Opt-out and compliance
How customers opt out, what an opt-out stops, how your system hears about it, and how long we keep integration data.
How a customer opts out
A contact is opted out when:
- they send a message that is just
STOP(any letter case) on WhatsApp, WhatsApp QR, Telegram, Messenger or Instagram; - they follow the opt-out link in a broadcast;
- someone on your team marks them opted out in the dashboard.
They are opted back in when they send START, or when someone on your team opts them
back in. Opt a customer back in only when they asked for it.
What an opt-out stops
| What | For an opted-out contact |
|---|---|
| Broadcasts | Skipped |
| Flows | Do not start; a run waiting for its next step ends |
| Flow triggers | Refused with 409 and "status": "opted_out"; nothing is sent |
Treat opted_out as final for that event: do not retry it, and do not work around it by
messaging the customer another way.
How your system hears about it
contact.opted_outfires when a contact opts out. It does not fire again for a contact who is already opted out.- Opting back in is
contact.updatedwith"optedOut": false. - Every
contact.*event carries the contact's currentoptedOut.
If your system sends messages to customers through other tools, apply the opt-out there too.
Data your integration receives
Events carry customers' names, phone numbers and what they wrote. That is why endpoints must use HTTPS and every request is signed. On your side, keep the signing secret on your server, store only the fields you use, and delete them on the schedule your own policies set.
How long we keep integration data
| Data | Kept |
|---|---|
| Webhook delivery log: each delivery, its body and the first 2 KB of your answer | 30 days after the delivery was created |
| Events waiting to be delivered | 7 days |
| The last request a flow trigger URL received, kept for mapping fields | 30 days after it arrived; each new request replaces it |
| Flow runs and the values they collected | 90 days after the run ends |
| A run's step-by-step history | 30 days |
| Log of calls to your API: host, path, status and timing, no bodies | 14 days |
| Records of templates automations sent | 30 days |
Conversations and contacts are not part of this schedule.