Channel policies

Messaging Channel Policies

For every channel you connect: what you agree to, whose terms apply, what data flows, and what we enforce.

Last updated: 15.09.2026

1. Overview: connecting a channel means accepting its provider's terms

When you connect a messaging channel to the Platform — WhatsApp, Instagram, Messenger, X, the website widget, or email — you accept that channel provider's terms in addition to our Terms & Conditions and Acceptable Use Policy. We are a technology provider only: with Meta we operate as a "Tech Provider", and you are the business that owns the number, the page, the account, and the relationship with your customers.

Your customers' data that flows through these channels is processed by us as a processor on your behalf, under the Privacy Policy and the Data Processing Agreement. The channel providers named here are listed on the Subprocessors page.

ChannelProviderThird-party terms that applyConnection method
WhatsAppMeta (WhatsApp Cloud API)Meta's WhatsApp Business Terms and Messaging PolicyMeta Embedded Signup
Instagram (DMs)Meta (Messenger Platform)Meta Platform Terms and Community StandardsFacebook Login for Business
Facebook MessengerMeta (Messenger Platform)Meta Platform Terms and Community StandardsFacebook Login for Business
X (DMs)X CorpX Developer Agreement and the X RulesOAuth 2.0 (PKCE)
Website chat widgetCapi AgentThis policy and your own privacy noticewidget.js script on your storefront
EmailResendResend's terms and your own domain reputationDNS verification of your domains from the dashboard
TikTok and SnapchatNot available (nothing is sent)

2. WhatsApp (Meta WhatsApp Business Platform)

You connect WhatsApp through Meta Embedded Signup. During the connection you grant us the whatsapp_business_management and whatsapp_business_messaging scopes so that we can receive your customers' messages and reply on behalf of your number. The number and your Meta Business account remain yours; we only operate on them.

  • Business verification: Meta may require verification of your Meta Business account before allowing full sending. That verification is between you and Meta, and we cannot do it for you.
  • The 24-hour window: after a customer's last message you can reply freely for 24 hours. Outside that window we send only message templates approved by Meta. Template approval is Meta's decision, not ours.
  • Opt-in: Meta's policies require that the customer agreed to receive messages from you before any message you initiate. You are responsible for obtaining and documenting that consent.
  • Quality rating: we monitor the quality rating Meta assigns to your number every 6 hours. If the rating drops, we automatically throttle or defer sending to protect your number from restriction or blocking.
  • Conversation fees: Meta bills conversation fees to you directly. They are not part of your subscription with us.
  • Disconnecting: from /dashboard/integrations?tab=channels; this clears the number and the tokens stored with us. Deauthorizing the app from your Meta Business settings also stops our access.

What we enforce on WhatsApp: the consent gate on every send, detection of opt-out keywords in Arabic and English, a daily sending budget for the number, and quiet hours in your store's timezone (once you enable sending controls — see the dedicated section below).

3. Instagram and Facebook Messenger (Meta Messenger Platform)

Both channels are connected through Facebook Login for Business on the same Meta app. You need a Facebook Page, and for Instagram a professional (business) Instagram account linked to that Page.

  • Scopes for Messenger: pages_show_list, pages_messaging, pages_manage_metadata, business_management.
  • Instagram adds: instagram_basic and instagram_manage_messages.
  • The Page access token is stored encrypted (AES-256-GCM), is never written to logs, and never reaches the browser.
  • The 24-hour messaging window is enforced on our side: after it, we do not send a new message until the customer messages you again.
  • Meta's Platform Terms and the Community Standards for Facebook and Instagram apply to you, and you are responsible for the content of messages sent in your Page's name.

Disconnecting: from /dashboard/integrations?tab=channels clears the Page token and the stored connection data. You can also deauthorize the app from your Facebook or Instagram settings, which stops our access immediately. Any conversations that remain with us you delete from the dashboard or by request — details on the Data Deletion page.

4. X (direct messages)

You connect your X account through OAuth 2.0 with PKCE. Scopes: tweet.read, users.read, dm.read, dm.write, and offline.access — the last one so that we can renew access without you signing in again every time.

  • The refresh token is stored encrypted and refreshed on every send.
  • The X Developer Agreement and Policy and the X Rules apply to you, including the direct-message limits imposed on your account. We do not attempt to bypass those limits.
  • Disconnecting from the dashboard clears the credentials. Revoking the app from your X settings also stops our access.

5. Website chat widget

The widget is a script (widget.js) you add to your storefront, connecting your visitors directly to the agent. There is no external channel provider here — we are the provider, and the rules that apply are this policy and your own privacy notice.

  • The widget stores a random visitor id and an attribution reference in the browser's localStorage — first-party to your store's domain. We set no third-party cookies on your storefront.
  • Widget settings are cached for 60 seconds, so any change to its appearance or text appears within a minute.
  • Disclosure is your responsibility: your website's privacy notice must state that the chat runs on an AI assistant and that AI Sales Agent processes it as a processor on your behalf. You can enable an optional notice text shown inside the widget (for example "AI assistant").
  • The agent does not present itself as human when asked directly — that rule comes from the AI Policy and applies to the widget like any other channel.

6. Email (Resend)

Sending and receiving go through Resend. You use two domains you own: a support address for inbound customer conversations and a marketing sender for campaigns. You verify each domain with DNS records from the dashboard before it goes live.

  • An unsubscribe link is mandatory in every marketing email. We add an unsubscribe token to each message; unsubscribing is recorded immediately as a consent event and stops marketing sends to that address.
  • Your sending-domain reputation is yours: bounces and spam complaints land on your domain, not on a shared one. Sending without consent damages your ability to reach inboxes.
  • Outbound attachments are not supported at present; links to files are the alternative.
  • Links in the messages we compose become tracking links — see the Tracking section below.

7. Channels not available: TikTok and Snapchat

We do not offer TikTok or Snapchat as messaging channels. If you see their name somewhere inside the product, it is only a reserved entry; we neither receive nor send any message through them. Do not promise your customers contact through them via the Platform.

9. Sending controls

Sending controls are off by default and you enable them. Once enabled they apply to all campaigns and automations:

  • Quiet hours in your store's timezone, and a Friday prayer pause.
  • A daily budget for WhatsApp sends, a weekly cap on marketing messages per customer, and cooldowns between messages.
  • Defer, not drop: a message that hits a control is deferred to the next allowed time, never deleted.
  • Messages in the TRANSACTIONAL or SERVICE class are exempt from marketing controls only with evidence: an order of this customer, or an inbound message from them within the last 24 hours. Without evidence they are treated as marketing.

Independently of these controls, throttling based on the WhatsApp quality rating is always active.

10. Turkey: İYS

If you send commercial electronic messages to recipients in Turkey, you are bound by İYS (the Message Management System) in addition to KVKK. The Platform is not integrated with İYS: you must register your business there and sync your customers' consents yourself before sending. Our consent gate protects your number and your domain, but it does not replace recording consent in İYS.

11. Link tracking

  • Links in the messages we compose are rewritten as /r/:token so that clicks and orders can be attributed to your campaigns. WhatsApp template button URLs are excepted because Meta approves them as they are.
  • Suspect clicks (bots, link previews) are labelled as suspect and not deleted, so your reports stay honest and auditable.
  • Attribution events are kept for 400 days for year-over-year comparison. Mention this tracking in your own privacy notice; our side of it is described on the Cookies & Local Storage page.

12. Your responsibilities as a merchant

  • Obtain explicit, documented consent before any marketing message, and honour opt-outs on every channel.
  • Comply with Meta's policies for WhatsApp, Messenger, and Instagram, the X Rules, Resend's terms, and your store platform's policies — and bear any restriction or ban that results from violating them.
  • Publish your own privacy notice naming Capi Agent as a processor and mentioning the widget, the AI, and link tracking.
  • Pay third-party fees directly to their providers (Meta conversation fees in particular).
  • Register with İYS if you address recipients in Turkey.
  • Answer your customers' requests about their data — you are the controller, and we assist you within 30 days at most.

13. Our responsibilities

  • We verify the signature of every inbound webhook from Meta, X, and Resend (HMAC-SHA256) before processing it.
  • We store every access token encrypted (AES-256-GCM), never log it or send it to the browser, and clear it when you disconnect.
  • We enforce the consent gate, the 24-hour window, and quality-rating monitoring automatically, even if you have not enabled sending controls.
  • If the model provider fails on a channel, we try the next provider you have configured; if all fail we hand the conversation to a human — we never go silent. And once a person on your team takes over a conversation, the agent does not take it back automatically.
  • We do not use your customers' messages for any purpose of our own, nor to train models, nor share them between merchants. Security details are on the Security page.

14. Changes to this policy

Provider terms (Meta, X, Resend) change on their side and outside our control, and apply to you as those providers determine. For material changes to what we ourselves enforce on the channels, we notify you by email or an in-dashboard notice before they take effect. The last-updated date is shown at the top of the page.

This page describes the Platform's actual practice on each channel and does not constitute legal advice. For any question, email us at legal@capiagent.com.