Skip to content
Whosta
How it works Pricing Integrations
Sign in Get started

Privacy Policy

Effective date: 14 July 2026  ·  Operator: Xborder Technologies, Odenthal, Germany  ·  Contact: support@whosta.com

This policy explains how Xborder Technologies (“Whosta”, “we”, “us”) collects, uses, shares, and protects personal data when you use whosta.com. We process personal data as a controller under the General Data Protection Regulation (GDPR). Please read this policy before using the service.

1. Who we are

Whosta is operated by Xborder Technologies, represented by its founder Mr. Satish Krishnan, Scheurener Str. 169, 51519 Odenthal, North Rhine-Westphalia, Germany.

Contact for privacy matters: support@whosta.com  ·  Phone: +49 1521 0686415

No Data Protection Officer has been formally appointed. Privacy enquiries are handled directly by the operator at the contact details above.

2. Data we collect and why

2.1 Account and registration data

When you create an account we collect your name, email address, and a securely hashed password. We use this data to authenticate you, send you service-related emails, and manage your account.

2.2 Integration and OAuth authorisation data

When you connect a third-party platform such as Google Ads, WooCommerce, or Shopify, we store authorisation credentials including encrypted OAuth refresh tokens, OAuth scope identifiers, the date authorisation was granted, and the platform account identifier. We do not store your Google password or any other platform login password.

2.3 Google Ads data

When you authorise the Google Ads integration, Whosta may access the following categories of data from your Google Ads account via the Google Ads API, using the https://www.googleapis.com/auth/adwords OAuth scope:

  • Google Ads customer account identifiers and account names
  • Campaign, ad group, and ad metadata and status
  • Keyword lists, match types, and bid data
  • Search term report data
  • Keyword Planner research data and historical performance metrics
  • Account-level performance statistics (impressions, clicks, cost, conversions)

This data is accessed solely to provide the Whosta reporting and AI-query features you request. We do not use Google Ads data to profile you for advertising, to build audiences for advertising unrelated to the requested service, to sell your data, or for any purpose beyond providing the Whosta service to you.

The Google Ads integration is currently in a testing phase. When enabled, the initial release is designed to operate in a read-only mode: Whosta’s application code does not call any Google Ads API write operations. Note that the OAuth scope used (adwords) technically permits broader API access; read-only behaviour is enforced at the application level, not by the OAuth scope itself. Whosta does not use that scope to create, modify, pause, or delete campaigns, bids, or ads.

2.4 Ecommerce store data

When you connect a WooCommerce or Shopify store, we may access order data, product catalogue information, stock levels, customer counts, and sales summaries. This data is used to answer your queries and generate reports within the Whosta service.

2.5 Technical and security data

We collect IP addresses, browser type and version, device type, operating system, referring URL, pages viewed, timestamps, session identifiers, and application error logs. This data is used for security monitoring, fraud prevention, debugging, and service improvement.

2.6 Support and communications

If you contact us for support, we retain the content of those communications, your email address, and any information you provide to help resolve your query.

2.7 Billing and subscription data

For paid accounts we collect and retain invoice records, subscription tier, and billing event history. Full payment card details are handled by our payment processor and are not stored on our servers.

2.8 Cookies and similar technologies

Whosta uses essential session cookies to keep you logged in. We do not currently use third-party advertising or tracking cookies. If we introduce optional analytics or marketing cookies in the future, we will update this policy and request consent where required by law.

3. Lawful basis for processing

Processing activityLawful basis (GDPR Art. 6)
Account creation and authenticationPerformance of contract (Art. 6(1)(b))
Providing the integration and reporting servicePerformance of contract (Art. 6(1)(b))
Google Ads API data processingPerformance of contract (Art. 6(1)(b))
Ecommerce data access and reportingPerformance of contract (Art. 6(1)(b))
Security monitoring and fraud preventionLegitimate interests (Art. 6(1)(f))
Service improvement and debuggingLegitimate interests (Art. 6(1)(f))
Responding to support requestsLegitimate interests (Art. 6(1)(f))
Billing records and invoicingLegal obligation (Art. 6(1)(c)) and contract
Compliance with data-subject rights requestsLegal obligation (Art. 6(1)(c))

4. Google API Services and Limited Use

Whosta’s use of information received from Google APIs, including the Google Ads API, complies with the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We access Google Ads data only to provide the features and functionality you explicitly request in the Whosta service.
  • We do not share Google user data with third parties except as necessary to provide the requested features, to comply with applicable law, or as explicitly authorised by you.
  • We do not use Google user data for serving advertisements or for building advertising profiles unrelated to the service you requested.
  • We do not sell Google user data.
  • We do not use Google user data to train machine-learning models that serve users other than you.
  • We do not allow humans to read your Google user data except where technically necessary to resolve a security or service issue you have reported, where required by applicable law, or where you have given explicit consent.

You can revoke Whosta’s Google account access at any time by visiting myaccount.google.com/permissions or by disconnecting the integration from your Whosta dashboard. See our Data Deletion page for the full disconnection and deletion process.

5. Credential security and encryption

  • OAuth refresh tokens are encrypted using AES-256-CBC with HMAC integrity verification before being stored in our database. The encryption key is stored as a protected environment variable, never in source code or version control.
  • Access tokens (short-lived Google API tokens) are cached in application memory for their validity period and are never written to the database in plain text.
  • No credentials are logged, printed, or committed to source control. Our engineering policy prohibits including any credential value in logs, chat history, documentation, or test fixtures.
  • All data in transit between your browser, our servers, and Google’s APIs is protected using TLS 1.2 or higher.

6. Data retention

CategoryRetention period
Active account dataRetained while your account is active
Account data after deletionRemoved or anonymised within 30 days, unless legal retention is required
OAuth refresh tokensDeleted immediately when you disconnect the integration, revoke access, or delete your account
Imported ecommerce and Google Ads dataRetained while needed to provide the service; deleted or anonymised within 30 days of account deletion or confirmed deletion request
Support communicationsUp to 3 years after the support matter is closed
Security and technical logsOrdinarily up to 12 months
Failed-login and fraud-prevention recordsOrdinarily up to 24 months where necessary for security
Billing, invoice, and tax recordsRetained for the applicable statutory period under German commercial and tax law. Depending on the type of document, the required retention period may be six, eight, or ten years. Whosta retains only what is necessary to comply with the applicable legal obligation.
Consent records and legal compliance evidenceRetained as long as needed to demonstrate compliance or defend legal claims

Legal, regulatory, fraud-prevention, security, or dispute-resolution obligations may require us to retain limited categories of information beyond the standard periods shown above.

7. Data sharing and recipients

We do not sell your personal data. We share data only as follows:

  • Subprocessors: Cloud hosting and infrastructure providers who process data on our behalf under contractual data-processing agreements. These parties process data only as instructed by Xborder Technologies.
  • Google LLC: We transmit data to Google’s APIs as directed by you when you use the Google Ads integration. Google’s use of data submitted through its APIs is governed by Google’s own privacy policy and terms.
  • Payment processor: Billing information is handled by our payment processor, who processes it only for payment purposes.
  • Legal requirements: We may disclose data where required by applicable law, court order, or instruction from a competent authority.
  • Security: We may share data where necessary to protect the rights, property, or security of Whosta, our users, or the public.
  • Your explicit instruction: We may share data where you have specifically directed us to do so.

8. International data transfers

Our production servers are currently hosted in the United States by a third-party infrastructure provider. This means that personal data processed by Whosta is transferred to, and stored in, the United States. We rely on the European Commission’s Standard Contractual Clauses (SCCs) as the appropriate safeguard for this transfer under Chapter V of the GDPR. Where we use additional subprocessors outside the EEA, we apply the same or equivalent safeguards.

9. Your rights under the GDPR

You have the following rights in respect of your personal data:

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — ask us to correct inaccurate or incomplete data.
  • Right to erasure — request deletion of your personal data, subject to legal retention obligations.
  • Right to restriction — ask us to restrict processing in certain circumstances.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interests.
  • Right to withdraw consent — where processing is based on your consent, withdraw it at any time without affecting prior lawful processing.

To exercise any of these rights, email support@whosta.com with the subject line “Data Subject Request”. We will acknowledge within 72 hours and respond within one calendar month. We may need to verify your identity before fulfilling the request.

You also have the right to lodge a complaint with the competent data protection supervisory authority. For users in North Rhine-Westphalia:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
www.ldi.nrw.de

10. Data deletion and integration disconnection

You can disconnect any integration at any time from your Whosta dashboard. On disconnection, the OAuth refresh token for that integration is immediately revoked at the provider and deleted from our systems. Cached access tokens are cleared. You may also revoke Whosta’s Google access directly at myaccount.google.com/permissions.

For full account and data deletion instructions, see our Data Deletion page.

11. Children’s privacy

Whosta is a business-to-business SaaS platform intended for businesses and their authorised users. It is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently done so, we will promptly delete the data.

12. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, or unlawful disclosure. These measures include encryption in transit and at rest, access controls, and continuous security monitoring. See our Security page for further detail. No method of internet transmission is completely secure; we cannot guarantee absolute security.

13. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or in applicable law. Material changes will be communicated by email or by a prominent notice on the website before they take effect. The effective date at the top of this page indicates when the policy was last updated. Continued use of the service after the effective date of a material change constitutes your acknowledgement of the updated policy.

14. Contact

  • Email: support@whosta.com
  • Phone: +49 1521 0686415
  • Operator: Xborder Technologies (represented by Mr. Satish Krishnan), Scheurener Str. 169, 51519 Odenthal, Germany
Whosta

AI access to your store’s data — by text or voice, in your own language.

Operated by Xborder Technologies
Odenthal, Germany

Product

How it works Pricing Integrations Google Ads Security

Company

About Us Contact FAQs

Legal & Support

Privacy Policy Terms of Service Data Deletion Impressum Google Ads Help support@whosta.com
© 2026 Xborder Technologies. All rights reserved. Odenthal, Germany  ·  support@whosta.com