Privacy policy
Last updated 21 September 2026
GotiMail is run by TRIP FINDY. When you connect WhatsApp or Facebook, Meta shows our app as “Goti” — it is the same service. This policy explains what information we handle, why, who else is involved, and what you can ask us to do with it.
1. Two kinds of information
Information about our customers. When a business signs up, we decide what we need to run their account: who they are, how they sign in and how they pay. For this we are responsible for the data.
Information our customers keep with us. The emails, mailboxes, files, contact lists and WhatsApp and Messenger conversations a business keeps in GotiMail belong to that business. We store and process them only to provide the service to that business, on its instructions. If you have been in touch with a business that uses GotiMail, that business decides what happens to your information, and you should start with them — but you can also ask us, and we will help (see section 9).
2. Your account
- Who you are: your name, email address, company name, country and currency.
- Signing in: a scrambled form of your password (never the password itself), your two-factor setting, and a history of sign-ins with the time, IP address and browser, so you and we can spot a sign-in that was not you.
- Business checks: if you send email in volume, the business details you give us to confirm you are a real business — name, address, phone, website, and trade licence or tax number.
- Payments: top-ups, invoices and the balance of your wallet. Card and mobile-wallet payments are handled by the payment provider; we receive a confirmation, never your card number or PIN.
- Your team: the names, email addresses and roles of the people you invite.
- Records of actions: a log of important changes in your account (for example, who connected a channel or changed a setting), kept for security and to resolve disputes.
3. What you keep and send with us
- Email you send through our API, SMTP or campaigns, the lists you send to, and delivery events (delivered, bounced, opened, clicked, complained).
- “Seen” reports: campaigns, and webmail messages whose sender switches it on, carry a tiny image; when your mail app loads it we record the time, IP address and mail app, and show them to the sender. Blocking images in your mail app stops it — the sender then just sees “not seen”.
- Business mailboxes: the mail in each mailbox. An employee’s mailbox can only be opened with that employee’s own password — not by the account owner and not by our panel.
- Free personal addresses (for example on gotimail.com): to open one we check an email address you already have and your mobile number by sending each a code, and keep both on your account. A free mailbox opens in your browser once you have signed in to GotiMail: its mailbox password is made by us, stored encrypted and never shown, which is also why mail apps cannot connect to a free mailbox. Your mobile number is used only for these codes and to allow one free account per number.
- Storage Box: the files and folders you upload, and the share links you create. When someone opens a share link, we record the time, their IP address and browser, and whether they viewed or downloaded a file, and show that to the account that made the link, so it can see who received it. Reporting a link is not part of that record: the person who shared it is not told who reported it.
- AI writing: if you ask the panel to draft an email template, the description you type is sent to our AI provider to write the draft. Nothing is sent unless you use that feature.
4. WhatsApp and Facebook Messenger
A business can connect its WhatsApp Business number or Facebook Page to GotiMail, so that its team can answer customer messages from one place. When it does:
What we receive from Meta
- The messages people send to that number or Page, and the business’s replies.
- For WhatsApp: the sender’s WhatsApp phone number and the profile name they chose.
- For Messenger: an ID that Meta creates for that person and that Page only, and their name.
- Pictures, voice notes, documents and locations people send. We fetch these from Meta when someone on the business’s team opens them; we do not keep our own copy.
- Whether each reply was delivered and read.
- An access token that lets us send replies on the business’s behalf. It is stored encrypted.
What we do with it
- Show the conversation to the business’s team as a support ticket, with the notes, tags and status they add.
- Send the replies they write.
- Nothing else. We do not use this information for advertising, we do not sell it, we do not share it with other customers, and we do not use it to train AI.
Connecting with Facebook
When a business owner connects a Page or WhatsApp number with “Continue with Facebook”, we use the permission they grant only to list the Pages and WhatsApp accounts they manage and to connect the one they choose. We do not store their personal Facebook profile, friends, posts or photos. The Channels page loads Facebook’s sign-in script only when you press a connect button.
Meta also processes these messages under its own terms: the WhatsApp Business Policy and Meta Privacy Policy.
When a business disconnects a channel, new messages stop reaching us immediately. The conversations already received stay in the business’s account until it deletes them or closes the account.
5. Who else is involved
We use a small number of companies to run the service. Each receives only what its part needs.
| Company | What they do for us | What they receive |
|---|---|---|
| Amazon Web Services | Delivers the email our customers send | The messages and their recipients |
| Hetzner Online | Servers for mailboxes and the Storage Box | Mailbox content and stored files |
| Meta Platforms | WhatsApp and Messenger | Replies the business sends, and the files attached to them |
| bKash, Stripe | Payments | The amount and what you enter on their payment page |
| Anthropic | AI template writing, only when you use it | The description you type |
We may also disclose information when the law requires it — for example, a valid order from a court or regulator — and only as much as it requires.
6. What we never do
- Sell information, or rent it out.
- Show advertising, or use anyone’s information to target advertising.
- Read a customer’s email, files or conversations, except when the customer asks us to help with a problem, or to investigate abuse such as spam or fraud.
- Share one customer’s data with another.
7. How it is protected
- Everything travels encrypted (HTTPS and TLS).
- Passwords are stored only as a salted Argon2 hash; two-factor sign-in is available to every user and required for our staff.
- Access tokens for WhatsApp and Messenger, and two-factor secrets, are encrypted with AES-256.
- Each business’s data is kept apart from every other’s, and access is checked on every request.
No system is perfectly secure. If a breach affects your information, we will tell you without undue delay.
8. How long we keep it
- While an account is open, we keep what the business keeps. Deleting something in the panel deletes it (items in a trash stay until the trash is emptied).
- When an account is closed, its content — mail, files, contacts and conversations — is deleted within 30 days.
- Invoices and payment records are kept for as long as tax and accounting law requires.
- Sign-in history is kept for 12 months, then deleted.
- Share-link activity (who opened a link, when, and from which IP address) is kept for 180 days, then deleted.
9. Your choices and rights
You can ask us to:
- tell you what information we hold about you, and give you a copy;
- correct information that is wrong;
- delete your information — see our data deletion page;
- stop using it for a particular purpose.
If the information is part of a business’s account — for example, messages you sent to a shop on WhatsApp — we will pass your request to that business, and act on it ourselves where the law requires. We reply to every request within 30 days.
10. Cookies
We use one cookie to keep you signed in, and nothing else of our own: no advertising or tracking cookies. If you press “Connect” on the WhatsApp & Messenger page, Facebook’s sign-in window sets its own cookies under Meta’s policy.
The service is for businesses and is not directed at children under 13.
11. Changes and contact
If we change this policy in a way that matters, we will tell account owners by email before it takes effect. The date at the top always shows the latest version.
Questions or requests: Email info@tripfindy.com, or use the form on our data deletion page. Phone +880 1716-164065. Post: TRIP FINDY, 100/A, 5th Floor, Shukrabad Main Road, Dhanmondi, Dhaka, Bangladesh.