Data collected
Whobam forms may collect names, email addresses, phone numbers, location, service details, ratings, case summaries, nomination evidence and consent timestamps. A one-way request fingerprint may be stored for anti-spam and rate-limiting controls; the plugin does not intentionally save a raw IP address in Whobam content records.
Survey data and anonymity modes
Survey Studio stores survey definitions, hashed access-token records, submitted answers, timestamps, retention dates and a restricted audit ledger. Survey creators receive questionnaire exports but never receive Whobam anti-abuse fingerprints, browser hashes or internal incident-audit records.
Strict-anonymous mode does not require a respondent account and blocks dedicated email and phone questions. It does not intentionally collect a name, email address, phone number or raw IP through the survey system. A free-text answer, a personally assigned token or a combination of unusual facts can still identify someone, so the survey design and token-distribution method must uphold the promise.
Each published survey carries its own notice. That notice should identify the actual controller, purpose, recipients, lawful basis where required, retention period, anonymity boundary and route for privacy enquiries. Whobam does not infer those facts for a survey creator.
What may become public
Approved artisan profiles, approved review text, shortened reviewer names, published advice and published recognition entries may appear publicly. Reviewer emails, private job references, support requests, nominator contact details, survey security records and internal notes are not rendered publicly.
Every public directory, review or nomination submission enters a moderation or editorial queue. Submission does not guarantee publication.
Retention and lawful holds
Support requests marked Closed are configured for automatic removal after 365 days. Survey creators set a response-retention period between 30 and 3,650 days; expired, non-held survey records are removed by the scheduled cleanup process. Short-lived survey security fingerprints are cleared separately.
An authorised administrator may place a documented hold on a survey response where necessary for safeguarding, a dispute, a legal claim or a regulatory obligation. Held records are excluded from automatic deletion until the hold is reviewed and removed.
Access and erasure
The plugin registers with WordPress personal-data export and erasure tools. Administrators can search supported records by email, export matching information and erase or anonymise eligible records. A response under a documented hold is reported for administrator review rather than silently erased.
Privacy enquiries can be routed to domainprivacypulse@gmail.com. The operating organisation should replace this with its approved privacy contact where different.
Security boundaries
Private queues and the incident ledger are restricted by WordPress capabilities. Forms use WordPress nonces, validation, honeypots and basic rate limiting. Access tokens are stored as keyed hashes; plaintext tokens appear only in the one-time generation export.
These controls do not replace correctly configured HTTPS, secure hosting, least-privilege administrator access, updates, backups, monitoring, processor agreements and an organisational incident-response process. Do not submit passwords, banking credentials or more sensitive material than the stated purpose requires.