WhatsChat privacy policy

WhatsChat privacy policy

Last updated: 12 September 2026

WhatsChat is an app that adds a floating chat button to a website, published by Nightly Solutions. The button sends visitors to WhatsApp, Messenger, Instagram, Telegram, SMS, a phone call, or one of eleven other channels the site owner chooses.

This page describes every piece of data the app touches. It is written to be checked against the source rather than taken on trust.

The short version

  • Everything the app stores is written into content collections on the site owner's own site. It is their data, on their site, under their account.
  • Nothing is sent anywhere else. There is no server of ours, no analytics vendor, no error reporter, no advertising network.
  • No cookies. No tracking identifier. No IP address is stored.
  • We cannot read any of it. Nightly Solutions has no access to a site's collections.

For visitors to a site that uses WhatsChat

What is recorded when you tap the chat button

One row, containing:

FieldExampleWhy
Time2026-09-12T14:03:22Zso the owner can see when people reach out
Channelwhatsappwhich app you chose
Which agentsales-1which member of their team you were sent to
Page path/products/denim-jacketwhich page the conversation started from
Devicemobileso the button can be placed sensibly on phones
Outside opening hourstrueso the owner can see what they are missing
How you arrivedsearchone of six broad buckets: direct, search, social, ads, referral, email

The page path only. The code reads location.pathname, which by definition stops at the ?. A query string is not stripped out later, it is never read in the first place, so whatever a site puts after the ? cannot reach the row.

"How you arrived" is a bucket, not a referrer. The referring domain is matched against a list and reduced to one of six words. The domain itself is not stored.

What is not in that row: your IP address, your name, any identifier for you, a cookie, a device fingerprint, or anything that ties one click to another. Two clicks by the same person are indistinguishable from clicks by two people.

If you fill in the away-hours form

Outside the business's opening hours, the widget may offer a short form instead of a chat link. If you complete it, what you typed is stored: your name, the email address or phone number you gave, your message, and the page you were on.

The form has a consent checkbox, and it is enforced twice: the browser will not submit without it, and the server checks again independently before anything is stored.

That information goes to the business you were contacting. It is theirs, on their site. To correct or delete it, contact that business directly. We cannot reach it.

Storage in your browser

Three flags, in sessionStorage:

  • whatschat:greeted — the greeting bubble has already been shown
  • whatschat:opened — the chat panel has already been opened
  • whatschat:dismissed — you closed the panel, so it should stay closed

sessionStorage is erased when you close the tab. These exist so the widget does not greet you on every page. They contain the character 1 and nothing else. They are not cookies, are never sent to any server, and cannot identify you.

What happens when you tap through

The widget opens WhatsApp, Messenger, Instagram or whichever channel was chosen, usually with a first message already typed. From that moment you are in that app, and that company's privacy policy applies, not this one. We have no visibility into the conversation. WhatsChat is not connected to the WhatsApp Business API or to any platform account: it opens a link, the same as a hyperlink you clicked yourself.

For site owners who install WhatsChat

What the app stores on your site

Three content collections, created on your site under your own account:

  • Settings — your widget configuration: channels, phone numbers and handles, agent names and photo URLs, colours, opening hours, the wording you wrote.
  • Events — the click rows described above.
  • Leads — the away-hours form submissions described above.

All three are yours. You can open them, edit them, export them, or delete them, without us. Uninstalling the app leaves them in place so that contact details you collected are not destroyed by an uninstall; delete the collections yourself if you want them gone.

What the app reads

  • Your app instance — whether the site is on a paid plan, and which version is installed. This is how paid features are unlocked. No billing details, no card, no payout information.
  • Your account language, to show the dashboard in it.
  • The visitor's cart, only if you turn on cart rules, and only the totals needed to word a greeting. Cart contents are read in the visitor's browser and are never stored.

What we can see

Nothing. There is no account with us, no login, no server of ours that your site talks to. We are told how many sites have installed the app and what they are paying, which is the same reporting every App Market developer receives. It does not include your data.

If you email support

coder.sagor@gmail.com is a mailbox. Whatever you send sits in it until you ask us to delete it, and we will.

Third parties

None receive data from this app.

The dashboard shows two links a site owner may choose to click: one to LeadStal.com and one to nightlysol.com. They are ordinary hyperlinks. Nothing is sent when the page renders, only when somebody clicks, and then only the fact that a browser arrived, the same as any link.

The channel logos in the widget are drawn from SVG path data bundled into the app itself. No image, script, font or stylesheet is fetched from any external host at runtime.

Legal basis, retention and your rights

Legal basis (UK/EU GDPR). For click rows, the legitimate interest of a business in understanding how visitors contact it, supported by the fact that the rows identify nobody. For form submissions, consent, collected by the checkbox described above.

Retention. Rows stay in the site owner's collections until the owner deletes them. We set no expiry, because it is not our data to expire.

Controller. For everything stored on a site, the site owner is the data controller. Nightly Solutions is a processor only in the narrow sense that we wrote the code; we hold no copy and have no access.

Your rights. Access, correction, deletion, portability and objection are exercised against the site owner, who holds the data. If they need help doing that, they can write to us and we will explain exactly where each row lives.

Transfers. Data stays wherever that site is hosted. We move it nowhere.

Children. The app is not directed at children and collects nothing from anyone except a form somebody chose to fill in.

Changes

If the app ever starts sending data somewhere, this page changes first and the change is described here in plain words, not folded into a version bump.

Contact

Nightly Solutions — coder.sagor@gmail.com