Privacy Policy
This policy explains how Xborder Technologies (“Whosta”, “we”, “us”) collects, uses, shares, and protects personal data when you use whosta.com. We process personal data as a controller under the General Data Protection Regulation (GDPR). Please read this policy before using the service.
1. Who we are
Whosta is operated by Xborder Technologies, represented by its founder Mr. Satish Krishnan, Scheurener Str. 169, 51519 Odenthal, North Rhine-Westphalia, Germany.
Contact for privacy matters: support@whosta.com · Phone: +49 1521 0686415
No Data Protection Officer has been formally appointed. Privacy enquiries are handled directly by the operator at the contact details above.
2. Data we collect and why
2.1 Account and registration data
When you create an account we collect your name, email address, and a securely hashed password. We use this data to authenticate you, send you service-related emails, and manage your account.
2.2 Integration and OAuth authorisation data
When you connect a third-party platform such as Google Ads, WooCommerce, or Shopify, we store authorisation credentials including encrypted OAuth refresh tokens, OAuth scope identifiers, the date authorisation was granted, and the platform account identifier. We do not store your Google password or any other platform login password.
2.3 Google Ads data
When you authorise the Google Ads integration, Whosta may access the following categories of data from your Google Ads account via the Google Ads API, using the https://www.googleapis.com/auth/adwords OAuth scope:
- Google Ads customer account identifiers and account names
- Campaign, ad group, and ad metadata and status
- Keyword lists, match types, and bid data
- Search term report data
- Keyword Planner research data and historical performance metrics
- Account-level performance statistics (impressions, clicks, cost, conversions)
This data is accessed solely to provide the Whosta reporting and AI-query features you request. We do not use Google Ads data to profile you for advertising, to build audiences for advertising unrelated to the requested service, to sell your data, or for any purpose beyond providing the Whosta service to you.
The Google Ads integration is currently in a testing phase. When enabled, the initial release is designed to operate in a read-only mode: Whosta’s application code does not call any Google Ads API write operations. Note that the OAuth scope used (adwords) technically permits broader API access; read-only behaviour is enforced at the application level, not by the OAuth scope itself. Whosta does not use that scope to create, modify, pause, or delete campaigns, bids, or ads.
2.4 Ecommerce store data
When you connect a WooCommerce or Shopify store, we may access order data, product catalogue information, stock levels, customer counts, and sales summaries. This data is used to answer your queries and generate reports within the Whosta service.
2.5 Technical and security data
We collect IP addresses, browser type and version, device type, operating system, referring URL, pages viewed, timestamps, session identifiers, and application error logs. This data is used for security monitoring, fraud prevention, debugging, and service improvement.
2.6 Support and communications
If you contact us for support, we retain the content of those communications, your email address, and any information you provide to help resolve your query.
2.7 Billing and subscription data
For paid accounts we collect and retain invoice records, subscription tier, and billing event history. Full payment card details are handled by our payment processor and are not stored on our servers.
2.8 Cookies and similar technologies
Whosta uses essential session cookies to keep you logged in. We do not currently use third-party advertising or tracking cookies. If we introduce optional analytics or marketing cookies in the future, we will update this policy and request consent where required by law.
3. Lawful basis for processing
| Processing activity | Lawful basis (GDPR Art. 6) |
|---|---|
| Account creation and authentication | Performance of contract (Art. 6(1)(b)) |
| Providing the integration and reporting service | Performance of contract (Art. 6(1)(b)) |
| Google Ads API data processing | Performance of contract (Art. 6(1)(b)) |
| Ecommerce data access and reporting | Performance of contract (Art. 6(1)(b)) |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Service improvement and debugging | Legitimate interests (Art. 6(1)(f)) |
| Responding to support requests | Legitimate interests (Art. 6(1)(f)) |
| Billing records and invoicing | Legal obligation (Art. 6(1)(c)) and contract |
| Compliance with data-subject rights requests | Legal obligation (Art. 6(1)(c)) |
4. Google API Services and Limited Use
Whosta’s use of information received from Google APIs, including the Google Ads API, complies with the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We access Google Ads data only to provide the features and functionality you explicitly request in the Whosta service.
- We do not share Google user data with third parties except as necessary to provide the requested features, to comply with applicable law, or as explicitly authorised by you.
- We do not use Google user data for serving advertisements or for building advertising profiles unrelated to the service you requested.
- We do not sell Google user data.
- We do not use Google user data to train machine-learning models that serve users other than you.
- We do not allow humans to read your Google user data except where technically necessary to resolve a security or service issue you have reported, where required by applicable law, or where you have given explicit consent.
You can revoke Whosta’s Google account access at any time by visiting myaccount.google.com/permissions or by disconnecting the integration from your Whosta dashboard. See our Data Deletion page for the full disconnection and deletion process.
5. Credential security and encryption
- OAuth refresh tokens are encrypted using AES-256-CBC with HMAC integrity verification before being stored in our database. The encryption key is stored as a protected environment variable, never in source code or version control.
- Access tokens (short-lived Google API tokens) are cached in application memory for their validity period and are never written to the database in plain text.
- No credentials are logged, printed, or committed to source control. Our engineering policy prohibits including any credential value in logs, chat history, documentation, or test fixtures.
- All data in transit between your browser, our servers, and Google’s APIs is protected using TLS 1.2 or higher.
6. Data retention
| Category | Retention period |
|---|---|
| Active account data | Retained while your account is active |
| Account data after deletion | Removed or anonymised within 30 days, unless legal retention is required |
| OAuth refresh tokens | Deleted immediately when you disconnect the integration, revoke access, or delete your account |
| Imported ecommerce and Google Ads data | Retained while needed to provide the service; deleted or anonymised within 30 days of account deletion or confirmed deletion request |
| Support communications | Up to 3 years after the support matter is closed |
| Security and technical logs | Ordinarily up to 12 months |
| Failed-login and fraud-prevention records | Ordinarily up to 24 months where necessary for security |
| Billing, invoice, and tax records | Retained for the applicable statutory period under German commercial and tax law. Depending on the type of document, the required retention period may be six, eight, or ten years. Whosta retains only what is necessary to comply with the applicable legal obligation. |
| Consent records and legal compliance evidence | Retained as long as needed to demonstrate compliance or defend legal claims |
Legal, regulatory, fraud-prevention, security, or dispute-resolution obligations may require us to retain limited categories of information beyond the standard periods shown above.
7. Data sharing and recipients
We do not sell your personal data. We share data only as follows:
- Subprocessors: Cloud hosting and infrastructure providers who process data on our behalf under contractual data-processing agreements. These parties process data only as instructed by Xborder Technologies.
- Google LLC: We transmit data to Google’s APIs as directed by you when you use the Google Ads integration. Google’s use of data submitted through its APIs is governed by Google’s own privacy policy and terms.
- Payment processor: Billing information is handled by our payment processor, who processes it only for payment purposes.
- Legal requirements: We may disclose data where required by applicable law, court order, or instruction from a competent authority.
- Security: We may share data where necessary to protect the rights, property, or security of Whosta, our users, or the public.
- Your explicit instruction: We may share data where you have specifically directed us to do so.
8. International data transfers
Our production servers are currently hosted in the United States by a third-party infrastructure provider. This means that personal data processed by Whosta is transferred to, and stored in, the United States. We rely on the European Commission’s Standard Contractual Clauses (SCCs) as the appropriate safeguard for this transfer under Chapter V of the GDPR. Where we use additional subprocessors outside the EEA, we apply the same or equivalent safeguards.
9. Your rights under the GDPR
You have the following rights in respect of your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data, subject to legal retention obligations.
- Right to restriction — ask us to restrict processing in certain circumstances.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on your consent, withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, email support@whosta.com with the subject line “Data Subject Request”. We will acknowledge within 72 hours and respond within one calendar month. We may need to verify your identity before fulfilling the request.
You also have the right to lodge a complaint with the competent data protection supervisory authority. For users in North Rhine-Westphalia:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
www.ldi.nrw.de
10. Data deletion and integration disconnection
You can disconnect any integration at any time from your Whosta dashboard. On disconnection, the OAuth refresh token for that integration is immediately revoked at the provider and deleted from our systems. Cached access tokens are cleared. You may also revoke Whosta’s Google access directly at myaccount.google.com/permissions.
For full account and data deletion instructions, see our Data Deletion page.
11. Children’s privacy
Whosta is a business-to-business SaaS platform intended for businesses and their authorised users. It is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently done so, we will promptly delete the data.
12. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, or unlawful disclosure. These measures include encryption in transit and at rest, access controls, and continuous security monitoring. See our Security page for further detail. No method of internet transmission is completely secure; we cannot guarantee absolute security.
13. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or in applicable law. Material changes will be communicated by email or by a prominent notice on the website before they take effect. The effective date at the top of this page indicates when the policy was last updated. Continued use of the service after the effective date of a material change constitutes your acknowledgement of the updated policy.
14. Contact
- Email: support@whosta.com
- Phone: +49 1521 0686415
- Operator: Xborder Technologies (represented by Mr. Satish Krishnan), Scheurener Str. 169, 51519 Odenthal, Germany