Privacy Policy
Last updated: 11 October 2026
What's The Source ("we", "us") helps businesses see which ad, campaign or page brought each of their WhatsApp leads. This policy explains what information we collect, why, and the choices you have. You can reach us at hello@whatsthesource.com.
Who this policy covers
There are two groups of people whose information we handle:
- Our customers: businesses and people who create an account with us.
- Our customers' contacts: people who visit a customer's website and message that business on WhatsApp.
For the information about a customer's own website visitors and WhatsApp contacts, the customer decides why and how it is used, and we process it on the customer's behalf. If you are one of those contacts and want to see or delete your information, please contact the business first, or email us and we will help.
Information we collect
Account information. Your email address, your name if you give it, your workspace name, and your password, which we store only in a hashed form.
Website visit information, collected by our tracking script. When a customer installs our script on their website, we record:
- a random visitor ID and session ID (see Cookies and browser storage below);
- the pages viewed and the referring website;
- campaign details in the web address, such as UTM parameters and the Google Ads click ID (GCLID), campaign ID, ad group ID and keyword;
- the visitor's IP address at the start of a visit;
- each press of a WhatsApp button, and a short code (for example "ref: K7M2") that we add to the pre-filled WhatsApp message so we can match the message to the visit.
WhatsApp message information, received from the customer's WhatsApp provider. When someone messages a customer, the customer's provider (for example WATI, Gupshup, Interakt, Meta or Twilio) sends us:
- the sender's phone number;
- the sender's WhatsApp profile name;
- the text of the message and the time it was sent.
Google Ads information. If a customer connects Google Ads, we receive, with their permission, their Google Ads account IDs and names and their campaign and ad group IDs and names. We also store the access tokens Google gives us, in encrypted form, so we can keep the connection working.
How we use information
- To match each WhatsApp lead to the visit and ad that produced it.
- To show customers their leads, sources, campaigns and reports.
- To keep campaign and ad group names up to date.
- To secure the service, prevent abuse and fix problems.
- To reply to support requests and send important service notices.
We do not sell personal information. We do not use it for advertising, and we do not build advertising profiles.
Google user data
What's The Source's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google Ads data only to show a customer their own campaign and ad group names in What's The Source and, when the customer approves it, to add tracking parameters to their account's Final URL Suffix. We do not share Google user data with third parties, use it for advertising, or let people read it except where needed to provide the service, to follow the law, or with the customer's consent. A customer can disconnect Google Ads at any time in Settings, and can also remove our access from their Google Account.
Cookies and browser storage
Our tracking script, running on a customer's website, stores a random visitor ID, a session ID and a session timestamp in the browser's local storage (named _wts_vid, _wts_sid and _wts_sts). If local storage is not available, it uses a first-party cookie with the same names. These values do not contain your name or contact details. They let the business recognise that visits belong to the same device.
Our own web app uses a session cookie to keep customers logged in, and stores a theme choice (light or dark) in the browser.
Who we share information with
We share information only with service providers that help us run What's The Source, under terms that protect it:
- our hosting provider, which runs our servers;
- our database provider, which stores the data;
- Google, when a customer connects Google Ads, to read campaign names and apply tracking settings they approve.
We may also disclose information if the law requires it, or to protect our users, our service or our rights.
Security
We use encrypted connections (HTTPS), hash passwords, encrypt Google access tokens at rest, and keep each customer's data separated from other customers. No online service can promise perfect security, but we work to protect your information and fix problems quickly.
How long we keep information
We keep information for as long as a customer's account is active, because the reports depend on it. A customer can ask us to delete their account and its data at any time by emailing hello@whatsthesource.com. We will delete it, except where the law requires us to keep something.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete the personal information we hold about you, and to object to or limit certain uses. To use these rights, email us. We may need to confirm who you are first. If you are a contact of one of our customers, we may direct you to that business, since it decides how your information is used.
International use
Our service providers may process information in countries other than your own. Where this happens, we take steps so that your information stays protected.
Children
What's The Source is built for businesses and is not directed to children. We do not knowingly collect information from children.
Changes to this policy
We may update this policy from time to time. When we do, we will change the date at the top, and for important changes we will tell customers by email or in the app.
Contact us
Questions or requests about privacy: hello@whatsthesource.com.

