IamBroker

Privacy policy

Last updated: 7 September 2026

IamBroker connects a business to its own WhatsApp Business account so that the software that business already runs can talk to its customers. This page states what data we receive from Meta, why we use each item, how long we keep it and how to reach us about it.

Platform Data we receive from Meta

When a business authorises IamBroker through Meta Embedded Signup, and while that authorisation stands, we receive from Meta:

Account and phone number identifiers
The identifier of the WhatsApp Business account and of the phone number the business connected.
Access token
The token that authorises calls to the WhatsApp Cloud API on behalf of that account.
Inbound messages
The messages the customers of that business send to the connected phone number, and the phone number each message came from.
Delivery status
Whether a message we sent was sent, delivered, read or failed.

Purpose of each use

We use each item for one purpose, and for nothing else. We do not sell data, we do not use it for advertising, and we do not use it to train models.

Account and phone number identifiers
To address the WhatsApp Cloud API on behalf of the right business, and to route an incoming event to the system that owns that number.
Access token
To authorise those calls. The token is encrypted at rest and never appears in an API response, a log line, an error message or an event payload.
Inbound messages
To hand the reply back to the system of the business the customer wrote to.
Delivery status
To report to that same system whether its message was delivered, read or failed.

Data belonging to one business is never shared with another business, and is never disclosed to a third party except to Meta itself, which is the platform carrying the conversation.

Retention period

We keep the identifiers, the access token, the messages and the delivery status of a business for as long as that business keeps its account connected to IamBroker. When the account is disconnected, or when the business asks us to delete its data, we delete it within 30 days. The procedure is on the data deletion page.

Tracking

This website sets no cookie, loads no third-party script and runs no analytics. The fonts are served from this same domain, so opening these pages tells nobody but this server that you did.

Contact for a data request

Write to contato@arturmoises.com.br to ask what data we hold about your business, to correct it or to have it deleted. The controller is 68.981.435 ARTUR MOISES ALVES DE PAULA, CNPJ 68.981.435/0001-06.