How XetaX uses WhatsApp and Facebook

Two parts of XetaX talk to Meta, and only after a business connects them itself. This page says exactly what is requested, what is stored and how to take it back.

In one paragraph

XetaX is a CRM. A business connects its own WhatsApp Business number so its team can chat with customers from the CRM instead of a phone, and connects its own Facebook Page so the leads its ads produce land in the CRM instead of a spreadsheet. XetaX never posts on anyone's behalf, never runs or edits ads, and never touches accounts the business has not connected.

1. WhatsApp Business Platform

What the business gets

How it is connected

Through Meta's Embedded Signup, inside the panel. The business signs in with its own Facebook account and picks its own WhatsApp Business account and number. XetaX receives an access token for that account only.

What is stored

DataWhy
WhatsApp Business account id, phone number id, display numberto send and receive on the right number
Access token, encrypted at rest (AES-GCM)to call Meta's API on the business's behalf; never shown in the browser
Messages sent and received, with the customer's phone number and namethe inbox itself, and the customer's history on their record
Template names and their approval statusso the panel knows what may be sent outside the 24-hour window

2. Facebook & Instagram lead ads

What the business gets

Permissions requested, and why

PermissionUsed for
pages_show_listshowing the business its own Pages so it can pick the right one
pages_read_engagementreading the Page's name and basic details for the connection screen
pages_manage_metadatasubscribing that Page to our webhook so its leads are delivered
leads_retrievalreading the answers of a lead form the customer just submitted
ads_readreading spend, impressions and results per ad, to report cost per lead and per sale
business_managementlisting the ad accounts the business owns, so it can pick one

XetaX does not request ads_management. It cannot create, edit, pause or spend on ads. Ads stay entirely in the business's own Ads Manager.

What is stored

DataWhy
Page id and name, Instagram account id, ad account idto know which Page and account the workspace connected
Page and user access tokens, encrypted at restto receive leads and read spend; never shown in the browser
The lead's own answers — typically name, phone, email and the form's questionsthis becomes the CRM record the business follows up
Which campaign and ad the lead came fromso the business can see which campaign produced sales
Daily spend, impressions, clicks and results per adthe cost-per-lead and cost-per-sale report

What XetaX never does

Where the data lives

On XetaX's own servers in a single database per deployment, separated by workspace: every row carries the id of the business that owns it, and a request can only ever read its own. Tokens are encrypted with a key held only on the server. Traffic runs over HTTPS. Meta's webhooks are accepted only when their signature matches our app secret.

How long it is kept

For as long as the business keeps its workspace. It can delete any record, chat or document itself at any time, and closing the account deletes everything. Details and timings are on the Data deletion page.

Taking access back

Either way XetaX immediately stops sending, receiving and reading. Nothing further is requested from Meta unless the business connects again.

Contact

Questions about this integration, or a request about data: xetacrm@gmail.com or +91 85878 12664. See also the Privacy Policy and Terms.