WhatsApp 查詢

How SharkFlows uses Meta and WhatsApp data

A reviewer-facing explanation of authorisation, requested permissions, product use, security, retention, revocation and deletion.

Operator and product

SharkFlows is field-service operations software operated by DONOW LIMITED, a Hong Kong company. It helps a customer business turn authorised WhatsApp enquiries into inbox conversations, customer records, reviewed work requests, quotations, work orders and service notifications. SharkFlows is not a Meta Partner and does not claim approval before Meta grants it.

Customer-controlled connection

  1. 1. An authorised company owner chooses Connect WhatsApp inside SharkFlows.
  2. 2. Meta-hosted Embedded Signup identifies the permissions and lets the owner choose their own Business Portfolio, WhatsApp Business Account and phone number.
  3. 3. SharkFlows verifies the returned assets before enabling the connection for that tenant.
  4. 4. The company can review connection status and disconnect the channel from its settings.

Requested permissions and necessity

whatsapp_business_management

Read and manage only the WhatsApp Business Account and phone-number assets selected by the customer business during Meta-hosted Embedded Signup.

whatsapp_business_messaging

Receive customer messages and send authorised service replies, templates and status updates for the connected business.

business_management

Identify and complete the customer-authorised selection of relevant Meta business assets when required by the Embedded Signup flow.

SharkFlows requests only permissions required by the enabled connection flow. Permissions that have not been approved or enabled do not make a corresponding product feature available.

Data received and product use

Depending on the connected assets and message, data may include Meta business and WABA identifiers, phone-number identifiers, customer phone numbers and profile names, message content, media references, message identifiers, timestamps, delivery status and authorised templates. The data is used for the connected company's inbox, customer matching, enquiry review, work-request creation, authorised replies, delivery status and support. Consequential business records remain subject to user review.

Security and tenant isolation

  • No Meta asset access before the customer business grants permission
  • Each connected asset is bound to the authorising SharkFlows tenant
  • Access tokens and provider secrets are kept out of client code
  • Webhook signatures and identifiers are verified before records change
  • Unknown WhatsApp phone-number assets are quarantined
  • Meta platform data is not sold or used for unrelated advertising

Disconnect, revoke and delete

A company administrator can disconnect a channel in SharkFlows under Dashboard → Settings → Channels. The company may also remove the app integration from its Meta Business settings. Disconnection stops new access and outbound use of the revoked connection.

Existing operational records are deleted, anonymised or restricted according to the customer's instructions, the Privacy Policy, contractual duties and necessary payment, warranty, dispute, security or legal retention. A person can submit an access, correction, export or deletion request through the Data Choices and Account Deletion page.

Contact and company identity

DONOW LIMITED (即做有限公司)

Room 316, 3/F, 143 Wai Yip Street, Kwun Tong, Hong Kong

Hong Kong Business Registration Number: 78863153

Business Registration certificate number: 78863153-000-09-25-2

Date of incorporation: 28 September 2025

Nature of business: Engineering services, workforce operations and intelligent technology

Email: admin@sharkflows.com.hk

Customer-support phone: +852 3460 4012

View the complete public company information

Meta and WhatsApp data use | SharkFlows