WhoopForge

Legal

Privacy Policy

Last updated 6 August 2026.

Who we are

WhoopForge is operated by Whoopmasters India Private Limited ("WhoopForge," "we," "us"). This policy covers the data we collect through this site — browsing the drone catalog, requesting a repair, submitting a build requirement, and the admin-issued access-code login system.

What we collect

  • Account access: your mobile number and an access code we issue you. The code is never stored in plain text — only a one-way hash of it is kept, the same way a password would be.
  • Repair requests: reporter and unit contact details, airframe information, a fault description, and the photos you submit with the request.
  • Build requirements: unit and point-of-contact details, mission parameters, and procurement preferences you choose to share.
  • Basic technical data: what any web server sees — request timestamps, and login attempts (including failed ones), used purely to keep the account system secure.

Why we collect it

To grant access to gated technical specifications and field footage, to act on a repair or build request, and to keep the account system itself secure — that's the whole list. We don't sell data, run advertising, or share it with anyone outside the small team handling your request.

Offline digital twins — how long your data actually lives online

Most sites keep everything you ever send them, forever, in a live database. We do the opposite by design. Once a repair ticket is closed, our team exports a complete copy of it — every field, the full status history, every photo — into an offline archive, and then removes the live copy from our cloud systems entirely. We call this the offline digital twin: a record that still exists, completely intact, but is no longer sitting on an internet-connected server for anyone to reach.

In practice this means your repair history isn't accumulating indefinitely in a live database somewhere — it moves offline once it's no longer active. If you ever need a closed ticket referenced again, we can retrieve it from that archive.

Security

Access codes and admin passwords are hashed, never stored as plain text. Sessions are encrypted and marked HTTP-only so they can't be read by page scripts. Administrator accounts support two-factor authentication, and every sign-in, access-code issuance, revocation, and data deletion is recorded in an internal security log.

Where it's stored

The site runs on Vercel and the database on Turso — both standard cloud infrastructure providers who host the platform, not who use or view your data. Photos and records live in that database until they're archived offline as described above.

Your rights, and auditing how we handle data

You can ask us what data we hold about you, ask for it to be corrected, or ask for it to be deleted. If you represent an organization that needs to review or audit how we manage your data — including our archive/deletion process described above — we welcome that. Reach us at legal@whoopmastersindia.com for any of the above.

Changes to this policy

If this policy changes in a way that affects how we handle your data, we'll update the date at the top of this page.