Guides9 min readJuly 18, 2026

Customer Data in WhatsApp: What You Must Not Store

A plain guide for small shops on which customer details are safe to keep in WhatsApp, which are not, and how to clean up a chat history that already has too much.

A repair shop keeps photos of customers' ID cards in a WhatsApp chat so they can prove who dropped off which phone. A small clinic has a group where staff discuss patients by name. A furniture shop has a customer's full card details typed out in a message because they read them over the phone. All three feel practical in the moment. All three are storing data they should not be storing, in a place they do not control, on a phone that could be lost tonight. This article is about drawing that line clearly enough that your staff can follow it without thinking.

The basic test: would this hurt if the phone was stolen?

Forget legal terminology for a second and use a physical test. If someone picked up your shop phone in the street, unlocked it, and scrolled your WhatsApp — what could they do with what they find? A name and a phone number: they could annoy someone. A photo of an ID card: they could open an account in that person's name. A card number with expiry: they could spend that person's money. A message saying which of your customers is not at home on Tuesdays: they could rob a house. The severity ladder is real, and it maps almost exactly onto what you should and should not keep in a chat app. WhatsApp encrypts messages in transit, but that protects the wire, not the device sitting on your counter.

Never in WhatsApp — no exceptions

  • Card numbers, expiry dates, CVV codes. Not in a message, not in a photo of a card, not "just for a minute". Card scheme rules are strict about this and a chat app is not a compliant environment for it.
  • Bank account details belonging to a customer, sent to you for a refund. Take them in a channel you control, use them, delete them.
  • Photos of ID cards, passports, driving licences, residence permits. If you genuinely need identity for a legal reason, that goes in a proper record, not a chat.
  • Passwords, PINs, phone unlock codes, alarm codes. Repair shops are the biggest offender here — a customer's unlock code sent in a message is a serious liability.
  • Health information: conditions, medications, treatments, anything a customer mentioned about why they need something. This category is treated as especially sensitive nearly everywhere.
  • Copies of contracts or documents containing someone's full address plus ID number plus signature. That combination is an identity theft kit.
  • Anything about a customer you would not be comfortable reading aloud to them. Staff groups drift into commentary about customers fast, and those messages are still data about an identified person.

Usually fine, with care

  • First name and phone number, for the purpose of serving them. This is the ordinary working minimum.
  • What they ordered and when, and whether it is ready.
  • Amount owed and amount paid, in EUR. A balance is not sensitive on its own; a running commentary about their financial difficulties is.
  • A photo of the item you are repairing or delivering — the item, not the room, and not the family in the background.
  • Delivery address for an active delivery. Keep it for the delivery, not forever.

The two failure modes that actually happen

Almost no small business gets into trouble through a sophisticated data breach. Two mundane things cause nearly all the damage. The first is device loss: a phone left in a taxi, unlocked, with two years of customer chat and no remote wipe. The second is the wrong group: a message intended for staff sent to a customer group, or a customer added to a group where they can see forty other customers' phone numbers and read a discussion about who has not paid. That second one is a genuine data disclosure — you have shared your customers' contact details with each other without asking them. If you run any group with customers in it, understand that every member sees every other member's number.

Groups: the rule that prevents most of this

Have separate groups for separate purposes and never mix. An internal staff group is for your team and can discuss operations. A customer group should ideally not exist at all — use broadcast lists or individual chats, because a broadcast sends to many people without any of them seeing each other. If you use a group for your own bookkeeping messages, keep it to your team, and log amounts and short descriptions rather than customer life stories. "Table 4, 45 EUR, card" is a record. "Mrs Silva again, still can't pay because of her divorce" is a liability sitting on three phones.

Data protection duties, the records you must keep, and how long you may keep them are set by law in your country and by your sector's rules, and they do change. This article is operational guidance, not legal advice. For anything involving identity documents, health information, or a data breach, check with the relevant authority in your country and with your accountant or a legal adviser — and confirm the current requirements rather than assuming last year's still apply.

Cleaning up a chat history that already has too much

  • Set a two-hour block and go through the media gallery of your business WhatsApp first. Photos are where the ID cards and documents are hiding.
  • Delete identity documents, cards, and anything with a signature. Delete on your device and, where the option is still available, for everyone.
  • Empty the deleted items in your phone gallery too — WhatsApp media is copied into device storage, so deleting the chat does not always remove the file.
  • Leave or archive old customer groups, and tell people you are moving to individual chats.
  • Turn off automatic media download to the gallery, so future photos stay inside the app rather than spreading across the phone.
  • Turn on device encryption, a strong screen lock, and remote wipe. This is the single most effective control you have.
  • Turn on two-step verification in WhatsApp so nobody can take over the number with a SIM swap.

What to do when a customer asks you to delete their data

People increasingly ask. Have a simple honest answer ready: what you hold, where, and what you will do. In practice this means deleting the chat thread, removing the photos of their item, and keeping only what you are legally required to keep — typically the transaction record, because purchase and payment records generally have to be retained for a period set by law. Say that plainly: "I've deleted our messages and the photos. The sale record stays in my books because I'm required to keep those, and my accountant handles it." That is a good answer. Confirm the retention specifics with your accountant, because they differ by country and by document type.

The structural fix: stop using chat as storage

Every problem above comes from the same root cause — the chat is doubling as the filing cabinet. A message is a fine way to communicate and a bad way to store. When the important information is extracted into a proper record (customer, item, amount, date) and the chat is just the conversation that produced it, you can delete freely, your data lives in one place with one set of access rules, and losing a phone is an inconvenience rather than a disaster. That separation also happens to be what makes your bookkeeping work, which is why the businesses with clean records usually have clean data practices too.

See ZapLedger

ZapLedger pulls the numbers out of your WhatsApp messages into a structured income and expense record — so what you need to keep lives in a proper ledger, and the chat can stay just a chat you're free to clear.

Try ZapLedger free