How XetaX uses WhatsApp and Facebook
Two parts of XetaX talk to Meta, and only after a business connects them itself. This page says exactly what is requested, what is stored and how to take it back.
In one paragraph
XetaX is a CRM. A business connects its own WhatsApp Business number so its team can chat with customers from the CRM instead of a phone, and connects its own Facebook Page so the leads its ads produce land in the CRM instead of a spreadsheet. XetaX never posts on anyone's behalf, never runs or edits ads, and never touches accounts the business has not connected.
1. WhatsApp Business Platform
What the business gets
- A shared team inbox for their own WhatsApp Business number.
- Message templates, submitted to Meta for approval from the panel.
- Campaigns to their own customer list, and automatic messages such as an order update.
- An optional AI assistant that answers on the number, hands over to a human on request.
How it is connected
Through Meta's Embedded Signup, inside the panel. The business signs in with its own Facebook account and picks its own WhatsApp Business account and number. XetaX receives an access token for that account only.
What is stored
| Data | Why |
|---|---|
| WhatsApp Business account id, phone number id, display number | to send and receive on the right number |
| Access token, encrypted at rest (AES-GCM) | to call Meta's API on the business's behalf; never shown in the browser |
| Messages sent and received, with the customer's phone number and name | the inbox itself, and the customer's history on their record |
| Template names and their approval status | so the panel knows what may be sent outside the 24-hour window |
2. Facebook & Instagram lead ads
What the business gets
- Every submission of its own lead-form ads becomes a CRM record within seconds.
- Spend and results per campaign, joined to what those leads turned into — cost per lead and cost per sale.
Permissions requested, and why
| Permission | Used for |
|---|---|
pages_show_list | showing the business its own Pages so it can pick the right one |
pages_read_engagement | reading the Page's name and basic details for the connection screen |
pages_manage_metadata | subscribing that Page to our webhook so its leads are delivered |
leads_retrieval | reading the answers of a lead form the customer just submitted |
ads_read | reading spend, impressions and results per ad, to report cost per lead and per sale |
business_management | listing the ad accounts the business owns, so it can pick one |
XetaX does not request ads_management. It cannot create, edit, pause or spend on
ads. Ads stay entirely in the business's own Ads Manager.
What is stored
| Data | Why |
|---|---|
| Page id and name, Instagram account id, ad account id | to know which Page and account the workspace connected |
| Page and user access tokens, encrypted at rest | to receive leads and read spend; never shown in the browser |
| The lead's own answers — typically name, phone, email and the form's questions | this becomes the CRM record the business follows up |
| Which campaign and ad the lead came from | so the business can see which campaign produced sales |
| Daily spend, impressions, clicks and results per ad | the cost-per-lead and cost-per-sale report |
What XetaX never does
- Post, comment or message as the business on Facebook or Instagram.
- Create, edit or pause ads, or move budget.
- Read a Page's followers, private inbox or anything unrelated to its lead forms.
- Sell data, share it between customers, or use one business's data for another's benefit.
- Use business data to train AI models.
Where the data lives
On XetaX's own servers in a single database per deployment, separated by workspace: every row carries the id of the business that owns it, and a request can only ever read its own. Tokens are encrypted with a key held only on the server. Traffic runs over HTTPS. Meta's webhooks are accepted only when their signature matches our app secret.
How long it is kept
For as long as the business keeps its workspace. It can delete any record, chat or document itself at any time, and closing the account deletes everything. Details and timings are on the Data deletion page.
Taking access back
- In XetaX — WhatsApp → Setup → Disconnect, or Facebook Ads → Disconnect. Tokens are deleted at once.
- In Meta — Business Settings → Business Integrations, or Facebook → Settings → Apps and Websites, and remove XetaX.
Either way XetaX immediately stops sending, receiving and reading. Nothing further is requested from Meta unless the business connects again.
Contact
Questions about this integration, or a request about data: xetacrm@gmail.com or +91 85878 12664. See also the Privacy Policy and Terms.