Privacy Policy
Last updated: 30 September 2026 · GainWells Global Sdn. Bhd.
Summary. This policy covers our website, our contact form, and our Messenger, Instagram and WhatsApp messaging integration. When a business connects its Facebook Page, Instagram professional account or WhatsApp Business number to us, we receive the messages its customers send and deliver them to that business’s own inbox. We do that on the business’s behalf and for no other purpose.
We never sell personal data, never use it for advertising or profiling, and never use message content to train AI models. Messages we hold are deleted automatically after 90 days.
1. Who we are
10xstation is a product of GainWells Global Sdn. Bhd. (“10xstation”, “we”, “us”), a company registered in Malaysia. Our address is Vista Tower, The Intermark, 348 Jalan Tun Razak, 50400 Kuala Lumpur, Malaysia. You can contact us about anything in this policy at hello@10xstation.com.
We handle personal data in two different roles:
- As a controller for data about visitors to app.10xstation.com, people who use our contact form or email us, our client businesses and their staff (for example, console accounts), and the data needed to set up and manage a Page or WhatsApp number connection. We decide how and why this data is used.
- As a processor for the conversations between a client business and its customers on Messenger, Instagram and WhatsApp. The client business is the controller of those conversations. We process them only on its instructions, to deliver messages between it and its customers.
If you sent a message to a business that uses our service, that business is responsible for your conversation. You can contact the business directly, or contact us and we will help (see Your rights).
2. Data we collect and where it comes from
Website visitors and enquiries
- Contact form: your name, email address, the channels you select and the message you write. We send a confirmation to the email address you give us.
- Emails you send us: your email address, name and whatever you choose to include.
- Technical data: our servers record standard request information such as IP address, browser type, the page requested and the time. These logs never contain message content. Cloudflare Turnstile processes device and browser signals to check that a form submission comes from a person.
Client businesses and their staff
- Business contact details such as names, work email addresses and the business name, which we receive from the business when we agree to provide the service.
- Console account details for authorised staff, including a hashed version of the password (we never store passwords in readable form).
- Client accounts: when you sign up or are invited to a workspace, your name, email address, business name, a hashed password, your role (owner or member), and when you signed in.
- Subscriptions and payments: your plan, billing period, trial and renewal dates and subscription status. Payments are processed by Stripe: your card details go directly to Stripe and are never seen or stored by 10xstation. Stripe shares with us the billing name, email, address and the last four digits and expiry of the card so we can show them in your account and on invoices.
Data from the Meta Platform
When a business connects its Facebook Page and linked Instagram professional account, or its WhatsApp Business number, we receive data from Meta Platforms. This is described in detail in the next section.
Sources
We collect data directly from you (for example, through the contact form or email), from client businesses, and from Meta Platforms, Inc. and its affiliates (including WhatsApp) when a business connects its Page, Instagram account or WhatsApp number and when people message that business.
3. Meta Platform data
Our messaging integration uses Meta’s APIs. A person who is an admin of a business’s Facebook Page signs in with Facebook Login for Business and chooses which Pages and business assets to grant to 10xstation. A business connecting WhatsApp does so through Meta’s WhatsApp Embedded Signup, in the same way. We then process the following data from the Meta Platform.
| Category | What it includes |
|---|---|
| Connection data | Page ID and name, Instagram professional account ID and username, the client business portfolio ID, and access tokens. For WhatsApp: the WhatsApp Business Account ID, phone number ID, display phone number and verified business name. |
| Conversation data | Page-scoped IDs (PSID) and Instagram-scoped IDs (IGSID) of people who message the business, message text, attachment links (images, video, audio and files) and their type, timestamps, postback (button tap) payloads, and the messages the business sends. |
| Profile data | For people who message the business, and as permitted by Meta: their name or username and profile picture URL. Used only to label the conversation in the business’s inbox. |
| Scheduled posts | Posts and stories the business writes and schedules in 10xstation for its Page or Instagram account: text, link, the photos and videos it uploads, the time to publish, and, once published, the post ID and link Meta returns. |
WhatsApp Business Platform data
A business can connect a number it already uses in the WhatsApp Business app (known as coexistence), or a new number used only through the API. For WhatsApp we process:
| Category | What it includes |
|---|---|
| People who message the business | Their phone number (when WhatsApp provides it), WhatsApp business-scoped user ID (BSUID), profile name, and username if they use one. |
| Messages | Message content and media (images, audio, video, documents, stickers, shared locations and shared contacts), delivery and read statuses, reactions, and the messages the business sends. Media files are not stored by 10xstation: they are fetched from Meta only when an authorised user or the client business’s system requests them. |
| WhatsApp Business app contacts (coexistence only) | Contact names from the business’s WhatsApp Business app address book, if the business chooses to share them. They are synced once when the number is connected and again when they change. |
| Chat history (coexistence only) | If the business chooses to share it, Meta makes up to 180 days of chat history available. We import only messages from the last 90 days, in line with our retention period, and sync messages the business later sends from the WhatsApp Business app into its inbox. |
| Message templates | The templates the business creates: name, category, language, content and Meta’s approval status. |
How we use it
We use Meta Platform data solely to deliver messages between the client business and its customers:
- forwarding incoming messages to the client business’s own system;
- sending the client business’s replies and, on its instruction, its WhatsApp template messages through Messenger, Instagram or WhatsApp; and
- showing the conversation to the client business’s authorised staff; and
- publishing the posts and stories the client business wrote and scheduled, to its own Page or Instagram account, at the time it chose.
Connection data is also used to set up, maintain and remove the connection (for example, to subscribe the Page or WhatsApp Business Account to our webhooks, manage message templates, start the contact and chat history sync a business chose to share, and unsubscribe on disconnection).
What we never do with it
- We never sell it.
- We never use it for advertising, marketing or profiling, including our own marketing.
- We never message anyone except on the client business’s instruction.
- We never use it to train AI models.
- We never share it with anyone other than the client business that owns the Page, Instagram account or WhatsApp number, and the sub-processors listed below that host and run the service.
- We never publish anything the client business did not write and schedule itself, and we do not read or manage ads, access Page insights, or read personal Facebook profiles.
The Meta permissions we request, and the reason for each, are listed on our Messaging Integration page. We handle Meta Platform data in line with the Meta Platform Terms and Developer Policies, and WhatsApp data in line with the WhatsApp Business terms and policies that apply to it.
4. How we use data and our lawful bases
We process personal data in line with Malaysia’s Personal Data Protection Act 2010 (PDPA). Where the EU or UK General Data Protection Regulation applies to you, the bases below are our lawful bases under it.
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries through our contact form or by email, and following up with potential clients | Legitimate interests (answering people who contact us and running our business), or steps taken at your request before entering into a contract |
| Providing the service to client businesses: accounts, workspaces, team invitations, staff console accounts, Page and WhatsApp number connections, and sending service emails (email confirmation, password reset, invitations) | Performance of our contract with the client business |
| Taking payment for subscriptions, running free trials, sending invoices and handling failed payments | Performance of our contract, and legal obligation (keeping tax and accounting records) |
| Delivering messages between a client business and its customers on Messenger, Instagram and WhatsApp, including sending WhatsApp template messages, importing the WhatsApp chat history and contacts a business chooses to share, and managing its message templates | We act as a processor on the client business’s instructions. The client business, as controller, is responsible for having its own lawful basis for messaging its customers, including any opt-in WhatsApp requires |
| Keeping the website and service secure, preventing spam and abuse (including Cloudflare Turnstile), and handling deletion requests | Legitimate interests (protecting our service, our clients and the people who message them), and legal obligation where it applies |
| Complying with law, keeping business records and dealing with legal claims | Legal obligation and legitimate interests |
| Any use where we specifically ask for your consent | Consent, which you can withdraw at any time by contacting us |
6. International transfers
We are based in Malaysia. Our service runs on servers rented from a cloud hosting provider, and some of those servers and our other providers (such as Meta, Stripe and our email provider) may process data outside Malaysia. When personal data is transferred outside Malaysia, we do so only as the PDPA allows and put appropriate safeguards in place, such as contractual commitments from the recipient to protect the data to a standard at least equivalent to the PDPA, and, where the EU or UK GDPR applies, the Standard Contractual Clauses or the UK International Data Transfer Agreement. You can ask us for more information about these safeguards at hello@10xstation.com.
7. How long we keep data
We keep personal data only for as long as we need it:
| Data | How long we keep it |
|---|---|
| Access tokens | Until the Page or WhatsApp number is disconnected, the client business ends the service, or we receive a deletion request. They are then deleted immediately. |
| Messages (including imported WhatsApp chat history), attachment and media references, and profile names, usernames and pictures held by 10xstation | 90 days from when the message was received or sent, then deleted automatically. The client business keeps its own copy in its inbox under its own policy. |
| Contacts synced from the WhatsApp Business app | Until the WhatsApp number is disconnected, or 90 days after the contact was last updated, whichever is sooner. |
| WhatsApp message templates | While the WhatsApp number is connected |
| WhatsApp media files | Not stored by 10xstation. Fetched from Meta only when requested. |
| Scheduled posts, and the photos and videos uploaded for them | Post records for 90 days after they are published, cancelled or fail. Uploaded photos and videos are held at a private, unguessable address so Meta can fetch them when publishing, and deleted 7 days after their post is done (or after 1 day if never used in a post). |
| Raw webhook event records | 14 days |
| Logs of deliveries to client systems | 30 days |
| Data deletion request records (confirmation code, date and status, with no message content) | 12 months |
| Server logs (no message content) | Up to 30 days |
| Client account details (name, email, role) | While the account is active, and deleted within 30 days after you ask us to close it |
| Subscription, invoice and payment records | For 7 years after the end of the year they relate to, as Malaysian tax law requires |
| Contact form submissions and enquiry emails | As long as needed to respond and for our business relationship, up to 24 months |
8. Security
We use technical and organisational measures appropriate to the data we handle, including:
- HTTPS/TLS encryption for all traffic;
- encryption of access tokens at rest using AES-256-GCM;
- verifying every webhook from Meta using its X-Hub-Signature-256 signature;
- signing every delivery to a client system with HMAC-SHA256 and a secret unique to that client;
- authenticating client API calls with per-client keys and signatures;
- individual staff console accounts with hashed passwords;
- never writing message content to application logs; and
- least-privilege access, both for our staff and for the Meta permissions we request.
No system is completely secure, but we work to protect your data and will act promptly, and notify affected parties and the Personal Data Protection Commissioner where the PDPA requires, if a breach occurs.
9. Your rights
Under the PDPA, you have the right to:
- access the personal data we hold about you;
- correction of data that is inaccurate, incomplete, misleading or out of date;
- withdraw consent to our processing of your data, where we rely on consent;
- prevent processing that is likely to cause you damage or distress, and processing for direct marketing;
- data portability, to have data you gave us transmitted to another controller where this is technically feasible; and
- complain to Malaysia’s Personal Data Protection Commissioner at pdp.gov.my. We would appreciate the chance to deal with your concern first, so please contact us.
If you are in the European Union or the United Kingdom, you also have the rights the GDPR gives you, including erasure and restriction, and you can complain to your local data protection authority.
To exercise any of these rights, email hello@10xstation.com. We may need to verify your identity before acting on a request. We will respond within 21 days, as the PDPA requires.
If your request relates to a conversation with a business that uses our service, that business is the controller. We will help it respond, and we will act on its instructions. If you contact us directly, we will handle the request as described in the next section and let the business know.
10. Data deletion
There are several ways to have data deleted:
- If you connected a Page using Facebook Login, remove the 10xstation app in your Facebook settings. Meta then sends us a data deletion request automatically. We delete the access tokens and all conversation data stored for the Pages you connected, and give you a confirmation code so you can check the status of your request.
- If you messaged a business that uses 10xstation, email hello@10xstation.com with the business name and your Facebook or Instagram name. We will verify the request, delete your messages within 30 days, and tell the business so it can remove its own copy.
- If you messaged a business on WhatsApp, email hello@10xstation.com with the business name and your WhatsApp number. We will verify the request, delete your messages, contact details and profile data within one month, and tell the business so it can remove its own copy.
- If your business connected a WhatsApp number, disconnecting it in your 10xstation account deletes our access tokens for it. You can also remove 10xstation in Meta Business Suite → Settings → Integrations, or in WhatsApp Manager → Partners.
Full instructions are on our data deletion page.
12. Children
Our website and service are intended for businesses and are not directed at children under 13. We do not knowingly collect personal data from children. Some of our client businesses, such as education providers, serve children, but the people who message them are typically parents or guardians. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. When we do, we will change the “Last updated” date at the top of this page. If a change significantly affects how we use personal data, we will take reasonable steps to let our client businesses know.
14. Contact us
For any question about this policy or your personal data, contact:
GainWells Global Sdn. Bhd.Vista Tower, The Intermark, 348 Jalan Tun Razak50400 Kuala Lumpur, MalaysiaEmail: hello@10xstation.com