Privacy Policy
Last updated:
1. Scope and our role
This policy explains how Wingifi handles personal information through our website, waitlist, demos, accounts, and business automation services. Contact [email protected] with questions or requests. Our Terms of Service describe the rules for using Wingifi.
For account administration, billing, website operations, and our own communications, Wingifi determines how information is used. When a business uses Wingifi to collect inquiries, exchange customer messages, schedule appointments, or request feedback, we process that customer information on the business's behalf. That business is responsible for its own privacy notices, lawful instructions, and customer relationships. If you contacted one of our business customers, direct requests about its records to that business first; we can help identify the appropriate contact.
2. Information we receive
Account and business information includes your email address, account identifiers, business name, service area, hours, services, pricing information, preferences, and knowledge-base materials you provide. Uploaded logos, images, advertising references, and imported website content may also contain personal information.
Customer workflow information may include names, email addresses, phone numbers, service addresses, inquiry text, conversation history, generated responses, lead stages, qualification summaries, appointment details, survey ratings, written feedback, and requests for follow-up. Businesses decide what information to submit and how their agents operate.
Waitlist submissions include email, trade, phone number, and marketing preference. Demo submissions include name, email, trade, and an example inquiry used to prepare and send a sample response. Support correspondence may include information you choose to share. Please use fictional job details in demos and do not submit passwords, payment card numbers, government identifiers, health records, or other unnecessary sensitive information.
Payment information includes subscription status, customer and transaction identifiers, and billing records supplied by Stripe. Stripe processes payment card details through its checkout; our application does not collect full card numbers. Connected services provide authorization tokens, account identifiers, and the information needed for the permissions you grant.
Technical information can include browser and device details, page and feature events, performance measurements, timestamps, network information used for security, delivery records, and error logs. Hosting and service providers may also process request logs to operate their infrastructure.
3. Why we use information
We use information to create and authenticate accounts, configure business workflows, respond to inquiries, send and receive messages, arrange appointments, generate advertising materials, collect feedback, process payments, provide support, and maintain service reliability. We also use information to prevent abuse, investigate incidents, enforce agreements, comply with legal obligations, and understand and improve the service.
Waitlist contact details support early-access planning and launch updates. Optional marketing follows the preference you provide; entering a phone number on the waitlist does not authorize marketing calls or texts. A demo request authorizes the requested sample email. You may ask support to stop optional communications; essential account, security, and billing messages may still be needed.
4. AI processing and automation
Relevant business knowledge, inquiry details, conversation context, and instructions may be sent to OpenAI to generate replies, summaries, suggestions, or advertising content. Image generation and website import features may also send selected materials to their service providers. Generated content can be inaccurate and should be reviewed by the business using it.
AI-assisted lead qualification and responses support business workflows; they are not intended for decisions about credit, employment, housing, insurance, healthcare, or other legally significant eligibility decisions. Contact the business directly if you need a person to review an automated response. Provider processing and retention depend on the service and applicable provider agreements; do not assume that submitting information to an AI feature means it is never retained.
5. Connected accounts and providers
Depending on enabled features, providers include Supabase for authentication and data storage; Stripe for checkout and subscriptions; OpenAI for AI generation; Resend for email delivery and related delivery events; Firecrawl for website imports; Google and Microsoft for authorized mailbox and calendar features; and Meta for connected advertising functions. Hosting and infrastructure providers also process information needed to deliver the site. These providers receive information relevant to their functions, not an unrestricted right to use your account.
Mailbox connections allow sending through your authorized account, and calendar connections support availability and appointment operations. Advertising connections use the authorized account and assets for enabled advertising features. OAuth tokens are stored to maintain authorized access. Review permissions before connecting and revoke access in the provider's account settings when no longer needed. Revocation stops future authorized access but does not automatically erase records already held in Wingifi.
Third-party sites and services, including public review destinations, have their own terms and privacy policies. Information you choose to post on those sites is subject to their practices.
8. Retention and deletion
Retention depends on the purpose and record type, account activity, customer instructions, security needs, contractual obligations, and legal requirements. Account, lead, conversation, appointment, uploaded content, and billing records do not all share a single deletion deadline. Cancellation of a subscription or disconnection of a provider is not a request to erase all information.
Product telemetry is scheduled for deletion after 90 days. Short-lived hashed network identifiers help limit abuse of the collection endpoint. Other records may be retained while needed for the service, financial recordkeeping, dispute resolution, fraud prevention, or legal holds. Backups and provider-held records may remain until their applicable retention cycles expire. Contact [email protected] to request deletion or information about a particular record category.
9. Your privacy rights and requests
Depending on your location and applicable law, you may have rights to access, correct, delete, or obtain a portable copy of your information; object to or restrict certain processing; withdraw consent; and opt out of a sale, qualifying sharing, or certain profiling. Some laws also provide an appeal right if a request is denied. These rights have exceptions, including records needed for legal obligations or another person's rights.
Email [email protected] with your request and the email associated with your account or inquiry. We may ask for proportionate information to verify identity and authority, including an authorized agent's permission, without asking for your password. We will respond within the time required by applicable law and explain applicable extensions or reasons for denial. Reply to that address to request review of a denial. We will not discriminate against you for exercising applicable privacy rights.
For information controlled by a business using Wingifi, we may refer your request to that business and assist it as appropriate. You may also complain to your local privacy regulator. Where European or UK law applies, processing may rely on performance of a contract, legal obligations, consent, or legitimate interests such as security and service administration, balanced against your rights.
10. International processing and security
Wingifi and its providers may process information in countries other than your own, including the United States. Those countries may have different privacy protections. Where applicable law requires safeguards for an international transfer, those safeguards must apply to the relevant processing arrangement. Contact us to discuss location or transfer requirements before submitting data that has special restrictions.
We use access controls and other technical and organizational measures intended to protect information. No service or transmission method is completely secure. Keep your credentials private, manage authorized users, and promptly report suspected unauthorized access to [email protected]. Do not email passwords or full payment details.
11. Children
Wingifi is a business service for adults and is not directed to children under 18. Do not knowingly submit children's personal information to the service. If you believe a child has provided personal information, contact [email protected] so we can investigate and take appropriate action.
12. Changes and contact
We may update this policy as the service or legal requirements change. The date above identifies this version. For material changes, we will provide additional notice or request consent when required by law. Questions, privacy requests, and requests for an accessible copy can be sent to [email protected]; general support is available at [email protected].
Contact [email protected] for privacy requests or [email protected] for support.
