Privacy Policy
Last updated: 19 September 2026
This Privacy Policy explains how KMF Ventures LLC (KMF Ventures, we, us, or our), which operates the Whooshly service (Whooshly or the Service), collects, uses, and shares information. Whooshly is a pay-once campaign link toolkit for short links, dynamic QR codes, UTMs, digital cards, link-in-bio, landing pages and events. The marketing and entity site is whooshly.co, the dashboard and API are at app.whooshly.co, and generated short links and hosted content use whshly.co or a custom domain you connect.
This policy describes how we handle personal information. It works alongside our Terms of Service. It explains our practices; it is not a request for your consent to processing, and where we rely on consent we ask for it separately (for example the analytics choice in our cookie banner).
Who this policy is for
This policy covers account holders who sign up and use Whooshly to create links, pages, events, and other content; visitors who click a short link, scan a QR code, or view a hosted page or vCard that an account holder created; event guests who register for or buy a ticket to an event hosted on Whooshly; and door staff an organizer gives a check-in link. Some sections below apply mainly to one group, and we say so where it matters.
Information we collect
Account information. When you create an account, we collect your email address and a password. We never store your password in plaintext; it is kept only as a secure cryptographic hash. Passwords must be at least 8 characters. You may also provide a display name (if you leave it blank, we default it to your email address), and your account may include an email-verification flag and an optional profile image. If you choose Continue with Google instead of a password, we receive a standard sign-in identity from Google (such as your email, name, and profile image) along with the related authentication tokens; we only do this if you choose Google sign-in.
Signup country and data region. When you create an account we record the country your request appears to come from, as reported by our infrastructure provider, and we use it once to choose where your account data is stored: accounts created from the EU, EEA, United Kingdom, or Switzerland are stored in an EU database, and all other accounts in a database in eastern North America. We keep the country and the resulting region with your account. We do not use this to profile you, and the region is not changed by later activity.
Content and settings you create. The Service stores the content you create, including destination URLs for your links, your link slugs and settings, QR code styling, UTM templates (source, medium, campaign, term, and content values), and the fields on your hosted vCards (such as first name, last name, organization, job title, phone, email, website, and a free-text note). It also stores any custom domain hostnames you connect. If you protect a Pro link with a password, that link password is stored only as a hash, never in plaintext. Please note that short links redirect publicly and hosted vCards are public web pages, so any content you publish through them can be accessed by anyone who has the link.
Payment information. Our payment processor, Polar, acts as the merchant of record and seller of record for purchases. Polar hosts the checkout, processes all payments, and handles billing and applicable sales tax. You enter your payment-card details directly with Polar. We never receive or store your card number or other payment-card details. We store only what we need to apply your purchases, namely entitlement flags (such as whether your one-time Core or Business purchase is unlocked and whether your Pro subscription is active), your credit-wallet balance, and a credit ledger that records grants, top-ups, and debits for accounting purposes.
Information collected automatically when links are used. When someone clicks one of your short links, or scans or views one of your QR codes or hosted vCards, the Service records an event with coarse, low-detail dimensions: an approximate country (derived by our infrastructure provider), a device-type bucket (such as mobile, tablet, or desktop, derived from the browser's user-agent), the referrer, and any UTM parameters present on the URL. We do not build advertising profiles, and we do not track visitors across other websites.
Visitor IP addresses. A visitor's IP address is processed only transiently at the edge to apply rate limiting and abuse prevention and to derive the approximate country and device signals described above. The visitor's IP address is not stored as part of the click or scan analytics record.
Security and session data. When you sign in, we create a login session and store a session record that includes a session token, an expiry time, and, for security purposes, the IP address and browser user-agent associated with that session. This session data is retained until the session expires or you sign out, and it is removed when you delete your account.
AI assistant conversations. When you use the Whooshly AI assistant, we process the questions you submit and the answers it returns. For a visitor who is not signed in, the current conversation is saved only in that browser's local storage. For a signed-in account, the current conversation is also saved to the account so it can continue on another device. Please do not submit passwords, payment details, or other sensitive or private information to the assistant.
Event registrations and tickets. When you register for or buy a ticket to an event hosted on Whooshly, the details you enter (such as your name, email address, number of guests, any names you give for your guests, and answers to the organizer's questions) go to that event's organizer, who decides how they are used. Only give a guest's name if they are happy for you to share it. We store and process them on the organizer's behalf to run the event page and your private ticket page, tell the organizer you registered or bought tickets, send your confirmation and notices about changes, cancellations, or refunds, and check you in at the door, when we record the time you were admitted. These emails show the organizer's name followed by "via Whooshly", and replies go to the contact address the organizer set for the event. Paid tickets are processed by Stripe on the organizer's Stripe account; we never receive your full card number. We count ticket page views and check-ins for each event without attaching your name or email address. We do not use your registration to market Whooshly to you.
Ticket and check-in links. Your ticket link is private: anyone who has it can view your ticket and, for a free registration, change or cancel it, so do not share it. Door staff use a separate check-in link from the organizer that lets them look up that event's guests and admit them. We store only a scrambled (hashed) form of ticket and check-in links, not the links themselves.
How you found Whooshly. When you open the Whooshly app, we note how you arrived: campaign tags in the link (such as utm_source), the domain of an external site that referred you, the Whooshly page or free tool you came from, and, if you clicked a "make your own" link on a hosted page, a random click token. This signup-source record is kept in your browser's local storage for up to 7 days and does not include your name, email address, or IP address. If you create an account in that time, we save it once with the new account and remove it from your browser; otherwise it expires. When you click from whooshly.co into the app, the campaign tags and referring domain travel in that link rather than being stored by the website. When someone clicks a "make your own" link on a free hosted Bio, vCard, or Landing Page, we record the click with the page it came from, a coarse channel, and a device type so we can measure how often hosted pages lead to new accounts. The visitor's IP address is not stored with that record, and the page owner is not told who signed up.
How and why we use information
We use the information above to:
- provide, operate, and maintain the Service, including creating and authenticating your account across all of its products;
- deliver your short-link redirects, hosted vCards, and QR codes, and apply the smart-routing rules available on the Business plan (such as geo, device, A/B testing, and expiry);
- produce the click and scan analytics shown in your dashboard, including per-day totals and country, device, referrer, and UTM breakdowns;
- answer questions through the AI assistant and, when you are signed in, keep your current conversation available across devices;
- understand which channels, campaigns, free tools, and hosted pages lead people to create an account, activate, and buy, using the signup-source record described above;
- process purchases, subscriptions, and credits through our payment processor, and apply the resulting entitlements to your account;
- keep the Service secure and prevent abuse, including rate limiting, enforcing resource limits, and disabling links, vCards, domains, or accounts that violate our Terms of Service; and
- comply with our legal obligations and respond to lawful requests.
Cookies
Whooshly uses essential cookies and browser storage for sign-in, security, theme preferences, your cookie choice, and anonymous AI-assistant conversation history. These are necessary for the features you use to function and cannot be switched off through our consent banner. Choosing New chat clears the assistant conversation from that browser and, when signed in, from your account. The app also keeps the short-lived signup-source record described under Information we collect; it is not used for advertising or cross-site tracking and is removed once it is saved with a new account or after 7 days.
If you select Accept, we use Google Analytics and PostHog to understand site and product use, performance, errors, and feature adoption. These optional analytics stay off until you consent. We do not use advertising cookies or cross-site tracking. You can accept, reject, or change your choice at any time using Cookie settings in the website footer or account menu.
Browser extension
We offer an optional Whooshly browser extension (for example, on the Chrome Web Store). The extension's QR code, UTM builder, and barcode tools run entirely on your device; what you enter into them is not sent to us and never leaves your browser. When you choose to shorten a link, the extension sends the URL you selected to Whooshly to create the short link, and, if you are signed in, saves it to your account – the same processing described above for links you create in the dashboard. To do this it checks whether you are signed in using your Whooshly session cookie on our own domains.
The extension accesses the URL of a page or link only when you explicitly act on it – by clicking the Whooshly toolbar button or a Whooshly right-click menu item – and it does not read your browsing history or the content of the pages you visit. It uses no analytics, tracking, or telemetry: it collects no usage data, sets no identifiers, stores nothing on your device, and makes no background network requests. It requests access only to Whooshly's own domains, and the only thing it ever sends is the URL you choose to shorten.
How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only in these limited ways:
- Cloud and hosting infrastructure. The Service runs entirely on our cloud and edge infrastructure provider, which hosts our compute, database, cache, analytics, and queues. Because the Service runs on this infrastructure, your data is processed there on our behalf.
- Payment processing. Our payment processor acts as the merchant of record. To enable checkout, we send it your email and an internal account identifier along with the product you selected; it returns billing and subscription status so we can apply your entitlements. Your card details go to it directly and never to us.
- Google sign-in. If, and only if, you choose to sign in with Google, you authenticate with Google and we exchange standard sign-in information with it.
- Email delivery. Our email delivery providers send account emails and event emails on our behalf. They receive the recipient's email address and the message.
- Event organizers and their door staff. If you register for or buy a ticket to an event, your registration and ticket details, and whether you have been checked in, are available to that event's organizer. Door staff the organizer gives a check-in link can see guests' names, a partly hidden email address, ticket or party details, and check-in status for that event only.
- Ticket payments. For paid tickets, we exchange order details with Stripe on the organizer's Stripe account, such as the ticket, quantity, amount, and the email address you give at checkout. Stripe processes the payment as described in its own privacy policy.
- QR scanning library. Door check-in pages can load an open-source QR scanning library from the jsDelivr content delivery network into the staff member's browser. As with any website request, jsDelivr receives that browser's IP address.
- AI processing. When you ask the AI assistant a question, we send that question and a limited set of relevant Whooshly source material through our AI gateway to the model provider so it can produce an answer. We do not give the assistant access to your Whooshly account data or tools.
- Legal and safety. We may disclose information if required by law, or where we believe in good faith that disclosure is necessary to comply with legal process, enforce our terms, or protect the rights, safety, or property of our users, the public, or us.
- Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy.
Data retention
We keep your account information and the content you create for as long as your account is active. Signed-in AI-assistant history is kept until you choose New chat or delete your account; anonymous history stays in that browser until you choose New chat or clear its site data. When you delete an item, it is removed; when you delete your account, your associated data, including your sessions, sign-in identities, links, vCards, QR configurations, UTM templates, custom domains, assistant history, credit ledger, and analytics rows, is removed along with it.
For analytics, the dashboard on the Core plan shows roughly the most recent 120 days of activity, and the Business plan roughly the most recent year. An active Pro subscription shows your full retained history. Exact per-day click and scan totals are kept while the related link and account exist and are removed when you delete the link or your account.
Event registrations, ticket admissions, and check-in times are kept for the organizer while the event page exists, and are removed when the organizer clears them or deletes the event. Records of paid ticket orders may be kept for as long as needed to handle refunds and disputes and to meet our legal and accounting obligations. Door-staff check-in links stop working when the organizer revokes them or shortly after the event ends.
You can delete your account and its data yourself at any time under Settings → Delete account, or ask us to at the address below. An active Pro subscription has to be cancelled first, and we keep paid ticket order records for refunds and accounting, so if your account has those we will handle the deletion with you by email.
Data security
We take reasonable measures to protect your information. Account passwords and Pro link passwords are stored only as cryptographic hashes, never in plaintext. Data is transmitted over encrypted connections (HTTPS), and access to systems is controlled. Billing and credit entitlements are written only from signature-verified messages from our payment processor. Ticket links and door-staff check-in links are stored only as hashes; check-in links are limited to one event, expire after it ends, and can be revoked at any time. No method of transmission or storage is completely secure, so while we work to protect your information, we cannot guarantee absolute security.
Your rights and choices
You can access and update much of your account information directly in the dashboard. You may also ask us to access, correct, delete, or provide a portable copy of your personal information, or to object to certain processing, by emailing us at legal@whooshly.co. We will respond consistent with applicable law.
If you registered for or bought a ticket to an event, its organizer controls that information, so please contact them first, usually by replying to your confirmation email. If you contact us instead, we will pass your request to the organizer or help as the law requires.
If you are in the European Economic Area or the United Kingdom, you have rights under the GDPR, including the rights to access, correct, delete, restrict, object to, and port your personal data, to withdraw consent at any time, and to lodge a complaint with your local data protection authority. We aim to respond within one month of receiving a request; we may need to verify your identity first. The legal bases we rely on are listed under Legal bases (GDPR) below.
If you are a California resident, you have rights under California privacy law, including the rights to know, access, delete, and correct your personal information, and to not be discriminated against for exercising those rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Our role: controller and processor
For your account, billing, security, and optional analytics, KMF Ventures is the controller. For personal information that an account holder puts into their own content, such as the people on a vCard, the leads a landing page collects, and the guests registered for an event, the account holder or event organizer decides why and how it is used and is the controller, and we process it on their behalf as a service provider. For paid tickets, the organizer is the seller of record through Stripe.
Legal bases (GDPR)
If you are in the EEA or the United Kingdom, we rely on these legal bases:
- Contract: creating and running your account, links, pages, events, and purchases.
- Legitimate interests: securing the Service, preventing abuse, rate limiting, fixing errors, measuring how the free tools and pages lead to signups (through the short-lived signup-source record), and answering support questions. You can object to processing based on legitimate interests by contacting us.
- Consent: optional analytics (Google Analytics and PostHog), which stay off until you accept, and Google sign-in if you choose it. You can withdraw consent at any time through Cookie settings.
- Legal obligation: tax, accounting, and responding to lawful requests.
Subprocessors
We use a small set of vendors to run the Service, and each acts on our instructions under a data processing agreement: cloud, edge, database, and queue infrastructure; email delivery; payment and billing processing (Polar, and Stripe for event tickets); optional analytics (Google Analytics and PostHog, only after consent); and an AI gateway for the public support assistant, which is configured for zero data retention and no prompt training. You can request the current list of subprocessors at legal@whooshly.co.
International data transfers
KMF Ventures is based in the United States. Accounts created from the EU, EEA, United Kingdom, or Switzerland keep their core account data (the account, links, pages, events, and their stored records) in a database located in the EU. Other parts of the Service, including caching, queues, click and scan analytics, file storage, email delivery, optional analytics, and the payment processors, run on global or United States infrastructure, so your information may be processed in the United States and other countries.
Where personal data is transferred from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, such as the Standard Contractual Clauses (and the UK Addendum to them) in our vendors' data processing agreements. You can request information about these safeguards at legal@whooshly.co.
Children
The Service is not directed to, and may not be used by, anyone under the age of 16. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has provided us with personal information, please contact us so we can remove it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the Last updated date at the top of this page and, where we can, tell account holders by email.
Contact
For any privacy or data questions, or to exercise your rights, contact us at legal@whooshly.co. This Privacy Policy works together with our Terms of Service.