Data Controller Information
ControllerWhispertise™ is operated by Whispertise LLC, Phoenix, Arizona 85001, United States. Email: privacy@whispertise.com. For users in the European Union, United Kingdom, and Switzerland, Whispertise LLC acts as the data controller for personal information processed under this policy. Inquiries or requests may be addressed to our designated Privacy Officer at privacy@whispertise.com.
Lawful Basis for Processing (GDPR Art. 6)
GDPR BasisWe process personal data under four primary lawful bases: (a) Contract Performance: processing necessary to provide our referral marketplace, campaign attribution, and commission payout services; (b) Legitimate Interests: platform integrity, bot defense, fraud prevention, and performance enhancement, balanced against user privacy rights; (c) Legal Compliance: fulfilling statutory accounting, tax, and sanctions screening obligations; and (d) Consent: where applicable, for non-essential communications, which may be withdrawn at any time.
Authentication & Local Storage Architecture
StorageWhispertise™ does not use third-party tracking or authentication cookies. Sessions are maintained via secure browser localStorage tokens. You can clear localStorage at any time via your browser developer settings or settings page to immediately revoke the local session.
1. Information We Collect
Data TypesWe collect: (a) Account data: name, email address, password hashes, and profile settings; (b) Referral and conversion telemetry: referral link clicks, campaign metrics, conversion timestamps, and payout identifiers; (c) Financial data: billing details and payout preferences handled directly through PCI-DSS Level 1 payment processors (e.g., Stripe) — Whispertise™ never stores raw debit/credit card numbers; (d) Technical logs: IP address, user-agent, and fraud detection signals.
2. How We Use Collected Information
UsageInformation is utilized solely to operate, maintain, and safeguard the platform, verify genuine referral conversions, disburse earned payouts to Whisperers, prevent abusive multi-accounting, provide transactional service updates, and satisfy legal audit trails.
3. Data Sharing & Third-Party Processors
TransfersWe do not sell personal data to brokers or advertising networks. Personal data is shared strictly on a need-to-know basis with trusted infrastructure partners: payment processors (e.g. Stripe) for funds settlement, cloud database providers for encrypted data storage, email delivery providers for transactional security codes, and legal or tax authorities when compelled by valid legal process.
4. Data Retention Schedules
RetentionAccount profile records are retained for up to 90 days following user account deletion before permanent purge. Financial ledger, billing records, and tax-relevant transaction logs are retained for seven (7) years to comply with statutory fiscal obligations. Machine learning and operational logs are purged after 30 days.
5. Your Global Rights (GDPR / CCPA / PIPEDA / NDPR / POPIA)
Your RightsSubject to applicable statutory requirements in your jurisdiction, you hold the right to: (a) Request access to your personal data; (b) Correct inaccurate or incomplete records; (c) Request erasure ("Right to be Forgotten"); (d) Request data portability in a machine-readable format; and (e) Object to or restrict specific processing operations. To exercise these rights, submit a verified request to privacy@whispertise.com.
6. California Privacy Rights (CCPA / CPRA)
CaliforniaUnder the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have specific statutory rights: the right to know what personal data is collected, the right to delete personal data, and the right to non-discrimination for exercising privacy rights. Whispertise™ does not sell or share personal information for cross-context behavioral advertising.
7. Canada & Québec Law 25 / PIPEDA
CanadaCanadian residents and users located in the Province of Québec benefit from statutory rights under PIPEDA and Québec Act Respecting the Protection of Personal Information in the Private Sector (Law 25), including designated privacy governance and breach notification safeguards. Contact our Privacy Officer at privacy@whispertise.com.
8. Nigeria (NDPR) & South Africa (POPIA)
AfricaUsers residing in Nigeria and South Africa enjoy access, rectification, and deletion rights under the Nigeria Data Protection Regulation (NDPR) and Protection of Personal Information Act (POPIA). All cross-border data transfers are handled under secure technical guarantees.
9. Cookie Policy & Tracking Notice
CookiesWhispertise™ operates without third-party tracking or advertising cookies. If optional analytics features are introduced in subsequent platform versions, an explicit opt-in consent banner will be provided in compliance with ePrivacy regulations.
10. Technical Security Controls
SecurityWe protect data using state-of-the-art cryptographic safeguards: argon2id password hashing, TLS 1.3 encryption for all data in transit, AES-256 encryption for data at rest, role-based database access, and continuous automated vulnerability monitoring.
11. Protection of Children
MinorsWhispertise™ is strictly a professional referral marketplace designed for businesses and adult introducers. The platform is not directed to individuals under 16 years of age. We do not knowingly collect personal data from minors.
12. Contacting the Privacy Officer
ContactIf you have inquiries, concerns, or requests regarding this Privacy Policy or your personal data, reach out to our Privacy Office at privacy@whispertise.com with the subject line "Privacy Request".
Official Entity & Notice Address
Whispertise™ is operated by Whispertise LLC, a registered company in Phoenix, Arizona, United States. Formal notices, DMCA notifications, and subpoena requests must be directed to legal counsel at legal@whispertise.com.