Privacy Policy
Last updated: 2026-04-25
This Privacy Policy describes how WipDesk ("we", "us") collects, uses, discloses, and protects personal data when you use WipDesk.
1. Data We Collect
1.1 Account data
- Email address
- Display name and username (optional)
- Hashed password (we never store plaintext passwords)
1.2 Profile and content data
- Commission titles, descriptions, statuses, milestones, prices
- Uploaded images, attachments, cover art
- Client names you record (you are responsible for ensuring you have a legitimate reason to record this data — see "Your Responsibilities as a Controller" below)
1.3 Payment data
Payment processing is handled by Stripe, Inc. We do not store full card numbers. We retain only the minimum data needed to reconcile your subscription (Stripe customer ID, plan, status, invoice IDs).
1.4 Technical data
- IP address and approximate location (city/country) at sign-in
- Browser, device, and OS at sign-in
- Authentication tokens stored in your browser
1.5 Communications
Emails you send to support, transactional emails we send you (verification, billing receipts, security alerts).
2. How We Use Your Data
- To operate and maintain the Service
- To process payments and manage subscriptions
- To send transactional notifications (billing, security)
- To respond to your support requests
- To enforce our Terms of Service and Acceptable Use Policy
- To comply with legal obligations
We do not sell your personal data. We do not use your Content to train machine-learning models.
3. Legal Bases (GDPR)
Where GDPR applies, we rely on: (a) contract — to provide the Service you signed up for; (b) legitimate interests — to keep the Service secure and improve it; (c) legal obligation — to comply with tax, accounting, and law-enforcement requirements; (d) consent — where applicable (you can withdraw at any time).
4. Sub-Processors
We share data with the following processors strictly to operate the Service:
- Stripe, Inc. — payment processing
- Cloud hosting provider — application hosting and database
- Email-delivery provider — transactional email
Each processor is bound by data-processing agreements. We will update this list when sub-processors change.
5. International Transfers
Some processors are located outside your country, including in the United States. Where required, transfers are protected by Standard Contractual Clauses or equivalent safeguards.
6. Retention
- Account & content data: while your account is active, plus 30 days after deletion
- Payment records: 7 years (tax and accounting requirements)
- Authentication tokens: until expiry or sign-out
- Backups: rotated within 30 days
7. Your Rights
Subject to applicable law (GDPR, CCPA, LGPD, and others), you may have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict or object to certain processing
- Data portability — receive your data in a machine-readable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with your data-protection authority
To exercise any right, email privacy@wipdesk.com. We will respond within 30 days.
8. Your Responsibilities as a Controller
When you record information about your clients (name, contact details) in WipDesk, you act as the data controller for that data. You are responsible for having a lawful basis to record and share such data with us, and for informing your clients accordingly.
9. Cookies and Tracking
We use strictly necessary cookies only — for authentication and session management. We do not use third-party analytics, advertising, or tracking cookies at this time. If we add analytics in the future, we will update this policy and request your consent where required.
10. Security
We use industry-standard measures including TLS/HTTPS, password hashing, encrypted backups, and access controls. No system is perfectly secure; we will notify affected users without undue delay in the event of a personal-data breach.
11. Children
The Service is not directed at people under 18. We do not knowingly collect personal data from minors. If you believe a minor has signed up, contact us at privacy@wipdesk.com.
12. Changes
Material changes to this Policy will be announced via email and an in-app banner at least 14 days before taking effect.
13. Contact
Privacy queries: privacy@wipdesk.com
Mailing address: [Mailing Address]