Privacy Policy
Effective September 28, 2026
This policy explains how Whop Inc. ("we", "us") handles information in the apps we run at whop.studio: Supplier Connector, Upsell, the ShipBob, DayOne and Order Desk connectors, and Google Feed (together, the "Apps"). The Apps are installed by businesses ("merchants") that sell on Whop, and they run inside the Whop dashboard.
Who we are
Whop Inc., 300 Kent Ave #401, Brooklyn, NY 11249. Questions or requests: support@whop.com.
For merchant data, the merchant is the controller and we act as its processor. For the account details of the people who install the Apps, we are the controller.
What we collect
- Whop account data: the Whop user and company IDs of whoever opens an App, used to confirm they are an admin of that company.
- Store and order data from Whop: products, plans, prices, images, payments, refunds and order status for the merchant's company.
- Customer shipping data: the buyer's name, shipping address, email and phone as provided on a Whop order, so the order can be fulfilled and tracked.
- Supplier credentials: API keys or tokens the merchant enters to connect a supplier or fulfillment service. These are encrypted before they are stored.
- Fulfillment data: supplier order numbers, carriers and tracking numbers.
- Google data (Google Feed only): when a merchant connects Google, we receive an OAuth token for the Google Merchant API, the list of Merchant Center accounts the merchant can access, and the status of the products we submit, including any issues Google reports. We do not access Gmail, Drive, Contacts or any other Google product.
- Technical logs: request logs such as timestamps, IP address and error details, used to run and secure the service.
How we use it
- Show orders, fulfillment status and tracking in the dashboard.
- Send orders to the supplier the merchant chose, and write tracking back to Whop.
- Show and charge post-purchase upsell offers the merchant set up.
- Suggest which supplier product matches a store product. Only product titles and catalog names are sent for this, never customer data.
- Create, update and remove the merchant's products in their own Google Merchant Center account, and show the merchant which ones Google approved or rejected.
- Keep the service secure, fix bugs and meet legal obligations.
We do not sell personal information, and we do not use it for advertising.
Google user data
Google Feed requests one permission, the Google Merchant API scope (https://www.googleapis.com/auth/content). We use it only to submit the merchant's own Whop products to the Merchant Center account the merchant picks, keep those products up to date, remove them when the merchant asks, and read back their approval status. The OAuth token is encrypted at rest. Google data is never transferred to others except as needed to provide this feature, for security, to comply with law, or as part of a merger or acquisition with the merchant's prior consent. It is never used for advertising or credit decisions, and our staff do not read it unless the merchant asks us to for support, it is needed for security, or the law requires it.
Google Feed's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
Legal bases (EEA and UK)
- Performing our contract with the merchant: running the Apps they installed.
- Legitimate interests: security, fraud prevention and improving reliability.
- Legal obligation: where the law requires us to keep or share data.
- Consent: connecting Google and connecting a supplier, which the merchant can withdraw at any time.
Who we share it with
We share data only with the services needed to run the Apps, each receiving only what its job needs:
- Whop: the platform the Apps run on (orders, products, tracking).
- Vercel: hosting.
- Neon: database hosting.
- Google: Merchant Center, only when the merchant connects it.
- OpenRouter and the AI model providers it routes to: product matching suggestions (product titles only).
- The supplier or fulfillment service the merchant connects, such as CJ Dropshipping, DayOne, ShipBob, Order Desk or ShipGoods: order and shipping details needed to fulfill the order.
We may also disclose data if the law requires it, or as part of a merger or sale of our business.
How long we keep it
We keep data while an App is installed. When a merchant uninstalls an App or asks us to, we delete their data, credentials and tokens within 30 days, except records we must keep by law. Logs are kept for up to 30 days.
Deleting your data and revoking Google access
- Email support@whop.com from the Whop account that installed the App, and we will delete your data.
- Disconnect Google inside Google Feed. That deletes the stored token.
- Revoke access at any time from your Google account at myaccount.google.com/permissions.
Security
Supplier credentials and Google tokens are encrypted at rest. All traffic uses HTTPS, and access to production systems is limited to the people who run the service. No system is perfectly secure, and we will notify affected merchants of a breach as the law requires.
Cookies
The Apps do not set advertising or analytics cookies. Whop may set the cookies needed to sign you in to the dashboard.
Your rights
Depending on where you live, including under the GDPR and the California Consumer Privacy Act, you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to not be discriminated against for using these rights. Buyers of a merchant's store should contact that merchant first, and we will help them respond. You can also complain to your local data protection authority.
International transfers
We and our providers process data in the United States and other countries. Where required, we rely on safeguards such as the EU Standard Contractual Clauses.
Children
The Apps are business tools and are not meant for anyone under 18.
Changes
If we change this policy, we will update the date above. If we change how we use Google data, we will ask for consent again before doing so.