Privacy Policy
1. Scope
This policy explains how WholeStack handles personal data when you visit our website, create an account, compile applications, request ShipGate verdicts, or run managed production applications. It covers data we control. Data you put into an application you operate is processed by us on your behalf, and you remain the controller of it.
2. Data we collect
- Account data: name, email address, company, authentication identifiers.
- Billing data: plan, transaction history, and billing contact. Card details are handled by our payment processor; we do not store full card numbers.
- Product data: intent specifications, prompts, compiled artefacts, verification evidence, deployment configuration, and logs.
- Usage data: pages viewed, features used, device and browser type, approximate location derived from IP address, and diagnostic events.
- Support data: messages you send us and their attachments.
3. Why we use it
- To provide, operate, and secure the Services (performance of a contract).
- To bill you and prevent fraud or abuse (contract and legitimate interests).
- To debug, monitor reliability, and improve product quality (legitimate interests).
- To send service, security, and billing notices (contract and legal obligation).
- To send marketing where you have opted in, with an unsubscribe link in every message (consent).
- To comply with legal obligations and to establish or defend legal claims.
We do not sell personal data, and we do not use your intent specifications or private application data to train publicly available models.
4. Sharing
We share personal data with processors and partners who help us run the Services, including cloud hosting, payment processing, email delivery, error monitoring, and analytics providers. They act on our instructions under contract. We may also disclose data where required by law, to protect rights and safety, or as part of a merger, acquisition, or asset transfer, in which case we will notify you.
5. International transfers
Data may be processed in countries other than yours. Where required, we rely on appropriate safeguards such as standard contractual clauses and apply supplementary technical measures including encryption in transit and at rest.
6. Retention
We keep account and billing records for as long as your account is active and afterwards for the period required by tax and accounting law. Prototype environments and their artefacts may be deleted after a period of inactivity. Logs are retained on a rolling basis. On request we will delete or anonymise data we no longer need to keep.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent. Californian residents may request disclosure of categories of data collected and disclosed, request deletion, and are protected against discrimination for exercising those rights. To exercise any right, contact privacy@wholestack.ai. You may also complain to your local data protection authority.
8. Security
We apply encryption in transit and at rest, least-privilege access control, audit logging, and signed verification artefacts. See the Security page for detail. No system is perfectly secure; we will notify affected users and regulators of a qualifying breach as required by law.
9. Children
The Services are not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
10. Cookies
Cookie and similar-technology use is described in the Cookie Policy.
11. Changes
We will post updates to this policy on this page and, for material changes, notify account holders by email or in-product notice.
12. Contact
Privacy questions and requests: privacy@wholestack.ai.