Meta Developer Verification Summary

Meta App Review & Platform Data Compliance

Technical Documentation & Disclosure Statement for Facebook App Reviewers & Meta Verification Team

1. Verification Overview & Entity Details

This document provides complete operational context and data usage compliance disclosures for Meta Platform App Reviewers evaluating the Sampad platform.

  • Legal Entity Name: Gyanovate Corp Private Limited
  • SaaS Product Platform: Sampad (Business ERP & CRM Platform)
  • Official Domain: getsampad.com / sampad website
  • Official Business Email: business@gyanovate.com
  • Support & Escalation Contact: +91 9732648724

2. Meta Permissions Requested & Functional Rationale

Sampad requests the following Meta WhatsApp Business API permissions strictly to serve our registered business clients:

whatsapp_business_messaging

Functional Rationale: Allows Sampad to initiate 1-click lead messaging from Sampad CRM cards, send automated transactional outbound notifications (such as PDF invoices, receipt confirmations, order tracking alerts, payment follow-ups) on behalf of our Clients, and receive incoming customer replies into Sampad's shared team CRM inbox for real-time sales and customer support.

whatsapp_business_management

Functional Rationale: Enables Clients to read, sync, create, and verify approved message template categories (Utility, Authentication, Marketing) and monitor phone number quality status directly inside the Sampad dashboard.

3. Technical Architecture & End-to-End Data Flow

  1. Client Onboarding (Embedded Signup): The Client initiates connection via Meta Embedded Signup popup inside Sampad Settings. The Client authenticates their Facebook Business Manager account and grants WABA permissions to Gyanovate Corp Private Limited.
  2. Token Storage & Access Control: OAuth system user tokens and Phone Number IDs are transmitted over TLS 1.3 and stored in isolated multi-tenant databases with AES-256 encryption.
  3. Outbound Notification & CRM Lead Outreach: When a Client generates an invoice, updates an order status, or initiates a 1-click lead outreach from a Sampad CRM profile, our engine formats the payload against the Client’s pre-approved Meta message template and calls the Graph API endpoint (`https://graph.facebook.com/v19.0/{phone_number_id}/messages`).
  4. Incoming Customer Reply (Webhook): When an end-customer responds to a message, Meta Graph API triggers an incoming message webhook to Sampad's secure webhook handler. The message payload is parsed and rendered in the Client's multi-agent CRM inbox and attached to the lead card.

4. Meta Platform Data Security & Non-Sharing Policy

  • Strict Data Isolation: Each Client’s Meta Platform Data (tokens, logs, templates, messages) is strictly isolated to their tenant account sandbox.
  • Zero Data Selling Guarantee: Gyanovate Corp Private Limited does NOT sell, rent, monetize, or disclose Meta Platform Data, customer phone numbers, or conversation content to any third parties or advertisers.
  • Encryption Standards: Data in transit is secured via TLS 1.3; cached secrets and tokens are encrypted at rest using AES-256.

5. User Data Deletion Callback & Callback Mechanism

Sampad complies fully with Meta’s Data Deletion Policy and provides both automated and manual deletion mechanisms:

Automated Webhook Deletion Callback

When a Client uninstalls the Sampad Meta App from Facebook Business Manager or revokes WABA access, Meta sends a `deauthorize` / data deletion request webhook to our handler:

POST https://getsampad.com/api/webhooks/meta-data-deletion

Upon receiving the webhook verification payload, Sampad automatically revokes all associated API tokens, clears cached WABA details, and marks log tables for permanent purge within 30 days.

Manual Deletion Request

Clients and end-users can also request immediate manual data wiping by emailing business@gyanovate.com with the subject line "Meta Data Deletion Request".