Privacy Policy

Last updated: 2026-09-17

1. What we collect

When you create an account: your email address, account/business name, and (optionally) a backup password and two-factor authentication secret.

When someone clicks a link, scans a QR code, or submits a form you created: timestamp, the destination it routed to, referral source, country (derived from IP, not stored as a precise location), device type, operating system, and browser (parsed from the request's user agent), and the raw IP address and user agent string.

Billing: Stripe or AurPay process your payment details directly — we don't store full card numbers or wallet private keys ourselves.

2. How we use it

3. Data retention

Click and scan analytics are retained for a default of up to 400 days on accounts with an active paid subscription (this window can be extended per plan) and up to 30 days on accounts without one, after which they're permanently deleted. Account records are kept until you close your account or request deletion.

4. Who we share it with

We don't sell your data. We share the minimum necessary with the service providers that make wapro.link work: our cloud hosting provider (Amazon Web Services), payment processors (Stripe, AurPay), and our transactional email provider. Each is bound by its own data-processing terms.

5. Cookies

We use a single session cookie to keep you logged in across wapro.link's apps. We don't use third-party advertising or tracking cookies.

6. Your rights

You can access, correct, or delete your account data at any time from your account settings, or by contacting us -- that request channel handles every jurisdiction's rights request today, including GDPR access/erasure/portability requests and CCPA "do not sell" requests (we don't sell personal data in any jurisdiction, so that request is already satisfied by default). We aim to respond within 30 days. If you're located somewhere with additional statutory rights beyond what's described here, contact us and we'll address the specific request; we haven't yet published a jurisdiction-by-jurisdiction breakdown of every regional variation.

7. Security

We use industry-standard practices to protect your data, including encryption in transit (TLS), optional two-factor authentication, and access controls limiting who can see account data. No system is 100% secure, and we can't guarantee absolute security.

8. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by an updated "Last updated" date above.

9. Contact

Questions about this policy or your data? Contact us.