Privacy Policy

Effective July 28, 2026

In short: WhenWhen stores what a scheduling poll needs and deletes it on a schedule. No ads, no trackers, and we do not sell your personal data. Third-party code runs in your browser in two places: the anti-bot check when you create an event, and Paddle's checkout if you buy a paid subscription.

WhenWhen is operated by Red Ninja LLC, a Minnesota limited liability company ("Red Ninja", "we", "us"). This policy explains what data the service at whenwhen.io handles and why.

What we collect

Who can see what

A scheduling poll is a shared page. Anyone with an event's share link sees the event details, every participant's name, and their votes - that is what the link is for, and whoever the organizer shares it with sees them too. If you would rather not be recognizable, you can vote under any name you like. An email address left with a vote is never exposed through any page or API response, and admin and edit links are never revealed to anyone who does not already hold them.

Cookies and your browser

There is no cookie banner because nothing we place in your browser tracks you. We set two cookies, both for sign-in: __Host-ww_session keeps you signed in for 30 days, and __Host-ww_auth_state protects the sign-in handshake and lasts only minutes. Neither is set unless you use sign-in.

Your browser's localStorage keeps the links to events you created and votes you cast, so you can get back to them, and - if you sign in - your email address, so the site can show who is signed in. These stay on your device; our database holds no copy of the email unless you submit it yourself, for example as the reply address on a support request. The anti-bot widget on the create page is Cloudflare's code, and any state it keeps is Cloudflare's, used to tell humans from bots.

Usage statistics

We count usage with aggregate counters recorded on the server. No analytics script runs in your browser, and no identifier is recorded - no account id, token, event id, name, email address, or IP address - so a count can never be tied back to a person. A counted page view records the type of page (never which event), the hostname of the referring site, campaign tags if the link carried them, a country code, and whether a sign-in cookie was attached. The cookie's value is never recorded, only that one was present. A counted action records what kind of thing happened, on which tier, whether the request was anonymous, signed in, or made with an API token, and the campaign tag of the page you came from. Where a count could be specific enough to pick out a single event, we record a range in place of the number. We also count what serving a page of event data costs us: the type of request, how many database rows it read, and how many bytes we sent back. Our host keeps these counters for about three months.

What we do not do

Service providers

These companies process data to run the service, on our instructions:

Independent of us, each under its own privacy policy:

Where data goes

Our providers are in the United States, so using the service moves personal data there. Where EU or UK law applies to a transfer, we rely on recognized safeguards: our providers participate in the EU-US Data Privacy Framework or offer the European Commission's Standard Contractual Clauses, as set out in each provider's own privacy documentation.

Our legal bases

Where the law where you live - the EU and UK among them - requires a legal basis for each use of personal data, ours are these. Event, participant, account, API-token, and support data: providing the service you asked for. Rate limiting, the anti-bot check, and the aggregate usage counters: our legitimate interest in keeping the service working and free of abuse. An email address you choose to leave with a vote: consent, which you can withdraw by asking us to remove it. And we process data where a law requires us to.

How long we keep data

Deleting data

Organizers can delete an event at any time from its admin page, which removes the event, its participants, and their votes from the live database immediately. Deleting your account removes the account record, every session, and every API token immediately, and removes your reply address from your stored support tickets. Events you created are not deleted with the account - other people may be mid-vote - but they stop being linked to you and age out on their normal schedule. Notification emails already sent still exist in our support mailbox.

Your rights

To access, correct, or delete personal data, email support@whenwhen.io. You do not need an account, and we do not ask for identity documents for routine requests - we verify you through what you already hold: an edit link, an admin link, or the email address a record carries. If someone else entered your email address into the service, write to us from that address and we will remove it. Depending on where you live you may have statutory rights to access, correct, delete, or object, and to complain to your local data-protection authority. We honor reasonable requests wherever you live.

Children

The service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.

Changes to this policy

Updates are posted here with a new effective date, and we give notice on the site before a material change. Changes work forward: we will not use data we already collected in a way this policy did not allow when we collected it, unless we ask you first.

Contact

Red Ninja LLC, Minnesota, USA · support@whenwhen.io