Privacy Policy

Last updated: August 2026

What we collect

When you create an account, we collect your name and email address through our authentication provider, Clerk. If your organization is onboarded as a customer, we also store basic company details: company name, a primary contact name, email, and phone number.

When you use the platform to run phishing simulations, your administrators upload an employee directory (names, emails, and departments) so campaigns can be sent and results tracked. This data belongs to your organization, and we process it only to operate the platform on your behalf.

What we do not do

  • We do not sell your data, your employees' data, or your company's data to anyone.
  • We do not use your data to train external AI models or share it with advertisers.
  • We do not access your organization's data unless needed to provide support you requested.
  • One customer's data is never visible to another customer. Each company's workspace is isolated.

Simulation and tracking data

When a simulated phishing email is opened or clicked, we record the timestamp, a coarse device and browser type, and an IP address, so your organization can measure and improve its security awareness. This data is used only for the reporting and analytics features inside your own dashboard, and only your organization's administrators can see it.

Who else touches this data

A small number of trusted service providers help us run the platform:

  • Clerk, for authentication and account sign-in.
  • Your chosen email provider (our shared gateway, or your own SMTP/SendGrid credentials if configured), to send simulation emails.
  • Our database host, to store your account and campaign data securely.

None of these providers are permitted to use your data for their own purposes.

Data retention and deletion

We keep your data for as long as your account is active. If you close your account or ask us to delete your organization's data, we will remove it, including employee records, campaign history, and audit logs, within a reasonable timeframe.

Security

All traffic to and from the platform is encrypted with HTTPS. Access to your organization's data is restricted by role, and administrative actions are recorded in an audit log that your own admins can review.

Contact us

If you have questions about this policy or want to request a copy or deletion of your data, email us at info@wcspl.net or support@wcspl.net.