Back to home

Security & Data Protection

This page states what Jawab24 does to protect your data — and the limit of each statement. Where a protection covers part of our systems rather than all of them, it is written that way here instead of being rounded up.

What we deliberately do not claim

We do not claim that everything we store is encrypted at rest. What is encrypted at rest is the credential set: the access tokens for the Facebook, Instagram, WhatsApp and store accounts you connect, held under AES-256-GCM. Conversation content is held on access-controlled servers we operate, without a second layer of application-level encryption. The broader claim would be easier to write and impossible for you to check.

Access and authentication

  • You never type a Facebook, Instagram or WhatsApp password on our site. Connecting runs through Meta's own OAuth 2.0 flow, on Meta's domain, and your password never reaches us.
  • We request a limited set of permissions, each tied to a feature you can see. From your own account we receive your name, email address and profile picture — that is what creates your Jawab24 account, and the Privacy Policy lists it. Posting to your personal profile, reading your friends list, and access to your ads account are not among the permissions we ask for.
  • You can revoke our access at any moment from Facebook's Business Integrations settings, without asking us and without notice.

Encryption

  • In transit: TLS 1.2 and 1.3 only, with HTTP Strict Transport Security. Plain HTTP is redirected to HTTPS.
  • At rest: access tokens and store credentials are encrypted with AES-256-GCM, and decrypted only at the moment of an outbound API call.
  • Card numbers never reach us at all. Stripe receives payment details directly and processes them under its own terms.

Message integrity

Every webhook we receive is authenticated before the event is processed — but the four platforms do not all offer the same proof, so this is stated per platform rather than rounded up. Meta, Shopify and Salla sign each delivery: we recompute the signature as HMAC-SHA256, compare it in constant time, and reject anything that does not match.

Zid does not sign its deliveries at all. Per-store events are authenticated instead with an HTTP Basic credential we set when we subscribe, checked on every delivery and rejected on failure. Zid's App Market lifecycle notifications carry no credential of any kind, so we treat them as untrusted triggers: nothing in the body is read as fact — we re-read the state from Zid's own API before acting on it, and each store's trigger is rate-limited.

Hosting and residency

  • Your data is held on dedicated servers we operate inside the European Union, leased from Hetzner Online GmbH in Germany. The hosting provider is named here and in the Privacy Policy rather than left as "a cloud provider" — it is the one sub-processor that holds everything.
  • For merchants in Saudi Arabia, data processed under the Personal Data Protection Law is transferred to those EU servers under the safeguards set out in the Privacy Policy.

Who else receives your data

Every third party that receives any part of your data is named in the Privacy Policy, together with what it receives and why. There is no unnamed "trusted partners" category:

OpenAI, Meta, Stripe, Sentry, Resend, Google, Shopify, Salla, Zid, Hetzner

We never send an advertising or analytics provider the content of your messages, comments, customer conversations, or Business Info.

Deletion and retention

  • When you request deletion, we remove your personal data from our active systems within 30 days.
  • Residual copies inside encrypted backups are purged on the normal backup-rotation cycle, within 90 days.

Monitoring

  • Availability is measured by UptimeRobot, an independent third party, and published with its measurement window rather than as a bare number.
  • Application errors are captured in Sentry so faults are found before they are reported.

Reporting a security issue

If you believe you have found a vulnerability, write to us with enough detail to reproduce it. We will confirm receipt and tell you what we find.

support@jawab24.com

Check these statements yourself

None of the above should be taken on our word. Each of these documents states one part of it, and the status page is not ours to edit: