Privacy Policy
Last updated: 2026-08-06
Who we are
This website is operated by Sprig For Information Technology Services (“Sprig”), a registered entity based at Hadah Street, Sanaa, Yemen, which is also the operator of the Wared platform. For anything concerning privacy and data protection, contact us at [email protected].
Scope of this policy
This policy covers your visit to our website, your email enquiries to us, and Sprig’s role as the operator of Wared.
This website is served at sprig-ye.com and at other addresses that lead to it; this policy applies to your visit whichever one you arrive at.
Processing inside the platform itself — message content and media, per-channel identifiers, and how long each is kept — is governed by Wared’s own privacy policy at https://wared.sprig-ye.com/privacy. That document is the reference on those points; we do not restate it here.
What we collect from website visitors
This website has no signup or subscription forms and asks nothing of you in order to browse it. Email is the only way to reach us from here.
If you write to us, we receive whatever your message contains: your email address, your name, and any detail you choose to share about your organization or your request. We use that correspondence only to reply to you and follow up on what you asked.
Our infrastructure providers keep ordinary operational logs (IP address, browser type, request time) for security, fault diagnosis, and abuse prevention. We do not build visitor profiles from those logs and do not use them for tracking.
Cookies and tracking
This website sets no cookies at all. It runs no analytics or visitor-measurement tools and carries no advertising pixel from Meta or anyone else. That is why you will not see a cookie consent banner here: there is nothing to consent to.
The fonts used on these pages are hosted on our own servers rather than a third-party service, so your visit leaks nothing to a third party by that route.
Wared is a separate application and does require cookies to run a session, keep you signed in, and remember your interface language — not for tracking or advertising. Its own policy sets that out.
Our role in processing data
When your organization uses Wared, it is the controller of its customers’ data and Sprig acts as a processor on its behalf: we receive incoming conversations from WhatsApp, Messenger, and Instagram, then store and display them in the shared inbox so your team can reply.
We do not act on that data for our own purposes, and we process it only as far as operating the service requires and your organization instructs.
Information the platform processes
From service subscribers, our business clients: account data — company name, team member names, their email addresses, and phone numbers.
From end customers, via Meta’s official platforms (the WhatsApp Business Platform, the Messenger Platform, and the Instagram API): the customer’s identifier on that channel — a phone number on WhatsApp, an account identifier on Messenger and Instagram — the display name where the channel provides one, message content and media, timestamps, and associated metadata.
What is stored per channel, where it is stored, and how long it is kept are set out in Wared’s privacy policy at https://wared.sprig-ye.com/privacy.
How we use information
We use this data solely to provide the service: receiving, routing, and displaying conversations to your team and enabling replies, plus supporting you and securing the platform.
We do not sell your data or your customers’ data to anyone, we do not use it for advertising or to train AI models, and we do not read message content except as far as needed to resolve a fault you report to us or to meet a legal obligation.
Contractual basis and consent
We process your organization’s data in performance of our contract with it to provide the service.
End-customer data is processed on the basis of the consent your organization obtains from those customers before messaging them, in line with Meta’s policies for each of WhatsApp, Messenger, and Instagram. Obtaining that consent is the subscribing organization’s obligation, not ours.
Service providers (sub-processors)
We rely on a limited set of providers to operate the service. Each receives only what its role requires, and none may use the data for its own purposes. Each is identified by its processing role rather than its trade name, except the Meta platforms, whose accounts your organization connects itself:
Meta Platforms — message exchange over the WhatsApp Business Platform, the Messenger Platform, and the Instagram API.
A cloud hosting provider — application and database hosting in Germany (EU).
An object-storage provider — storage of media and attachments.
A network and content-delivery provider — protection and request routing in front of the website and the platform; requests pass through it and transport encryption (TLS) terminates there before reaching our servers, so it sees their content in transit.
A transactional email provider — outbound email from the platform, such as team invitations and account notifications.
An inbound email provider — hosting of the mailbox that receives the enquiries and deletion requests named in this policy.
We share data with no other party, and disclose it only where the law compels us to.
Storage locations and data transfer
Platform data is stored on servers in Germany (EU); media and attachments are held with an object-storage provider.
Because Sprig is registered in Yemen while its technical infrastructure sits outside it, operating the service involves transferring data across borders to providers in the European Union and the United States. We select providers committed to data protection, and data is encrypted in transit.
Retention
We retain conversation data for as long as the organization’s account remains open. On account closure we keep it for no more than 90 days for backup and compliance purposes, after which it is permanently deleted.
On a verified deletion request we permanently delete the data within 30 days. Operational backups purge on a rolling 30-day cycle.
Data security
We apply reasonable technical and organizational measures to protect data against unauthorized access, loss, or alteration: encryption of connections throughout, encryption of channel-connection credentials in the database, and access limited to the narrowest scope that does the job.
Your rights
You have the right to access, correct, or request deletion of your data, and to request a copy of it. To exercise any of these, contact us at [email protected] or follow the steps on the Data Deletion page.
If you are an end customer of an organization that uses Wared — that is, you messaged it on WhatsApp, Messenger, or Instagram — direct your request to that organization, which is the controller of your data; we assist it in carrying out what you ask.
Data deletion
To learn how to request deletion of your data, please see our dedicated Data Deletion page.
Our relationship with Meta’s platforms
Wared integrates with WhatsApp, Messenger, and Instagram through the official APIs provided by Meta Platforms, Inc. Sprig is an independent company: it is not part of Meta, not sponsored by Meta, and not endorsed by Meta, and those platform names and marks remain the property of their respective owners.
Your use of those channels remains subject to Meta’s own policies and terms alongside this policy.
Children’s privacy
Our services are directed at businesses and are not intended for children; we do not knowingly collect data from minors.
Changes to this policy
We may update this policy from time to time and will post every change on this page, updating the last-updated date shown above.
Contact
For any privacy enquiry, contact us at [email protected], or at: Hadah Street, Sanaa, Yemen.