Skip to content

Privacy Policy

Last updated: 2026-08-06

This Privacy Policy describes how WipDesk ("we", "us") collects, uses, discloses, and protects personal data when you use WipDesk.

1. Data We Collect

1.1 Account data

  • Email address
  • Display name and username
  • Your password — we don't store it. Authentication is handled by AWS Cognito, our identity provider; only they hold your password, and only in hashed form, never in plaintext

1.2 Profile and content data

  • Commission titles, descriptions, statuses, milestones, prices
  • Uploaded images, video, audio, GIFs, attachments, and cover art
  • Client records you create — name, email, notes, tags, pronouns, timezone, any contact handles you add (e.g. Discord, social media), and a profile photo if you upload one. You are responsible for ensuring you have a legitimate reason to record this data about your clients — see "Your Responsibilities as a Controller" below

We strip embedded metadata from uploaded images. EXIF data — which can include the GPS coordinates where a photo was taken, along with device and software details — is removed when we process your uploads. Your location never travels with the files you publish.

1.3 Payment data

Subscriptions are sold, and payments processed, by Paddle.com Market Ltd, acting as our Merchant of Record. Paddle is the seller of record and collects your billing and card details directly; we never see or store them. Paddle's own privacy notice covers that data.

We retain only the minimum needed to reconcile your subscription on our side: the Paddle customer and subscription identifiers, your plan, status, billing period, and invoice identifiers.

1.4 Technical data — we don't keep it

We do not store your IP address, your approximate location, or anything about your browser, device, or operating system. There is no such column in our database, and our server logs record only the time, method, path, response status, and size of a request — never who made it.

Your IP is still seenin the moment a request arrives — it has to be, for the request to reach us — and it's held in memory for about a minute so we can rate-limit abuse. It is never written down.

The same goes for the outside services we use (see 4). Each one is configured to discard your IP rather than record it: our error monitor strips it from every report before sending, our product analytics discards it on arrival, and Google Analytics runs with IP anonymization on. This is a choice we made and can change, so if it ever stops being true, this paragraph is where it will say so.

The one place this doesn't apply is our sub-processors: your sign-in provider, our payment provider, and the anti-abuse check on public forms each see the request directly and keep their own records under their own policies. We can't see or control those.

Your session tokens live in your own browser. We don't keep a copy.

This is where things stand today. If we ever start collecting technical data — for security forensics, for example — we'll say so here before we do it.

1.5 Communications

Emails you send to support, transactional emails we send you (verification, billing receipts, security alerts).

2. How We Use Your Data

  • To operate and maintain the Service
  • To process payments and manage subscriptions
  • To send transactional notifications (billing, security)
  • To respond to your support requests
  • To enforce our Terms of Service and Acceptable Use Policy
  • To comply with legal obligations

We do not sell your personal data. We do not use your Content to train machine-learning models.

3. Legal Bases (GDPR)

Where GDPR applies, we rely on: (a) contract — to provide the Service you signed up for; (b) legitimate interests — to keep the Service secure and improve it; (c) legal obligation — to comply with tax, accounting, and law-enforcement requirements; (d) consent — where applicable (you can withdraw at any time).

4. Sub-Processors

We share data with the following processors strictly to operate the Service:

  • Paddle.com Market Ltd — Merchant of Record: payment processing, invoicing, and sales tax
  • Amazon Web Services (AWS) — application hosting (EC2), database (RDS/PostgreSQL), file storage (S3), content delivery (CloudFront), asynchronous processing such as image, video, and audio transcoding and watermarking (Lambda), secrets/configuration management (Secrets Manager), and transactional email (SES)
  • AWS Cognito— authentication, including "Sign in with Google" (Cognito talks to Google on your behalf when you choose that option — we never receive your Google credentials, and Cognito is the only place any password is stored; we never receive or hold it either)
  • Google — reCAPTCHA on the sign-in, sign-up, and public report forms (separate from the Cognito-mediated Google sign-in above). Google receives the request directly and keeps its own technical records — including your IP and browser — under its own privacy policy
  • Sentry (Functional Software, Inc.) — error monitoring. When something breaks, Sentry receives the error and the page it happened on, so we can fix it. We configure it to not send your IP address, cookies, or request headers, and session replay is switched off entirely
  • PostHog — product analytics (which features get used), hosted in the European Union and reached through our own domain rather than directly. Your IP address is discarded and never stored. Only loads if you accept analytics
  • Google Analytics — aggregate web analytics, with IP anonymization enabled and advertising features off. Only loads if you accept analytics

Each processor is bound by data-processing agreements. We will update this list when sub-processors change.

5. International Transfers

Some processors are located outside your country, including in the United States. Where required, transfers are protected by Standard Contractual Clauses or equivalent safeguards.

6. Retention

  • Account & content data: while your account is active, plus 30 days after deletion
  • Payment records: 7 years (tax and accounting requirements)
  • Session tokens: they live in your browser until they expire or you sign out. We keep no copy
  • Technical data (IP, location, browser, device): not collected, so there is nothing to retain
  • Server logs: 30 days. They record the time, method, path, status, and size of each request — not who made it
  • Backups: rotated within 30 days

7. Your Rights

Subject to applicable law — including Peru's personal-data protection law (Ley N.° 29733), the GDPR, CCPA, LGPD, and others — you may have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Restrict or object to certain processing
  • Data portability — receive your data in a machine-readable format
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with your data-protection authority

To exercise any right, email privacy@wipdesk.com. We will respond within 30 days.

8. Client Data: Your Role and Ours

When you record information about your clients — name, contact details, notes, or a photo — in WipDesk, you act as the data controller for that data, and we act as your processor. In plain terms: it is your data about your clients, held on your behalf. We process it only to run the Service for you, and we do not use it for our own purposes.

You are responsible for having a lawful basis to record and share such data with us, and for informing your clients accordingly. If one of your clients asks us directly to access or delete data you hold about them, we will refer them to you, since you are the controller — and we will support you in responding.

9. Cookies and Tracking

Strictly necessary— always on. Cookies for authentication and session management: without them you cannot stay signed in. Google's reCAPTCHA cookie on the sign-in, sign-up, and public report forms also sits here; it is there to tell humans from bots, not to profile you, and we never read it.

Analytics — off until you say otherwise. PostHog and Google Analytics help us see which features get used and what breaks. Nothing analytics-related loads, and no analytics cookie is set, until you accept. Declining is a real choice, not a delayed yes: if you decline, those scripts are never fetched at all. You are asked once, and we remember your answer in your own browser.

Where this applies— the consent gate above runs on the WipDesk app at app.wipdesk.com and on the artist profile pages we host. Our marketing site at www.wipdesk.com is a separate site and loads Google Analytics through Google Tag Manager. Until we bring it under the same gate, you can opt out there with your browser's tracking protection or Google's opt-out add-on.

Error monitoring (Sentry) runs regardless, because it is how we find out the app is broken. It records what failed and where — never your IP, cookies, or headers — and it does not record your screen. Its events travel through our own domain rather than straight to Sentry, so that tracker blockers do not silently hide crashes from us; nothing extra is collected on that path.

10. Security

We use industry-standard measures including TLS/HTTPS, encrypted backups, and access controls. Passwords are never stored by us at all — they live only with our identity provider (see 1.1). No system is perfectly secure; we will notify affected users without undue delay in the event of a personal-data breach.

The share links you send to clients are backed by random 256-bit tokens that we store only as a hash — the link itself is never kept in our database. File download URLs are signed and expire.

11. Children

The Service is not directed at people under 18. We do not knowingly collect personal data from minors. If you believe a minor has signed up, contact us at privacy@wipdesk.com.

12. Changes

Material changes to this Policy will be announced via email and an in-app banner at least 14 days before taking effect.

13. Contact

Privacy queries: privacy@wipdesk.com

We'd like to use analytics to understand how WipDesk is used. Nothing loads until you choose, and we never record your IP address. Privacy Policy