Privacy Policy
This Privacy Policy explains how Firetminds Private Limited collects, uses, shares, stores, and protects information when customers use Kshana API and related WhatsApp- and Meta-connected communication workflows.
Last updated: August 7, 2026
Scope
This Privacy Policy applies to Kshana API, our public website, our hosted application, and related services operated by Firetminds Private Limited. It explains how we collect, use, disclose, store, and protect information when businesses, team members, prospects, customers, and website visitors interact with Kshana API.
Kshana API supports WhatsApp-first sales, support, marketing, and workflow operations. When our customers connect Meta or WhatsApp Business Platform services, we may process information made available through those services to deliver the features requested by the customer.
Information We Collect
We collect business account details such as organization name, workspace details, user names, email addresses, phone numbers, billing or subscription records, and administrator settings.
We collect CRM and workflow data that customers choose to add, import, or sync into Kshana API, including contacts, leads, companies, notes, meetings, proposals, tasks, assignments, and activity history.
When WhatsApp or Meta services are connected, we may process phone numbers, profile names, conversation content, media references, template messages, delivery and read status, error events, timestamps, webhook events, and related messaging metadata.
We collect technical and security data such as IP address, browser type, device information, authentication records, cookies or similar session data, crash logs, audit logs, and usage analytics required to operate and secure the service.
If you contact us directly, we may collect the information you provide in support requests, demo requests, or other business communications.
How We Use Information
We use information to provide the Kshana API service, including shared inbox workflows, message routing, contact management, campaign execution, reporting, permissions, and customer support.
We use messaging and contact data to send, receive, display, organize, and monitor WhatsApp conversations and business-initiated communications that our customers request us to handle on their behalf.
We use information to authenticate users, prevent fraud or abuse, troubleshoot incidents, maintain uptime, enforce product rules, and improve product performance and usability.
We may use business contact information to respond to inquiries, provide onboarding, share transactional notices, and communicate service updates relevant to the customer relationship.
Cookies and Browser Storage
See our Cookie Policy for browser controls and current usage.
We use essential cookies and similar browser storage to authenticate users, renew sessions, protect accounts, route requests, remember product preferences, and provide requested application functionality.
With permission, we use Google Analytics 4 to measure page usage and improve the website and application. Analytics remains disabled until a visitor allows it. We configure page tracking to exclude query strings, mask identifier-like route segments, and avoid sending WhatsApp message content, contact details, phone numbers, credentials, or payment details.
Visitors can decline analytics and continue using essential Kshana API functionality. The Cookie Policy explains the analytics preference and how to reset it.
Meta and WhatsApp Business Platform Disclosures
Kshana API integrates with services provided by Meta, including the WhatsApp Business Platform. If a customer enables those integrations, information exchanged through Meta services may be transmitted to or received from Kshana API so that the connected workflow can function.
In line with Meta's developer privacy expectations, this policy explains the categories of data we collect through the integration, the purposes for which we use that data, and the limited circumstances in which we share it.
We do not use Meta platform data for independent advertising profiles, resale, or any unrelated purpose that is inconsistent with providing and securing the customer-requested service. Meta and WhatsApp may also process data under their own terms and privacy policies.
Legal Bases and Business Purpose
We process information to perform our contract with customers, to pursue legitimate business interests such as operating and improving the platform, to comply with legal obligations, and, where required, based on consent or customer instructions.
Our customers are generally responsible for ensuring they have an appropriate legal basis to collect, upload, and use the end-user data they control within Kshana API, including contact and messaging data.
How We Share Information
We do not sell personal information. We share information only as necessary to operate the service, comply with law, protect rights and safety, or complete a corporate transaction such as a merger, financing, or asset transfer.
Information may be shared with infrastructure, hosting, storage, analytics, authentication, communication, or support providers that process data on our behalf under appropriate contractual or operational controls.
Information may also be shared with integrations, channels, or downstream systems that a customer chooses to connect, including Meta and WhatsApp services used by that customer.
Service Providers and Processors
We use providers for cloud hosting, managed databases, caching and queues, object storage, email delivery, payments, monitoring, customer support, and Meta or WhatsApp connectivity. They receive only the information reasonably required for the service they perform and are subject to their own security, confidentiality, and legal obligations.
A customer's selection of an integration may cause information to be transmitted to that provider under the provider's terms. Customers should review enabled integrations and remove access that is no longer required.
Data Retention
We retain information for as long as reasonably necessary to provide the service, maintain security and audit records, resolve disputes, enforce agreements, and comply with legal or regulatory obligations.
Retention periods vary depending on the type of data, the customer's subscription status, contractual requirements, backup cycles, and operational or legal needs.
Data Access, Correction, and Deletion
Follow our Data Deletion Instructions for the required request details and verification process.
Account administrators can update or remove certain data directly within the product. Subject to applicable law and operational constraints, users and customers may also request access, correction, export, or deletion of personal information.
Requests can be sent to support@kshanaapi.com. Permanent deletion requests should follow the public Data Deletion Instructions. To protect privacy and security, we may verify the requestor's identity and authority before processing a request.
If a request relates to data controlled by one of our business customers, we may direct the request to that customer because they determine the purposes and means of processing their customer relationship data.
Security
Our current security practices and reporting channel are described on the Security page.
We use reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, encrypted transport, audit logging, environment separation, credential protections, and monitoring.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Security Incidents
We investigate suspected unauthorized access, disclosure, alteration, or loss according to the evidence and risk involved. Where notification is required, we will coordinate notices with affected customers, providers, or authorities as applicable.
Security concerns can be reported through the public Security and Support pages. Customers should promptly rotate exposed credentials and take reasonable steps to contain incidents within systems they control.
International Processing
Our service providers, infrastructure, or support operations may process information in multiple countries. Where required, we take reasonable steps to use appropriate safeguards for cross-border data handling.
Children
Kshana API is intended for business use and is not directed to children. We do not knowingly collect personal information directly from children through the service.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect product, legal, security, or operational changes. The updated version will be posted on this page with a revised effective date.
Contact Us
Firetminds Private Limited
Product: Kshana API
Kshana API Team: info@kshanaapi.com
Phone: +91 9346195204
