Privacy Policy
Last Updated: July 2026
Whizzly Ltd ("Whizzly", "we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
This policy applies to merchants who use the Whizzly platform and to customers who interact with Whizzly-powered storefronts.
1. Who We Are (Data Controller)
Whizzly Ltd is the data controller for personal data collected through the Whizzly platform. We are registered in England and Wales.
Whizzly Ltd
Email: hello@whizzly.co.uk
Website: whizzly.co.uk
Note on Merchant Storefronts: When you interact with a Whizzly-powered storefront as a customer placing an order or booking, the merchant who operates that storefront is an independent data controller for your personal data submitted during checkout. Whizzly processes that data as a data processor on the merchant's behalf.
2. What Data We Collect
We collect the following categories of personal data:
From Merchants:
- Account information: name, email address, phone number (WhatsApp number).
- Business information: business name, address, store configuration, product catalogue, pricing.
- Billing information: subscription plan details (payment card data is handled directly by Stripe and is never stored by Whizzly).
- Usage data: dashboard activity, feature usage, login timestamps, IP addresses.
- Communications: messages sent to our support team.
From Storefront Customers (via Merchant Storefronts):
- Contact details: name, email address, phone number (WhatsApp number).
- Order data: items purchased, quantities, delivery address, order notes, payment method selected.
- Booking data: selected service, appointment date and time, booking notes.
- Loyalty data: stamp or points balances associated with a phone number or email.
- Marketing consent: opt-in status for WhatsApp marketing messages.
Automatically Collected Data:
- Device and browser information (user agent, screen resolution).
- IP address and approximate location.
- Storefront visit data, page views, and session duration (via Google Analytics where enabled by the merchant).
- Cookies and similar tracking technologies (see Section 6).
3. How We Use Your Data
We use personal data for the following purposes and on the following lawful bases under UK GDPR:
To provide the platform (Contractual necessity): Account creation, storefront generation, order processing, booking management, payment facilitation, and customer notification delivery.
To send transactional communications (Contractual necessity / Legitimate interest): Order confirmations, booking confirmations, WhatsApp OTP authentication, status updates, and appointment reminders via our approved Meta WhatsApp Cloud API templates.
To operate and improve the platform (Legitimate interest): Analysing usage patterns, debugging, performance monitoring, fraud detection, and product development.
To send marketing communications (Consent): Promotional emails or WhatsApp broadcasts are only sent where you have given us explicit consent. You may withdraw consent at any time.
To comply with legal obligations (Legal obligation): Retaining financial records, responding to regulatory requests, fraud prevention.
4. Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected:
- Active merchant accounts: Data is retained for the duration of your subscription plus 30 days after cancellation to allow for account recovery.
- Expired trial accounts: Data is retained for 30 days after trial expiry before deletion.
- Order and transaction records: Retained for 7 years to comply with UK tax and financial record-keeping obligations.
- Authentication OTPs: Automatically deleted from our systems within minutes of use or expiry.
- Support communications: Retained for up to 2 years.
5. Third-Party Sub-Processors
We share personal data with the following trusted third-party sub-processors who assist us in operating the platform. All sub-processors are contractually required to handle data securely and in compliance with applicable data protection laws.
| Processor | Purpose | Location |
|---|---|---|
| Google Firebase / Firestore | Database, authentication, media storage | USA (SCCs apply) |
| Stripe | Payment processing and billing | USA (SCCs apply) |
| PayPal | Alternative payment processing | USA (SCCs apply) |
| Meta (WhatsApp Cloud API) | Transactional WhatsApp message delivery | USA (SCCs apply) |
| Google Gemini / AI Platform | AI product generation, menu import, storefront assistant | USA (SCCs apply) |
| Google Analytics | Storefront visitor analytics (where enabled by merchant) | USA (SCCs apply) |
| Meta Pixel | Ad conversion tracking (where enabled by merchant) | USA (SCCs apply) |
| Mailchimp / Intuit | Email list management (where enabled by merchant) | USA (SCCs apply) |
| Vercel | Platform hosting and edge delivery | USA / EU |
| Resend | Transactional email delivery | USA (SCCs apply) |
SCCs = Standard Contractual Clauses approved by the ICO for lawful UK-to-USA data transfers.
6. Cookies & Tracking Technologies
We use the following types of cookies and local storage:
- Essential cookies: Required for platform functionality — authentication sessions, shopping cart state, and security tokens. These cannot be disabled.
- Analytics cookies: Used by Google Analytics (where enabled by the merchant on their storefront) to measure visitor behaviour. These cookies are subject to Google's Privacy Policy.
- Marketing / tracking pixels: Meta Pixel may be deployed on merchant storefronts (where enabled by the merchant) for ad conversion tracking. Subject to Meta's Privacy Policy.
You can control cookie preferences through your browser settings. Note that disabling essential cookies will affect platform functionality.
7. Your Rights Under UK GDPR
Under the UK GDPR, you have the following rights regarding your personal data:
- Right of Access: You may request a copy of all personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete data.
- Right to Erasure ('Right to be Forgotten'): You may request deletion of your personal data, subject to our legal retention obligations.
- Right to Restriction: You may request that we restrict processing of your data in certain circumstances.
- Right to Data Portability: You may request a machine-readable copy of your data for transfer to another service.
- Right to Object: You may object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making: You have the right not to be subject to solely automated decisions that significantly affect you.
To exercise any of these rights, contact us at hello@whizzly.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe your data has been mishandled.
8. International Data Transfers
Some of our sub-processors (including Google, Stripe, Meta, and Vercel) are located in the United States or other countries outside the UK/EEA. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the UK Information Commissioner's Office (ICO), or rely on adequacy decisions where applicable.
9. Data Security
We implement industry-standard technical and organisational security measures to protect your personal data, including:
- HTTPS/TLS encryption for all data in transit.
- Google Firebase Security Rules restricting data access by authentication role.
- Automatic expiry and deletion of authentication OTP codes.
- Payment card data is never stored on Whizzly servers — all card processing is handled exclusively by Stripe and PayPal.
- Access to production systems is restricted to authorised Whizzly personnel.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
10. Children's Privacy
The Whizzly platform is intended for use by individuals aged 18 and over. We do not knowingly collect personal data from children under the age of 13. If you believe a child has provided us with personal data, please contact us at hello@whizzly.co.uk and we will take steps to delete that information promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the platform. The updated policy will display the revised "Last Updated" date at the top. Your continued use of the platform after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
For any data protection queries, access requests, or to exercise your rights under UK GDPR, please contact:
Whizzly Ltd — Data Protection Enquiries
Email: hello@whizzly.co.uk
Website: whizzly.co.uk
You also have the right to raise a concern directly with the Information Commissioner's Office (ICO):
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
Note: This Privacy Policy is provided for informational purposes and should be reviewed by a qualified legal professional before relying on it.