Privacy Policy

Last updated 2 August 2026

This policy explains what personal data Viral Group Link collects, why we collect it, how long we keep it and what rights you have over it. We have deliberately built the Service to need as little personal data as possible: there are no visitor accounts, and browsing requires nothing from you.

1. Who is responsible

The operator of Viral Group Link is the data controller for the processing described here. For any privacy question or request, contact hello@example.com.

2. What we collect

Data you give us

  • Group submissions — group name, WhatsApp invite link, description, category, country and language.
  • Abuse reports — the reason you select and any details you type.
  • Contact form — your name, email address and message.

Data collected automatically

  • IP address — recorded against submissions and reports, solely to enforce rate limits and investigate abuse.
  • Session cookie — a single strictly necessary cookie that carries the CSRF token protecting our forms and prevents view counts being inflated by reloads. It holds no identifier and is not used for advertising or tracking.
  • Aggregate counters — how many times a listing was viewed or its join button clicked. These are per-listing totals, not linked to any individual.
  • Server logs — your web host records standard request logs (IP, timestamp, URL, user agent) as a normal part of running a website.

What we never collect

We do not ask for your phone number, we do not create visitor accounts, we do not run device fingerprinting, and we have no access whatsoever to the contents, membership or activity of any WhatsApp group. A group invite link is a public address, not a window into the conversation.

3. Why we process it, and on what legal basis

For visitors in the UK/EU, our lawful bases under the GDPR are:

  • Legitimate interests (Art. 6(1)(f)) — operating the directory, preventing spam and abuse, keeping the site secure, and producing aggregate usage counts.
  • Consent (Art. 6(1)(a)) — where you voluntarily submit a group, send a report or use the contact form, and for any non-essential advertising cookies where consent is required.
  • Legal obligation (Art. 6(1)(c)) — retaining or disclosing records where the law compels it.

We do not use your data for automated decision-making or profiling that produces legal effects, and we never sell your personal data.

4. A note about what you publish

A group listing is public by design. Anything you type into the submission form — the group name, description and the invite link itself — is visible to anyone on the internet and may be copied, cached or indexed by search engines beyond our control. Do not put personal information in those fields, and remember that publishing an invite link exposes the group to strangers.

5. Cookies

We set one strictly necessary session cookie, described above. It expires when you close your browser and requires no consent under the ePrivacy rules.

If advertising is enabled on this site, third-party ad providers may set their own cookies or use device identifiers to select and measure ads. That processing is carried out by those providers under their own privacy policies, and where your jurisdiction requires consent, it is requested before those cookies are set. You can also manage ad personalisation in your browser settings or through the ad provider's own controls.

6. Who we share data with

We do not sell or rent personal data. Limited sharing occurs with:

  • Our hosting provider, which stores the database and serves the site on our behalf;
  • Advertising providers, if ads are enabled, as described above;
  • Law enforcement or regulators, where we receive a valid, legally binding request, or where disclosure is necessary to prevent serious harm.

Where data is transferred outside your region, we rely on the safeguards offered by the relevant provider, such as standard contractual clauses.

7. How long we keep it

  • Published listings — until removed by us or at the submitter's request.
  • Rejected submissions — retained for a limited period so the same spam is not resubmitted, then deleted.
  • Submission and report IP addresses — kept only as long as needed for abuse prevention, then cleared.
  • Contact messages — kept as long as needed to handle your enquiry and any follow-up.
  • Server logs — per our host's standard retention schedule.

8. Security

We use prepared database statements, CSRF protection on every form, hashed administrator passwords, and HTTP-only session cookies restricted to secure transport where HTTPS is available. No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable technical measures appropriate to the limited data we hold.

9. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased (“right to be forgotten”);
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw consent at any time, without affecting prior processing;
  • lodge a complaint with your local data protection authority.

To exercise any of these, write to hello@example.com or use the contact page. To have a listing removed, include its URL so we can identify it. We respond within one month, as required by the GDPR, and we do not charge for reasonable requests.

California residents

Under the CCPA/CPRA you have the right to know what personal information is collected, to request its deletion, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA.

10. Children's privacy

The Service is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact us and we will delete it promptly. See also the age requirement in our Terms of Use.

11. Changes to this policy

We may update this policy from time to time. The "last updated" date above reflects the current version. Material changes will be highlighted on the site where practical.


Please note: this document is a general template, not legal advice. Before publishing, insert your operator identity and contact details, confirm the retention periods match what your setup actually does, and have a qualified lawyer or privacy specialist review it against the laws that apply to you.