Overview

Last Updated: September 28, 2026

Whim provides flexible access to products from the brands our customers love. Customers and partners trust us with their information to make that possible, and we take the responsibility of protecting it seriously.

This page outlines how we approach security at Whim and how to report a potential security issue to our team.

Data Protection

We encrypt customer data in transit and at rest using industry-standard encryption. We collect only the information we need to provide our services, and we retain it only as long as necessary for the purposes described in our Privacy Policy.

Card details are entered into secure fields provided by PCI DSS–compliant payment partners and are tokenized before they reach Whim. Whim does not store full payment card numbers on its own systems. Identity verification is performed through a dedicated, secure identity-verification partner.

Infrastructure Security

Whim runs on established cloud infrastructure providers that maintain their own independent security certifications. We monitor our systems for availability and suspicious activity, and we keep the software we depend on up to date.

Access Control

Access to production systems and customer data is limited to authorized personnel who need it to do their jobs. Access is granted on a least-privilege basis and removed promptly when it is no longer needed.

Secure Development

Security is part of how we build Whim. Code changes are reviewed before they are deployed.

Vendor Management

We evaluate the service providers that help us operate Whim and expect them to protect any information they handle on our behalf.

Incident Response

We maintain a process for investigating and responding to security incidents. If an incident affects your information, we will notify you as required by applicable law.

Compliance

Whim is currently pursuing SOC 2 compliance. We will update this page as our compliance program progresses.

Report a Vulnerability

If you believe you have found a security vulnerability in any Whim website, application, or service, please let us know. We review every report and appreciate the work of researchers who help keep Whim and our customers safe.

To help us investigate, please include a description of the issue, the steps needed to reproduce it, and any relevant URLs or screenshots. When researching and reporting, we ask that you:

  • Give us reasonable time to investigate and address the issue before sharing it publicly

  • Avoid accessing, modifying, or deleting data that does not belong to you

  • Avoid actions that could degrade or interrupt our services for other users

Email reports to security@whim.com. For privacy questions or requests, see our Privacy Policy.

Subscribe to news