How It Works Track a Case Sign In Make a Report

Privacy Policy

Last updated: March 2026

What We Collect

Data Type Collected? Details
Report contentYesCategory, description, location, date
Personal nameNeverNot requested or stored
Email (sign-in)OptionalStored as hash, isolated from report content
IP addressNeverNot logged on public pages
CookiesNeverNo cookies on public pages
AnalyticsNeverNo third-party analytics or tracking pixels

Data Retention

Data Retention Legal Basis
Active reportsUntil resolution + 7 yearsSOX, Dodd-Frank, SEC
Closed reports7 years after closureCompliance & legal defense
Email hashUntil deletion requestConsent
MessagesSame as linked reportAudit & compliance
Dashboard access logs12 monthsSecurity

Your Rights

  • Right to erasure: Request deletion of the link between your email and reports at any time.
  • Anonymous content: Reports without personal identification cannot be subject to individual deletion requests.
  • Data export: Data linked to your email can be exported upon request.
  • Breach notification: In case of a data breach, notification within 72 hours per CCPA and GDPR requirements.

Compliance

WhistlePlace is designed to comply with:

Sarbanes-Oxley (SOX)

Whistleblower protections for publicly traded companies

Dodd-Frank Act

SEC Whistleblower Program & financial protections

CCPA

California Consumer Privacy Act compliance

GDPR Ready

Prepared for EU market expansion

Questions about privacy? Contact us at privacy@whistleplace.com