Privacy Policy

1. Scope

This policy explains how WholeStack handles personal data when you visit our website, create an account, compile applications, request ShipGate verdicts, or run managed production applications. It covers data we control. Data you put into an application you operate is processed by us on your behalf, and you remain the controller of it.

2. Data we collect

3. Why we use it

We do not sell personal data, and we do not use your intent specifications or private application data to train publicly available models.

4. Sharing

We share personal data with processors and partners who help us run the Services, including cloud hosting, payment processing, email delivery, error monitoring, and analytics providers. They act on our instructions under contract. We may also disclose data where required by law, to protect rights and safety, or as part of a merger, acquisition, or asset transfer, in which case we will notify you.

5. International transfers

Data may be processed in countries other than yours. Where required, we rely on appropriate safeguards such as standard contractual clauses and apply supplementary technical measures including encryption in transit and at rest.

6. Retention

We keep account and billing records for as long as your account is active and afterwards for the period required by tax and accounting law. Prototype environments and their artefacts may be deleted after a period of inactivity. Logs are retained on a rolling basis. On request we will delete or anonymise data we no longer need to keep.

7. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent. Californian residents may request disclosure of categories of data collected and disclosed, request deletion, and are protected against discrimination for exercising those rights. To exercise any right, contact privacy@wholestack.ai. You may also complain to your local data protection authority.

8. Security

We apply encryption in transit and at rest, least-privilege access control, audit logging, and signed verification artefacts. See the Security page for detail. No system is perfectly secure; we will notify affected users and regulators of a qualifying breach as required by law.

9. Children

The Services are not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

10. Cookies

Cookie and similar-technology use is described in the Cookie Policy.

11. Changes

We will post updates to this policy on this page and, for material changes, notify account holders by email or in-product notice.

12. Contact

Privacy questions and requests: privacy@wholestack.ai.