Privacy policy
Last updated: September 2026
This privacy policy explains what personal data Whazzup collects when you use our website, create an account, sign in with Google, or run support conversations through our platform and website widget — and what we do with that data.
1. Controller
EINSZWEIDREI SOLUTIONS UG
Hochstraße 2
56242 Ellenhausen
Germany
Email: hello@whazzup.io
The controller within the meaning of Art. 4 No. 7 GDPR decides on the purposes and means of the processing described below.
2. Data we collect
Depending on how you use Whazzup, we collect the following categories of data:
- Account data: name, email address, password (stored only as a cryptographic hash), company name, website and logo.
- Billing data: selected plan, seat quantity, billing address, tax information, payment status and invoice references. Card details are collected directly by Paddle and are not stored by Whazzup.
- Onboarding and settings data: your role, time zone, support hours, widget appearance and configuration choices.
- Usage and log data: IP address, date and time of access, browser type and version, operating system, pages requested and referrer URL.
- Support conversation content: messages, attachments, contact details of your customers and technical context such as the page a visitor was on when starting a conversation.
- Widget data: interactions of website visitors with the chat widget, selected topics and, where enabled, session context such as current page and browser. From the visitor's IP address we additionally derive an approximate location (country, region, city) so support teams can help in context; this is an estimate, not an exact address, and no precise tracking takes place.
3. Visiting our website
When you open our website, your browser automatically transmits technical data (IP address, date and time, browser type, requested page). We process this data to deliver the site securely and reliably and to detect and prevent abuse. Legal basis: our legitimate interest in secure operation (Art. 6 (1) (f) GDPR). Server logs are deleted after a short period unless they are needed to investigate an incident.
4. Account, login and Google sign-in
To create and manage your account we process your email address, password (hash only), name, company and onboarding settings. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR).
If you choose to sign in with Google, Google Ireland Limited / Google LLC transfers your name, email address and profile picture to us after you confirm the sign-in on Google's site. We use this data exclusively to create or access your Whazzup account and to authenticate you on later visits. We do not send data back to Google beyond what is technically required for authentication, and we do not receive access to your Google password, emails, files or other Google services. The legal basis is performance of a contract (Art. 6 (1) (b) GDPR); the data transfer by Google itself is governed by Google's privacy policy.
If you reset your password, we send you an email with a recovery link. This email is sent solely to fulfil your request (Art. 6 (1) (b) GDPR).
5. Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Website delivery and logs | Secure, reliable operation | Art. 6 (1) (f) GDPR |
| Account creation and login (incl. Google) | Provide the service you signed up for | Art. 6 (1) (b) GDPR |
| Support conversations | Answer requests, run the inbox and widget | Art. 6 (1) (b), (f) GDPR |
| Screen sharing | Remote help after explicit consent | Art. 6 (1) (a) GDPR |
| Billing | Invoicing, statutory retention | Art. 6 (1) (b), (c) GDPR |
6. Support conversations, widget and your customers
If you contact us via chat, email or the widget, we process the content of your message, your contact details and technical context such as the page you were on. This is used solely to answer your request.
If you embed the Whazzup widget on your own website, we process your visitors' conversation data on your behalf as a data processor (Art. 28 GDPR). You remain the controller towards your visitors and are responsible for informing them in your own privacy policy. Visitors are not tracked across websites, and we do not build advertising profiles from widget data.
Remote help only starts after the visitor explicitly agrees in the moment and chooses the window themselves. The visitor's microphone and the agent's voice and optional camera are transmitted live, direct between both browsers, and only while the session runs. Nothing is recorded; only the start, duration and end are noted in the ticket. The visitor can stop the session at any time.
7. Recipients and processors
We work with carefully selected service providers who process data on our behalf under a data processing agreement (Art. 28 GDPR), in particular:
- Supabase (database, authentication, file storage)
- Lovable / Cloudflare (hosting and delivery of website, app and widget)
- Resend (sending and receiving transactional and support emails)
- Google, only if you choose Google sign-in (identity provider)
- Paddle.com Market Ltd (Merchant of Record and independent recipient for checkout, subscription management, payment processing, fraud prevention, tax compliance, invoicing and refunds). Paddle collects payment and billing details directly under its own privacy notice; Whazzup receives only the information required to activate and manage your plan.
Further information about Paddle's processing is available in Paddle's privacy notice.
The complete list with purpose, place of processing and transfer safeguards is published at Subprocessors. Business customers process their own end-user data with us under our data processing agreement.
Where data is processed outside the EU/EEA, this takes place on the basis of the EU standard contractual clauses or an adequacy decision. We do not sell personal data and do not share it with third parties for their own marketing purposes.
8. Cookies and local storage
We use technically necessary browser storage only. We do not use advertising, analytics or cross-site tracking cookies. Concretely, your browser stores:
- Session token (keeps you signed in; provided by Supabase Auth)
- Your consent decision for external content (key “whazzup.consent”), so we do not ask again on every visit
- Language preference (English or German)
- Interface preferences such as sidebar state, widget configuration and workspace settings
You can delete this data at any time via your browser settings; the app then simply forgets your preferences.
External fonts (Google Fonts): our public pages can display the fonts “Space Grotesk” and “DM Sans” provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. These fonts are only loaded after you actively agree in our consent banner. When they are loaded, your IP address and browser information are transmitted to Google and may be processed on servers in the USA on the basis of the EU standard contractual clauses. Legal basis is your consent under Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. Without consent no request is sent to Google and your device fonts are used instead.
You can change or withdraw your decision at any time with effect for the future via “Cookie settings” in the footer of our website. Withdrawal does not affect the lawfulness of processing carried out before it.
9. Chrome browser extension
We offer an optional browser extension for Chrome and other Chromium browsers. Its single purpose is to show the number of your new, still open support tickets as a badge on the toolbar icon and, if enabled, to play a short sound when a new ticket arrives. The extension does not read the content of any website you visit, does not modify web pages and does not track your browsing history.
The extension processes:
- The email address and session token of your Whazzup account (to sign you in and authorize requests)
- Subject and timestamp of your own open support tickets, in order to display them in the popup
- Your extension settings (sound on/off, check interval) and the IDs of tickets you have already seen, so that only genuinely new tickets are announced
Settings, the session and the seen-ticket IDs are stored exclusively locally in your browser (chrome.storage.local). They are removed when you sign out of the extension or uninstall it.
The extension communicates solely with the Whazzup backend (our Supabase instance). No data is passed on to third parties, used for advertising or analysed. Signing in with Google runs through the browser's secure OAuth flow; only your name and email address are transferred, as described in section 4.
Legal basis is Art. 6 (1) (b) GDPR (performance of the contract for the use of Whazzup). Uninstalling the extension ends this processing immediately; your account data is not affected by it.
10. Retention
- Account and settings data: stored for as long as your account exists; deleted or anonymized after account deletion, unless statutory retention applies.
- Support conversations: stored for as long as needed to handle the request and as long as the customer account exists.
- Server logs: deleted after a short period (typically a few weeks), unless needed to investigate an incident.
- Billing records: retained according to statutory tax and commercial law periods (in Germany generally 6 to 10 years).
- Widget sessions, identity tokens and rate-limit records: deleted automatically once they expire, checked hourly.
- Page views, events and anonymous visitor records: kept for the analysis period and then removed automatically; anonymous contacts without any data are not stored at all.
- Screen sharing: no recording is created; only start, duration and end are noted in the ticket.
11. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw any consent at any time with effect for the future (Art. 7 (3) GDPR).
You also have the right to lodge a complaint with a supervisory authority. Responsible for us is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (LfDI Rheinland-Pfalz), Hintere Bleiche 34, 55116 Mainz, Germany.
To exercise your rights or ask any data protection question, write to hello@whazzup.io.
12. Security incidents and data protection officer
If a personal data breach occurs, we notify the competent supervisory authority within 72 hours where required and inform affected customers without undue delay, at the latest within 24 hours of becoming aware, with a description of the incident and the measures taken. Suspected security issues can be reported at any time to hello@whazzup.io.
Due to our size and the nature of our processing we are not required to appoint a data protection officer under Art. 37 GDPR and § 38 BDSG. All data protection matters are handled by the management at the address above.
13. Changes to this policy
We update this privacy policy when our processing changes or when the law requires it. The current version is always available on this page with its date of last update.
