This Privacy Policy applies specifically to the Chrome extension “WASendly – WhatsApp Bulk Message Sender” (Chrome Web Store item ID: nhdbfplejhncelchgoknmkmndladimmp), hereafter “the Extension”.
The Extension is published and operated by Addons Chrome, hereafter “we”, “us” or “the Developer”, who is the data controller for the personal data described below. You can reach us at any time at contact@addonschrome.com.
This document explains, for the Extension: (a) what data we collect, (b) how we use it, (c) how and where it is stored and for how long we keep it, and (d) whether and with whom it is shared. It also covers your rights and how to delete your data.
1. Summary at a Glance
- Your recipient phone numbers, contact lists, message texts and attachments never leave your computer. They are stored only in your browser’s local storage on your own device and are never uploaded to our servers or to any third party.
- We do not read, collect, store or transmit the content of your WhatsApp conversations.
- The only personal data that reaches our servers is your Google account identity (if you choose to sign in) and a numeric daily message counter used to enforce free-plan limits.
- We never sell, rent or trade your personal data. We do not use your data for advertising, profiling or cross-site tracking.
2. Data We Collect
2.1 Data collected by us and transmitted to our servers
a) Google account information (personally identifiable information)
- Google account ID
- Email address of the Google account
- Display name (first and last name) on the Google account
- Profile picture URL of the Google account
- A short-lived OAuth 2.0 access token
This data is collected only if you actively choose to sign in by clicking “Sign in with Google” inside the Extension. Sign-in is performed through Google’s official OAuth 2.0 flow, using only the read-only scopes userinfo.email and userinfo.profile. The Extension never sees or handles your Google password. If you do not sign in, none of this data is collected.
b) Subscription and licence information
- Internal membership ID assigned by us
- Plan type (free or Pro) and subscription status
Payments are processed exclusively by our payment provider, Paddle. We never receive, process or store your credit/debit card number, CVV or bank details.
c) Daily usage counter (aggregate usage data)
- The number of messages sent on a given day, together with your Google account ID and the application ID
This is a count only. It contains no phone numbers, no recipient identities and no message content. Its sole purpose is to enforce the daily sending limit of the free plan and to display your remaining quota.
2.2 Data processed only on your own device and never transmitted
To provide its core functionality, the Extension processes the following data locally in your browser only. This data is stored in the browser’s local extension storage (chrome.storage.local) on your own computer. It is never sent to us, never sent to any third party, and never leaves your device:
- Recipient phone numbers that you type, paste, import from an Excel/CSV file, or extract from WhatsApp Web
- Contact names, group member lists and chat lists extracted from your own WhatsApp Web session at your request
- Message content: the message text, templates, personalisation variables and emojis you compose
- Attachments you select (images, videos, documents, spreadsheets) — these are read from your device and passed directly to WhatsApp Web
- Number validation results: whether a given number is registered on WhatsApp
- Sending reports and history: delivery status per recipient for campaigns you ran
- Your settings: sending delays, privacy/blur mode preferences, language and interface preferences
- Exported chat data: when you use the chat export feature, the file is generated on your device and downloaded directly to your computer
2.3 Data we explicitly do NOT collect
- Your WhatsApp credentials, phone number, WhatsApp session or WhatsApp authentication tokens
- The content of your incoming or outgoing WhatsApp conversations
- Your browsing history, the content of any website other than
web.whatsapp.com, or activity on other tabs
- Keystrokes, screenshots, clipboard contents or microphone/camera data
- Credit card numbers or bank account details
- Health, financial, biometric, precise location, or any other sensitive category of personal data
3. How We Use Your Information
Each category of data is used strictly for the purpose listed next to it, and for no other purpose:
- Google account ID and email → to create and identify your account, to authenticate you when you open the Extension, and to link your Pro licence to you.
- Display name and profile picture → to show who is signed in inside the Extension’s interface.
- Subscription and licence data → to unlock Pro features, to manage renewals and cancellations, and to provide billing support.
- Daily usage counter → to enforce the free-plan daily message limit and to display your remaining daily quota.
- Email address → to respond to your support requests and to send essential service notices (for example a change to this policy or to your subscription). We do not send marketing email without your separate opt-in consent.
- Locally stored data (numbers, messages, attachments, reports) → used exclusively on your device to compose and send your messages through WhatsApp Web and to show you the results.
We do not use any data for advertising, ad targeting, audience building, profiling, credit scoring, resale, or for training machine-learning models. We do not determine your identity or behaviour beyond what is described above.
4. Legal Basis for Processing (GDPR / KVKK)
- Performance of a contract (Art. 6(1)(b) GDPR): account creation, authentication, delivery of the Extension’s features, subscription management.
- Legitimate interests (Art. 6(1)(f) GDPR): enforcing free-plan limits, preventing abuse and fraud, keeping the service secure.
- Consent (Art. 6(1)(a) GDPR): the Google sign-in itself, which you initiate voluntarily, and any optional communications. You may withdraw consent at any time by signing out and requesting deletion.
- Legal obligation (Art. 6(1)(c) GDPR): retention of invoicing records where tax law requires it.
5. How and Where Your Data Is Stored and Secured
- On your device: all operational data described in section 2.2 is stored in the browser’s sandboxed extension storage (
chrome.storage.local), accessible only to this Extension on your own computer. It is not synced to any cloud service by us.
- On our servers: the account and counter data described in section 2.1 is stored on secured servers operated for us within the European Union, in access-controlled databases.
- In transit: all communication between the Extension and our servers is encrypted with HTTPS/TLS. Authentication uses the OAuth 2.0 protocol.
- Access control: access to production data is limited to authorised personnel who need it to operate the service, and is protected by individual credentials.
- Payments: card data is handled entirely by our PCI-DSS compliant payment provider and never reaches our systems.
- Breach notification: in the event of a personal data breach affecting you, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay where the law requires it.
6. How Long We Keep Your Data (Retention)
- Account data (Google ID, email, name, profile picture, membership record): retained for as long as your account exists. It is deleted within 30 days of your deletion request, and automatically after 24 months of complete inactivity.
- Daily usage counter: the daily figure resets every day; historical counters are retained for a maximum of 12 months for abuse prevention, then deleted.
- OAuth access token: short-lived; it expires automatically and is erased from your device when you sign out or remove the Extension.
- Locally stored data (numbers, messages, attachments, reports, settings): retained on your own device until you delete it inside the Extension, clear the browser data, or uninstall the Extension — uninstalling permanently erases it. We cannot access or recover it.
- Support correspondence: retained for up to 24 months after the request is closed.
- Invoicing and tax records: retained by us and by our payment provider for the period required by applicable tax legislation (typically up to 10 years).
7. Data Sharing and Disclosure
We do not sell, rent, trade or otherwise transfer your personal data to third parties for their own purposes. We share data only with the following processors, only to the minimum extent necessary, and only under contractual confidentiality and data-protection obligations:
- Google LLC — used solely to authenticate you when you choose “Sign in with Google”. Governed by the Google Privacy Policy.
- Paddle.com Market Ltd — our payment provider and merchant of record. Receives the billing details you enter on its own checkout page in order to process your subscription. Governed by the Paddle Privacy Policy.
- Our hosting provider — stores the account database on our behalf under a data processing agreement, with no right to use the data for its own purposes.
In addition, we may disclose data where we are legally required to do so — in response to a valid court order, subpoena or lawful request from a competent authority — or where strictly necessary to establish, exercise or defend legal claims, or to protect the rights and safety of our users. If the business is transferred to another entity, users will be notified in advance and the same protections will continue to apply.
The data listed in section 2.2 (phone numbers, contacts, message content, attachments, reports) is never shared with anyone, because it never leaves your device.
8. Google API Services — Limited Use Disclosure
The Extension’s use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Specifically, information obtained through Google APIs (your email address, name and profile picture) is used only to provide and improve the user-facing features of the Extension — namely account authentication and licence management. It is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with prior notice. It is not used for advertising or any advertising-related purpose, and no humans read this data except where you have given explicit consent for specific messages, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
9. Permissions Requested and Why
The Extension requests the minimum set of Chrome permissions needed for its stated purpose:
identity — to run the Google sign-in flow so your Pro licence can be recognised. No other identity data is accessed.
storage — to keep your recipient lists, message drafts, settings and reports locally on your device between sessions.
tabs and scripting — to detect and interact with the WhatsApp Web tab so messages can be composed and sent in your own session.
downloads — to save the Excel/CSV template and the reports or exports you request, directly to your computer.
- Host access to
web.whatsapp.com — strictly required to operate within WhatsApp Web on your behalf. The Extension does not read or act on any other website.
- Host access to
addonschrome.com, accounts.google.com and googleapis.com — solely for sign-in and licence/quota verification.
10. Your Rights
Under the GDPR, the Turkish KVKK, the CCPA/CPRA and other applicable laws, you have the right to:
- Access — obtain a copy of the personal data we hold about you
- Rectification — have inaccurate or incomplete data corrected
- Erasure — have your personal data deleted (“right to be forgotten”)
- Portability — receive your data in a structured, machine-readable format
- Restriction — ask us to limit how we process your data
- Objection — object to processing based on our legitimate interests
- Withdraw consent — at any time, without affecting the lawfulness of prior processing
- Opt out of sale or sharing — we do not sell or share personal data as defined by the CCPA/CPRA, so there is nothing to opt out of
- Lodge a complaint — with your local data protection supervisory authority
To exercise any of these rights, email contact@addonschrome.com. We respond within 30 days and never charge a fee for a first request. We will not discriminate against you for exercising your rights.
11. How to Delete Your Data
- Data on your device: use the clear/delete buttons inside the Extension, or remove the Extension from
chrome://extensions. Removing it permanently deletes all locally stored numbers, messages, attachments, reports and settings.
- Your account on our servers: send a deletion request to contact@addonschrome.com from the email address associated with the account. We erase your account record, email, name, profile picture and usage counters within 30 days and confirm by email.
- Google access: you can additionally revoke the Extension’s access to your Google account at any time via myaccount.google.com/permissions.
12. International Data Transfers
Our servers are located in the European Union. Where a processor (for example Google or Paddle) processes data outside your country, the transfer is protected by an adequacy decision of the European Commission or by Standard Contractual Clauses, together with appropriate technical and organisational safeguards.
13. Children’s Privacy
The Extension is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16 (or under 13 where that lower threshold applies). If we learn that we have collected such data, we will delete it promptly. If you believe a child has provided us with personal data, contact contact@addonschrome.com.
14. Your Responsibilities as a Sender
When you use the Extension to contact other people, you are the controller of those recipients’ personal data. You are responsible for having a lawful basis (such as consent) to contact them, for honouring opt-out requests, and for complying with WhatsApp’s Terms of Service and all applicable anti-spam and data protection laws in your jurisdiction. We do not receive, store or process your recipients’ data at any point.
15. Independence from WhatsApp
WASendly is an independent product. It is not affiliated with, endorsed by, sponsored by or in any way officially connected to WhatsApp LLC, Meta Platforms, Inc. or any of their subsidiaries. “WhatsApp” is a trademark of its respective owner and is used here only to describe compatibility.
16. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top always reflects the current version. If we make a material change to how we handle your personal data, we will notify you by email and through a notice inside the Extension before the change takes effect. Continuing to use the Extension after a change indicates your acceptance of the updated policy.
17. Contact and Data Controller
18. Compliance
This Privacy Policy is designed to comply with:
- The EU General Data Protection Regulation (GDPR)
- The Turkish Personal Data Protection Law (KVKK No. 6698)
- The California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA)
- The Chrome Web Store Developer Program Policies and User Data Policy, including the Limited Use requirements
- Other applicable regional data protection laws