Privacy Policy
Last updated: 16 August 2026
This policy explains what data WaHttp collects, why we collect it, how long we keep it, and what rights you have over it.
For anything in this policy, write to [email protected].
WaHttp is not affiliated with, endorsed by, or connected to WhatsApp LLC or Meta Platforms, Inc.
1. A note on how WaHttp works
WaHttp connects to WhatsApp using the WhatsApp Web protocol. You link your own WhatsApp number by scanning a QR code or entering a pairing code, and our servers then hold an authenticated session on your behalf so that messages can be sent and received over our API.
This has a direct privacy consequence you should understand before signing up: to keep that session alive, our servers store the authentication credentials WhatsApp issues for your linked device, and messages passing through your session pass through our infrastructure. If you are not comfortable with that, WaHttp is not the right tool for you.
2. Data we collect
Account and workspace data. Your name, email address, a hashed password, your workspace name, team member names and email addresses, and the roles assigned to them.
Billing data. Your plan, renewal date, billing history and country. Card details are entered directly with our payment processor, Stripe or PayPal, and are never stored on WaHttp servers. We receive only a payment reference, the last four digits, and the outcome of each transaction.
WhatsApp session data. The phone number you link, a session identifier, connection status and timestamps, and the encrypted authentication credentials that keep your linked device connected. These credentials are what allow WaHttp to act as a linked device on your account. Deleting a session destroys them.
Message content and metadata. Messages sent and received through your sessions, including text, media, sender and recipient numbers, group identifiers, timestamps and delivery receipts. Message history is shown to you in the Chats area of your dashboard and is retained so that feature works.
Integration data. Webhook endpoint URLs, event subscriptions, delivery logs and signing secrets. API keys, their scopes and their usage records. MCP connection records.
Technical and usage data. IP address, browser and device type, pages visited, API request logs, error logs and rate-limit counters.
Support correspondence. Anything you send us by email or WhatsApp, including the WhatsApp number you contact us from.
3. Why we collect it, and our legal basis
| What we do | Legal basis under UK/EU GDPR |
|---|---|
| Create and run your account, deliver the service you pay for | Performance of a contract |
| Take payment and manage renewals | Performance of a contract |
| Keep sessions connected and messages flowing | Performance of a contract |
| Log requests, monitor abuse, enforce rate limits, protect against fraud | Legitimate interests (running a secure service) |
| Improve reliability, diagnose faults, plan capacity | Legitimate interests |
| Answer support requests | Performance of a contract / legitimate interests |
| Send service notices about outages, billing or security | Performance of a contract / legal obligation |
| Send marketing email, if you opt in | Consent, withdrawable at any time |
| Keep financial records | Legal obligation |
We do not sell your data, and we do not share it with advertisers.
4. Your role as a data controller
This is the part most WhatsApp API providers gloss over, and it matters if you are a business.
When you use WaHttp to message your own customers, you decide who gets messaged and why. Under data protection law that generally makes you the controller of your contacts' personal data, and WaHttp the processor acting on your instructions. In practice this means:
- You are responsible for having a lawful basis to message the people you message, and for honouring opt-outs.
- You are responsible for telling your own contacts how their data is handled, in your own privacy notice.
- We process contact data only to deliver the service, and we do not use it for our own purposes.
If your organisation needs a signed Data Processing Agreement covering this arrangement, email [email protected] and we will provide one.
5. Who we share data with
We use a small number of service providers, each of which processes data only on our instructions:
Hosting, Stripe or PayPal or Support mail.
Your messages are delivered to WhatsApp's own servers as part of normal operation. WhatsApp's handling of that data is governed by WhatsApp's own privacy policy, not ours.
6. Your rights
Under UK and EU data protection law you can ask us to:
- give you a copy of the data we hold about you
- correct anything inaccurate
- delete your data, where we have no overriding reason to keep it
- restrict how we use it while a dispute is resolved
- export your data in a portable format
- stop processing based on legitimate interests, where you object
- withdraw consent for marketing, at any time
Email [email protected] and we will respond within one month. We may ask you to verify your identity first, since we are not going to hand over account data to someone who merely claims to own it.
7. Children
WaHttp is a developer tool for businesses. It is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, email us and we will delete it.