Legal
Privacy Policy
Draft — not yet in force
Who we are
ChatWatch is operated by [COMPANY: LEGAL ENTITY NAME], [COMPANY: COMPANY FORM], registered at [COMPANY: REGISTERED ADDRESS] (“ChatWatch”, “we”). We are the data controller for the personal data described here. Contact: [email protected].
What we collect
- Account data — your email address, your password, the platform you signed up from (web, iOS, or Android), which of our sites you signed up on, your language, your time-zone offset, and the date you registered.
- Marketing attribution — if you arrived through a campaign link, a
campaignIdcookie is read once at registration and stored on your account, so we know which campaign brought you. - Payment data — handled entirely by our payment providers. Depending on how you subscribed we store a Stripe customer and subscription ID, a PayPal payer ID and billing-agreement token, or the purchase receipt issued by Apple or Google, plus your plan and its start and expiry dates. Card details are entered directly with Stripe; we never receive or store your card number, and we do not store the last four digits either.
- Push and messaging identifiers — a Firebase push token for your device if you enable notifications, and your Telegram chat ID if you connect our Telegram bot.
- WhatsApp link — when you link a WhatsApp account by scanning the QR code, your phone authorises us as an additional linked device, exactly as WhatsApp Web does. To keep that link alive we store the device credentials your phone issues: an encryption key pair, a signed identity key and pre-keys, a registration ID, a pairing secret, your own WhatsApp ID and display name, and the per-conversation and app-state keys the protocol needs. These are held in our Redis store, keyed to your account, for as long as the link is active, and are deleted when you unlink or the session is revoked. They are the equivalent of a logged-in session on your account: we keep them only to maintain the connection, and we never use them to send anything from your account. They are encrypted at rest.
- Tracked contacts — the phone numbers you add and the names you give them.
- Your WhatsApp contacts list — so that you can pick the numbers you want to track from a list instead of typing them, we ask your WhatsApp account for your contacts and keep a copy — phone number and saved name — while your WhatsApp link is active. It is deleted when you unlink. We do not track, analyse, or contact anyone in that list unless you add them.
- Activity observations — for each contact you track, the online and offline timestamps we record, the profile picture URL WhatsApp exposes for them, and the analytics we derive from these (online history, NightWatch, chat probability).
- Technical data — IP address, browser, device type, screen size at sign-in, and server logs, kept for security and debugging.
- Usage analytics — which pages you visit, how you got here, your approximate location (from your IP address), your device and browser, and the steps you take in the sign-up and purchase flow (account created, WhatsApp linked, plan chosen, purchase completed). Collected through Google Analytics and Google Tag Manager, as described under Cookies and analytics. These events carry no name, email, or phone number.
What we do not collect
We do not read, store, or have access to the content of anyone’s messages, calls, or media. Our connection to WhatsApp does not subscribe to message events and does not request your message history, so message content never reaches our servers — only presence (online / offline) and the contacts list described above.
Why we use it, and on what legal basis
- To provide the service you signed up for (contract): running your account, keeping your WhatsApp link alive, recording and showing activity for the contacts you track, billing.
- To keep the service secure and working (legitimate interest): fraud prevention, abuse detection, debugging, capacity planning.
- To contact you (contract / legitimate interest): account notices, billing receipts, and — only with your consent — product updates.
- To understand which campaigns work (legitimate interest): the campaign identifier stored at registration.
- To understand how the site is used and whether our advertising works (consent where the law requires it, otherwise legitimate interest): the usage analytics above, and the conversion signal we send to Google Ads when a purchase completes.
How long we keep it
- Account data — for as long as your account exists. You can delete your account at any time, which removes your account record, the numbers you track, their activity history, and your cached data.
- Activity observations — the online / offline history we record for the contacts you track is kept for 12 months, then deleted automatically.
- WhatsApp session credentials and your contacts list — deleted when you unlink WhatsApp or close your account.
- Live status cache — the most recent online flag expires after 20 minutes, last-seen timestamps after 30 days, and profile picture URLs after 7 days.
- Payment records — as required by tax law, typically [COMPANY: N] years.
- Diagnostic logs — off by default. When enabled for troubleshooting, phone numbers and account identifiers are shortened so they cannot identify anyone, the files are capped in size, and they are deleted when you unlink your WhatsApp account.
Who we share it with
- Stripe — card payments and subscriptions.
- PayPal — payments, for accounts that subscribed that way.
- Apple and Google — in-app purchase and subscription validation, for accounts that subscribed in a mobile app.
- SendGrid (Twilio) — transactional email.
- Mixpanel — counts of subscription events (a trial starting, a subscription being cancelled). We send the event name only, with no identifier attached, so these cannot be traced back to you.
- Firebase Cloud Messaging (Google) — push notifications, if you enable them.
- Telegram — only if you choose to connect the Telegram bot.
- Google (Google Analytics, Google Tag Manager, Google Ads) — usage analytics for this website and conversion measurement for our advertising. Google receives your IP address and the identifiers in its own cookies; see Cookies and analytics below.
- Cloudflare — sits in front of our servers as a network proxy and firewall, so every request to chatwatch.net passes through it, and provides cookie-free, aggregate web analytics.
- DigitalOcean — servers and databases, hosted in their New York (NYC3) region in the United States.
- Authorities, where the law requires it.
We do not sell personal data. We do not give advertisers your name, email, phone number, or anything about the contacts you track. The only thing an advertising platform receives from us is the Google Ads conversion signal described below.
International transfers
Your data is processed in the United States. Our servers and databases run in DigitalOcean’s New York region, and every company we rely on — Stripe, PayPal, Apple, Google, SendGrid, Firebase, Mixpanel and Cloudflare — is US-based. If you use ChatWatch from the UK, the EEA, or anywhere else with data-transfer rules, your data leaves that region.
[COMPANY: STATE THE TRANSFER MECHANISM RELIED ON — Standard Contractual Clauses, the UK Addendum, or the EU-US Data Privacy Framework — AND WHICH PROCESSORS ARE COVERED BY WHICH. COUNSEL TO CONFIRM: this is the last substantive compliance gap in this policy, not a wording choice.]
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. You can delete your account and everything attached to it yourself, from your account settings. For anything else, email [email protected] with the subject line Data request. You can also complain to your local data-protection authority.
People you track
The contacts you add are not ChatWatch users. Their online / offline status is information WhatsApp already makes visible to your account according to their own privacy settings. You are responsible for having a lawful basis to monitor anyone you add — see the Terms of Service. [COUNSEL TO REVIEW THIS SECTION CAREFULLY — note that we also hold a copy of the linked account’s full contacts list and the profile picture URLs of tracked numbers, which is third-party personal data collected without those people’s knowledge.]
Cookies and analytics
Strictly necessary. Your session token and your contact list are held in your browser’s local storage so you stay signed in, and a campaignId cookie records the campaign you arrived from. These are needed for the service to work and are not used for tracking.
Analytics. We use Google Analytics 4, loaded through Google Tag Manager, to understand how the site is used: pages viewed, where visitors come from, device and browser, approximate location, and the steps of the sign-up and purchase flow. It sets Google’s _ga and _ga_* cookies, which hold a random identifier for your browser (not your name). Google processes this data on our behalf and retains the event data for [COMPANY: GA4 DATA-RETENTION SETTING]. We do not send Google your email, phone number, or the numbers you track.
Advertising measurement. When a purchase completes, a Google Ads conversion tag tells Google that a click on one of our ads led to a subscription, so we can see which ads pay for themselves. It uses Google’s _gcl_* cookies. [COMPANY: CONFIRM WHETHER REMARKETING AUDIENCES ARE ENABLED IN THE ADS ACCOUNT; IF SO, SAY SO HERE.]
Cookie-free measurement. Cloudflare Web Analytics counts page loads and performance without cookies or any identifier. Our subscription-event counts (Mixpanel) are recorded on our servers, not in your browser.
Your choices. You can block or delete cookies in your browser, install Google’s Analytics opt-out add-on, or manage advertising personalisation in your Google Ads Settings. The service works without the analytics and advertising cookies. [COUNSEL: for EEA and UK visitors these tags require prior consent under the ePrivacy rules. Decision needed before this policy takes effect: a consent banner with Google Consent Mode, or region-gating the tags.]
Children
ChatWatch is for adults. You must be 18 or older to create an account.
Changes to this policy
We will post any changes here and update the date above. For material changes we will also email account holders.
Contact
[email protected] — or see the contact page.