Privacy Policy
Last updated 11 August 2026
This policy explains what personal data WAButton handles, why, and what rights you have over it. It covers our website, our dashboard, and the chat widget our customers embed on their own sites.
Who we are
WAButton provides an embeddable WhatsApp chat and lead capture widget. For questions about this policy or about your data, contact privacy@wabutton.app.
Two different roles
This distinction matters, because it decides who you should contact about what.
- For our own customers, we are the controller. When you create a WAButton account, we decide what account data we hold and why.
- For the people who message our customers, we are a processor. If you filled in a form on a business's website and it was powered by WAButton, that business is the controller of your data. We handle it on their instructions. Please contact them first. If you cannot reach them, write to us and we will help.
What we collect
Account data
Your name, email address, hashed password, and the organisation and team membership you belong to. If you sign in with Google, we receive your name, email address and profile picture from Google. We never receive your Google password.
Billing data
Your plan, billing period, and subscription status. Payments are processed by Stripe. We do not store card numbers. Card details are entered directly with Stripe and never reach our servers.
Widget configuration
Everything you set up in the editor: agent names and WhatsApp numbers, greetings, business hours, routing rules, form fields, and the domains you have authorised.
Leads captured through widgets
Whatever the widget owner chose to collect before the conversation moves to WhatsApp, which is typically a name, an email address or phone number, and a message. The widget owner decides these fields. We store them so the owner can see and export them.
Technical data
IP address, user agent, and requested page. We use these to apply rate limits, enforce the IP blocking and domain restrictions our customers configure, resolve country for geo targeting, and investigate abuse. IP addresses are not used to build advertising profiles.
Error and diagnostic data
When something breaks, our error monitoring records the technical context of the failure. This can incidentally include an account identifier.
Why we are allowed to process it
| Data | Lawful basis |
|---|---|
| Account and widget configuration | Performance of our contract with you |
| Billing | Performance of contract, and our legal obligation to keep financial records |
| Leads captured through a widget | Processed on the widget owner's instructions, under their lawful basis |
| Security, rate limiting, abuse prevention | Our legitimate interest in keeping the service available and unabused |
| Error monitoring | Our legitimate interest in a service that works |
| Marketing email to customers | Consent, withdrawable at any time |
Who else touches your data
We use a small number of sub-processors. We do not sell personal data to anyone.
| Provider | Purpose | Where |
|---|---|---|
| Google Cloud | Application hosting and databases | Belgium (europe-west1) |
| Cloudflare | Edge delivery of the widget script | Global edge network |
| Stripe | Payment processing and subscription billing | EU and US |
| Resend | Transactional email | EU and US |
| Sentry | Error monitoring | EU |
| Optional sign-in with Google | EU and US |
We may also disclose data where the law requires it, or to establish or defend legal claims.
Where your data lives
Our application servers and databases run in Google Cloud's europe-west1 region in Belgium. Some sub-processors above operate outside the UK and the EEA. Where that happens, transfers rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.
How long we keep it
- Account and widget data: while your account is open, then deleted within 90 days of closure.
- Leads: until the widget owner deletes them or closes their account.
- Billing records: six years, as UK tax law requires.
- Technical and security logs: up to 90 days.
Your rights
Under the UK GDPR and the EU GDPR you can ask us to:
- give you a copy of your data, or send it to another provider
- correct data that is wrong
- delete your data
- restrict or object to how we process it
- withdraw consent you previously gave, without affecting what came before
Write to privacy@wabutton.app and we will respond within one month. You do not have to pay to exercise these rights.
If you are unhappy with our response you can complain to the UK Information Commissioner's Office at ico.org.uk, or to your local supervisory authority in the EEA.
Cookies
Our dashboard sets a cookie to keep you signed in. That cookie is strictly necessary, so it does not require consent. This marketing site does not set advertising or tracking cookies. The embedded widget uses your browser's local storage to remember whether it has already greeted you, so it does not repeat itself on every page.
Security
Data is encrypted in transit. Passwords are hashed, never stored in readable form. Access to production systems is limited to those who need it. No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your rights, we will notify the ICO within 72 hours and tell you where the law requires it.
Children
WAButton is a business tool and is not directed at children under 16. We do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
Changes
We will update this page when our practices change and revise the date at the top. If a change materially affects your rights, we will tell account holders by email.