How website, portal, licensing, and support information is handled
Effective and last updated: August 9, 2026
This Policy covers information handled by WAPIServer through the WAPIServer public website, licensing/customer portal, purchases, downloads, updates, and support. It does not make WAPIServer the controller of all data stored inside a customer’s self-hosted WAPI installation.
1. Scope and data roles
For the website, licensing portal, account, purchase, update, and direct support records described here, WAPIServer determines why and how the information is used, subject to applicable law. When a customer installs WAPI on infrastructure it controls and uses it for contacts, messages, campaigns, forms, chatbots, orders, appointments, invoices, files, employees, or other business records, that customer normally decides the purposes and means of processing. The customer is responsible for notices, lawful basis, permissions, retention, security, and rights handling for that environment.
If Support receives a customer-approved diagnostic context, attachment, or other data to resolve a request, we process it only for the support, security, quality, and legal purposes described here and the applicable support terms.
2. Information we may collect
Account and identity: name, email, company, role, authentication provider, verification state, and security events.
License and deployment: authorized domain, license key identifiers, plan, feature entitlement, version, activation, validation, update, and installation status. Private license secrets are protected and are not intended for public display.
Transaction: selected plan, billing cycle, order, invoice, payment status, and checkout/provider references required to administer a purchase. Payment-card details may be handled directly by the selected payment provider rather than stored by us.
Support: ticket or chat subject, messages, selected category, product/version context, attachments you intentionally provide, support entitlement, replies, ratings, and resolution history.
Technical and security: IP address, browser/device and request metadata, session and authentication data, timestamps, rate-limit and abuse signals, error/security events, and portal activity required to protect and operate the service.
Contact and preference: general enquiry fields, onboarding interest, communication preferences, and consent or unsubscribe state where applicable.
3. Sources of information
We receive information directly from you; from authorized administrators or colleagues acting for your organization; from the WAPI software when it performs licensed activation, validation, update, support-context, or security operations; and from selected authentication, checkout, email, hosting, security, or integration providers. We may also derive limited status and risk information from those records.
4. How information is used
create, verify, authenticate, and secure portal accounts;
issue, validate, administer, suspend, recover, and support software licenses and entitlements;
provide downloads, updates, release information, onboarding, tickets, chat, and requested support;
process or confirm purchases, plans, billing, cancellations, and related records;
send verification, security, license, billing, update, support, and other requested operational notices;
prevent fraud, spam, misuse, unauthorized access, and attacks;
measure service reliability, support quality, and website/portal operation using appropriately limited data;
comply with law, enforce terms, protect rights and safety, and establish or defend legal claims;
send marketing only when permitted and provide the required choice to stop it.
The applicable legal basis depends on location and context and may include performance of a contract, steps requested before a contract, legitimate interests in operating and securing the service, compliance with legal obligations, protection of vital interests, or consent where required.
5. Cookies, consent, and analytics
The website and portal use session cookies or local storage needed for login, CSRF protection, OAuth state, security, preferences, and essential operation. Browser settings may block storage, but essential portal functions may then stop working.
Google Analytics 4 is configured with analytics storage denied by default. If you choose Allow analytics, Google Analytics may store analytics identifiers and measure page views, navigation, and the conversion events described on this website. Advertising storage, ad user data, ad personalization, and Google signals remain disabled. WAPIServer does not intentionally send form values, email addresses, message content, license keys, or other account secrets to Google Analytics. You can reopen Cookie choices in the footer and change the choice on this browser.
6. Operational and marketing communications
Operational messages may include account verification, password recovery, security alerts, license or plan changes, purchase records, update information, and support replies. These are connected to the requested service and may continue while the related account, contract, or request is active. Marketing communications, when used, must provide the required opt-out. Stopping marketing does not stop necessary operational notices.
7. Service providers, legal disclosure, and organizational access
Information may be shared with service providers that support hosting, email, authentication, payments, security, storage, delivery, analytics, or support, but only to the extent reasonably required for their task and subject to appropriate obligations. Authorized staff and contractors receive access according to role and need.
Information may also be disclosed when required by law or valid legal process; to protect users, the service, rights, safety, and security; to investigate fraud or violations; or in connection with a merger, acquisition, financing, reorganization, or sale subject to applicable safeguards and notice obligations.
8. Customer-selected third-party services
Google, authentication, checkout, email, WhatsApp/Meta, CRM, ecommerce, automation, payment, tax-authority, and other optional providers apply their own privacy terms to information they receive. The customer decides whether to connect an optional provider and which supported records or fields to exchange. WAPIServer is not responsible for a third party’s independent practices.
9. International data transfers
The website, portal, support team, and selected providers may operate in more than one country. Where personal information is transferred across borders, the responsible party must use the mechanism and safeguards required by applicable law. Contact us for information relevant to a specific portal or support transfer.
10. Retention
We retain website, account, license, transaction, security, and support records for periods reasonably necessary to provide the service, maintain license and release integrity, prevent fraud, resolve disputes, meet legal/accounting obligations, protect security, and enforce agreements. Different records may require different periods. When information is no longer required, it is deleted, anonymized, or access-restricted according to the applicable process. Backups and immutable security or transaction evidence may expire on a delayed cycle.
Customers control retention and deletion inside their self-hosted WAPI environments, subject to their legal and operational obligations.
11. Security
We use technical and organizational measures appropriate to the portal and support risks, such as access controls, password hashing, protected credentials, CSRF and authentication controls, validation, logging, restricted attachments, and secure transport where configured. No system or transmission can be guaranteed completely secure. Customers must secure their own server, database, files, backups, users, integrations, and network.
12. Access, correction, deletion, objection, and other choices
Depending on applicable law and the record, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review of a decision. We may need to verify identity and may retain information when required for licensing, transactions, security, legal obligations, claims, or another lawful exception.
For data inside a customer-controlled WAPI installation, contact that customer first. For WAPIServer portal or support information, use the contact path below. You may also update available account fields, unsubscribe from optional marketing, or close an account through the provided workflow.
13. Children
WAPIServer is a business product and is not directed to children. Do not create a portal account or submit a child’s personal information unless you have the authority, lawful basis, notices, and safeguards required for the business purpose and applicable law.
14. Policy changes
We may update this Policy when product, provider, legal, or operational practices change. The effective date will be updated here. Material changes may also be notified through the website, portal, or account email when required or reasonably appropriate.