Privacy policy.
Last updated 24 May 2026. PromotionBot is GDPR-compliant. This page explains what we collect, why, and how long we keep it.
What we collect
- Account data — email, display name, password hash (bcrypt), timezone preference, org name.
- Linked WhatsApp account — phone number, profile name, and session login credentials (stored locally on the server).
- Messages you send — body, attachments, target groups, scheduled time. Retained 90 days for delivery + audit purposes, then auto-deleted.
- Messages you receive — when you enable the Monitor feature, incoming group messages that match your keyword filters. Retained 180 days.
- Click logs — when you opt into link tracking, the timestamp and country (geolocated from IP, never stored) of each click. Retained 180 days.
- Operational metadata — login IPs (for fail2ban / audit), API access logs (30 days), error logs (14 days).
- Product analytics — pages viewed, buttons and links clicked, browser/device type, and approximate location (country/region, derived from IP at collection time; the IP itself is not stored). Collected on both this website and the signed-in app, and processed by PostHog in the EU (see Sub-processors). Inside the app it's linked to your user and organisation so we can see which features are actually used; on the public pages it's anonymous until you sign up.
- Session replay (signed-in app only) — a reconstruction of your dashboard session (clicks, scrolls, navigation) to help us debug problems you report. All text is masked before it leaves your browser, so message content, group names, and contact details are never recorded — we see the shape of the page, not what's written on it. Not enabled on this public website.
What we don't collect
- Plain IP addresses of message recipients or link-clickers.
- The content of WhatsApp messages outside the groups you've configured for monitoring.
- Advertising or cross-site tracking. Our product analytics (above) are first-party and used only to improve PromotionBot. No ad networks, no Google Analytics, no Facebook Pixel, no data sold or shared for advertising, and no tracking of you across other websites.
How we use it
Strictly to deliver the service: deliver your messages, render your dashboard, send you billing emails, and respond to support requests. We do not sell, rent, or share your data with anyone except the processors listed below.
Sub-processors
- Creem.io (EU) — merchant of record. Handles checkout and stores your billing details (card number, billing address) under their own privacy policy. We receive only the subscription status, plan tier, and customer ID.
- Resend (US/EU) — transactional email delivery (signups, password resets, invites). They process recipient email + body for the duration of the send.
- Cloudflare (global) — tunnel/CDN in front of the app. Cloudflare may see request IPs for DDoS protection; they don't store request bodies.
- PostHog (EU — data stored in Frankfurt, Germany) — product analytics and session replay. Receives the events described above. Analytics requests are routed through our own domain rather than PostHog's, so you'll see them as first-party requests in your browser's network tab; this is to keep the data accurate, not to hide it from you.
Your rights (GDPR)
- Access — export everything we hold about you via the dashboard's Account → Export button or by emailing us.
- Correction — edit your profile, org name, and notification preferences from Settings.
- Deletion — close your account from the billing portal, or email us. We delete within 30 days.
- Objection / restriction — email [email protected].
Cookies
- Essential — one cookie (
connect.sid) to keep you signed in. - Analytics — PostHog sets first-party cookies (named
ph_*) on our domain to recognise a returning browser and group page views into a session. These are first-party only and are not used for advertising or shared with ad networks. - Preferences — the theme toggle stores a preference in
localStorage; this never leaves your browser.
No advertising cookies, and nothing that tracks you onto other websites.
Opting out. We honour your browser's “Do Not Track” setting — switch it on and we collect no analytics from you at all. You can also email [email protected] and we'll exclude your account. Note that a content blocker will not reliably opt you out: because we serve analytics from our own domain, blocklists that work by domain name don't catch it. Use Do Not Track instead.
Children
PromotionBot isn't intended for users under 16. We don't knowingly collect data from anyone under that age.
Changes
Material changes are announced via in-app banner and email at least 30 days before they take effect.
Contact
Email [email protected] with any privacy-related question. We respond within 7 days.