Privacy Policy
At whatsh.app/ening ("whatsh.app", "we", "us", or "our"), privacy, automated data hygiene, and confidentiality are fundamental pillars of our platform architecture. This Privacy Policy details our practices concerning information collection, automated PII scrubbing, and data protection.
1. The Information We Collect
Because whatsh.app is an enterprise B2B data service rather than a consumer-facing app, we collect limited personal information strictly necessary for commercial relationships:
- Client Account Information: Name, work email address, company name, and billing details provided when requesting API keys or pilot subscriptions;
- Contact Form Inquiries: Name, email address, company affiliation, and project descriptions submitted through our contact form;
- API Telemetry & Usage Logs: Endpoint request paths, timestamps, HTTP status codes, response latencies, and client IP addresses captured for security, audit, and rate-limiting enforcement.
2. Automated PII Sanitization Guarantee
Our AI-powered ingestion pipeline strictly enforces automated Personally Identifiable Information (PII) redaction across all scraped event records and venue feeds. Before any event title, description, or notes field is stored in our database or exposed via API, it passes through specialized regex and Named Entity Recognition (NER) filters that automatically redact:
- Personal and corporate email addresses (replaced with
[EMAIL REDACTED]); - Telephone and mobile numbers (replaced with
[PHONE REDACTED]); - Social Security numbers (replaced with
[SSN REDACTED]); - Payment card and financial account patterns (replaced with
[CARD REDACTED]).
3. Venue Connection Script Privacy
The whatshappening.js snippet installed by venue partners is engineered with privacy-by-design principles:
- No Consumer Tracking: It does NOT drop tracking cookies, fingerprint individual site visitors, or log end-user IP addresses;
- Scoped Extraction: It solely extracts public Schema.org Event metadata declared in the site's HTML markup;
- Secure Transmission: All event payloads are encrypted in transit via HTTPS/TLS 1.3.
4. Zero Third-Party Advertising & Cookies
We do not serve third-party advertisements, sell contact lead lists, or use third-party behavioral advertising cookies. Essential cookies or local session storage may be utilized solely for developer documentation preferences and API key authentication.
5. Data Security & Storage
All client data, API credentials, and inquiry submissions are encrypted in transit and stored within hardened PostgreSQL databases behind strict UFW firewalls and Cloudflare edge proxies. API keys are salted and hashed using one-way SHA-256 cryptographic hashing—plaintext keys are never stored in our systems.
6. Contact Us
For privacy inquiries, data deletion requests, or compliance auditing, please contact our data protection team at privacy@whatsh.app or via our Contact Form.