WhatsApp Business Platform
WhatsApp Business Platform Client Terms
v1.0 · Last updated 12 September 2026
These Terms govern one thing: connecting a WhatsApp number to Gango Tech Ltda.’s messaging service and using it to message people. They do not replace the terms of the product you subscribe to — GerTruck or Ternavi — and they never reduce a right those terms give you. Section 3 says exactly how the two fit together.
This document is published in English and in Portuguese. Between Gango Tech Ltda. and you, the Portuguese version prevails — see section 26. The English text is the canonical version filed with Meta and written for readers outside Brazil. The Portuguese companion is at /pt-br/legal/termos, and what we do with personal data is in the Privacy Policy.
1.Who these Terms bind, and what they cover
Gango Tech Ltda., CNPJ 50.086.381/0001-41 (“Gango”, “we”), builds and operates the software products GerTruck and Ternavi and the messaging service that delivers their messages. “Client” (“you”) means the business that connects a WhatsApp number through one of those products, or whose messages are delivered over a number we operate.
What these Terms cover
- Connecting a WhatsApp Business Platform number, and the credentials that connection needs.
- Sending and receiving messages over that number through our service, including templates, the 24-hour service window, and delivery records.
- The obligations Meta requires us to pass on to you as a condition of operating on its platform — Part III of this document.
- How the cost of messages works, who is billed by whom, and what we count.
- Disconnection, suspension, and what happens if Meta restricts or bans the number.
What they do not cover
- The product itself — subscription, plans, prices, features, accounts, payments. Your product's Terms of Use govern those.
- Anything you do on WhatsApp outside our service. If you also message people from the same number using another tool, these Terms say nothing about it.
- Your relationship with Meta. Where you bring your own WhatsApp Business Account, that relationship is directly between you and Meta.
Acceptance and version
These Terms apply to you from the moment a number is connected for your business and for as long as messages are sent on your behalf over the channel. The version in force is the one identified at the top of this page by number and date; facts that occurred while an earlier version was in force remain governed by that version.
The connection point is where we want this document affirmed: an affirmation naming these Terms by URL and version date, never pre-checked. A pre-checked box erases the only evidence that you were informed, which is the reason we do not use one.
What the connection screen does not show yet
That affirmation is not on the connection screen of either product today. Until it is, we do not claim a click as proof that you were told. The notice is this published document, and these Terms bind you by the act of connecting a number and by continued use of the channel — not by a record of consent we do not have.
2.Definitions
Where a term below is Meta’s, we adopt Meta’s meaning rather than inventing our own. This matters for one term in particular: an obligation flowed down without adopting Platform Data as Meta defines it flows nothing down.
- WhatsApp Business Platform (also “Cloud API”) — Meta’s official programmatic messaging platform. It is the only path our service supports. There is no pairing and nothing is scanned: a number is registered in Meta Business Manager with a six-digit PIN.
- WABA — a WhatsApp Business Account in Meta Business Manager. It owns the number and the credential.
- Platform Data — all data and information you or we obtain from or through the WhatsApp Business Platform. It includes message content, media and captions, a recipient’s phone number and WhatsApp ID, the profile name WhatsApp exposes, message identifiers, delivery statuses, pricing and conversation-category metadata, template metadata, and the phone number and WABA identifiers. It also includes the access token.
- Client Number — a number in your own WABA, connected with your own credential. It is the number on your cards, your website and your shopfront.
- Platform Number — one number per product, in Gango’s own WABA, used for messages from the product to its tenants. See section 8.
- Template — a message body Meta approved in advance, and the only thing that can start a conversation or reach someone outside the service window.
- Service window — the 24 hours following the last message a person sent to your number, inside which free-text replies are accepted.
- Opt-in — the permission Meta requires you to hold before messaging someone. It is Meta’s requirement and is not an LGPD consent; see section 9.
- Meta Terms — Meta’s own published rules for the platform, including the WhatsApp Business Terms of Service, the WhatsApp Business Messaging Policy, the Meta Platform Terms and the Meta Developer Policies, each as Meta amends them.
- Product Terms — the Portuguese-language Terms of Use and Privacy Policy of the product you subscribe to, published at gertruck.com.br/termos or ternavi.com.br/termos.
3.Order of precedence, and why it is asymmetric
Where documents disagree, this is the order:
- 1. A written contract signed between you and Gango, including its data protection annex.
- 2. Your Product Terms.
- 3. These Terms.
- 4. Technical documentation, integration guides and support material.
The order is not symmetric, and the asymmetry is the point. These Terms prevail over 2 and 4 only where they add an obligation, a prohibition or a disclosure that arises from Meta’s rules for the channel — which is what this document exists to do. They never prevail where applying them would reduce a right that a signed contract or your Product Terms give you. If a reading of these Terms would have that effect, that reading is not adopted and the higher document governs.
Repeating what your Product Terms already say, because it is true of this document too: these Terms are the instrument that governs the channel between Gango and you while no specific written contract is signed between the parties. Once such a contract is signed, it prevails over these Terms in whatever it provides differently, taking effect from its signature and without reaching earlier facts, which remain governed by the version of these Terms in force at the time.
We write the asymmetry down rather than leaving it to interpretation for two reasons. Article 424 of the Civil Code strikes down, in a contract of adhesion, the advance waiver of a right resulting from the nature of the transaction; and article 423 requires ambiguities to be read against the party that drafted them — which is us. A precedence clause that could only ever work in our favour is the kind of clause article 51, IV of the Consumer Protection Code removes.
4.Relationship with Meta’s terms
The channel is Meta’s product. Your use of it is also subject to the Meta Terms, and where you bring your own WABA you have your own direct relationship with Meta under them. Meta is not a party to these Terms.
- Gango operates as a technology provider on Meta's platform. Meta requires a provider in that position to impose on its clients obligations at least as protective as the ones Meta imposes on itself. Part III of this document is that flow-down, and it is the reason this document exists as a separate instrument.
- Meta's rules apply to you directly. They change without passing through us, and we are not able to grant a permission Meta withholds or to keep a permission Meta removes.
- Where Meta's rules and these Terms conflict, Meta's rules govern what Meta will allow. These Terms cannot make a prohibited message deliverable.
- Meta sets the price of messages and the conversation categories. Neither is negotiated with us.
- We do not hold a platform-wide credential that reaches every Client's account. The credential is per number and belongs to the WABA that owns it — a platform token valid for everyone would give us access to every Client's WhatsApp account, which is why there is none.
5.What you have to provide before a number can be connected
Five prerequisites, in this order. Each depends on the one before it, and out of order the next simply does not appear on Meta’s screen. They are written out here rather than linked, because an obligation that depends on the reader following a link is not an obligation.
- 1. A WhatsApp Business Account (WABA) in Meta Business Manager.
- 2. Business verification approved by Meta. Meta asks for company documents and this takes days, not minutes.
- 3. The number added to that account and registered, which includes confirming a six-digit PIN. A number already in use on the consumer WhatsApp app has to leave it first.
- 4. A permanent access token from a system user, with permission to send messages.
- 5. The number’s identifier (the
phone_number_id), shown on Meta’s API configuration screen.
The commonest first-connection failure is using the temporary token the configuration screen displays prominently: it is valid for 24 hours. What works is the permanent token from step 4. If a connection was refused saying the token had expired, this is almost always why.
The clicks inside Business Manager change without notice, so we point at Meta’s own documentation for them instead of describing Meta’s screens. What does not change is the order above.
6.The access token: whose it is, and what disconnection does
The token from step 4 gives access to your WhatsApp account. It is typed into the connection screen and goes straight to the service, which verifies it against Meta’s Graph API before storing anything.
- Verification first: a credential Meta rejects produces an error and nothing is written — there is no half-created instance and no stored credential. A Graph API that does not answer produces a different error, also without writing. A successful connection is already live; there is no wait for a background job to confirm it.
- We never ask for the token by chat, e-mail or ticket, and you should never send it that way. A token that passes through one of those becomes a copy in a channel nobody audits and nobody knows how to revoke. If someone asks you for it that way, the request is not from us.
- The token is never returned by any of our API responses and is never written to any log. That is enforced at compile time: the object our API returns for an instance has no field for the token, and adding one would break the published contract.
The token is not encrypted in our database
It is held in cleartext in a database column, by design. Encrypting it with a key that lives in the same process moves the secret without putting it out of reach of whoever reaches the database. What protects it is access control over the database, the fact that no API response has a field for it, and the fact that it is never logged. We state that plainly rather than claiming a cryptographic protection the column does not have.
Disconnection deletes our copy, and only our copy
- Disconnecting a number deletes the instance row, the credentials we hold, and by database cascade each contact's 24-hour service window.
- It does not revoke anything at Meta. The token stays valid at Meta until you revoke it yourself in Business Manager. If your intention was to cut access, that is the step that does it.
- There is no logout route. It was removed with the old provider and now answers 404. The way to silence a number is to revoke its token at Meta.
- When you do, our reconciliation reads Meta's authentication error (code 190, OAuthException), translates it to a lost session, and that number's queue starts damming. Nothing is discarded. Reconciliation runs on an hourly job, so the queue dams within the hour rather than instantly.
One operational note that is wider than the hour
Our own runbook has said the queue dams “within five minutes”. The scheduled job that detects a lost session runs hourly. Between the revocation and the next run, sends against the revoked token fail and are retried rather than delivered — they are not lost, but they are also not silent. We state the hour because that is what the schedule does.
7.The service window, templates, and error 131047
The Cloud API refuses free text to anyone who has not written to you in the last 24 hours. Meta’s error for it is 131047. Our service checks the window before calling Meta:
- Inside the window, free text goes out.
- Outside the window, a free-text message becomes an immediate dead letter, with the cause telling you to resend it as an approved template. It is not retried, because retrying cannot change the answer.
- A template always goes out, inside the window or not.
- If Meta itself answers 131047 — for instance because the window closed between our check and the call — the send is treated as rejected and retried, and after five attempts it dies.
The window opens when the contact writes, and what registers it is Meta’s webhook to us. If messages start dying as “outside the window” for contacts who have just written, the webhook is not arriving — that is an operational fault on our side, not a rule you broke, and it is ours to fix.
Starting a conversation always requires a template Meta approved beforehand. Approval takes days, and it is the longest-lead item in setting up a channel.
8.Two numbering layers, and which one you are on
Client Number
- Your own WABA, your own number, your own credential. Messages display your business name.
- Meta bills your WABA directly. The monthly free allowance described in section 20 is yours alone.
- You can revoke the credential at any time, and you carry the risk described in section 18 on an asset that is yours.
Platform Number
- One number per product, in Gango's WABA, used for messages from the product to its tenants — billing, onboarding, service notices.
- Messages display the product's verified name, not yours. A recipient sees the product, not your business.
- Its monthly free allowance is a single allowance shared by every tenant of that product. See section 20.3, which is the paragraph most likely to matter to you.
Which layer applies is decided by the audience the product asks for when it sends: a message to your own customers goes out on your number, and a message from the product to you goes out on the Platform Number. There is no route by which a product can ask us to “send to the end customer from the platform number”, because there is no route by which it can name a number at all. A Client that needs its own identity on the message, or a predictable allowance, has to bring its own number.
9.Opt-in — and why it is not an LGPD consent
Part III of these Terms (sections 9 to 15) is the flow-down of Meta’s rules. Each item is tagged W for a warranty you give, D for a duty you take on, or P for a prohibition, with the Meta document it comes from. These are obligations to Gango under these Terms, and independently obligations to Meta under the Meta Terms.
- 9.1 (W) You hold an opt-in from every person before the first message you send them, obtained through a channel where that person could reasonably expect it, clearly stating your business name, and clearly stating that they are opting in to receive messages from your business over WhatsApp. Those three requirements are Meta’s, and all three have to be met. (WhatsApp Business Messaging Policy.)
- 9.2 (D) You choose the opt-in method and you keep the record of it. We do not hold it and cannot produce it for you. (WhatsApp Business Messaging Policy.)
- 9.3 (P) No lists that were bought, rented, scraped, or obtained from a third party. An opt-in given to another business, or for another channel, does not carry over to you or to WhatsApp. (WhatsApp Business Messaging Policy.)
- 9.4 (D) Where Gango supplies an affordance that helps you collect the opt-in or display a data-protection notice, that text is standard wording provided as a facility. You remain responsible for checking that it fits the purposes and the legal basis you determined, and you may ask for it to be replaced or supplemented. Providing the facility does not transfer your responsibility to us.
Meta’s opt-in is not an LGPD consent
Meta’s opt-in is a third party’s contractual requirement. It is not a consent under article 8 of the LGPD, and it does not become the legal basis for the processing. The legal basis is chosen and documented by you, as controller — typically performance of the contract the person is party to (article 7, V) or legitimate interest with the balancing test article 10, §2 requires (article 7, IX). Holding the opt-in Meta asks for does not create a legal basis, and holding a legal basis does not satisfy Meta’s requirement. Both have to be met, separately.
We do not ask products to put a mandatory consent checkbox in front of the recipient, and that is a considered position rather than an omission. A consent required as a condition of the service is not free (article 8 read with article 9, §3), so it is defective from the start; and being revocable (article 8, §5), it would convert a single objection into an erasure duty (article 18, VI read with article 16, III), destroying the service record the person may still need. The correct affordance is a clear notice plus a working opt-out, which is what section 10 is about.
10.Opt-out, on WhatsApp and off it
- 10.1 (D) You honour every opt-out request, whatever words the person uses, and wherever it arrives — on WhatsApp, by telephone, in person, by e-mail, or on your own website. An opt-out is not limited to the channel it was sent on. (WhatsApp Business Messaging Policy.)
- 10.2 (D) You stop sending to that person within a reasonable time of the request, and you keep the record of the request and of when you acted on it. (WhatsApp Business Messaging Policy.)
- 10.3 (P) You do not require a particular keyword, format or reply channel as a condition of the opt-out taking effect, and you do not make a person ask twice. (WhatsApp Business Messaging Policy.)
- 10.4 (D) You do not treat our mechanism as your compliance, and your duty does not depend on our having a button for it. Two things follow. First, stopping is something you do in your own product, by no longer asking us to send to that person. Second, when a stop request reaches you off the channel — by telephone, in person, by e-mail — you pass it to us as well, so that the messaging layer stops too and not only your product.
- 10.5 The mechanism, stated as it actually works. A WhatsApp opt-out reaches our messaging layer by being recorded by us on your request. Once it is recorded, enforcement is automatic and it happens at the moment of delivery — that is the only place in our service where the check exists at all, and it is deliberate: between a message being queued and being delivered the recipient may have asked to stop, and a request recorded in that gap still catches the message. The widest applicable scope wins, so a suppression recorded across the platform also silences an address for a product that never recorded it.
There is no self-service way to record a WhatsApp opt-out
The enforcement above is real and channel-agnostic. The intake is not: the route a product calls to record a suppression accepts the e-mail channel only, and the one automatic intake we have fires on e-mail bounce and complaint events from our e-mail provider. A WhatsApp stop request is therefore recorded by hand, by us, on request.
The consequence is the part that matters to you: until a WhatsApp opt-out is recorded — by you in your product, or by us on your request — the platform will keep sending whatever your product asks it to send. An opt-out that is never recorded anywhere exists only in your memory of it.
We are not promising an endpoint, a screen or a date for one. Publishing a mechanism we do not have is the defect this document avoids in 20.6 as well, and it would be worse here, because you would plan around it.
One thing this does not touch: where your product puts its own unsubscribe link in the messages it sends, that is the product’s own mechanism, operated by the product and described in its privacy policy. It works independently of the platform list above, and nothing in this section narrows it.
11.Templates, categories, and what Meta charges
- 11.1 (D) You submit each template truthfully, in the category that matches what the message actually does. (WhatsApp Business Messaging Policy.)
- 11.2 (W) You accept that Meta approves, rejects, pauses, disables and re-classifies templates at its discretion, and that Meta charges according to its own category, not the one you requested. (WhatsApp Business Terms of Service.)
- 11.3 In Brazil the difference is large: a marketing message runs at roughly R$0.32 and a utility message at roughly R$0.035 — about nine times. Meta sets those prices and changes them without passing through us.
- 11.4 (P) Approval is not permission. A template Meta approved may still carry content the Messaging Policy prohibits, and sending it is a breach whether or not the body was approved. (WhatsApp Business Messaging Policy.)
- 11.5 The pre-send guard, which blocks rather than warns. Before calling Meta we refuse a send whose template is not in an approved state, and we refuse a send where the category Meta granted differs from the category requested. The second refusal is deliberate and costs you a delivery: we would rather you decide to pay the higher rate than discover the reclassification on an invoice.
The template guard only knows what went through us
It checks against our own record of templates — the ones submitted through our API, plus the category changes Meta announces by webhook. A template created directly in Business Manager and sent by name is unknown to the guard, and nothing is blocked: the send goes, in whatever category Meta decided, at whatever price Meta charges. The guard also passes anything whose granted category Meta has not told us.
12.Automation, and reaching a human
- 12.1 (D) Where you use automation in a conversation, you tell the person clearly that they are dealing with an automated system, and you give them a way to reach a human being within a reasonable time. (WhatsApp Business Messaging Policy.)
- 12.2 (D) You answer the people who write to your number. Unanswered inbound traffic, and traffic people block or report, is one of the things that drives a number’s quality rating down — and the quality rating is what section 18 is about.
- 12.3 (P) You do not present an automated system as a person, and you do not use the channel to run a conversation whose purpose is to avoid giving the person an answer. (WhatsApp Business Messaging Policy.)
There is no auto-responder in our service
Nothing in our messaging service composes or sends a reply on your behalf. Every outbound message exists because a product asked for it. The one synchronous path that looks like a reply is the interactive-form endpoint, which proxies a form step to your own endpoint inside a session the person opened, and does not compose a WhatsApp message.
The consequence is direct: the duty in 12.1 and 12.2 is entirely yours, and there is no mechanism here by which we could discharge it for you. We say so rather than leaving you to assume the platform is covering it.
13.Prohibited and restricted businesses
Meta prohibits certain categories of business and content on the platform irrespective of any licence, registration or authorisation you hold to carry on that activity offline. A pharmacy licence does not make pharmaceutical sales permissible on WhatsApp, and a licence to trade animals does not make selling them permissible here. The list below reproduces Meta’s published categories as at the date of this document.
- 13.1 (P) Illegal, unlawful or unsafe products and services; and any offer, sale, promotion or facilitation of them. (Meta Commerce Policy.)
- 13.2 (P) Drugs — prescription, recreational, or otherwise controlled — together with drug paraphernalia; tobacco and nicotine products, including vaping devices; weapons, ammunition and explosives. (Meta Commerce Policy; WhatsApp Business Messaging Policy.)
- 13.3 (P) Animals, including live animals, and the offer or sale of parts or fluids of the human body. (Meta Commerce Policy.)
- 13.4 (P) Medical and healthcare products and services, including medical devices, and the promotion or sale of them. (Meta Commerce Policy.)
- 13.5 (P) Adult products and services; gambling and real-money gaming; multi-level marketing, get-rich-quick offers, and misleading, deceptive or fraudulent offers of any kind. (Meta Commerce Policy.)
- 13.6 (P) Third-party debt collection, and financial products and services Meta restricts — including loans, cash advances, and offers of debt renegotiation. (Meta Commerce Policy; WhatsApp Business Messaging Policy.)
- 13.7 (D) Meta’s list is Meta’s, and it changes without notice to us. You are responsible for checking Meta’s published policy as it stands, and where it and the list above differ, Meta’s governs. A category we did not reproduce is not a category we permitted.
Veterinary clinics (Ternavi): the health line and the live-animal line
The Ternavi channel is clear of Meta’s health category by architecture, not by promise: the notice that goes out carries minimal identification and a secure link — no clinical content, no CPF, not even the animal’s name — and everything clinical stays behind the link, inside the platform. But nothing in the platform stops a clinic having a template body approved that carries a diagnosis, and a clinic that is also a pet shop selling live animals is squarely inside 13.3. So, as a clinic Client:
- You do not put human health information through the channel, and you do not use it for human telemedicine or for any medical consultation about a person.
- You do not offer or sell live animals, veterinary medicines, medical products or medical devices over the channel.
- Your template bodies carry no clinical content — no diagnosis, no prognosis, no treatment, no test result — whatever the template was approved for.
- Where a tutor replies with clinical content of their own inside the service window, you may answer within the channel, but the answer stays at the level of identification and the link.
What Gango undertakes in return, and can keep: notice payloads are generated from a fixed shape carrying minimal identification and the secure link; and no affordance that would put clinical free text on WhatsApp ships without this analysis being re-run and the outcome recorded.
Truck centres (GerTruck): the debt-collection line
Renewal reminders are the textbook utility case and are not near any line. The payments module is where the line is. Today the truck centre bills its own customer for its own service, inside its own payment account at the payment institution — first-party billing, not the third-party debt collection 13.6 prohibits. The day an overdue-dunning sequence ships over WhatsApp, two things fire at once: Meta’s debt-collection category becomes arguable, with debt-collection activity on the company’s registered CNAE (8291-1/00) available to whoever argues it; and articles 42 and 42-A of the Consumer Protection Code attach to Gango directly rather than only to the truck centre. So, as a truck centre Client:
- You use the channel only for your own receivables, arising from your own service to your own customer. You do not use it to collect a debt owed to anyone else, and you do not let anyone else use your number to collect through it.
- Where the recipient is a consumer, your collection messages comply with articles 42 and 42-A of the Consumer Protection Code: no exposure to ridicule, no threat, coercion or embarrassment, no contact that interferes with the person's work, rest or leisure, and a notice that identifies the creditor, the amount, and the origin of the debt.
- You do not offer loans, cash advances, receivables factoring or debt renegotiation through the channel.
What Gango undertakes in return, and can keep: no overdue-dunning sequence ships over the channel without a recorded review against Meta’s prohibited categories and against articles 42 and 42-A, dated and kept as part of the compliance record.
14.Business profile, identity and impersonation
- 14.1 (D) You keep an accurate business profile — display name, description, address, e-mail and website that correspond to the business actually operating the number. (WhatsApp Business Terms of Service.)
- 14.2 (P) You do not impersonate another business or person, and you do not operate the channel under a name that is not yours. This includes messaging as though you were the product, the payment institution, a public authority, or Gango. (WhatsApp Business Messaging Policy.)
- 14.3 (D) Your display name has to comply with Meta’s display-name rules. Meta reviews it and can reject it, and a rejected display name blocks messaging on that number until it is fixed. (WhatsApp Business Terms of Service.)
- 14.4 The Platform Number identity consequence. A message sent from a Platform Number displays the product’s verified name. The recipient sees the product, not you, and cannot tell from the message that you are behind it. That is a feature of the shared number and a limitation of it: where your own identity has to be on the message, you have to bring your own number.
15.Use of Platform Data, and Meta’s enforcement right
- 15.1 (D) You use Platform Data only as reasonably necessary to support your messaging with the person it came from. Anything beyond that is outside the permission the platform gives. (Meta Platform Terms §3.a.)
- 15.2 (P) You do not sell, licence, purchase or otherwise trade Platform Data. (Meta Platform Terms §3.a.)
- 15.3 (P) You do not use Platform Data to build profiles of people, to make or inform eligibility decisions — credit, insurance, employment, housing, education, or comparable — to discriminate, for surveillance, or to re-identify anyone. You do not use it to train artificial intelligence or machine learning models. (Meta Platform Terms §3.a.)
- 15.4 (P) You do not share Platform Data across your own customers, or with a third party, except with a processor acting on your documented instruction and under obligations at least as protective as these. (Meta Platform Terms §3.a.)
- 15.5 (D) You delete Platform Data when you no longer have a permitted purpose for it, when the person asks and no legal retention duty applies, or when Meta or Gango instructs you to. (Meta Platform Terms §3.d.)
- 15.6 Meta’s enforcement right, stated here as a fact about the platform. Meta may, at its discretion and without prior notice, rate-limit, restrict, downgrade, suspend or permanently ban a number, a WABA, a template or the application; may reclassify a template’s category; and may change its policies and its prices. We cannot appeal on your behalf and cannot reverse a Meta decision. You learn this here as a characteristic of the channel you are connecting to. Section 18 is where it is allocated between us.
16.Gango’s position, and the three obligations it carries
Gango operates as a technology provider on Meta’s platform: we run the integration, the webhook and the sending infrastructure. We do not own your WABA, your number or your credential, and we cannot represent you to Meta.
Meta requires a provider in that position to do three things. We undertake all three:
- 16.1 Impose on our Clients, by contract, obligations at least as protective of Platform Data and of the people it is about as the ones Meta imposes on us. Mechanism: Part III of this document, and the fact that it applies to every Client on the channel rather than only to those who signed a contract.
- 16.2 Keep technical and organisational measures that protect Platform Data. Mechanism: transport encryption; API keys stored only as a hash; every Meta webhook signature-verified and refused when it does not match, with an empty secret refusing everything rather than accepting everything; a least-privilege database role; recipient addresses masked in support views, including inside provider error text where a provider repeats the number verbatim; an append-only event record of what was sent, skipped, held or failed; and credentials that no API response can carry and no log contains.
- 16.3 Maintain an up-to-date list of our Clients on the platform, and provide it to Meta on request.
The Client list is a procedure, not a table
Our messaging service has no tenant entity. A number’s owner is recorded as an opaque reference the service deliberately does not normalise, so the mapping from a WABA to a legal identity exists only by joining that reference against each product’s own tenant table. The list in 16.3 is therefore produced by a written procedure across two products, not by a query against one register.
We state that rather than describing a register we do not have. Of the three obligations above, two are kept by a mechanism in the code and this one is kept by a procedure a person runs.
17.What Gango does to protect your number
Everything in this section is an obligation of Gango under these Terms, not a feature we may withdraw at will. We may change how a protection is implemented; we do not remove one without the change notice in section 25.
- 17.1 Per-number rate limiting. A token bucket per number: a burst of 10, refilled at one token every three seconds — 20 messages a minute per number.
- 17.2 A 24-hour ceiling, with a warm-up ramp for a new number. A newly-connected number is limited to 50 messages in its first day of life, then 100, 200, 400 and 800 on the following days, reaching 1,000 per 24 hours once warmed up. The ramp is clocked off the number’s first successful connection, not off the date you signed up.
- 17.3 A hard stop on marketing traffic when the number starts failing. Above a 20% failure rate in the rolling 24-hour window, measured on a sample of at least 20 sends, marketing sends stop for that number. Transactional traffic keeps passing, because stopping it would not protect the number and would break the service the person is expecting.
- 17.4 Pre-send checks that block rather than warn. A template that is not approved, and a mismatch between the category requested and the category Meta granted, both refuse the send. See 11.5 for why the second one is deliberate.
- 17.5 Damming without discarding. When a number’s session is lost, when a tenant is suspended, or when a limit above is hit, messages are held back — not deleted — and they go out when the cause clears. Damming has a ceiling, and the ceiling is part of the honest version: a message waiting for the channel to come back becomes a dead letter after 24 hours, because a notice delivered later than that has usually stopped being useful. A hold applied under section 22 has its own, wider ceiling of about seven days.
- 17.6 Fail-closed defaults. A missing rate-limit record denies a send rather than allowing it. A Meta webhook whose signature does not verify is refused. A webhook for a number we do not know produces no event for anyone rather than being routed to a best guess.
What these measures do not do
None of them prevents a Meta decision. They reduce the causes we can see and control: bursts, an unwarmed number, a collapsing delivery rate on marketing traffic, a miscategorised template. They do not reach your own content, a recipient blocking or reporting you, a policy Meta changes, or a decision Meta takes for a reason it does not disclose.
The reason this section exists in a contract rather than in a feature list is that the engineering only helps you if you can rely on it being there.
18.Restriction, suspension and ban of the number by Meta
18.1 The fact. Meta restricts, rate-limits, downgrades, suspends and permanently bans numbers on the official Cloud API too — for a policy breach, for a fall in the number’s quality rating, for template abuse, for recipients blocking or reporting the number. This is not a risk peculiar to some unofficial route. It exists on the official platform, and it is the platform this document is about.
18.2 Whose asset is at risk. The number that dies is yours: the one printed on your cards, on your website and on your shopfront. We cannot recover it, we have no appeal, and Meta is not obliged to explain the decision or to give notice before taking it.
18.3 What Gango undertakes about it. The measures in section 17 are obligations, restated here as obligations owed in respect of this risk: to keep the per-number rate limiting and the warm-up ramp in force; to keep the marketing hard stop in force; to keep the pre-send checks blocking rather than warning; to dam rather than discard; to fail closed; and not to remove any of those protections without the change notice in section 25. We also undertake to have told you that this risk exists before you connect — this document is that notice.
18.4 Information duties, and they run both ways.
- You tell us, without delay, of any notice, warning, restriction, quality-rating drop or policy decision you receive from Meta about the number or the WABA — including one that reaches your Business Manager and not us.
- We tell you, without delay, of anything of the same kind that we observe: a Meta error or state change on your number, reconciliation reading a lost session, the rate limiter stopping marketing traffic for the number, and the allowance counters in section 20.
- Neither side sits on what it learns. What makes this clause worth having is that most of the early signals are visible to only one of us.
18.5 Allocation, and its limit. As between Gango and you, and to the maximum extent the law permits, Gango does not answer for Meta’s decision to restrict, rate-limit, downgrade, suspend or ban your number or your WABA, nor for the direct consequences of that decision — interrupted messaging on that number, the loss of the service windows attached to it, and the commercial effect of the number being unreachable.
This allocation reaches Meta’s decision and nothing else. It expressly does not exclude Gango’s own conduct. If the restriction results from our breach of these Terms, from a failure of an obligation in section 17 or 18.3, or from any other act or omission of ours, this paragraph does not apply to it and the liability rules in section 24 govern.
18.6 What Gango does if it happens. All three of these already work, which is why they are promised:
- Your delivery history stays and is made available to you — what was sent, to whom, when, and whether it arrived. Losing the number does not lose the record.
- A replacement number can be connected through the same five steps in section 5, and the queue that was dammed goes out through the new number without anything needing to be re-sent. The qualifier matters: damming has the 24-hour ceiling in 17.5, so what is still in the queue when you reconnect goes out, and what had been waiting longer than that has already become a dead letter and has to be sent again.
- What does not travel is each contact's 24-hour service window, because the window belongs to the number and ends with it. There is no number migration, and we do not claim one.
18.7 How this section reads if consumer law applies. If in the particular case the relationship is found to be a consumer relationship under the Consumer Protection Code, or you are found to be technically or economically hypossuficient, this section reads as an information clause — the disclosure of a real risk before it is run, under articles 6, III and 46 of that Code — and not as a limitation of liability. We do not rely on this section to defeat a right that Code gives you.
This section does not make the risk smaller
It makes it known. We disclose it because our own service already treats a permanent ban of your number as a real and material risk — the code that limits sends per number says so in as many words, and the rate limiter exists for no other reason. A platform that spends engineering on a risk and whose terms mention it nowhere has an asymmetry worth nothing to you.
Nothing in 18.5 is offered as a complete answer. It allocates one decision, taken by a third party, and it says in the same breath what it does not reach.
19.Availability of the channel, and what is not warranted
The channel depends on Meta, on your WABA, on your number, on your credential, and on a payment method registered at Meta. To the maximum extent the law permits, the channel is provided as it is and as available: we do not warrant uninterrupted delivery, a delivery time, or any percentage of availability, and no percentage is promised by these Terms. This is the same position your Product Terms take, and these Terms do not change it in either direction.
The absence of a warranty of result does not displace the duty of diligence: Gango Tech Ltda. undertakes to use its best efforts to keep the channel working and to restore it as promptly as possible when it is not.
Specific to this channel, a message may fail for reasons that are neither party’s:
- The recipient's device, network or WhatsApp settings, or the recipient having blocked the number.
- An outage or a policy change at Meta, including a template being paused or reclassified.
- The service window being closed, when what was sent was free text (section 7).
- A template not yet approved, or approval still pending — which takes days.
- No payment method registered at Meta for the WABA (section 20.4), which stops delivery of service messages without producing any refusal on our side.
20.What messages cost, who is billed, and what we count
20.1 Meta charges per message and sets the prices. They change without passing through us, and we do not mark them up.
20.2 From 1 October 2026 the rules tighten. A free-text reply inside the 24-hour service window — from a person, a bot or an automation — stops being free and becomes a billable service message. On the same date, a utility template answered inside the window also stops being free. Each number receives 1,000 free service messages per civil month, non-cumulative; from the 1,001st, the market utility rate applies, with no volume tiers. We count the month as a civil month in the America/São_Paulo time zone; Meta resets its own allowance on its own clock, so expect a few hours of divergence at the turn of the month.
20.3 The allowance belongs to the number, not to you. A Client with its own number has its own 1,000. A product’s Platform Number serves every tenant of that product and has one allowance between them — it aggregates, so it runs out sooner than a number used by one business would, and the depletion is not attributable to any particular tenant. This is a structural disadvantage of a shared number, not an incident. A Client that needs a predictable allowance has to bring its own number. We put this here, before you connect, because a Client who learns it from an invoice was told too late.
20.4 The payment-method deadline, and it fails silently. A payment method has to be on file at Meta by 30 September 2026, and it is one per WABA — so one for each Client Number’s WABA, plus one for the Platform Number’s. From 1 October 2026 Meta stops delivering service messages for a WABA without one.
We have no way to check whether you have done it
It is a registration inside your Business Manager, and nothing in our service can read it. The failure mode looks like nothing: delivery simply stops. It is not a refusal on our side, no error of ours appears, and the billing ledger shows delivery stopping with no apparent cause. If service messages stop around that date, check this first.
20.5 Two counters, and the distance between them is information. Meta did not document how the 1,000 allowance appears in the pricing object it sends us, so our ledger keeps both figures per number and per month, available at GET /v1/whatsapp/billing through your product:
serviceDelivered— our count, and an upper bound. At the moment of sending there is no way for us to know about Meta’s free inbound window, so this figure can count as billable something Meta will not charge for. This is the figure that runs against the 1,000 and triggers the alerts.serviceBillable— what Meta declared billable, and a lower bound, because it only reflects what Meta has told us so far.- The same response also carries the free count, the count of utility templates answered inside the window, the allowance, and what is left of it.
The invoice sits between the two, and that gap is information rather than a discrepancy to be reconciled away. Forcing the two figures to agree is how the signal would be lost.
20.6 The allowance alerts, stated as they actually work. Our service emits an event at 80% and another at 100% of the allowance, once per number per month, into the signed event stream it delivers to the product. Whether the product then shows it to you is the product’s decision, and the event is only delivered at all if that product has a webhook configured to receive it.
No product reads that alert today
The events are emitted and nothing consumes them. Do not rely on receiving a warning. If the allowance matters to you, read the counters in 20.5 through your product, on whatever cadence matters to your costs.
We would rather write this sentence than the stronger one. A published commitment with no mechanism behind it is worse than no commitment, because you would plan around it.
20.7 We deliberately do not block at the ceiling. A service message is a reply to someone who wrote to you first, and not replying costs more than the tariff does. The decision to keep paying belongs to whoever pays the invoice, so the counter exists to let that decision be made with the number in hand rather than being made for you by a block.
20.8 Who is billed by whom. For a Client Number, Meta bills your own WABA directly: we neither collect that charge nor re-invoice it, and we have no visibility of what you paid. For the Platform Number, Meta bills Gango, and for this version of these Terms Gango bears that cost — it is not passed on to you and is not added to your subscription. If that changes, it changes by the notice in section 25, prospectively, and never for a month already counted.
20.9 A plan cap and Meta’s allowance are different things. Both of the following are true, and reading one without the other makes it look as though a document is lying:
- Ternavi's Terms of Use describe a monthly cap on WhatsApp notices per plan. That cap does block: reaching it stops the external notice until the next cycle, while updates keep being published in the channel the family reads. It is a commercial limit of the product.
- Meta's 1,000 free service messages are not a cap. Passing them changes the price, not the permission, and we deliberately do not block (20.7). It is a tariff threshold at Meta.
- So a message can be stopped by the first and never by the second, and an invoice can grow because of the second while the first was never reached.
20.10 Disputing a figure. The ledger can be re-projected from the delivery receipts: the ledger governs and the monthly counter is a cache of it. Receipt records are kept beyond the point at which message content is erased, precisely so that an invoice can still be checked against them. If a figure looks wrong, ask through your product and say which month and which number.
21.Disconnection, and what survives it
You may disconnect a number at any time, through your product. The request echoes the instance name back as a confirmation, which is why it cannot be triggered by guessing an identifier.
What goes
- Our copy of the credential, and the instance record itself.
- Each contact's 24-hour service window on that number, by database cascade. They belong to the number.
What stays
- The delivery history — what was sent, to whom, when, and whether it arrived — subject to the retention rules below.
- The queue that was dammed for your tenant, which goes out through the next number you connect. Nothing needs to be re-sent.
- The billing ledger for months already counted, so an invoice remains checkable.
What we do not do
We do not revoke the token at Meta. Disconnection destroys our copy; the credential stays valid in your Business Manager until you revoke it there. There is no number migration and no provider to change to — what exists is changing numbers, by the five steps in section 5.
Retention
Retention is described in the Privacy Policy and in your product’s privacy policy. In summary, for the channel: at 90 days a daily job erases the recipient address and the message content from the delivery log, keeping the delivery record — provider, identifier, timestamps, status — and it deletes the service-window rows and strips the recipient identifier from delivery receipts.
What the 90-day scrub does not reach
Two things are not on that clock, and we would rather publish the limit than an unqualified claim. The raw copy of each webhook Meta sends us is kept for duplicate-detection and forensics, and it can contain an inbound sender and message text. Events already handed to a product carry their payload in a record that job does not touch. Neither is erased by the 90-day pass; both are erased on a deletion request handled as described in the data deletion instructions.
22.When Gango holds your queue
Gango may dam the outbound queue for a Client, immediately, where:
- there is risk to security, to the integrity of the platform, or to third parties;
- Meta requires it, or Meta has restricted the number or the account;
- the use of the channel breaches Part III of these Terms; or
- your Product Terms or a signed contract provide for suspension, including for non-payment.
It dams and does not destroy, and that is built rather than promised. Held messages are deferred: a hold rewrites when a message will next be attempted, it never deletes it. A held message is re-checked periodically, and there is a ceiling — after about seven days a held message becomes a dead letter rather than being held indefinitely, so nothing sits in an invisible queue forever. Releasing a hold wakes the queue immediately and the held messages go out.
Ternavi’s Terms of Use already promise this for a suspension for non-payment: messages in transit are deferred, not discarded. The suspension records in our service exist to make that promise true rather than aspirational, and this section extends the same behaviour to the other grounds above.
We tell you as soon as possible, and we say which of the grounds above applied. A hold applied for one ground is not silently kept in place for another.
23.Data protection
Roles
- For Platform Data about the people you message, you are the controller and Gango is the processor (LGPD, article 5, VI and VII). You determine the purposes and the legal basis; we process on your instruction.
- For our own account, billing and audit data about you as a Client, Gango is the controller.
- Gango qualifies as a small-scale processing agent under ANPD Resolution CD/ANPD nº 2/2022 and publishes a channel for data subjects at privacy@gango.tech in place of formally appointing the officer the LGPD would otherwise require, as that Resolution permits.
This section is not a second data processing agreement
Where a written contract is signed between the parties — today, Ternavi clinics under the SaaS contract — its data protection annex governs the processing, and this section adds only the channel layer: the categories of Platform Data in section 2, Meta as a processor for delivery, and the transfer disclosure below. Nothing here overrides that annex, and where the two differ, the annex governs (section 3).
Where no contract is signed — which is the case for every GerTruck tenant — this section, together with your Product Terms, your product’s privacy policy and our Privacy Policy, is the instrument of your documented instructions for the channel under article 39 of the LGPD. We say so plainly, because a processor operating without documented instructions is the defect the article exists to prevent.
Instructions, subprocessing and transfer
- We process Platform Data only to operate the channel for you and for the purposes of these Terms, and we will tell you if we believe an instruction breaches the law, in which case we may decline to carry it out.
- Meta is a processor for delivery. It receives the recipient's phone number and the content of the message, and it processes on its own global infrastructure.
- That transfer is grounded on article 33, IX read with article 7, V of the LGPD: it is necessary to perform the service you contracted, of which delivering the message is the object. The hypotheses of article 33 are alternative and not cumulative, and we identify the one we rely on rather than referring generally to safeguards.
- For transparency, and because choosing a Brazilian region does not resolve it: our cloud suppliers are foreign companies, and remote administrative access from abroad under their own contracts may itself amount to processing outside Brazil. We record the point rather than omitting it.
- The full list of processors, with what each receives and where, is in the Privacy Policy and in your product's privacy policy.
Data subject requests, incidents, deletion
- Requests from data subjects are answered by you, as controller. A request that reaches us directly is not answered on the merits: we forward it to you within 5 business days and support you technically in answering it.
- Security incidents: we inform you immediately upon becoming aware of an incident that may create relevant risk or harm and, in any event, within no more than 24 hours, with the elements of article 6, §2 of ANPD Resolution CD/ANPD nº 15/2024 that we hold. Notifying the ANPD and the data subjects is the controller's duty.
- How anyone — a WhatsApp end user, a Client business, or a data subject exercising article 18 rights — asks for deletion is set out at /legal/data-deletion, including what we can and cannot do and how long it takes.
- A change of processor, of destination, or of the legal hypothesis relied on is notified in advance: 30 days where a contract is signed, with the right to object and, if the objection stands, to terminate without penalty; and under section 25 where none is signed.
24.Liability — these Terms create no new limit
These Terms create no new limitation of liability, no new cap, and no new exclusion beyond the allocation in 18.5. The limitation in your Product Terms — GerTruck section 15, Ternavi section 13 — or in a signed contract where one exists, applies unchanged to anything arising under these Terms, including the channel. So do its four exceptions, which we restate here so that the same substance is published in all three documents:
- wilful misconduct by Gango Tech Ltda.;
- breach by Gango Tech Ltda. of the confidentiality duties it owes you;
- infringement by Gango Tech Ltda. of intellectual property rights of yours or of a third party; and
- an administrative sanction imposed on you by a data protection authority arising exclusively from conduct of Gango Tech Ltda. contrary to those Terms, to the signed contract, or to your documented instructions.
Those exceptions bear exclusively on the cap: in the cases listed, liability that is recognised ceases to be limited to the subscription amount. They do not create liability where none exists.
Nothing in these Terms displaces either party’s liability towards third parties, or the joint liability provided for in article 42, §1 of Law nº 13.709/2018 (LGPD). The allocation in these Terms governs exclusively the relationship between Gango Tech Ltda. and the contracting Client, including the right of recourse between them, and is not opposable to data subjects or to any other third party.
And to close the loop with section 3: if any reading of these Terms would reduce a right your Product Terms or a signed contract give you, that reading is not adopted.
25.Changes to these Terms
These Terms are versioned and dated. The version in force is identified at the top of this page, earlier versions are archived, and the version in force at the time governs facts that occurred then. Changes take effect prospectively.
- Material changes are notified by e-mail or in the product before they take effect, with the date at the top of this document updated.
- Where a written contract is signed, a change of processor, of destination or of the legal hypothesis for a transfer is notified 30 days in advance, with the right to object with reasons and, if the objection stands, to terminate without penalty — aligned with the contract's data protection annex.
- Where no contract is signed, a material change is notified with reasonable advance notice through the product or by e-mail.
- Removing any protection in section 17, or changing who bears the Platform Number cost under 20.8, is a material change and is notified as one.
- Continued use of the channel after a change takes effect means you accept it. Where you do not, disconnecting the number is the way to decline it, and section 21 says what survives.
A change that only reflects something Meta changed — a price, a category, a policy — takes effect when Meta’s change does, because we have no power to hold it back. We will still say what changed and when.
26.Governing law, forum and language
These Terms are governed by the laws of the Federative Republic of Brazil. The courts of São Paulo, State of São Paulo, Brazil are elected to settle any dispute, waiving any other however privileged.
The election of forum observes article 63, §1 of the Code of Civil Procedure, as it falls on the domicile of Gango Tech Ltda.. If in the particular case the Consumer Protection Code is found to apply to the relationship, or the Client is found to be hypossuficient, the forum of the Client’s domicile prevails where it is more favourable to the Client.
Language
This document is published in English and in Portuguese, as a single document in two languages with the same 27 sections and the same numbering. Between Gango Tech Ltda. and the Client, the Portuguese version prevails — article 46 of the Consumer Protection Code requires terms to be given in a way the reader can actually understand, and article 423 of the Civil Code reads ambiguities against the drafter. The English version is the canonical text filed with Meta and written for readers outside Brazil. Where the two differ, the Portuguese text governs the relationship with the Client, and the difference is a fault of ours to correct rather than a choice to exploit.
27.Contact
Gango Tech Ltda., CNPJ 50.086.381/0001-41.
- privacy@gango.tech — this document, data protection, and the rights in article 18 of the LGPD. This is the channel referred to in section 23, and it is the one to use for a deletion request.
- security@gango.tech — reporting a security vulnerability in the platform or in the integration.
- Anything about the product itself — your subscription, plan, features or invoices — goes through the product’s own support channel, in its Terms of Use.
If you believe your personal data has been mishandled, you may complain to us at privacy@gango.tech, to the Client business where it is the controller, and to Brazil’s National Data Protection Authority (ANPD).