Privacy policy
Last updated: September 8, 2026
The English version of this policy governs. Translations are provided as a courtesy.
This policy describes what data Whilehaus processes, what we use it for and what rights you have over it.
It covers two things: the whilehaus.com site, and the Whilehaus account together with the Google integration shared by our products. Each product (the client Portal, Markery and Whallet) also has its own detailed policy on its domain, which prevails over this one on anything specific to that product.
Who we are
Whilehaus is the business name under which Martin Bonafede trades, Argentine tax ID (CUIT) 20-33215496-7, registered under the simplified tax regime (monotributo), domiciled at Av. Rivadavia 5785, floor 15, apartment 1, City of Buenos Aires (postcode 1406), Argentina. A studio for business, design and systems.
For any question about this policy or your data, write to info@whilehaus.com.
What data we collect on this site
Data you give us: if you request a callback, we store your phone number, your name (if you leave it) and your country. If you use the live chat, we store the messages of that conversation and, if you leave it, your email to follow up. If you write to us by email or WhatsApp, we receive whatever you send through those channels.
Usage data: visit metrics (page views, approximate country, device type) through the analytics tools described below. We do not use this data to identify you.
What we use it for
To reply to you and continue the conversation you started, to understand how the site is used and improve it, and for nothing else. We do not sell your data or use it for targeted advertising.
Google integration: your account, your Google Drive and your YouTube channel
Whilehaus products integrate with Google APIs for three things: signing in with your Google account, storing files in Google Drive when you enable it, and publishing to your YouTube channel when you enable it. All three use a single Google application registered under the name Whilehaus, one application for the whole studio, which is the one you see on the consent screen.
We request four permissions and no more. openid and userinfo.email: to identify the account and obtain your email address, solely to establish the session or to show you in the interface which account is connected. drive.file: access limited exclusively to the files and folders the application itself creates, or that you deliberately open with it. youtube: to publish to the channel you connect, and only if you turn that feature on.
drive.file does NOT give us access to the rest of your Google Drive. We cannot read, list, modify or delete files or folders the application did not create. Your personal Drive, your documents and anything that does not go through the app are outside our technical reach, not merely outside our commitment.
The https://www.googleapis.com/auth/youtube permission is requested only when you connect your channel in order to publish from a Whilehaus product. It allows us to upload the video, set and later update its details (title, description, tags, category, privacy status and scheduled publishing time), set its thumbnail, and read which channel is yours so we can show it to you in the interface. We do not request a narrower permission because a narrower one is not enough: youtube.upload on its own uploads the file, but it cannot update the details afterwards or read which channel the publication is going to.
Publishing to YouTube from a Whilehaus product means using YouTube API Services. The YouTube Terms of Service, at https://www.youtube.com/t/terms, therefore apply, together with the Google Privacy Policy, at https://policies.google.com/privacy, which describes how Google handles your account data.
From your channel we store the minimum the connection needs and the minimum we show you: the channel id, its title, its public handle, its avatar, the email address of the account that connected it, and the refresh token, encrypted. Tokens are kept for as long as your consent lasts. The channel data that comes from the API (id, title, handle and avatar) is kept for no more than thirty calendar days from the moment it was obtained, and is fetched again from the API if it is still needed. All of it is deleted when you disconnect the channel, and if you ask us to delete it we do so within thirty days.
You decide the video and its details: the file, the title, the description, the thumbnail, the privacy status and the publishing moment all come from what you approved inside the product. Nothing is uploaded or published to your channel without your express approval of that particular piece.
Whilehaus’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Specifically, with respect to data obtained from Google APIs: it is used exclusively to provide and improve the user-facing features of the product; it is not transferred to third parties, except as strictly necessary to provide those features, where required by law or a competent authority, or where you give express consent; it is not used for advertising purposes, nor disclosed to advertising platforms, data brokers, information resellers or market intelligence providers; it is not read by humans, unless you expressly consent to a specific support operation, it is necessary for security purposes (including the investigation of abuse or vulnerabilities), or it is required by law; and it is not used to train generalised artificial intelligence models.
Credentials issued by Google (access and refresh tokens) are stored encrypted with AES-256-GCM and are used solely to operate the application’s folder and, where you enabled it, to publish to your channel, always within the connected account.
Because the Google application is a single one for all of Whilehaus, in your Google account permissions screen you will see one entry named Whilehaus. Revoking it there cuts off access for all our products at once. To revoke access for one product only, do it from that product: its storage settings for Drive, its connections settings for the YouTube channel.
You can revoke access at any time, from the product itself or from your Google account permissions screen, at https://myaccount.google.com/permissions or at https://security.google.com/settings/security/permissions. Revoking does not delete files already in your Google Drive, nor videos already published to your YouTube channel: they remain yours and under your exclusive control, and videos are edited or deleted from YouTube itself.
Analytics and cookies
Cloudflare Web Analytics: measures visits without cookies or identifiers. Always on.
Google Analytics 4: uses cookies to measure site usage. If you visit from the European Union or the European Economic Area, GA4 does not load until you accept it in the cookie notice; you can reject it and the site works the same. Your choice is stored in your browser.
Language cookie (wh_lang): stores the language you picked for the site. A preference, not a tracker.
Whilehaus products use their own cookies, all technically necessary (session, language, interface preferences). The detail is in each product’s policy.
Advertising
This site does not show ads. Some Whilehaus products show ads on their free plans; that happens on each product’s domain and is governed by that product’s privacy policy. This site includes an AdSense verification tag that sets no cookies and loads no scripts.
We never use data obtained from Google APIs, or the content you upload to our products, to target advertising.
Who we share data with
With the providers that run the site: Vercel (hosting), Supabase (live chat infrastructure), Google (analytics, under the conditions of the previous section), Cloudflare (cookieless analytics) and Resend (email delivery). Each processes data on our behalf, to provide us the service.
With Google, when you publish to your channel from a Whilehaus product: the video and its details are sent to YouTube on your instruction, and from that moment they live on your channel, under your own terms with that platform.
The providers that run each product are listed in that product’s policy.
We do not sell personal data to third parties.
The products and their policies
Client Portal, at app.whilehaus.net: terms at app.whilehaus.net/terms and privacy at app.whilehaus.net/privacy.
Markery, at markery.whilehaus.net: terms at markery.whilehaus.net/terms and privacy at markery.whilehaus.net/privacy.
Whallet, at wallet.whilehaus.net: terms at wallet.whilehaus.net/terms and privacy at wallet.whilehaus.net/privacy.
Those policies describe in detail what data each product processes, with which providers, where it is hosted and for how long. This policy does not replace them.
How long we keep it
Contact data is kept while the conversation or business relationship remains open. You can ask us to delete it at any time.
YouTube channel data obtained from the API (channel id, title, handle, avatar) is kept for no more than thirty calendar days. Tokens issued by Google are kept for as long as your consent lasts. All of it is deleted when you disconnect the channel, and also on your request, within thirty days.
Retention periods within each product are set out in that product’s policy.
Your rights
You can request access, correction or deletion of your data by writing to info@whilehaus.com.
If you are in Argentina, you are covered by Law 25,326 on Personal Data Protection. The data subject is entitled to exercise the right of access to their data free of charge at intervals of no less than six months, unless a legitimate interest to the contrary is established, pursuant to section 14, subsection 3 of Law 25,326. The Agency for Access to Public Information, the supervisory body under Law 25,326, has the power to hear complaints and claims brought by persons whose rights are affected by non-compliance with the rules in force on personal data protection.
If you are in the European Union, the European Economic Area or the United Kingdom, you additionally hold the rights conferred by the GDPR and equivalent United Kingdom legislation, including the right to lodge a complaint with the supervisory authority of your jurisdiction.
Changes to this policy
We may update this policy when the site, the products or the tools they use change. The current version always lives on this page, with its update date.