Privacy Policy - Webux WhatsApp Chat Button

Last updated: July 16, 2026

This Privacy Policy explains how Rank Fast LLC ("we", "us", "our") collects, uses, and protects information in connection with the Webux WhatsApp Chat Button Shopify application (the "App"). It is written to comply with the Shopify App Store's data and privacy requirements and applicable data protection law, including the EU/UK GDPR and the California Consumer Privacy Act (CCPA).

1. Who we are

Rank Fast LLC ("we") operates the App. You can contact us at:

2. What information we collect

2.1 Store owner / merchant information. When you install the App, Shopify shares the following with us via OAuth: your shop's myshopify.com domain, an access token scoped to the permissions you approve (read_files, write_files, used only when you upload a custom button icon), and basic shop metadata needed to operate the App (e.g. shop ID).

2.2 App configuration data. We store the WhatsApp chat button settings you configure in the App dashboard, including enable/disable status, WhatsApp phone number and greeting message, button position, size, spacing, colors, shape, icon and animation choices, and visibility rules (device, page type, schedule, customer login state). This data is stored in our database, associated only with your shop domain, and is also written to a Shopify shop metafield (namespace webux_whatsapp) so your storefront can render the button.

2.3 Storefront visitor data. The App does not collect, store, or process any personal data about your customers or storefront visitors. The chat button is rendered entirely from your shop's settings; no visitor identifiers, IP addresses, cookies, or browsing behavior are captured by the App. When a visitor clicks the button, they are redirected to wa.me, WhatsApp's own service, governed by Meta's Privacy Policy - not by us.

2.4 Uploaded icons. If you upload a custom icon image, it is stored using Shopify's Files API on Shopify's infrastructure and referenced by URL in your settings. We do not maintain a separate copy of uploaded images outside Shopify's CDN.

3. How we use information

We use the information described above solely to authenticate your store and operate the App, persist and apply your chat button configuration, render the button correctly on your storefront, provide customer support when you contact us, and comply with legal obligations and Shopify's Partner Program requirements. We do not sell, rent, or share merchant or store data with third parties for marketing purposes.

4. Legal basis for processing (GDPR)

Where GDPR applies, we process merchant data on the basis of (a) performance of a contract (providing the App's functionality you requested), and (b) our legitimate interest in operating and improving the App.

5. Data retention

We retain your shop's configuration data for as long as the App remains installed. When you uninstall the App, we automatically and permanently delete all associated settings and session data from our database, generally within a few minutes and no later than 48 hours, triggered by Shopify's app/uninstalled webhook. Shopify also automatically removes the shop metafield we wrote once the app is uninstalled.

6. Mandatory GDPR webhooks

In compliance with Shopify's requirements, the App implements the mandatory GDPR webhooks: customers/data_request (because the App never stores customer-level personal data, we respond acknowledging there is no data to provide), customers/redact (same as above; there is no customer data to erase), and shop/redact (triggered ~48 hours after uninstall; we erase all remaining shop-level data as a safety net).

7. Data storage and security

Data is stored in a PostgreSQL database (production) hosted by our infrastructure provider (Railway). All traffic to and from the App is encrypted in transit via HTTPS/TLS. Access tokens are stored securely and are never exposed to the browser. We validate and sanitize all inputs, and apply the principle of least privilege to our requested Shopify access scopes.

8. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete the personal data we hold about you. Merchants can request deletion of their store's data at any time by uninstalling the App, or by emailing inquiry@rankfastllc.com. We will respond within the timeframe required by applicable law (e.g. 30 days under GDPR).

9. International data transfers

Depending on where our hosting provider's servers are located, your data may be processed outside of your country of residence. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.

10. Children's privacy

The App is intended for use by Shopify merchants and is not directed at children. We do not knowingly collect data from children.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Continued use of the App after changes take effect constitutes acceptance of the revised policy.

12. Contact us

Questions about this Privacy Policy or your data can be sent to: inquiry@rankfastllc.com.