privacy policy

Last Updated: 23 August 2026 Shift Next ("Shift Next", "we", "our", or "us") respects your privacy and is committed to protecting personal data processed through our websites, applications, WhatsApp Business communication platform, APIs, integrations, and related services (collectively, the "Services"). This Privacy Policy explains what information we collect, how we use and protect it, when we share it, and the rights available to users and customers. By accessing or using our Services, you acknowledge the practices described in this Privacy Policy. 1. About Shift Next Shift Next provides technology solutions that may include: WhatsApp Business Platform integration Customer communication management Message template management Campaign and notification management Chat and conversation management Automated responses and workflows Chatbots and AI-enabled communication features Contact and customer management API integrations Webhook integrations Reporting and analytics White-label communication solutions Software development and technology services Certain communication functionality may depend upon third-party platforms such as Meta Platforms, Inc., WhatsApp, cloud infrastructure providers, telecommunications providers, and other technology partners. 2. Scope of This Privacy Policy This Privacy Policy applies to personal data processed when you: Visit a Shift Next website; Register for a Shift Next account; Purchase, subscribe to, or use our Services; Connect a WhatsApp Business Account or other third-party service; Contact our sales or support teams; Communicate with us through email, WhatsApp, forms, telephone, or other channels; Use our APIs, applications, dashboards, or integrations; or Otherwise interact with Shift Next. It also describes how Shift Next processes certain information on behalf of our business customers. 3. Information We Collect Depending on how you use our Services, we may collect the following categories of information. 3.1 Account and Business Information We may collect: Name Business or organization name Business address Email address Mobile or telephone number Job title Country or location Login credentials Account identifiers Subscription or plan information GST or tax-related business information where required Billing and invoicing details 3.2 WhatsApp Business and Integration Information When you connect WhatsApp Business Platform, Meta services, or another supported integration, we may process information such as: WhatsApp Business Account ID Business Portfolio or Business Manager identifiers WhatsApp phone number identifiers Display phone numbers Message template information Messaging status information Webhook events Message IDs Delivery, read, sent, failed, and other message statuses Business profile information Access credentials or tokens necessary to operate integrations Integration configuration information We only use such information as necessary to provide and maintain the relevant integration and Services. 3.3 Contact and Recipient Information Our customers may upload, synchronize, enter, or otherwise provide information regarding their own customers, prospects, members, employees, beneficiaries, or other contacts. This information may include: Name Mobile or WhatsApp number Email address Customer reference number Tags or groups Communication preferences Custom fields configured by the customer Campaign information Conversation history Message content Files or media sent or received through supported communication channels For this information, the Shift Next customer generally determines why the personal data is being processed, and Shift Next processes such data to provide the Services on behalf of that customer. Customers are responsible for ensuring that they have an appropriate lawful basis, consent, authorization, or other permission required to collect, upload, use, and communicate with their contacts. 4. Message Content Depending on the Services being used, Shift Next systems may process: Incoming messages Outgoing messages Template messages Conversation content Images Documents Audio or video files Message metadata Delivery and read-status information We process this information for purposes such as delivering messages, displaying conversations, supporting automation, troubleshooting, reporting, security, and providing functionality requested by our customers. Shift Next does not claim ownership of customer message content. 5. How We Use Personal Data We may process personal data for purposes including: Creating and maintaining customer accounts; Providing access to the Shift Next platform; Delivering WhatsApp Business and communication services; Processing messages and communication workflows; Managing contacts and campaigns; Executing automated responses, workflows, and chatbots; Providing customer support; Processing subscriptions, payments, invoices, and billing; Monitoring platform performance; Preventing fraud, misuse, spam, and unauthorized activity; Maintaining security; Troubleshooting technical problems; Improving our Services; Providing product updates and service-related notifications; Complying with legal and regulatory requirements; Maintaining audit and operational records; Enforcing our agreements, policies, and acceptable-use requirements; and Protecting Shift Next, our customers, users, and third parties. We do not process personal data for purposes that are incompatible with the purpose for which it was collected unless permitted by applicable law. 6. Customer Responsibilities Customers using Shift Next to communicate with their own users are responsible for their use of personal data. Customers must ensure that: Contact information has been collected lawfully; Required notices have been provided; Required consent or authorization has been obtained; WhatsApp and Meta messaging requirements are followed; Opt-out and unsubscribe requests are respected; Messages are not sent for unlawful, fraudulent, misleading, abusive, or unsolicited purposes; Uploaded information does not violate third-party privacy rights; Applicable data protection, telecommunication, marketing, and consumer protection laws are followed. Shift Next may suspend or restrict accounts reasonably suspected of unlawful messaging, spam, platform abuse, fraud, or violations of applicable third-party platform policies. 7. Meta and WhatsApp Services Certain Shift Next Services integrate with services provided by Meta and WhatsApp. When a customer connects or uses WhatsApp Business Platform, certain information may be transmitted to or received from Meta or WhatsApp as necessary to provide the messaging service. Use of WhatsApp and Meta products may additionally be governed by their applicable: Terms of Service; WhatsApp Business Terms; Meta Platform Terms; Data processing terms; Privacy policies; and Messaging policies. Shift Next does not control how an independent third-party platform processes information within its own systems. Customers are responsible for ensuring that their use of WhatsApp Business Platform complies with applicable Meta and WhatsApp requirements. 8. Third-Party Service Providers We may use trusted third-party providers to operate our Services, including providers of: Cloud hosting Data storage Databases Email services SMS services WhatsApp Business services Payment processing Customer support Analytics Security monitoring Application monitoring Backup services Artificial intelligence services Authentication services These providers may process information only to the extent reasonably necessary to provide their services to us, subject to applicable contractual and legal requirements. 9. Artificial Intelligence Features Shift Next may provide AI-assisted features such as: Automated replies; Chatbots; Message suggestions; Content generation; Conversation classification; Summarization; Customer-support assistance; and Workflow automation. Where an AI feature requires message content or other customer data to be processed by a third-party AI provider, we will use appropriate technical and contractual safeguards according to the configuration of the relevant Service. Customers should not submit highly sensitive personal information to AI-enabled functionality unless the Service is specifically designed and authorized to process such information. 10. Cookies and Usage Information When you visit our websites or use our applications, we may automatically collect technical information such as: IP address Browser type Operating system Device information Login timestamps Pages visited Application activity Session information Error logs Security logs Approximate geographic information derived from IP address We may use cookies and similar technologies for authentication, preferences, security, analytics, and improving the user experience. Where required by applicable law, non-essential cookies will be used subject to appropriate consent. 11. Payment Information Where paid Services are offered, payment transactions may be processed through third-party payment providers. Shift Next may receive payment-related information such as: Transaction reference Payment status Invoice information Subscription information We generally do not store complete debit card or credit card credentials when payment processing is performed directly by an authorized payment gateway. 12. Legal Basis and Consent Depending on the jurisdiction and circumstances, we process personal data based upon: Consent; Performance of a contract; Compliance with legal obligations; Legitimate or permitted business purposes; Provision of requested services; or Other grounds permitted under applicable law. Where consent is the applicable basis, individuals may withdraw that consent subject to applicable law and legitimate retention requirements. Withdrawal of consent does not affect processing already lawfully carried out before withdrawal. 13. Digital Personal Data Protection Compliance Where applicable, Shift Next processes personal data in accordance with India's Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, and other applicable Indian laws and regulations. Depending upon the nature of the processing relationship, Shift Next may act as a Data Fiduciary or process personal data on behalf of another organization. Where Shift Next processes end-customer information solely on instructions from a business customer, that customer remains responsible for determining the purpose and lawful basis for such processing. 14. Data Sharing We do not sell personal data. We may share or disclose information: With service providers necessary to operate the Services; With Meta or WhatsApp when required to provide WhatsApp Business functionality; With authorized integration partners; With payment processors; With professional advisers such as auditors, accountants, or legal advisers; Where required by law, court order, or lawful government request; To investigate fraud, abuse, security threats, or violations of our agreements; In connection with a merger, acquisition, restructuring, financing, or transfer of business assets; or Where the individual or customer has authorized the disclosure. We require appropriate confidentiality and security protections where applicable. 15. Data Retention We retain personal data only for as long as reasonably required for: Providing the Services; Maintaining active customer accounts; Customer-requested message history; Billing and accounting; Security; Fraud prevention; Backup and disaster recovery; Legal obligations; Dispute resolution; and Enforcement of agreements. Retention periods may differ depending on the type of information, applicable law, customer configuration, and contractual requirements. When personal data is no longer required, we may delete, anonymize, or securely dispose of it in accordance with our data-retention procedures. Backups may retain deleted information for a limited additional period until backup rotation is completed. 16. Data Security Shift Next implements reasonable administrative, organizational, and technical safeguards designed to protect personal data against: Unauthorized access Unauthorized disclosure Accidental loss Destruction Alteration Misuse Fraud Security threats Depending on the Service and infrastructure, safeguards may include: Encryption in transit; Encryption at rest where appropriate; Authentication controls; Role-based access; Restricted administrative access; Secure credential management; Logging and monitoring; Backup procedures; Vulnerability management; Security updates; and Infrastructure security controls. However, no internet-based service, computer system, or electronic storage mechanism can guarantee absolute security. 17. Access Credentials and API Tokens Customers are responsible for maintaining the confidentiality of: Passwords API keys Access tokens Meta credentials WhatsApp credentials Webhook secrets Integration credentials Customers should immediately notify Shift Next if they believe their account or credentials have been compromised. Shift Next will never request customers to publicly disclose passwords, API secrets, or authentication tokens. 18. International Data Transfers Some infrastructure providers, technology partners, Meta services, or other service providers may process information in jurisdictions outside the customer's country. Where international processing occurs, Shift Next will take reasonable steps required by applicable law to ensure that appropriate safeguards apply. Where customer-specific data residency requirements exist, they should be agreed separately as part of the applicable service agreement. 19. Your Privacy Rights Subject to applicable law, individuals may have rights concerning their personal data, including the ability to: Request information regarding personal data being processed; Request access to personal data; Request correction of inaccurate or incomplete information; Request deletion or erasure where legally applicable; Withdraw consent where processing is based on consent; Raise a grievance regarding processing; Request that certain processing be stopped where applicable; and Exercise other rights available under applicable privacy legislation. Some requests may be subject to identity verification, legal limitations, retention obligations, or legitimate security requirements. 20. Requests Relating to a Shift Next Customer If you received a WhatsApp message or other communication from an organization using Shift Next, that organization normally controls its contact database and decides why the communication was sent. For requests relating to: Why you received a particular message; Updating your contact information; Removing yourself from a customer database; Marketing preferences; Campaign consent; or Deletion of information held by that organization, you should first contact the organization that communicated with you. Where appropriate, Shift Next will assist its customers in responding to valid privacy requests. 21. Marketing Communications We may send Shift Next customers information relating to: Product announcements; New features; Offers; Events; Service updates; or Other business communications. Where legally required, promotional communications will be sent based upon appropriate permission. Recipients can opt out of promotional communications through the unsubscribe mechanism provided or by contacting us. Service-related, security-related, transactional, or account-related communications may continue where necessary even if marketing communications are disabled. 22. Children's Privacy Shift Next's business Services are not intended for direct use by children unless specifically stated otherwise. Customers must not knowingly use our Services to unlawfully collect or process children's personal data. Where processing involving children is permitted, customers are responsible for obtaining any parental or guardian consent required under applicable law. 23. Data Breach and Security Incidents If Shift Next becomes aware of a personal-data breach affecting information for which notification is legally required, we will take reasonable steps to: Investigate the incident; Contain the incident; Mitigate potential harm; Notify affected customers where required; and Notify applicable authorities or affected individuals where legally required. 24. Law Enforcement and Legal Requests Shift Next may disclose information where required to comply with applicable laws, regulations, judicial proceedings, court orders, or lawful government requests. Where legally permissible, we will seek to ensure that requests are valid, proportionate, and appropriately authorized. 25. Account Termination and Data Deletion Upon termination of a Shift Next account: Access to the Services may be disabled; Customer data may remain available for a limited retention period; Customers may be permitted to export certain data where supported; Data may subsequently be deleted or anonymized; Information required for legal, financial, security, fraud-prevention, or regulatory purposes may be retained as permitted by law. Customers should export any information they require before their account is terminated where export functionality is available. 26. Third-Party Links Our websites and Services may contain links to third-party websites, applications, or services. Shift Next is not responsible for the privacy practices of independent third parties. Users should review the privacy policies of those services before providing personal information. 27. Changes to This Privacy Policy We may update this Privacy Policy periodically to reflect: Changes to our Services; Changes in technology; New integrations; Changes to applicable laws or regulations; or Changes to our privacy and security practices. The revised version will display an updated "Last Updated" date. Where a material change requires additional notice or consent under applicable law, we will take appropriate steps to provide such notice. 28. Grievance and Privacy Contact Questions, privacy requests, complaints, or concerns regarding this Privacy Policy or Shift Next's handling of personal data may be directed to: Shift Next Above Radhe Collection, Opp. Rama Complex, Mogri Janta Raod, Mogri, Anand, Gujarat, India Privacy Email: hello@shiftnext.in Support Email: hello@shiftnext.in Website: shiftnext.tech Where required under applicable law, Shift Next will publish or provide the details of its designated grievance or data-protection contact. 29. Contact Us If you have questions about this Privacy Policy or the way Shift Next processes personal information, please contact us using the details provided above.