Privacy Policy
Last updated: 2 August 2026
TrackReply is a WhatsApp follow-up scheduler. It consists of a Chrome extension that runs on WhatsApp Web and a web app at trackreply.com. This policy explains exactly what data we handle, why we handle it, how long we keep it, and how you can have it deleted.
The short version. We store the follow-up messages you choose to schedule, the phone number each one is addressed to, and your account details. We do not read, collect, or store your WhatsApp conversation history. We do not sell your data, and we do not use it for advertising.
1. Who we are
TrackReply ("we", "us") operates the TrackReply Chrome extension and the TrackReply web application. For any privacy question, or to request access to or deletion of your data, contact us at support@trackreply.com.
2. Data we collect
| Data | Why we need it |
|---|---|
| Email address and password | To create and secure your account. Passwords are stored only as salted hashes by our authentication provider; we never see them in plain text. |
| First and last name (optional) | To address you in the app. |
| Your own WhatsApp phone number | To link your account to the WhatsApp session that sends your follow-ups, and to show its connection status. |
| Follow-up messages you schedule — the message text, the recipient's phone number, and the send time | This is the core function of the product. We must store the message in order to send it at the time you chose. |
| Delivery status of each follow-up (pending, sent, failed, retry count, error reason) | To show you whether a follow-up actually went out and to retry or stop it correctly. |
| Technical logs (timestamps, error messages, request data) | To keep the service running, diagnose failures, and prevent abuse. |
What we do not collect
- We do not collect or store your WhatsApp chat history, contact list, media, or any message you did not schedule through TrackReply.
- We do not collect browsing history, and the extension is active only on WhatsApp Web. It does not run on other websites.
- We do not collect health, financial, location, or biometric data, and we do not use tracking cookies or third-party advertising trackers.
A note on replies
When a pending follow-up exists for a conversation, TrackReply needs to know whether the recipient has already replied, so that it can cancel a follow-up that is no longer appropriate. This check only determines whether a reply occurred. The content of your conversations is not stored on our servers.
3. How we use your data
We use the data above only to:
- send the follow-up messages you scheduled, at the time you set;
- show you the status and history of your own follow-ups;
- authenticate you and keep your account secure;
- operate, debug, and improve the service, and respond to your support requests.
We do not sell or rent your data, transfer it to third parties for advertising, use it to build advertising profiles, or allow humans to read your messages except where you explicitly ask us to investigate a problem, or where we are legally required to.
4. Chrome Web Store Limited Use disclosure
TrackReply's use of information received from Google APIs and from your browser adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically, data obtained through the extension is used solely to provide and improve the user-facing features described above, is never sold, is never used for advertising or credit assessment, and is never transferred to others except as necessary to run the service, to comply with the law, or as part of a merger or acquisition with your prior notice.
5. Who we share data with
We share data only with the infrastructure providers required to run TrackReply, and only to the extent they need it:
- Supabase — database and authentication hosting; it stores your account and your scheduled follow-ups.
- Cloudflare — application hosting and delivery of the web app and API.
These providers process data on our instructions under their own security and privacy commitments. We may also disclose data where we are legally compelled to do so, or where it is necessary to protect our rights or the safety of users.
6. Storage, retention, and security
- Data is transmitted over HTTPS and stored in an access-controlled database. API requests from the extension are authenticated with a per-number key.
- Scheduled follow-ups and their delivery records are retained while your account is active, so that you can see your own follow-up history.
- If you delete a follow-up, it is removed from the sending queue and from our records.
- If you delete your account, your account details, connected number, and scheduled follow-ups are deleted. Backups and technical logs may persist for up to 30 days before being overwritten.
No system is perfectly secure. We take reasonable technical and organisational measures to protect your data, but we cannot guarantee absolute security.
7. Your rights and choices
- Access and correction — you can view and edit your account details and your scheduled follow-ups from the dashboard at any time.
- Deletion — you can delete individual follow-ups from the dashboard, or email support@trackreply.com to have your entire account and all associated data deleted. We action deletion requests within 30 days.
- Withdrawal — uninstalling the extension stops all data collection by the extension. Deleting your account removes the data we hold.
- Depending on where you live, you may have additional rights under the GDPR or similar laws, including the right to data portability and the right to lodge a complaint with your local data protection authority. Our legal basis for processing is the performance of our contract with you and our legitimate interest in operating and securing the service.
8. Children
TrackReply is a business tool and is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
9. International transfers
Our providers may process and store data in countries other than yours, including the United States and the European Union. Where required, such transfers are covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. Changes to this policy
We may update this policy as the product changes. The "last updated" date at the top always reflects the current version. For material changes affecting how we use your data, we will notify you by email or in the app before the change takes effect.
11. Contact
Questions, data requests, or complaints: support@trackreply.com.