Scope and our role
This Privacy Policy explains how White IO, Inc., a Florida corporation (“White IO,” “we,” “us,” or “our”), handles personal information through whiteio.io, the White IO territory-management platform, and related support and integration services.
White IO acts as a controller of account, billing, website, and support information used to operate our business. For contacts, leads, notes, routes, calls, visits, appointments, imports, and similar information submitted by a customer organization (“Customer Data”), White IO generally processes that information on the organization’s behalf. The organization determines why and how its Customer Data is used.
Information we collect
Depending on how the Services are used, we collect:
- Account and organization information: name, email address, authentication identifiers, organization name, membership, role, invitations, and account settings.
- Customer Data: company and contact names, addresses, email addresses, phone numbers, notes, statuses, imported spreadsheet fields, calls, call outcomes, visits, routes, route stops, follow-ups, appointments, and related activity.
- Calendar information: connected provider identity, supported event identifiers, appointment times, titles, locations, descriptions, synchronization status, and encrypted OAuth credentials.
- Billing information: plan, seat quantity, subscription status, billing period, Stripe customer, subscription, price, invoice, and event identifiers. Stripe—not White IO—collects and processes full payment-card details.
- Support information: support category, message, account email, organization identifier, delivery status, and related communications.
- Technical and security information: session information, IP address and request metadata available to our hosting and authentication providers, device/browser information, error information, audit events, and security-related activity.
- Location-related information: addresses and map coordinates associated with Customer Data, search or route inputs, and device location only when a user grants browser or device permission for a location-based feature.
Please do not submit Social Security numbers, full payment-card details, medical records, authentication secrets, or other highly sensitive information that White IO is not designed to process.
Sources of information
We receive information directly from users and organization administrators; from files users choose to import; from actions performed in the Services; from connected Google and Microsoft accounts; from Stripe and Resend; from authentication providers; and automatically from the infrastructure used to deliver and secure the Services.
How we use information
We use personal information to:
- create accounts, verify identity, maintain sessions, and provision organization access;
- provide contacts, maps, routes, calls, visits, scheduling, imports, reports, and collaboration features;
- connect and synchronize calendar events at the user’s direction;
- process subscriptions, maintain seat limits, and respond to payment events;
- send transactional invitations, authentication messages, and support communications;
- secure the Services, enforce organization boundaries, prevent fraud and abuse, investigate incidents, and maintain audit records;
- diagnose errors, maintain reliability, provide support, and improve existing user-facing functionality;
- comply with law, enforce agreements, and protect White IO, customers, users, and others.
White IO does not sell Customer Data or use Customer Data for third-party behavioral advertising.
Google user data
Google sign-in and Google Calendar are separate connections. Google sign-in provides supported identity information, such as name and email address, for authentication. If a user separately connects Google Calendar, White IO requests the limited Calendar Events permission needed to create, update, cancel, and synchronize supported appointment events.
White IO stores the connected Google account identity, encrypted access and refresh tokens, token expiration, synchronization tokens, provider event identifiers, event links, timestamps, and synchronization status. Calendar event information is used only to provide and maintain the calendar features the user chooses.
Google user data is shared only with infrastructure providers acting for White IO as necessary to operate and secure the feature, when the user directs an integration, when required by law, or as part of a corporate transaction subject to appropriate protections. White IO does not use Google Calendar data for advertising or sell it.
A user may disconnect Google Calendar through account settings. Disconnecting revokes or removes the stored connection credentials and stops future synchronization. Account deletion removes the account and associated organization data subject to the limited retention described below.
White IO’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Microsoft user data
Microsoft sign-in and Outlook Calendar are separate connections. Microsoft sign-in uses basic identity scopes for authentication. If a user separately connects Outlook Calendar, White IO requests calendar permissions to create, update, cancel, and synchronize supported appointment events.
White IO stores connected-account information, encrypted access and refresh tokens, synchronization state, provider event identifiers, event links, timestamps, and status information. White IO does not request Microsoft Mail or Outlook email-reading permissions. A user may disconnect Outlook Calendar through account settings to stop future synchronization and remove the stored connection.
Service providers and disclosures
We disclose information only as reasonably necessary for the Services, as directed by a customer or user, or for legal and security purposes. Current provider categories include:
- Supabase: authentication, PostgreSQL database, authorization, and related backend services.
- Vercel: application hosting, network delivery, and operational infrastructure.
- Google: Maps, geocoding, routing, Google authentication, and optional Google Calendar integration.
- Microsoft: Microsoft authentication and optional Outlook Calendar integration.
- Stripe: hosted checkout, payment processing, subscription management, invoices, and billing portal.
- Resend: transactional support and invitation email delivery.
- Navigation applications: route or destination information when a user chooses to launch Google Maps, Waze, Apple Maps, or another supported navigation provider.
Information may also be disclosed to professional advisers under confidentiality duties; to authorities when legally required; to protect rights, safety, and service integrity; or in connection with a merger, financing, acquisition, reorganization, or sale of assets. We do not disclose Customer Data to unrelated third parties for their own marketing.
Organization access and customer responsibilities
Customer Data is visible to authorized members of the customer organization according to their roles. Organization owners and administrators control invitations, permissions, billing, and certain integrations. If an organization has provided your personal information to White IO, direct requests about that Customer Data to the organization first; we will assist the organization as appropriate.
Cookies and similar technologies
White IO uses cookies and comparable browser storage that are necessary for authentication, secure sessions, user preferences, and core functionality. Third-party map, authentication, calendar, and payment pages may use their own technologies under their privacy policies. White IO will update this Policy and provide any legally required choices before introducing non-essential advertising or cross-site tracking technologies.
Retention and deletion
We retain account information and Customer Data while the account or organization is active and as needed to provide the Services. Retention also depends on customer instructions, the nature of the record, security and audit needs, billing and tax obligations, dispute preservation, and applicable law.
Users may disconnect calendar integrations without deleting their White IO account. Account deletion is available through account settings and is designed to permanently delete the account, personal organization, workspace, and associated operational data, subject to authorization safeguards.
Limited billing, transaction, fraud-prevention, audit, support, legal, and backup records may remain for a reasonable period when required for legitimate business or legal purposes. Backups are isolated from ordinary use and expire through applicable provider retention cycles. When information is no longer required, we delete, anonymize, or securely isolate it as appropriate.
Security and incident response
White IO uses safeguards designed for the nature of the information processed, including encrypted HTTPS transport, protected authentication sessions, server-side authorization, organization-scoped database controls, encrypted calendar credentials, restricted privileged operations, webhook verification, and audit logging.
No service can guarantee absolute security. Users should protect their devices and credentials, use unique passwords, limit organization access, and promptly report suspected misuse. If a security incident affects personal information, White IO will investigate and provide notifications when required by applicable law.
Privacy rights and choices
Depending on where you live and whether a privacy law applies, you may have rights to request access, correction, deletion, portability, or restriction of certain personal information, or to object to certain processing. You may also disconnect integrations, update account information, and delete an eligible account through the Services.
Submit a privacy request to support@whiteio.io. We may need to verify your identity and authority before completing a request. Authorized agents may be required to provide proof of authority. We will not discriminate against a person for exercising an applicable privacy right.
White IO does not currently sell personal information or share it for cross-context behavioral advertising. If that practice changes, we will update this Policy and provide legally required opt-out methods before the change applies.
International use and children
White IO is operated from the United States, and information may be processed in the United States and other locations where our providers operate. Those locations may have different data-protection laws than your location. Where legally required, appropriate transfer safeguards will be used.
The Services are intended for business users and are not directed to children under 18. We do not knowingly solicit personal information directly from children. Contact us if you believe a child has created an account.
Changes and contact
We may update this Policy as the Services, providers, or legal requirements change. Material changes will be communicated through the Services, by email, or by another reasonable method and will apply from the stated effective date.
For privacy questions, requests, or security reports, contact White IO, Inc. at support@whiteio.io. We intentionally use an electronic business contact and do not publish a private residential address on the Services.