Privacy Policy
Last updated: 12 July 2026
This Privacy Policy explains what personal data Whao ("Whao", "we", "us") collects, why, on what legal basis, and what rights you have. It applies to whao.dev and the Whao dashboard application.
1. Who we are
The data controller for the account and billing data described in this policy is:
Roma, Italia
Contact: privacy@whao.dev
2. Two roles: when we are a controller, when we are a processor
Whao is a white-label SEO reporting tool used by marketing agencies ("you", the "Agency") to report on the search performance of the Agency's own clients ("End Clients"). Because of this, we act in two different capacities:
- As a controller — for data about you and your Agency account: your sign-up email, authentication data, agency name, logo, and brand colour. We decide why and how this data is processed, to run and improve the Whao service itself.
- As a processor — for data you enter about your End Clients (name, contact email, website, business type, country) and for the Google Analytics 4 / Search Console data connected for those End Clients. Here, you (the Agency) are the controller — you decide which End Clients to add and which Google properties to connect. We only process this data on your instructions, to provide the reporting service, under the terms of our Data Processing Agreement.
If you are an End Client (i.e. a customer of one of our Agency users) and have questions about your own data, please contact the Agency directly — they are the controller for that data, and we act on their instructions.
3. Data we collect and why
| Category | What we collect | Purpose | Legal basis |
|---|---|---|---|
| Account data | Email address, password (hashed by our authentication provider), or your Google account identifier if you sign up with Google | Create and secure your account, let you log in | Performance of a contract (Art. 6(1)(b) GDPR) |
| Agency profile | Agency name, logo, brand colour | Power the white-label reports you generate for your End Clients | Performance of a contract |
| Google OAuth tokens (per End Client) | Encrypted access and refresh tokens for the Google account you connect on behalf of an End Client, scoped to read-only Google Analytics and Search Console access | Retrieve the End Client's SEO metrics to build reports | Performance of a contract (with you, as processor for the End Client data) |
| GA4 / Search Console metrics | Monthly organic sessions (last 180 days) and top search queries with clicks, impressions and average position (last 28 days) for the connected property | Render the traffic and keyword sections of a report | Performance of a contract (processor) |
| End Client records | Name, contact email, website, business type, country — entered by you | Organise your clients and their reports inside the dashboard | Performance of a contract (processor) |
| Report content | The narrative notes you write into a report (traffic, keywords, pages, backlinks, agency commentary) | Produce the report you share with your End Client | Performance of a contract (processor) |
| Consent record | Timestamp of your acceptance of our Terms of Service and Data Processing Agreement at sign-up | Evidence that you accepted our terms | Legal obligation / legitimate interest in demonstrating consent (Art. 6(1)(c)/(f)) |
| Analytics cookies | Google Analytics 4 identifiers (only if you accept the cookie banner) | Understand how visitors use our marketing site | Consent (Art. 6(1)(a)) — see our Cookie Policy |
We do not knowingly collect any special category data (Art. 9 GDPR) through the service. Please do not enter special category data into free-text fields such as report notes.
4. What we deliberately do not store
The raw Google Analytics and Search Console data shown in a report (session counts, keywords, clicks, impressions) is fetched live from Google every time you open a report and is not written to our database. Only the narrative text you choose to save as report content is persisted. This is a deliberate data-minimisation choice: the less raw analytics data we store at rest, the smaller the impact of any potential incident.
5. Who we share data with (sub-processors)
We use a small number of infrastructure providers to run Whao. We do not sell personal data, and we do not share it with anyone for their own marketing purposes.
| Sub-processor | Role | Location / safeguard |
|---|---|---|
| Supabase | Database, authentication, and file storage | Hosted in the EU (Frankfurt, eu-central-1). See Supabase's DPA. |
| Vercel | Application hosting and compute | Serverless functions run in the EU (Frankfurt, fra1). Static assets may be cached on Vercel's global edge network for performance; see Vercel's DPA for the safeguards that apply to that network. |
| Google LLC (Analytics Data API, Search Console API) | Source of the End Client SEO metrics you choose to connect, and (if accepted) our site analytics | Global infrastructure; transfers outside the EEA rely on the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses. See Google's own privacy and data processing terms. |
We do not currently use a third-party service for transactional email or payment processing — billing on the platform is not yet live. This policy will be updated, and this table extended, before any such processor is switched on.
6. International data transfers
Our database (Supabase) and application compute (Vercel) both run in the EU. Where data does leave the EEA — for example when we call Google's APIs, or when Vercel's edge network serves cached static content from a location outside the EEA — we rely on the transferring provider's own safeguards (Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework, as applicable). No End Client analytics data is itself stored outside the EEA.
7. How long we keep data
We keep your account data, agency data, End Client records, and report content for as long as your account is active. We do not currently apply an automatic time-based deletion on top of that — data is kept until you remove it.
- You can delete an individual End Client or report at any time from the dashboard.
- You can permanently delete your entire account, including your agency, all End Clients, all reports, and any uploaded logo, from Settings → Danger Zone → Delete account. This is irreversible and takes effect immediately.
- Google OAuth tokens are deleted the moment the associated End Client or account is deleted.
8. Your rights
If you are in the EEA or UK, you have the right to: access the personal data we hold about you; correct inaccurate data; request erasure; restrict or object to processing; receive your data in a portable format; and withdraw consent at any time (for consent-based processing, such as analytics cookies). You can exercise most of these directly from your account (Settings), or by contacting us at privacy@whao.dev. You also have the right to lodge a complaint with your local data protection authority.
If we are a processor for your data (i.e. you are an End Client of one of our Agency users), please direct your request to that Agency first, since they control the data. We will assist them in fulfilling it under our Data Processing Agreement.
9. Security
We apply the following technical measures:
- Google OAuth access and refresh tokens are encrypted at rest with AES-256-GCM before being stored.
- Database access is restricted with Row Level Security (RLS): an Agency can only ever read or write its own agency, clients, and reports.
- All data in transit is encrypted with HTTPS/TLS.
- The OAuth connection flow uses PKCE and a random state parameter to protect against interception and CSRF.
10. Google API Services User Data Policy
Whao's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only request read-only access scopes:
analytics.readonlyandwebmasters.readonly. - We use Google user data solely to display SEO performance metrics (organic sessions and search query performance) inside the report you build for your End Client.
- We do not use Google user data to serve advertisements, and we do not sell, rent, or otherwise transfer Google user data to third parties, except as necessary to provide the Whao service or to comply with applicable law.
- We do not allow humans to read Google user data unless: we have your affirmative agreement for specific messages, doing so is necessary for security purposes, we do so to comply with applicable law, or the data has been aggregated and anonymised.
- You can revoke Whao's access to your Google account at any time from your Google Account permissions page, or by disconnecting the End Client in your Whao dashboard.
11. Children
Whao is a business tool intended for use by marketing agencies and their staff. It is not directed at, and we do not knowingly collect data from, individuals under 16.
12. Changes to this policy
We may update this policy as the product changes. If we make material changes, we will notify active accounts by email or via an in-app notice before the changes take effect.
13. Contact
Questions about this policy or your data: privacy@whao.dev.