This Privacy Policy explains how the operator of the WaTrack brand ("WaTrack," "we," "us," or "our") handles personal data. It covers the WaTrack website, web dashboard, mobile applications, support, and related services (collectively, the "Services"). It explains what we collect, why we use it, when we share it, how long we keep it, and how we protect it. It also explains the choices and rights available to users. Those rights may also apply to people whose phone numbers or visible status events are submitted to the Services.
Use WaTrack only for lawful, authorized purposes. If you submit another person's phone number or status information, you are responsible for having a lawful basis and providing any notice or obtaining any consent required in your location.
1. Controller, Scope, and Roles
WaTrack decides why and how it processes account, security, web checkout, support, and core product-operation data. WaTrack generally acts as the controller for that processing. If you use WaTrack in a business or professional context, you may have a separate role for the numbers you select. For example, you may be a controller or business for that third-party data. WaTrack may act as a service provider or processor when the parties' roles and applicable law require it.
This Policy does not govern independent processing by Stripe, Apple, Google, RevenueCat, WhatsApp, Meta, your bank, or another third-party service. Review their privacy notices for their separate practices.
2. Information You Provide
2.1 Web account and authentication data
- Email address, normalized where needed to keep one account per address.
- One-time-code request, verification, expiry, attempt, and consumption records. WaTrack stores a cryptographic representation of the code rather than a reusable password.
- Session identifiers, account identifiers, login times, and last-session activity needed to keep you signed in and secure the account.
2.2 Numbers and monitoring instructions
- Country selection, country calling code, and phone number submitted for monitoring.
- The optional phone number identified as your own in supported mobile versions so the product can prevent self-monitoring.
- Monitoring start, collection, delay, error, online/offline notification preference, and removal instructions.
2.3 Linked-device data
- QR or phone-code pairing requests, pairing method, connection status, linked identifier, connection timestamps, and technical error state.
- Linked-device authentication material required to maintain the connection you authorize. Persistent linked-device credentials are protected using encryption and access controls.
2.4 Support and communications
- Your name or email, message, attachments, transaction references, and follow-up communications when you contact support, request a refund, make a complaint, or exercise a privacy right.
- We ask you not to send passwords, full card data, one-time codes, QR codes, pairing codes, or unnecessary information about another person.
3. Purchase, Subscription, and Entitlement Data
Stripe processes eligible web purchases. Apple or Google processes store purchases, and RevenueCat is used to verify supported mobile entitlements. We may receive or create the following records:
- Purchase email, internal user identifier, selected plan, amount, currency, payment status, provider, checkout-session identifier, customer identifier, subscription identifier, invoice identifier, and provider event time.
- Subscription state, renewal or current-period end, scheduled cancellation, lifetime status, invoice history, hosted invoice link, and entitlement activation or revocation state.
- For supported mobile access, a cryptographically derived RevenueCat identity, entitlement name, product identifier, active state, and account creation/update times.
WaTrack does not receive or store your complete card number or card security code. Stripe, Apple, Google, your bank, and the relevant payment network process payment credentials under their own privacy notices.
4. Activity and Notification Data
When monitoring is active, we may process the selected number and its observed online or offline state. We may also process event timestamps, calculated durations, last-event times, monitoring status, and recent activity history. These records cover only events visible through the linked account. They do not guarantee a complete chronology.
Supported mobile versions let you enable or disable online and offline alerts for each followed number. If you enable notifications, we process an Apple Push Notification service (APNs) token or Firebase Cloud Messaging (FCM) endpoint. We may also process the provider, environment, locale, delivery state, and related watch identifier. Your device platform can separately process delivery and interaction information.
5. Technical, Security, and Usage Data
- IP address at the network or infrastructure layer, and a keyed cryptographic derivative of the IP where implemented for authentication and checkout rate limiting.
- Request time, route, response status, request identifier, browser or device type, operating system, locale, app version, crash or error context, and security signals.
- Cookie and local-storage values used for authentication, country/phone formatting, interface state, and remembering product choices on the device.
- Limited page-view and interaction data if optional analytics is enabled, as described below.
6. Information We Do Not Intend to Collect
The Services are not designed to collect WhatsApp message content or call audio. They are also not designed to collect contact lists, precise device location, address-book data, account passwords, or full payment-card credentials. Do not submit any of these categories to support. The linked service and platform providers may process broader information under their own policies.
7. Sources of Information
We obtain information:
- Directly from you when you enter an email, number, pairing request, support message, preference, or checkout instruction.
- Automatically from your browser, App, device, network, and our security and operational systems.
- From Stripe, Apple, Google, RevenueCat, APNs, FCM, and your bank or payment network regarding purchases, entitlement, delivery, refunds, disputes, or fraud signals.
- From the linked service when the account you authorized exposes connection or visible status information.
8. Why We Process Data and Our Legal Bases
8.1 Contract performance and requested steps
We use account and session data to create and secure your account. We use checkout and entitlement data to validate purchases, provide invoices, and restore access. We use linked-device, number, activity, and notification data to establish the connection you request. This data also lets us operate monitoring, display history, and deliver enabled alerts. We use relevant records to answer support requests.
8.2 Legitimate interests
We use proportionate technical, transaction, and usage records to prevent fraud and abuse. These records help us rate-limit attacks, diagnose failures, and secure infrastructure. They also help us understand aggregate product performance, enforce our Terms, respond to disputes, and improve reliability. We balance these interests against the rights and expectations of affected people. We limit data where practical.
8.3 Consent
We rely on consent where it is required for optional analytics, notifications, device permissions, or another optional feature. You can withdraw consent through the relevant control or your browser or device settings. You can also contact us. Withdrawal does not invalidate earlier lawful processing. It may prevent the requested feature from working.
8.4 Legal obligations and legal claims
We process and retain information when reasonably necessary to comply with tax, accounting, consumer, sanctions, law-enforcement, court, data-protection, or app-store obligations and to establish, exercise, or defend legal claims.
9. Data About Other People
A monitored number and its visible activity can be personal data about someone who is not the account holder. The user who submits that number must identify and document an appropriate lawful basis. The user must provide required notices, avoid excessive collection, limit access, and delete data when it is no longer needed. Do not use WaTrack to infer sensitive traits or build a secret profile. Do not use it to make a significant decision about a person.
A person who believes their number is being processed unlawfully may contact us. We may request enough information to locate the record and verify the request. We may also need information to protect another user's account and determine the parties' roles. We will then identify the lawful response. We may restrict or remove monitoring while we investigate where appropriate.
10. Service Providers and Recipients
We disclose only the information reasonably needed for the following recipients and purposes:
- Cloud and infrastructure providers, including Cloudflare: hosting, databases, network delivery, security, rate limiting, logging, and email dispatch.
- Stripe: web checkout, customer portal, subscription status, invoices, refunds, fraud prevention, and payment disputes.
- Apple and Google: app distribution, store purchases, refunds, subscription management, device services, and required compliance.
- RevenueCat: supported mobile purchase and entitlement verification.
- APNs and FCM: delivery of notifications you enable.
- Google Analytics, if enabled: limited website analytics with IP anonymization configuration. The Services can operate without this optional measurement.
- WhatsApp or Meta systems: linked-device connection and visible status functionality initiated by the account you authorize.
- Professional advisers: legal, accounting, insurance, security, or audit assistance subject to confidentiality duties.
Providers can process data under their own legal obligations. We use contracts, access controls, and data-gd measures appropriate to the service and our role.
11. Legal Disclosure and Business Transfers
We may preserve or disclose data when we reasonably believe the law requires it. This includes valid legal process or a request from a court or regulator. We may also act when disclosure is necessary to protect a person from harm. We may preserve or disclose data to investigate fraud, security incidents, abuse, or violations of the Terms. Where permitted, we assess each request for scope and legal validity.
WaTrack may become involved in a merger, financing, reorganization, acquisition, insolvency, or asset transfer. In that event, data may be disclosed under confidentiality. Any transfer will remain subject to this Policy unless we give notice of a materially different policy.
12. No Sale or Cross-Context Behavioral Advertising
We do not sell personal data for money and do not share personal data for cross-context behavioral advertising as those terms are defined by California privacy law. We do not use tracked-number or activity-history data to target advertising.
13. Cookies, Local Storage, and Analytics
The web service uses a secure, HTTP-only session cookie to keep an authenticated user signed in. Functional browser storage can remember a country selection and phone formatting. It can also remember tracked-number interface state and other requested preferences. Blocking functional storage can prevent authentication or product features from working.
Google Analytics loads only when a valid measurement identifier is configured. Where consent is required, optional analytics remain disabled until we obtain the required choice. Browser privacy controls, content blockers, or consent controls can limit analytics. There is no uniform standard for browser "Do Not Track" signals, so we do not currently respond to every signal. We honor legally required opt-out signals when they apply to our processing.
14. International Transfers
WaTrack and its providers may process information in the United Kingdom, European Economic Area, United States, or other countries where they operate. Those countries may have different privacy laws. Some transfers require a legal safeguard. Depending on the transfer, we may use an adequacy decision, the UK International Data Transfer Agreement or addendum, or Standard Contractual Clauses. We may use another lawful mechanism when appropriate. We also apply supplementary measures where needed.
15. Retention
We keep data only for as long as reasonably necessary for the purpose collected, the duration of the account or feature, security and dispute periods, backup cycles, and legal obligations. The following criteria apply:
- Account and session data: while the account is active and for a limited period needed for authentication, security, recovery, or claims. Web sessions are configured to expire, and mobile refresh sessions are time-limited or revoked on logout.
- One-time-code data: codes expire quickly; verification and abuse-prevention records may remain for a limited security and audit period.
- Tracked numbers and activity: while the number remains attached to the account or history is needed for the requested service, until removal or account deletion, subject to backup, fraud, dispute, and legal exceptions.
- Linked-device material: while you maintain the connection, then deleted or rendered unusable after unlinking or account deletion, subject to operational backup cycles and records needed to document the action.
- Purchase and invoice records: for the life of the entitlement and any longer period required for tax, accounting, chargeback, refund, fraud, audit, and consumer-law records, which can extend for several years.
- Support and legal records: until the request is resolved and for an appropriate claims, compliance, or audit period.
- Provider copies: Stripe, Apple, Google, RevenueCat, banks, and other independent providers retain information under their own schedules and legal duties.
Backups are protected and removed or overwritten on their normal cycle. We may retain de-identified aggregate information that can no longer reasonably identify a person.
16. Security
We use measures designed to reduce risk. These measures include encrypted transport, protected secrets, and one-time authentication. We also use hashed or keyed identifiers, secure cookies, access controls, and rate limits. Other controls include provider webhook verification, encrypted linked-device credentials, least-privilege practices, and operational monitoring. Mobile access and refresh tokens are stored as cryptographic hashes on the server.
No system is completely secure. You are responsible for protecting your email account, device passcode, provider accounts, login codes, and pairing credentials. Notify us promptly at info@watrack.co if you suspect unauthorized access. Where applicable law requires notification of a qualifying breach, we will notify affected people and regulators within the required period.
17. Automated Processing
Automated rules validate phone formats and rate-limit requests. They also verify payment and entitlement status, calculate durations, and determine whether a feature is available. We do not use WaTrack data to make solely automated decisions that have legal or similarly significant effects on monitored people. Contact us if you believe an automated access or billing result is incorrect.
18. Notification and Device Choices
You can deny or revoke notification permission in device settings. Supported mobile versions also provide per-number online and offline alert controls. Disabling an alert stops future requested delivery for that setting but does not automatically delete existing activity history. Deleting an App can remove local data but does not cancel a subscription or necessarily delete server-side account data.
19. Account Deletion, Unlinking, and Number Removal
Supported mobile versions provide an in-app account deletion request. The request removes the mobile account, watches, events, sessions, and push subscriptions from the active mobile database. It also requests deletion of the related linked session. Web users can request account deletion at info@watrack.co. We may verify control of the account email before acting.
You can separately remove a tracked number or unlink WhatsApp without deleting the whole account. Account deletion, number removal, and unlinking are distinct from cancellation and refund. Cancel the recurring plan through Stripe, Apple, or Google before deleting the account if you also want renewal to stop.
We may retain limited transaction, fraud, security, dispute, legal-request, and accounting records where deletion is not required or is prohibited. We will restrict retained information to the permitted purpose.
20. Your Privacy Rights
Depending on your location and subject to legal exceptions, you may have rights to:
- Know whether we process your personal data and access a copy.
- Correct inaccurate or incomplete data.
- Delete data in qualifying circumstances.
- Restrict processing or object to processing based on legitimate interests.
- Receive certain data in a structured, commonly used, machine-readable format.
- Withdraw consent for future processing.
- Appeal a qualifying refusal where local law provides an appeal right.
- Complain to a data-bt authority.
Send requests to info@watrack.co. State the right you want to exercise and provide the account email, country or state, and enough detail to locate the data. We may verify your identity and authority or request clarification. Where law permits, we may refuse excessive or manifestly unfounded requests. We may redact information that would expose another person's rights, security, or confidential data. We respond within the period required by applicable law.
21. UK and EEA Rights
UK and EEA users may have rights of access, rectification, erasure, restriction, objection, portability, consent withdrawal, and complaint. These rights depend on applicable data-bt law. Erasure is not absolute. We may retain information for legal obligations, freedom of expression, public-interest grounds, or legal claims. You can complain to the UK Information Commissioner's Office if it is your relevant authority. You can otherwise contact the supervisory authority where you live or work.
22. California and Other U.S. State Rights
Residents of California and other states with comprehensive privacy laws may have specific rights. These may include rights to know, access, correct, delete, and obtain a portable copy of covered personal information. Residents may also have a right to opt out of sale, sharing, targeted advertising, or qualifying profiling. Some laws provide a right to appeal certain decisions and receive equal service for exercising a right. WaTrack does not sell or share personal information for cross-context behavioral advertising. Where law permits, an authorized agent may submit a request. We may verify the agent's authority and the consumer's identity.
23. Children's Privacy
The Services are intended for adults and are not directed to children. We do not knowingly allow a person under 18 to create an account or submit monitored-person data. If you believe a child provided personal data, contact us so we can investigate and delete it where required.
24. Third-Party Links and Non-Affiliation
Links to Stripe, Apple, Google, WhatsApp, or other services do not make their privacy practices ours. WaTrack is not affiliated with, endorsed by, sponsored by, or associated with WhatsApp LLC or Meta Platforms, Inc. Linked-device functionality remains subject to the linked service's terms, privacy settings, and independent processing.
25. Changes to This Policy
We may update this Policy to reflect changes in the Services, providers, security, law, or processing. We will update the date above and provide additional notice where a material change or applicable law requires it. If consent is required for a new purpose, we will request it rather than relying only on continued use.
26. Contact and Complaints
Use the subject Privacy request for rights requests. Do not include passwords, one-time codes, full card data, QR codes, pairing codes, or unnecessary third-party information. If we cannot resolve a concern, you may complain to the competent privacy regulator in your jurisdiction.