Skip to content

Privacy Policy

Last updated: 2026-04-25

This Privacy Policy describes how WipDesk ("we", "us") collects, uses, discloses, and protects personal data when you use WipDesk.

1. Data We Collect

1.1 Account data

  • Email address
  • Display name and username (optional)
  • Hashed password (we never store plaintext passwords)

1.2 Profile and content data

  • Commission titles, descriptions, statuses, milestones, prices
  • Uploaded images, attachments, cover art
  • Client names you record (you are responsible for ensuring you have a legitimate reason to record this data — see "Your Responsibilities as a Controller" below)

1.3 Payment data

Payment processing is handled by Stripe, Inc. We do not store full card numbers. We retain only the minimum data needed to reconcile your subscription (Stripe customer ID, plan, status, invoice IDs).

1.4 Technical data

  • IP address and approximate location (city/country) at sign-in
  • Browser, device, and OS at sign-in
  • Authentication tokens stored in your browser

1.5 Communications

Emails you send to support, transactional emails we send you (verification, billing receipts, security alerts).

2. How We Use Your Data

  • To operate and maintain the Service
  • To process payments and manage subscriptions
  • To send transactional notifications (billing, security)
  • To respond to your support requests
  • To enforce our Terms of Service and Acceptable Use Policy
  • To comply with legal obligations

We do not sell your personal data. We do not use your Content to train machine-learning models.

3. Legal Bases (GDPR)

Where GDPR applies, we rely on: (a) contract — to provide the Service you signed up for; (b) legitimate interests — to keep the Service secure and improve it; (c) legal obligation — to comply with tax, accounting, and law-enforcement requirements; (d) consent — where applicable (you can withdraw at any time).

4. Sub-Processors

We share data with the following processors strictly to operate the Service:

  • Stripe, Inc. — payment processing
  • Cloud hosting provider — application hosting and database
  • Email-delivery provider — transactional email

Each processor is bound by data-processing agreements. We will update this list when sub-processors change.

5. International Transfers

Some processors are located outside your country, including in the United States. Where required, transfers are protected by Standard Contractual Clauses or equivalent safeguards.

6. Retention

  • Account & content data: while your account is active, plus 30 days after deletion
  • Payment records: 7 years (tax and accounting requirements)
  • Authentication tokens: until expiry or sign-out
  • Backups: rotated within 30 days

7. Your Rights

Subject to applicable law (GDPR, CCPA, LGPD, and others), you may have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict or object to certain processing
  • Data portability — receive your data in a machine-readable format
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with your data-protection authority

To exercise any right, email privacy@wipdesk.com. We will respond within 30 days.

8. Your Responsibilities as a Controller

When you record information about your clients (name, contact details) in WipDesk, you act as the data controller for that data. You are responsible for having a lawful basis to record and share such data with us, and for informing your clients accordingly.

9. Cookies and Tracking

We use strictly necessary cookies only — for authentication and session management. We do not use third-party analytics, advertising, or tracking cookies at this time. If we add analytics in the future, we will update this policy and request your consent where required.

10. Security

We use industry-standard measures including TLS/HTTPS, password hashing, encrypted backups, and access controls. No system is perfectly secure; we will notify affected users without undue delay in the event of a personal-data breach.

11. Children

The Service is not directed at people under 18. We do not knowingly collect personal data from minors. If you believe a minor has signed up, contact us at privacy@wipdesk.com.

12. Changes

Material changes to this Policy will be announced via email and an in-app banner at least 14 days before taking effect.

13. Contact

Privacy queries: privacy@wipdesk.com
Mailing address: [Mailing Address]