Privacy Policy
What we collect, why we collect it, how we use and share it, how long we keep it, and what rights you have under US and EU privacy law.
Effective: January 23, 2026 · Privacy Policy Version 1.4 · Last updated: August 25, 2026
1. Introduction
Whitecap Data LLC ("Whitecap Data," "we," "us," or "our") operates the website at whitecapdata.com, the authentication gateway at login.whitecapdata.com, and the tenant analytics dashboard at cana.whitecapdata.com (collectively, the "Services"). This Privacy Policy describes what personal information we collect, why we collect it, how we use and share it, how long we keep it, and what rights you have.
This policy applies to all visitors to whitecapdata.com and all authorized users of the Whitecap Data dashboard.
If you are a California resident, see Section 13 for additional disclosures required under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). If you are an EU, UK, or Swiss resident, see Section 14b for your rights under the GDPR / UK GDPR / Swiss FADP. If you receive text messages from us, see Section 9, which covers our text-messaging program and states plainly that we never share mobile opt-in data.
This policy does not apply to information we process solely on behalf of our business customers as a data processor. Those arrangements are governed by a separate Data Processing Agreement (DPA) executed with each customer.
Contact for any privacy question: privacy@whitecapdata.com, or write to Whitecap Data LLC, 19 Columbia Street, Geneva, NY 14456.
2. Information We Collect
We collect information in three ways: information you provide to us, information collected automatically, and information received from third parties.
2a. Information You Provide
| Category | Examples | When |
|---|---|---|
| Contact-form submissions | Name, email, business name, message text | Marketing-site contact form |
| Phone and mobile numbers | Business or mobile number, and the record of your consent to be called or texted | When you give it to us on a call, by text, on a form, or in a signed agreement |
| Account credentials | Email address, password (managed by Clerk — we never see or store passwords) | Creating an account |
| Billing information | Business name, billing email, payment method (tokenized by Stripe — we never store raw card data) | Subscribing |
| Communications | Content of emails or support messages | When you contact us |
| Customer data (B2B) | Data your organization authorizes us to access (e.g., Shopify store data via API) | Per the customer agreement |
2b. Information Collected Automatically
- Log data: IP address, user agent, referring URL, pages visited, timestamps. Retained per Section 6.
- Cookies and similar technologies: Strictly necessary cookies (Clerk session, cookie-consent preference) plus, only after you accept via the consent banner, Matomo analytics cookies and first-party visitor identifiers used to understand marketing-site and concept-demo usage. See Section 8 for the full cookie table.
- Consented analytics data: A pseudonymous Matomo visitor ID; page URLs and titles with query strings and fragments removed; referrer source; campaign label; timestamps; clicks, downloads, and approved custom events; browser and browser version; operating system; device type; screen size; language; and country, region, or city-level coarse location derived from a truncated IP address. We do not use analytics to collect a precise GPS location.
- Consented usability data: On a limited sample of eligible public marketing and service pages, heatmaps and masked session recordings may capture clicks, pointer movement, scrolling, page changes, element positions, and a sanitized page structure. Forms are permanently masked, keystroke capture is disabled, and account, legal, deletion, demo, and authenticated pages are excluded.
- Visitor-to-lead linking: If a consented visitor later voluntarily submits a contact form, signs up, or logs in, we may deterministically associate that pseudonymous visitor with the corresponding CRM lead or account. We do not use browser fingerprinting to guess a person's identity.
- Error events: Errors encountered while using the Services are sent to our error-tracking service (Sentry). PII is redacted before transmission; stack traces and exception messages are retained for 90 days.
2c. Information from Third Parties
- Stripe: Payment-confirmation metadata via webhook (charge ID, customer email, business name from the checkout custom field). We do not receive or store raw payment card data. Stripe acts as an independent data controller for its own fraud-prevention and compliance purposes.
- Clerk: User identity data (user ID, email, organization membership) shared with us to authorize dashboard access.
- Shopify (B2B customers only): Customer's Shopify store data (products, sales, inventory) accessed under authorization granted by the merchant customer. Processed on behalf of the customer, not for Whitecap Data's independent purposes.
3. How We Use Your Information
| Purpose | Lawful basis (GDPR) |
|---|---|
| Providing and operating the Services | Contract (Art. 6(1)(b)) |
| Responding to your inquiries | Legitimate interest (Art. 6(1)(f)) |
| Billing and subscription management | Contract |
| Security, fraud prevention, abuse prevention | Legitimate interest |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Service improvement (aggregated / de-identified) | Legitimate interest |
| Measuring engagement with concept demos | Consent (Art. 6(1)(a)) |
| Text messaging you about your project or account (Section 9) | Consent (Art. 6(1)(a)) |
We do not use personal information to make automated decisions that produce legal or similarly significant effects. We do not currently send marketing email; if that changes, we will obtain consent first where required and you will be able to unsubscribe from every message.
4. How We Share Your Information
We do not sell or rent personal information to third parties for their own marketing purposes. We share information in these limited circumstances:
- Service providers (sub-processors): Third-party vendors who help operate the Services. Each is bound by a written data processing agreement. The current sub-processor list is at whitecapdata.com/trust/sub-processors.
- Business transfers: If Whitecap Data is acquired, merged, or undergoes a change of control, personal information may be transferred as part of that transaction. We will notify affected users via email or a notice on our website before any transfer.
- Legal compliance: We may disclose information if required by law, court order, or government authority, or to protect the rights, property, or safety of Whitecap Data, our customers, or others.
- With your consent: When you have given us explicit consent to do so.
We do not share personal information with advertising networks or data brokers. We do not use cross-context behavioral advertising pixels.
Mobile information and text-messaging consent. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the categories above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Section 9 sets out our text-messaging disclosures in full.
5. Customer Data (Whitecap Data as Processor)
When a business customer grants us access to their systems or uploads data to the dashboard, we process that data strictly on the customer's behalf and under their instructions, as a data processor. Our processing of such customer data is governed by our Data Processing Agreement (DPA), not this Privacy Policy. If you are an individual whose data was shared with us by a Whitecap Data customer, please contact that customer directly regarding your rights.
6. Data Retention
| Category | Retention period |
|---|---|
| Contact-form submissions | Emailed to our team via Postmark and mirrored to a private, staff-only internal Discord channel (#sign-up-notifications) for prompt follow-up; retained in our inbox and that channel for as long as reasonably necessary to respond and follow up. |
| Raw analytics actions | 90 days |
| Aggregate analytics reports | 25 months |
| Heatmap and masked session recordings | 30 days |
| Consent receipts | 3 years after an identified visitor's latest consent action. The full receipt history is retained together until that window expires. Anonymous receipts are retained for 3 years from the action. |
| Visitor-to-lead identity links | Until the lead is deleted, the link is revoked or unlinked, or consent is withdrawn |
| Visitor profile access audit | 1 year |
| Legacy concept-demo IP values | 14 days, after which the IP field is removed from the retained visit row |
| Legacy concept-demo rows | 90 days after the explicit analytics cutover date; no cutover date is configured before cutover |
| Account data | Duration of account + 90 days after termination |
| Billing records | 7 years (IRS record-keeping obligation) |
| Edge request logs (Cloudflare) | 400 days (shipped via Cloudflare Logpush to our R2 storage; lifecycle rule retention-400d enforced) |
| Server access logs (nginx) | 14 days rolling |
| Server mail logs (postfix/rsyslog) | 28 days rolling |
| Systemd journal | Bounded by disk; effective 7–30 days |
| Error events (Sentry) | 90 days |
| Support communications | 3 years from last interaction |
| Text-message content | Held in our business phone system for as long as the number stays in our contact records, and deleted on request |
| Text-message opt-in and opt-out (STOP) records | At least 4 years after the last message or the opt-out request. We keep the opt-out record even after you leave, because that record is what stops us from texting you again. |
| Customer data (B2B) | Per DPA — returned or deleted within 30 days of contract termination |
| Security incident records | 5 years (NY SHIELD documentation) |
7. Security
We implement administrative, technical, and physical safeguards appropriate to the size of our business and the sensitivity of the data we hold. These include:
- TLS 1.2+ on every external request; HSTS with preload on every public domain.
- Multi-factor authentication required on every administrative account.
- Encryption at rest for backups; documented secret rotation cadence; least-privilege access.
- An incident-response program with documented runbooks.
- Quarterly security audits across infrastructure, dependencies, and configuration.
Our full security program is documented in our Written Information Security Program (WISP), which is available to customers under NDA on request.
No method of transmission over the Internet is 100% secure. If you believe your account has been compromised, contact us immediately at security@whitecapdata.com.
8. Cookies and Tracking
The dashboard (cana.whitecapdata.com) and gateway (login.whitecapdata.com) set Clerk-managed session cookies that are strictly necessary for authentication. The marketing site and concept demos on whitecapdata.com show a consent banner on your first visit; non-essential cookies are blocked until you accept, and declining sets nothing beyond the consent-preference cookie itself. The cookies in use:
| Cookie | Provider | Purpose | Retention |
|---|---|---|---|
wcd_consent | Whitecap Data (first-party) | Stores the Matomo analytics flag for your one combined optional choice and acts as one of the consent identifiers (strictly necessary) | 1 year |
wcd_replay_consent | Whitecap Data (first-party) | Stores the heatmap and session-recording flag for the same combined optional choice (strictly necessary) | 1 year |
wcd_pending_consent | Whitecap Data (first-party) | Temporarily retries the exact consent receipt when a browser or network failure prevents acknowledgement, without adding analytics identifiers (strictly necessary) | Until acknowledged, up to 7 days |
__Host-wcd_analytics_grant | Whitecap Data (first-party) | Strictly necessary proof that the server acknowledged your Analytics grant. It does not contain a visitor identifier, request ID, Matomo ID, IP address, or location. | Absolute one-year maximum |
wcd_vid | Whitecap Data (first-party) | first-party visitor identifier for aggregate concept-demo pageview and contact-intent measurement (only after consent) | 1 year |
wcd_internal | Whitecap Data (first-party) | Marks Whitecap team visits so they are excluded from concept-demo engagement totals (only after consent) | 1 year |
_pk_id*, _pk_ses*, _pk_ref* | Matomo | Records pages visited, referrers, browser, device, and coarse region for aggregate site improvement (only after consent) | Up to 13 months |
_pk_hsr* | Matomo | Supports heatmaps and masked session recording on eligible public pages (only after consent and only when the separate deployment gate is enabled) | Session |
__session, __client* | Clerk | Authentication session on the dashboard/gateway subdomains (strictly necessary) | Session / 7 days |
You can change your choice at any time: open cookie preferences. The banner presents one combined optional choice for Matomo analytics, heatmaps and session recording. Behind that single control, we retain two internal consent flags: analytics permission and usability-recording permission. The current banner grants or denies both flags together. Heatmaps and masked session recording, when enabled, use click, pointer, scroll, page-change, and sanitized page-structure signals with keystrokes disabled. Forms are permanently masked. Recording is limited to a 10% sample on an allowlist of public marketing and service pages. Signup, privacy, terms, data-deletion, trust, prospect-demo, showcase, API, and all authenticated subdomains are excluded. Usability recording remains deployment-disabled until a server-side gate is explicitly enabled after staging review; granting the combined optional choice stores permission in both internal flags but does not start recording today. We do not run Cloudflare's browser analytics beacon on whitecapdata.com.
Cloudflare edge request analytics and security logs are separate from the optional browser analytics tools controlled by consent. Edge systems may process request metadata such as IP address, URL, user agent, timestamp, and security events to serve, secure, and operate the site; the browser consent banner controls the optional client analytics and replay tools described above.
Global Privacy Control (GPC): If your browser transmits a GPC signal, we honor it as a valid opt-out for California residents under CCPA §1798.135(b)(1) — analytics stays off and the consent banner is not shown unless you explicitly opt in.
9. Text Messaging (SMS and MMS)
We use text messaging to talk with prospective and current customers about their projects. This section explains how that program works, what we do with the information involved, and how to stop the messages.
9a. How you opt in
You can consent to receive text messages from Whitecap Data in any of these ways:
- Telling a member of our team, on a call or in a meeting, that we may text you.
- Sending a text to one of our business numbers, which we treat as consent to reply.
- Giving us your mobile number on a form, quote request, proposal, or signed agreement that shows the consent language.
Consent to receive text messages is never a condition of buying anything from us, and you can decline without affecting the service you get. We do not buy, rent, or otherwise obtain mobile numbers from lead lists or data brokers for text messaging.
9b. What we send
- Conversational messages: replies to your questions, scheduling, and project updates from the person you are working with.
- Account and service notices: appointment confirmations, invoice and renewal reminders, and notices about work in progress.
Message frequency varies and depends on the conversation. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
9c. How to stop the messages
Reply STOP to any message to opt out. We send one confirmation and then stop texting that number. Reply HELP for help, or write to privacy@whitecapdata.com. Opting out of texts does not by itself stop email or phone contact, so tell us if you want those stopped as well.
9d. We do not share mobile information
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the categories of information described in this policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We do not sell, rent, or trade mobile phone numbers or the contents of text messages. The only outside parties that handle this data are the vendors that carry a message for us, such as our business phone provider and the mobile carriers. They may use it only to deliver the message and are not permitted to use it for their own marketing. Those vendors are listed on our sub-processor page.
9e. What we keep
We keep the mobile number, the record of your consent, the message content, and any opt-out request. Retention periods are in Section 6. You can ask us to delete your number and message history at any time using the contact details in Section 15, and we will keep only the opt-out record needed to make sure we do not message you again.
10. Children's Privacy
The Services are intended for use by businesses and professionals. We do not knowingly collect personal information from children under 13, and the Services are not directed to children under 13. If you believe a child has provided us with personal information, contact us at privacy@whitecapdata.com and we will promptly delete it.
11. International Transfers
Whitecap Data operates from the United States and our sub-processors are listed at whitecapdata.com/trust/sub-processors. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country.
For European Economic Area (EEA), United Kingdom, and Swiss data subjects: transfers of your personal data from the EEA, UK, or Switzerland to the United States rely on either (a) the EU–US Data Privacy Framework (and its UK Extension and Swiss–US Data Privacy Framework) where the receiving sub-processor is certified under those frameworks (Cloudflare, Stripe, GitHub, Sentry, and others on our sub-processor page are DPF-certified), or (b) the European Commission's Standard Contractual Clauses (SCCs) where DPF certification is unavailable, supplemented by additional technical and contractual safeguards. A copy of the executed SCCs for any specific data flow is available on request to privacy@whitecapdata.com.
We do not currently appoint an EU representative under Article 27 GDPR because our processing of EEA-resident data is occasional, does not include large-scale processing of special-category data, and is unlikely to result in a risk to the rights and freedoms of data subjects. This determination will be revisited if our EEA-facing activities expand.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy at this URL with an updated effective date. For material changes, we will provide at least 30 days' advance notice by email to account holders before the change takes effect. Your continued use of the Services after the effective date of any update constitutes your acceptance of the revised policy. Prior versions are archived in our public Git history.
13. California-Specific Rights (CCPA / CPRA)
This section supplements the disclosures above for California residents.
13a. Categories of Personal Information Collected
| CCPA Category | Examples | Source | Business Purpose |
|---|---|---|---|
| Identifiers | Name, email, phone or mobile number, IP address, user ID | Directly from you; automatically | Account management, security, contacting you |
| Commercial information | Subscription tier, billing email | Stripe webhook | Billing, account management |
| Internet / network activity | Pages visited, feature usage, error logs | Automatically | Security, service improvement |
| Professional / employment information | Business name (if provided) | Directly from you | Account management |
| Inferences drawn from above | Usage patterns for service improvement | Derived | Service improvement |
We do not collect: biometric data, precise geolocation data, audio/visual data, government-issued identifiers, mental-health data, or sensitive personal information beyond the account credentials we manage through Clerk.
Every category above excludes text messaging originator opt-in data and consent. That information is never sold, shared, rented, or otherwise disclosed to any third party, and no mobile information is shared with third parties or affiliates for marketing or promotional purposes.
13b. Sub-processors
The current sub-processor list is at whitecapdata.com/trust/sub-processors. As of 2026-08-26 it includes Cloudflare, DigitalOcean, Clerk, Stripe, Postmark, Discord, GitHub, Sentry, and Shopify (a B2B data source in the customer's account, used under customer authorization only). Analytics runs on Whitecap's self-hosted Matomo service rather than a third-party Matomo hosting provider. The deployed Whitecap Data products do not call third-party AI APIs at runtime.
13c. California Consumer Rights
California residents have the right to:
- Know: request disclosure of what personal information we have collected, used, disclosed, or sold about you in the past 12 months.
- Delete: request deletion of personal information we have collected from you, subject to exceptions in CCPA §1798.105(d).
- Correct: request correction of inaccurate personal information.
- Opt-Out of Sale/Sharing: we do not sell or share personal information. We honor Global Privacy Control (GPC) signals.
- Limit Use of Sensitive PI: we do not use sensitive personal information for purposes beyond those permitted without the right to limit.
- Non-Discrimination: we will not discriminate against you for exercising these rights.
To exercise any of these rights, submit a request to privacy@whitecapdata.com with the subject "California Privacy Rights Request." We will respond within 45 days (extendable to 90 days with notice). We may verify your identity before processing the request. Authorized agents may submit requests on your behalf with your written authorization.
14. Your Rights (General)
Regardless of your location, you may contact us at privacy@whitecapdata.com to:
- Access or correct your personal information
- Request deletion of your account
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local data protection authority
14b. EU / UK / Swiss Resident Rights (GDPR)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the EU General Data Protection Regulation, the UK GDPR, or the Swiss Federal Data Protection Act, as applicable:
- Right of access (Art. 15) — confirmation of whether we process your data and a copy of that data
- Right to rectification (Art. 16) — correction of inaccurate data
- Right to erasure (Art. 17) — deletion subject to the exceptions in Art. 17(3)
- Right to restriction of processing (Art. 18) — pause processing while a dispute is resolved
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interest, including direct marketing
- Right not to be subject to automated decision-making (Art. 22) — we do not currently engage in automated decision-making with legal or similarly significant effects
- Right to withdraw consent (Art. 7(3)) — where processing is based on consent, you may withdraw at any time without affecting prior processing
- Right to lodge a complaint with a supervisory authority (Art. 77) — contact your local Data Protection Authority
To exercise any of these rights, email privacy@whitecapdata.com with the subject "EU / UK Privacy Rights Request." We will respond within one month per Art. 12(3), extendable by two additional months for complex requests with notice. We may verify your identity before processing the request.
Data Protection Officer: we are not required to appoint a DPO under Art. 37 GDPR (our processing does not meet the thresholds for mandatory appointment). For data-protection matters, contact privacy@whitecapdata.com directly.
Supervisory authority for EU residents in the absence of an appointed lead supervisory authority: your local national Data Protection Authority. For UK residents: the Information Commissioner's Office (ICO).
15. Contact Us
Whitecap Data LLC
19 Columbia Street
Geneva, NY 14456
Email: privacy@whitecapdata.com
For security disclosures: security@whitecapdata.com