Legal
Privacy Policy
Last updated: 5 July 2026
This Privacy Policy describes how WhenTap ("we", "us", "our") collects, uses, and protects your personal data when you use our Webflow Marketplace App ("Service").
1. Who we are
WhenTap is native scheduling and booking software for Webflow sites. We are the controller for the account, usage, and billing data we collect about you as a customer. Where we process the personal data of your own end customers (the people who book with you), we act as your processor under the Data Processing Agreement.
WhenTap is operated from the Netherlands by WhenTap, registered with the Dutch Chamber of Commerce (KvK) under number 97282812. For any legal or data-protection matter, reach us through our support form.
2. What we collect
| Category | Examples | Lawful basis (GDPR) |
|---|---|---|
| Account data | Your email, Webflow user ID | Contract performance |
| Site data | Webflow site IDs, the CMS content and fields you map, service and staff records | Contract performance |
| Booking data | Names, emails, phone numbers, timezones and appointment details of the people who book with you | Contract performance (as your processor) |
| Usage data | Feature usage, API call counts | Legitimate interest (analytics, abuse prevention) |
| Billing data | Stripe customer ID, plan, payment method (held by Stripe, not us) | Contract performance |
| Support data | Messages and attachments you send us | Contract performance |
| Technical data | IP address, browser user-agent, session timestamps | Legitimate interest (security) |
3. How we use it
- To provide the Service: compute availability, sync your Webflow CMS, render your dashboard, and serve the booking widget on your site
- To bill you and handle subscription payments, via Stripe
- To send transactional email (booking confirmations, reminders, billing notices, security alerts)
- To respond to your support requests
- To improve the Service using aggregate, anonymized analytics
- To comply with legal obligations
We do not sell your data. We do not use your data for advertising. We do not use your data, or your end customers' data, to train AI or machine-learning models.
4. Sub-processors
We use the following third parties to operate the Service. Each is bound by a data processing agreement.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server and database hosting | EU (Germany / Finland) |
| Webflow, Inc. | The platform we integrate with; source of the CMS content and OAuth we process on your behalf | US (EU SCCs) |
| Google LLC | Google Calendar sync (when a staff member connects Google) and web font delivery (Google Fonts) | US (EU SCCs) |
| Microsoft Corporation | Outlook / Microsoft 365 calendar sync via Microsoft Graph (when connected) | US / EU (EU SCCs) |
| Stripe Payments Europe, Ltd. | Subscription billing, and booking payments routed to your own connected account | EU (Ireland) / US |
| Resend, Inc. | Transactional email delivery | US (EU SCCs) |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | US (EU SCCs) |
We will notify you of any intended change to this list, giving you the opportunity to object.
5. Data retention
- Account and site data: retained while your subscription is active, and deleted within 30 days of account deletion.
- Booking data: held on your behalf while your account is active; you can delete it, and it is removed when you delete your account.
- Billing data: retained as required by tax law (invoices for 7 years).
- Support data: retained 2 years for quality and audit purposes.
- Webhook event logs: retained 90 days for debugging and abuse prevention.
6. Your rights (GDPR)
- Access: request a copy of the data we hold about you. Most of it is a one-click export from the panel.
- Rectification: correct inaccurate data.
- Erasure: delete your account and all associated data (one-click from the Account dialog; processed within 30 days).
- Portability: receive your data in machine-readable JSON.
- Objection: object to processing based on legitimate interest.
- Restriction: limit how we process your data.
- Complaint: file a complaint with your local data protection authority (in the Netherlands, the Autoriteit Persoonsgegevens).
To exercise any right you cannot self-serve in the panel, contact us through our support form. We respond within 30 days.
7. International transfers
Where data is transferred outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) or adequacy decisions. See the DPA for specifics.
8. Security
We encrypt stored OAuth tokens with AES-256-GCM. All connections are HTTPS-only. Access to production systems is restricted to authorized personnel via SSH keys and multi-factor authentication. Vulnerability reports can be sent via the contact in our security.txt or through the support form.
9. Google and Microsoft user data
When you connect a Google account to a staff member, WhenTap requests read access to that person's calendar busy times and the ability to manage the events it creates. We use this access only to:
- read the busy times of existing calendar events, so the booking widget never offers a slot when that person is already busy; and
- create, update, and delete the calendar events that correspond to WhenTap bookings.
We store only the OAuth access and refresh tokens (encrypted at rest with AES-256-GCM) and the IDs of events we create. We do not retain the contents of your calendar, and you can disconnect at any time from the panel, which deletes the stored tokens.
WhenTap's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell or transfer Google user data, we do not use it for advertising, and we do not use it to develop, improve, or train generalized AI or ML models. The same access model applies to Microsoft Outlook calendars connected via Microsoft Graph.
10. Cookies and tracking
The app panel uses one essential cookie to keep you signed in. Our pages load Geist from Google Fonts, which means your browser makes a request to Google to fetch the font files. We do not use advertising or cross-site tracking cookies.
11. Children
The Service is not directed at children under 16. We do not knowingly collect data from children.
12. Changes
Material changes to this policy will be communicated by email at least 30 days in advance.
13. Contact
For any privacy question or data request, contact us through our support form.