Privacy policy
Your business data, explained plainly
This policy explains what Whoa collects, why it is used, who processes it, how long it is kept, and the choices available to account owners, staff, clients, and riders.
1. Scope, company, and privacy roles
This policy applies to the Whoa iOS, iPadOS, watchOS, and Android apps, Whoa-hosted invoice and support workflows, and related services operated by Graffiti Labs US LLC ("Whoa", "we", "us", or "our"). It does not replace the privacy policies of Apple, Google, Stripe, a trainer, a barn, or another independent service.
Whoa acts as a controller or business for account identity, subscriptions, service administration, security, support, and product operation. When a trainer or equestrian business enters information about its clients, riders, horses, staff, services, and invoices, that business generally decides why and how the information is used. For those records, the business may be the controller or business and Whoa generally processes the information to provide the service. Local law may describe these roles differently.
Businesses using Whoa are responsible for giving appropriate notices, obtaining any required consent or other legal basis, responding to their clients and staff, and limiting entries to information reasonably needed for billing and operations.
2. Information we collect
| Category | Examples | Source |
|---|---|---|
| Account identity | Name, email, phone number, user ID, sign-in provider, authentication status | You, Apple, Google, Firebase Authentication |
| Business profile | Legal and trade name, contact details, country, region, currency, tax labels, tax rates, registration number | Company owner |
| Operational records | Facilities, clients, riders, horses, services, lesson dates, trainer attribution, notes, prices, recurring billing settings | Owners and authorized staff |
| Billing records | Invoice number, line items, amounts, tax, currency, due date, delivery status, payment status, hosted invoice link | Owners, staff activity, Whoa, Stripe |
| Payment metadata | Stripe customer, account, invoice, payment, charge, and transfer identifiers; payout readiness; last status; dispute or failure state | Stripe and Whoa |
| Subscription data | Selected plan, trial and access dates, product ID, purchase token or transaction identifiers, entitlement state, promo redemption | Apple, Google Play, Whoa, authorized administrators |
| Team data | Staff name, email, user ID, role, invitation, membership, trainer attribution, access status | Company owner, staff member, Whoa |
| Device and security data | Push token, device identifier assigned by messaging services, notification preferences, App Check signals, IP address, user agent, security events | Your device, Firebase, Apple, Google |
| Passkey data | Credential identifier, public key, authenticator properties, counter, creation and last-used timestamps | Your device and Whoa |
| Support data | Messages, screenshots you choose to send, device and app version, troubleshooting history | You |
Whoa does not ask you to enter full client card numbers, card security codes, online banking passwords, or full trainer payout bank details into the Whoa database. Stripe, Apple, or the relevant financial provider collects sensitive payment credentials in its own interface.
We may receive technical request data such as IP address, time, user agent, app or project identifier, response status, and abuse-prevention signals from our hosting and cloud providers. We do not currently use a third-party advertising SDK or a cross-app tracking identifier.
3. How and why information is used
We use information to:
- create and authenticate accounts using Apple, Google, Firebase, and passkeys;
- set up business profiles, facilities, clients, riders, horses, service templates, staff roles, and billing rules;
- sync authorized company data across iPhone, iPad, Android devices, and Apple Watch;
- log work, generate invoices, deliver hosted payment links, update payment status, and create accounting exports;
- create and manage Stripe connected accounts, facilitate payments, calculate platform instructions, and track payouts or failures;
- verify trials, App Store and Google Play subscriptions, plan level, complimentary access, and event codes;
- send owner-authorized payment and overdue notifications;
- prevent fraud, secure the service, enforce role restrictions, investigate failures, and comply with law;
- answer support, privacy, and account requests; and
- maintain and improve service reliability using operational information.
Legal bases in the EEA and similar jurisdictions
Depending on the activity, we rely on performance of a contract to provide Whoa; legitimate interests in securing, supporting, and improving a business billing service; compliance with legal obligations; and consent where required, such as optional notifications. A business using Whoa is responsible for identifying its legal basis for client, rider, minor, and staff data it enters.
Where we rely on legitimate interests, we consider the expected business context, data sensitivity, safeguards, and user rights. You can object as described below. Withdrawing consent does not affect processing completed before withdrawal.
5. Payments, payouts, and subscriptions
Stripe Connect
A business that enables client payments creates or links a Stripe connected account. Stripe collects required identity, tax, business, bank, and payout information. Whoa can create activity on that connected account and receives status and transaction information needed to provide invoices, payment tracking, transfers, record copies, support, and compliance operations. Stripe may perform fraud, risk, identity, sanctions, and eligibility checks under its own legal obligations.
The platform payment record and a connected-account record may both exist as part of the configured funds flow. These are financial records, not duplicate client charges. Stripe determines which payment methods and payout capabilities are available by country, currency, account status, and risk requirements.
App-store subscriptions
Apple or Google processes payment for the Whoa app subscription purchased on its platform. Whoa receives signed or server-verified purchase and entitlement information, such as product, transaction or purchase-token identifiers, environment, and expiration, cancellation, or revocation state, to grant access. We do not receive your store password or complete store payment credentials.
Deleting Whoa data does not cancel an App Store or Google Play subscription because the applicable store controls the subscription contract and renewal. Manage it separately through that store account.
6. Team accounts, clients, riders, and minors
The owner of a Team workspace can invite sub-trainers. Staff access is limited to operational data needed to log services and does not include owner billing, payout, tax, subscription, or administrative controls. Owners can see trainer attribution in activity and reports.
Whoa is a business tool intended for adult trainers, barn operators, farriers, and equestrian service companies. It is not directed to children and children may not create owner or staff accounts. A business may enter the name of a minor rider when reasonably necessary to identify who received a service and bill the responsible client. The business must have authority to do so, provide any required notice, use the minimum necessary information, and avoid sensitive notes that are not needed for billing. Parents, guardians, and riders should direct record questions to the business that created the entry; they may also contact us for assistance identifying the correct process.
A horse name or service record may become personal information when linked to an identifiable client or rider and is protected accordingly.
7. International storage and transfers
Whoa is offered to businesses in Canada, the United States, Mexico, and continental Europe. Graffiti Labs US LLC and its service providers may process information in the United States, Canada, the European Economic Area, and other locations where those providers operate. Privacy laws in a receiving country may differ from those in your home country.
Firebase Authentication is operated from US data centres, while other Firebase and cloud services may use global infrastructure or configured regions. Stripe assigns processing entities and locations based on the connected account, transaction, and applicable services. We use provider contracts and available data-protection terms intended to support lawful transfers, such as data processing addenda and recognized transfer mechanisms where required.
Contact us for more information about the safeguards relevant to your account. Do not use Whoa where your legal or contractual obligations prohibit the required international processing.
8. Retention, account deletion, and backups
We keep information only as long as reasonably needed for the purposes described above, a valid business need, dispute handling, security, or a legal obligation. Typical rules are:
- Active workspace data: retained while the account is active or until an authorized user deletes an eligible record.
- Financial and transaction records: retained for the period required for tax, accounting, anti-money-laundering, chargeback, payout, fraud, and legal obligations. Stripe may retain its own records independently.
- Subscription records: retained while needed to verify access, reconcile Apple or Google Play notifications, prevent duplicate grants, and meet accounting or fraud obligations.
- Passkey challenges: short-lived and deleted after successful use or expiry; registered public credential data remains until the passkey or account is removed.
- Push devices: retained while registered to provide requested notifications and deleted when the account is deleted; invalid tokens may be removed earlier.
- Support and security records: retained for a reasonable period based on the issue, risk, and legal need.
- Backups and provider logs: may persist for a limited cycle before being overwritten or de-identified and may not be immediately accessible for individual deletion.
Delete from the app
The company owner can select Setup > Account > Delete Whoa account. Confirmed deletion removes the Firebase authentication account, company workspace and eligible subcollections, staff memberships and invitations, passkey credential records, push device registrations, and other Whoa application data associated with that owner or workspace. The process also requests deletion or closure of connected Stripe resources where Stripe allows it.
Some data cannot be erased immediately or at all when another party controls it or retention is legally required. This includes Apple or Google Play subscription records, Stripe compliance and transaction records, bank records, copies already delivered to clients, and exports held by the business or its accountant. If deletion partially fails, Whoa may return a warning so the remaining issue can be completed manually. You can also start a request from our account deletion page.
9. Your privacy rights
Depending on where you live and your relationship to Whoa, you may have rights to request access, correction, deletion, restriction, portability, objection, withdrawal of consent, or information about disclosure. You may also have the right to complain to a privacy or data-protection authority. These rights can be limited by identity verification, another person's rights, the business customer's instructions, financial recordkeeping duties, legal claims, security, or other lawful exceptions.
European Economic Area
EEA data subjects may object to processing based on legitimate interests, request restriction, receive portable information they provided where technically applicable, and lodge a complaint with the supervisory authority in their usual residence, workplace, or place of the alleged infringement. We do not use Whoa account data for solely automated decisions that produce legal or similarly significant effects. Stripe may independently use automated fraud and risk systems under its own notice.
Canada
Canadian individuals may request access and correction and ask how personal information has been used or disclosed, subject to federal and provincial law. You may challenge compliance with the applicable privacy commissioner.
United States
Residents of states with applicable consumer privacy laws may have rights to know, access, correct, delete, or obtain a portable copy of certain information and to appeal a denied request. Whoa does not sell personal information or share it for cross-context behavioural advertising, so no sale or targeted-advertising opt-out is required for our current practices.
Mexico
Individuals may have rights of access, rectification, cancellation, and opposition, along with rights to limit use or disclosure and revoke consent where applicable. Statutory exceptions may apply.
How to exercise a right
Email legal@graffitilabs.io with "Whoa Privacy Request" in the subject. State your country, your relationship to the account, the account email or business involved, and the request. Do not send identification documents unless we specifically request a secure verification method. We may verify identity and authority before acting. We will respond within the period required by applicable law and explain any denial or appeal process.
If a trainer or barn entered your information, that business is often best placed to respond first. We will assist the business or route the request where appropriate.
10. Security, notifications, and tracking
Whoa uses encrypted network connections, Firebase security rules, role-based access, server-side authorization, App Check, signed webhook verification, secure provider interfaces, and device-protected authentication options. No system is perfectly secure. Protect your Apple or Google account, use a passkey where available, restrict team invitations, remove staff promptly, and report suspected compromise.
Push notifications are optional. When enabled, Whoa registers a device token and sends payment or late-payment alerts to authorized owners. Notification text may appear on a locked device according to device settings. Staff billing alerts are restricted. You can disable notifications in Whoa and in iOS or Android system settings.
The public Support, Privacy, and Terms pages do not include advertising pixels or cross-site behavioural analytics. Firebase Hosting and network providers may still process ordinary request logs and security data. The authenticated admin portal is restricted and is not a public consumer tracking page.
Whoa does not respond to browser "Do Not Track" signals because it does not currently perform cross-site tracking. If practices change materially, this policy and required choices will be updated before the new use begins.
11. Changes, contact, and language assistance
We may update this policy when the product, providers, or law changes. The effective date will be revised and material changes may be announced in the app or by another appropriate channel. Continued use after an effective update is subject to the updated policy, but we will seek consent where law requires it.
Privacy questions and requests can be sent to legal@graffitilabs.io. This address reaches the Whoa privacy contact for Graffiti Labs US LLC.
Assistance is available in English, French, German, Spanish, Italian, Dutch, and Portuguese. We accept requests in every official European Union language through our EU language access directory. The English policy is the controlling version to the extent permitted by law; mandatory rights in your country remain unaffected.