Privacy Policy

Last updated: August 30, 2026

1. Who we are

wavalid is operated by Rizon LLC ("Rizon," "we," "us," or "our"). This policy explains what data we collect when you use wavalid (the marketing site, the dashboard, the API, the MCP server, and the Chrome extension), why we collect it, and how it's handled.

2. Numbers you validate

Phone numbers submitted for WhatsApp validation are checked against the WhatsApp network in real time, and the number along with the result of the check is stored on your account so you can review it later, including inside batches you create to group related validations. You can delete this data by deleting your account.

3. Account data

When you create an account, we collect:

  • Your name and email address.
  • A securely hashed password (we never store your password in plain text).
  • Account activity such as sign-in timestamps and session metadata, used to keep your account secure.

4. Payment data

Credit-pack purchases are processed by Polar (polar.sh), which acts as merchant of record. Polar collects and processes your payment details (card information, billing address) directly. We don't receive or store your full payment card number. We do receive purchase confirmation and credit-balance records from Polar so we can grant you credits.

5. Usage and rate-limiting data

To protect the Service from abuse, we apply rate limits keyed off your account and, for anonymous requests, your IP address. IP addresses used for rate limiting are cryptographically hashed before storage. We don't keep a plain-text log of the IP addresses that hit our API.

6. Error monitoring

We use Sentry, routed through Better Stack, to capture unhandled errors so we can fix bugs. Error reports can include technical context (request path, stack trace, and similar debugging data) but are not used to build a profile of you.

7. Email

We use Resend to send transactional email: sign-up verification, password resets, account notifications, and similar messages tied directly to your use of the Service. We don't send marketing email you haven't asked for.

8. Analytics on the marketing site

Our marketing site (wavalid.rizon.agency, outside the dashboard) uses Umami, a privacy-focused analytics tool, to understand aggregate traffic. Umami doesn't use cookies or track you across sites.

9. Cookies

We use a session cookie to keep you signed in to the dashboard. We don't use third-party advertising or tracking cookies.

10. How we use your data

We use the data described above to: operate and secure the Service, process your credit purchases, respond to support requests, send account-related email, and diagnose and fix technical issues.

11. Data sharing

We share data with the service providers named in this policy (Polar for payments, Resend for email, Sentry/Better Stack for error monitoring, Umami for site analytics) strictly to operate the Service. We don't sell your personal data. We may disclose data if required by law or to protect our legal rights.

12. Data retention

We keep account data for as long as your account is active, plus a reasonable period afterward for legal, tax, and security purposes. You can request deletion of your account and associated data at any time (see below).

13. Your rights

Depending on where you're located, you may have rights to access, correct, export, or delete your personal data. You can delete your account directly from your account settings, or contact us to exercise these rights.

14. Children

The Service isn't directed at children, and we don't knowingly collect data from anyone under 16.

15. Changes to this policy

We may update this policy from time to time. If we make material changes, we'll post the update here with a new "Last updated" date.

16. Contact

Questions about this policy or your data? Reach us at [email protected].