Privacy Policy
Last updated: September 2026
This Privacy Policy explains what personal data WALinkr ("we", "us") collects when you use our website and WhatsApp API service (the "Service"), why we collect it, and the choices you have. It should be read together with our Terms & Conditions.
1. Data we collect
- Account data: your email address and a securely hashed version of your password (we never store your password in plain text).
- WhatsApp connection data: the phone number linked to each connected number, its connection status, the session created for it, and the API key and optional webhook URL you set for it. We do not see or store your WhatsApp chats outside of the Service's own message log described below.
- Message data: for messages sent or received through the Service we keep a log with the direction, type, contact number, message text, status, and time, so you can see your history and so the Service can work.
- Billing data: your chosen plan, billing period, plan dates, and a record of each payment attempt (amount, status, and payment reference). Card and bank details are handled by our payment provider and are never stored by us.
- Security data: one-time login codes, and the identifiers of devices you choose to trust so we don't ask for a code every time.
- Technical data: standard server logs (such as requests and errors) that our hosting infrastructure generates when you use the Service.
2. How we use your data
- to create and run your account, connect your numbers, and send and receive messages on your behalf;
- to log you in securely, including email verification codes for new devices;
- to take payments, apply your plan, and manage trials and renewals;
- to send service emails, such as verification codes, notices about your account or plan, and alerts when one of your numbers disconnects (you can switch the disconnect alerts off in Settings);
- to detect and prevent abuse, fraud, and misuse of the free trial;
- to keep the Service reliable and secure, and to provide support.
We do not sell your personal data and we do not use your messages for advertising.
3. Legal bases (EU / EEA / UK users)
Where data-protection law such as the GDPR applies, we process your data because it is necessary to provide the Service you asked for (contract), to meet our legal obligations, for our legitimate interests in running, securing, and preventing abuse of the Service, and, where required, with your consent.
4. Cookies and similar technologies
- Session cookie: keeps you logged in.
- Trusted-device cookie: remembers a device you verified by email so we don't ask for a login code again for up to a year.
- Local cache: the app can cache static files (styles, icons) in your browser so pages load faster and the site can be installed as an app.
These are essential to the Service. We don't use advertising or third-party tracking cookies.
5. Who we share data with
We share data only with service providers that help us run the Service, and only what they need:
- Mollie — payment processing;
- Resend — sending our emails (for example login codes and alerts);
- Bunny.net — hosting and content delivery of the Service;
- WhatsApp / Meta — your messages are delivered through WhatsApp's network when you send them;
- the webhook URL you configure — incoming messages and connection events are sent there, so you are responsible for that endpoint.
We may also disclose data if required by law, or to protect our rights, our users, or the Service. These providers may process data outside your country, including outside the EEA, under their own safeguards.
6. How long we keep data
- Account and connection data is kept while your account is active. When you delete your account, your numbers, sessions, and API keys are removed.
- Message history is kept for the history period that comes with your plan, and older entries may be deleted.
- Login codes are short-lived and expire after 10 minutes.
- We may keep limited billing records for as long as required by tax and accounting laws.
7. Security
We protect your data with measures such as hashed passwords, email verification for new devices, HTTPS, and access limits. No system is perfectly secure, so please use a strong password, keep your API keys secret, and regenerate a key if you think it has been exposed.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, to withdraw consent, and to complain to your local data-protection authority. You can change your password and delete numbers or your account from the dashboard. For anything else, contact us using the details below and we'll respond within a reasonable time.
9. Your recipients' data
When you message people through WALinkr you are the one deciding why and how their data is used, and we process it for you. You are responsible for having a lawful basis, such as their consent, and for honouring their requests.
10. Children
The Service is intended for businesses and adults. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. The date at the top shows the latest version, and we'll notify you of significant changes by email or in the dashboard.
12. Contact
Questions or privacy requests? Email us at support@walinkr.com.