path":92,"stem":93,"children":94,"icon":97},"AI Chatbots","\u002Fdocs\u002Fai-chatbots","docs\u002F6.ai-chatbots\u002F1.index",[95,98,103],{"title":96,"path":92,"stem":93,"icon":97},"WhatsBox Bots","i-lucide-bot",{"title":99,"path":100,"stem":101,"icon":102},"Tools","\u002Fdocs\u002Fai-chatbots\u002Ftools","docs\u002F6.ai-chatbots\u002F2.tools","i-lucide-wrench",{"title":104,"path":105,"stem":106,"icon":107},"MS Copilot Studio","\u002Fdocs\u002Fai-chatbots\u002Fcopilot-studio","docs\u002F6.ai-chatbots\u002F3.copilot-studio","i-lucide-cpu",{"title":109,"path":110,"stem":111,"children":112,"icon":136},"Integrations","\u002Fdocs\u002Fintegrations","docs\u002F7.integrations\u002F1.index",[113,116,121,126,131],{"title":114,"path":110,"stem":111,"icon":115},"Developer API","i-lucide-code",{"title":117,"path":118,"stem":119,"icon":120},"Google Sheets","\u002Fdocs\u002Fintegrations\u002Fgoogle-sheets","docs\u002F7.integrations\u002F2.google-sheets","i-lucide-sheet",{"title":122,"path":123,"stem":124,"icon":125},"Firebase Extension","\u002Fdocs\u002Fintegrations\u002Ffirebase-ext","docs\u002F7.integrations\u002F3.firebase-ext","i-lucide-flame",{"title":127,"path":128,"stem":129,"icon":130},"Slack","\u002Fdocs\u002Fintegrations\u002Fslack","docs\u002F7.integrations\u002F4.slack","i-lucide-slack",{"title":132,"path":133,"stem":134,"icon":135},"Zapier","\u002Fdocs\u002Fintegrations\u002Fzapier","docs\u002F7.integrations\u002F5.zapier","i-lucide-blocks","i-lucide-plug",{"title":138,"path":139,"stem":140,"children":141,"icon":155},"Settings & Billing","\u002Fdocs\u002Fsettings","docs\u002F8.settings\u002F1.index",[142,145,150],{"title":143,"path":139,"stem":140,"icon":144},"Team Members","i-lucide-users-round",{"title":146,"path":147,"stem":148,"icon":149},"Miscellaneous","\u002Fdocs\u002Fsettings\u002Faccount-settings","docs\u002F8.settings\u002F2.account-settings","i-lucide-building",{"title":151,"path":152,"stem":153,"icon":154},"Billing","\u002Fdocs\u002Fsettings\u002Fbilling-usage","docs\u002F8.settings\u002F3.billing-usage","i-lucide-credit-card","i-lucide-settings",{"id":157,"title":158,"authors":159,"badge":164,"body":166,"date":514,"description":515,"draft":516,"extension":517,"image":518,"meta":519,"navigation":520,"path":521,"schemaOrg":522,"seo":523,"sitemap":525,"stem":528,"__hash__":529},"posts\u002Fblog\u002Fwhatsapp-privacy-message-rules-why-the-thread-beats-the-policy-page.md","WhatsApp Privacy Message Rules: Why the Thread Beats the Policy Page",[160],{"name":161,"avatar":162},"WhatsBox Team",{"text":163},"WB",{"label":165},"Whatsapp privacy message",{"type":167,"value":168,"toc":496},"minimark",[169,176,183,186,189,194,199,202,205,208,227,242,246,249,252,258,264,270,273,277,280,304,313,317,320,388,391,395,398,406,409,412,416,419,422,425,428,432,438,451,463,467,472,475,479,482,486,489,493],[170,171,172],"p",{},[173,174,175],"strong",{},"A WhatsApp privacy message is a short notice, delivered inside the chat thread, that tells a person who is messaging them, what happens to their data, and how to make it stop.",[170,177,178],{},[179,180],"img",{"alt":181,"src":182},"cover","https:\u002F\u002Fstatic.whatsbox.io\u002Fblog-images\u002Fwhatsbox\u002Fai-1887442233-2f194d7d1c41f1b795e95cde.webp",[170,184,185],{},"Put it in the thread, before the first campaign goes out, and every later message inherits that record. Leave it on a website privacy policy and you have a document that nobody in the conversation ever read.",[170,187,188],{},"Most consent advice treats the policy page as the finish line. We think that is backwards for messaging channels, and the reason is structural rather than legalistic. A web page is a destination. A message is an event with a sender, a timestamp, and a reply path attached. Only one of those can be produced as evidence when a customer asks why they are receiving promotions.",[190,191,193],"h2",{"id":192},"what-a-whatsapp-privacy-message-is-and-what-it-is-not","What a WhatsApp Privacy Message Is, and What It Is Not",[170,195,196],{},[173,197,198],{},"A WhatsApp privacy message is a consent and disclosure notice sent through the messaging channel itself, where the recipient can read it, act on it, and reply to it without leaving the conversation.",[170,200,201],{},"That definition does the work. It is not a link to a policy page, and it is not a checkbox on an order form. Both of those live outside the thread, which means neither one travels with the message that follows.",[170,203,204],{},"The distinction matters because messaging channels behave differently from email. An email address is a passive identifier; you can mail it and the recipient may never see it. A WhatsApp number is tied to a device a person carries, and the channel's own rules assume the recipient has a relationship with the sender. That assumption is what makes outreach on this channel effective, and it is also what makes careless outreach expensive. Senders who treat the number as another email list run into a different set of consequences.",[170,206,207],{},"Three audiences need this notice, and they need different versions of it.",[209,210,211,215,224],"ul",{},[212,213,214],"li",{},"A customer who initiated the conversation needs to know what you will store and how to stop future marketing.",[212,216,217,218,223],{},"A lead captured through a form or a ",[219,220,222],"a",{"href":221},"\u002Fwhatsapp-chat-widget","chat widget"," needs to know how their number got here and what it will be used for.",[212,225,226],{},"A past customer receiving a re-engagement message needs a reminder of the relationship plus a working stop instruction.",[170,228,229,230,236,237,241],{},"Compare this with the consumer app. The WhatsApp Business App is free to download and use, with a mix of free and paid features (",[219,231,235],{"href":232,"rel":233},"https:\u002F\u002Fapps.apple.com\u002Fus\u002Fapp\u002Fwhatsapp-business\u002Fid1386412985",[234],"nofollow","Apple App Store listing","). A business running a handful of chats a day can handle notice and consent manually and keep decent records. Past that volume, manual tracking of who consented to what stops working, which is a different problem from the one this article answers and a real one for anyone still ",[219,238,240],{"href":239},"\u002Fblog\u002Fpayment-reminder-whatsapp-message-why-the-personal-number-fails","sending payment reminders from a personal number",".",[190,243,245],{"id":244},"where-consent-actually-gets-recorded","Where Consent Actually Gets Recorded",[170,247,248],{},"Consent that is not stored somewhere is not consent, it is a memory. The useful question is not whether a person agreed but whether you can show which message produced the agreement and when.",[170,250,251],{},"In practice, three storage patterns cover almost every business.",[170,253,254,257],{},[173,255,256],{},"The chat transcript itself."," The notice and the reply sit in the same thread. Anyone on the team who opens that conversation sees the exchange. This is the weakest record, because transcripts get lost when numbers change or accounts churn, and it does not survive a platform migration.",[170,259,260,263],{},[173,261,262],{},"A structured log."," The consent event is written to a sheet or a database row with a timestamp, the source, and the number. Google Sheets works for this on small volumes, and it is exportable when someone asks. The weakness is human entry: a manually maintained log drifts the moment the team gets busy.",[170,265,266,269],{},[173,267,268],{},"An attribute on the contact record."," The consent state lives next to the number inside the sending platform, so every broadcast checks it before sending. This is the pattern that scales, because the record and the decision to send are in the same place. Automation helps here. We connect workflow automations through an embedded Zapier integration, which means a consent reply in a thread can write a row somewhere the rest of your stack already reads.",[170,271,272],{},"Whichever pattern you pick, the record needs four fields: the number, the timestamp, the exact notice text the person saw, and the channel they replied on. Notice text changes over time, and a copy of the notice that no longer exists is not a record.",[190,274,276],{"id":275},"how-to-send-a-notice-and-capture-consent-in-the-thread","How to Send a Notice and Capture Consent in the Thread",[170,278,279],{},"Sequence matters more than wording. These steps run in order, and each one depends on the state the previous step created.",[281,282,283,286,289,292,295,298,301],"ol",{},[212,284,285],{},"Identify the entry point for every number in your list. A number that came from a web form has a different consent story than one that arrived as an inbound reply, and mixing them corrupts the whole set.",[212,287,288],{},"Send a short notice as the first outbound message to that number. State who is messaging, what you will send, how often, and what you store.",[212,290,291],{},"Ask for a reply, not a click. A one-word confirmation in the thread creates a visible record and keeps the exchange inside the channel.",[212,293,294],{},"Write the confirmation to a log with a timestamp and a copy of the notice text.",[212,296,297],{},"Route the same message to your team inbox so a human can read the reply and tag the contact, which is what separates a real opt-in from an assumed one.",[212,299,300],{},"Send the first campaign only to numbers marked confirmed, and check that tag before every subsequent send.",[212,302,303],{},"Keep the stop instruction live and honest. If someone replies with a stop word, that reply has to reach a system that suppresses the number.",[170,305,306,307,312],{},"Notice text outside an open customer service window has to go out as a template, and templates need approval. Replies to user-initiated conversations inside the customer service window are free on the WhatsApp Business Platform (",[219,308,311],{"href":309,"rel":310},"https:\u002F\u002Fwww.authgear.com\u002Fpost\u002Fwhatsapp-api-pricing\u002F",[234],"Authgear","), which is one reason a notice sent as a reply to an inbound message costs less than one sent cold. The free tier does not change the privacy obligation, only the bill.",[190,314,316],{"id":315},"what-to-check-before-you-pick-a-sending-platform","What to Check Before You Pick a Sending Platform",[170,318,319],{},"The platform you send through determines whether the consent record lives in a place that can enforce anything. Judge a candidate on these, and ask for the evidence rather than the claim.",[321,322,323,336],"table",{},[324,325,326],"thead",{},[327,328,329,333],"tr",{},[330,331,332],"th",{},"What to check",[330,334,335],{},"The evidence to ask for",[337,338,339,348,356,364,372,380],"tbody",{},[327,340,341,345],{},[342,343,344],"td",{},"Where the consent state lives",[342,346,347],{},"Whether the contact record carries an opt-in field that broadcasts check before sending",[327,349,350,353],{},[342,351,352],{},"Whether the thread and the record are the same system",[342,354,355],{},"A demonstration of a reply writing back to the contact record without manual entry",[327,357,358,361],{},[342,359,360],{},"How opt-outs are handled",[342,362,363],{},"What happens, step by step, when a recipient replies with a stop word",[327,365,366,369],{},[342,367,368],{},"Whether templates are managed in the tool",[342,370,371],{},"Where the notice template text is stored and how approved status is tracked",[327,373,374,377],{},[342,375,376],{},"Team visibility over a thread",[342,378,379],{},"Who else can read the notice exchange and how the record is shared",[327,381,382,385],{},[342,383,384],{},"Export of consent data",[342,386,387],{},"Whether you can pull a list of confirmed numbers with timestamps and notice versions",[170,389,390],{},"The strongest evidence is a screenshot of the contact record after a test reply, not a description of how it should work.",[190,392,394],{"id":393},"mistakes-that-turn-a-compliant-thread-into-a-blocked-number","Mistakes That Turn a Compliant Thread Into a Blocked Number",[170,396,397],{},"Burying the notice behind a link is the mistake that hides best. A message that says \"we care about your privacy, see our policy\" transfers the reading work to the recipient and creates no record. The notice itself should fit in the message. Short is not the same as vague, and a two-sentence notice that names the sender and the stop method beats a paragraph that cites a regulation.",[170,399,400,401,405],{},"Collecting consent before you have a reason to message is another one. A number captured at checkout with no stated purpose will send your first campaign into a cold contact, and cold contacts behave like spam. State the purpose at capture and the first message has a reason to exist. Teams that skip this end up rebuilding their list from scratch a year later. Think about ",[219,402,404],{"href":403},"\u002Fblog\u002Fwhatsapp-message-chat-is-a-state-machine-not-a-text-box","a message chat that behaves like a state machine"," rather than a text box: a notice, a confirmation, and a campaign are three different states, and sending a campaign to a number in the wrong state is the failure that gets numbers reported.",[170,407,408],{},"Treating a read receipt as consent is the third. Someone reading your notice has agreed to nothing. Reading is not replying, and platforms do not report reads for exactly this kind of reason. Only a returned message, a form submission, or another affirmative act counts as the record.",[170,410,411],{},"Running the same notice text for every relationship is the fourth. A customer who bought from you last month and a lead who downloaded a guide are not in the same position, and a notice that pretends they are will read as boilerplate to both. Write two versions and keep both on file with the dates they were in use.",[190,413,415],{"id":414},"when-in-thread-notice-is-the-right-move-and-when-it-is-overkill","When In-Thread Notice Is the Right Move, and When It Is Overkill",[170,417,418],{},"You should send a notice inside the thread when the number came from somewhere you cannot verify and the first message you plan to send is promotional. That is the case where a notice buys you something: it converts an unknown number into a documented relationship, and it gives you a defensible answer if the recipient later says they never agreed to anything.",[170,420,421],{},"You also need it when more than one person on your team touches the same contact. Shared visibility of the consent state is what stops a colleague from restarting a campaign to someone who opted out three months ago, and no amount of policy documentation substitutes for seeing the record in the conversation.",[170,423,424],{},"The machinery is not worth building if every message you send is a direct reply to a person who contacted you first, and you send fewer than a few dozen of those a day. In that case a notice inside the reply and a simple shared spreadsheet will hold, and heavier tooling adds cost without changing the outcome. Be honest with yourself about the direction of travel, though. Businesses rarely stay in that state, and the migration from manual records to a structured log is easier before a list reaches four figures.",[170,426,427],{},"The harder case is a list you already own, built without an in-thread notice. You cannot retroactively create consent. What you can do is send a re-permission message that states plainly why the person is hearing from you, and treat non-response as a stop. It will shrink the list. A smaller list of confirmed numbers outperforms a larger one with a complaint rate attached.",[190,429,431],{"id":430},"about-whatsbox","About WhatsBox",[170,433,434,435,437],{},"WhatsBox is a WhatsApp Business API messaging platform. The pieces that matter for this problem are the ones that keep the notice and the consent record in the same place: a shared team inbox with session timers and assignment, so a colleague sees the consent state before replying, and workflow automations through an embedded Zapier integration, so a confirmation reply can write to ",[219,436,117],{"href":118}," or trigger whatever comes next. We send broadcast campaigns through the WhatsApp Business API, which is what keeps high-volume sending inside Meta's official rails.",[170,439,440,441,445,446,450],{},"For capturing consent at the source, our chat button and ",[219,442,444],{"href":443},"\u002Fwhatsapp-qr-code-generator","QR code generator"," put a WhatsApp entry point on a page or a physical surface, and people who arrive through it have already initiated the conversation. A ",[219,447,449],{"href":448},"\u002Fblog\u002Fwhitelabel-whatsapp-chat-widget-why-most-options-fall-short-on-branding-alone","whitelabel chat widget"," for websites does the same job on a site, with the thread starting inside your own branding.",[170,452,453,454,458,459,241],{},"If your volume is small enough that a spreadsheet and the free consumer app handle notice and consent, stay there until the list outgrows it. You can ",[219,455,457],{"href":456},"\u002Fcontact-us","contact us"," to see how the inbox and automations fit, and the current plan is on our ",[219,460,462],{"href":461},"\u002Fpricing","pricing page",[190,464,466],{"id":465},"frequently-asked-questions","Frequently Asked Questions",[468,469,471],"h3",{"id":470},"what-are-whatsapp-privacy-messages","What are WhatsApp privacy messages?",[170,473,474],{},"A WhatsApp privacy message is a notice delivered inside the chat thread that tells the recipient who is contacting them, what data the business stores, and how to stop future messages. It differs from a website privacy policy because it lives in the conversation rather than on a page, and it produces a reply that can be logged with a timestamp. Businesses send it before the first promotional message, usually as a reply to an inbound contact or as an approved template.",[468,476,478],{"id":477},"can-someone-see-my-whatsapp-messages-without-me-knowing","Can someone see my WhatsApp messages without me knowing?",[170,480,481],{},"Not without either physical access to an unlocked device or a linked device that was authorized through your account. Voice and video calls use end-to-end encryption, and messages between two people in a standard chat carry the same protection. The realistic exposure is a linked device you forgot about or a cloud backup that is not protected, not a silent read of your live chats by a third party.",[468,483,485],{"id":484},"how-do-i-know-if-someone-is-checking-me-on-whatsapp","How do I know if someone is checking me on WhatsApp?",[170,487,488],{},"WhatsApp does not provide read receipts for other people's activity on your account, and no third-party app can see who viewed your profile or opened your chats. Read receipts (the blue ticks) show only that your own message was read. Treat any app that promises viewer lists for a personal account as a data-collection tool, not a monitoring tool.",[468,490,492],{"id":491},"how-do-i-know-if-my-partner-has-hidden-chats-on-whatsapp","How do I know if my partner has hidden chats on WhatsApp?",[170,494,495],{},"Archived chats sit at the bottom of the chat list and can be revealed with a scroll, and a device linked through the linked devices screen would appear in that list. If you have physical access to the phone, those two places are where a hidden conversation would show up. On the business side, nothing here changes how your own account appears to customers, since a business number's activity is visible to the team through its own inbox rather than to individual contacts.",{"title":497,"searchDepth":498,"depth":498,"links":499},"",2,[500,501,502,503,504,505,506,507],{"id":192,"depth":498,"text":193},{"id":244,"depth":498,"text":245},{"id":275,"depth":498,"text":276},{"id":315,"depth":498,"text":316},{"id":393,"depth":498,"text":394},{"id":414,"depth":498,"text":415},{"id":430,"depth":498,"text":431},{"id":465,"depth":498,"text":466,"children":508},[509,511,512,513],{"id":470,"depth":510,"text":471},3,{"id":477,"depth":510,"text":478},{"id":484,"depth":510,"text":485},{"id":491,"depth":510,"text":492},"2026-10-06","A WhatsApp privacy message is a notice plus a consent record delivered inside the thread. Sending it there, before the first campaign, changes how every later message gets treated.",false,"md",{"src":182},{},true,"\u002Fblog\u002Fwhatsapp-privacy-message-rules-why-the-thread-beats-the-policy-page",null,{"title":158,"description":524},"A WhatsApp privacy message belongs in the chat thread, not buried in a website policy. Here is what to send, when, and what breaks consent.",{"loc":521,"images":526},[527],{"loc":182},"blog\u002Fwhatsapp-privacy-message-rules-why-the-thread-beats-the-policy-page","eblQgS8W7hmCeWNp7CH4KgA8u9Tmtl2cGSA4ZYfx8w8",[522,531],{"title":532,"path":533,"stem":534,"description":535,"children":-1},"WhatsApp Send Message Link: Why the Link Is the Smallest Part","\u002Fblog\u002Fwhatsapp-send-message-link-why-the-link-is-the-smallest-part","blog\u002Fwhatsapp-send-message-link-why-the-link-is-the-smallest-part","A click-to-chat link gets a stranger into your inbox, but it leaves no record of who they are, who answered, or which campaign sent them. We break down when a link is enough and when it quietly becomes a liability.",1791313020818]