Privacy Policy

    Last updated: June 20, 2026

    This Privacy Policy explains how Webistry collects, uses, shares, and protects information when you visit our website, complete checkout, submit intake forms, upload files, communicate with us, or interact with our outreach and business systems.

    1. Information We Collect

    We may collect:

    • Contact information, including name, email, phone number, business name, role, and communication details.
    • Business information, including service category, city, state, service area, website, links, hours, testimonials, brand preferences, domain preferences, and project notes.
    • Intake and uploaded files, including logos, photos, screenshots, documents, file names, file paths, file types, and related metadata.
    • Payment and order information, including Stripe Checkout session ID, payment status, amount, selected plan, invoice or receipt links, customer email, and order records.
    • Website and analytics data, including pages visited, referrer, UTM parameters, session ID, device type, browser, user agent, approximate location from IP, timestamps, and conversion events.
    • Communications, including emails, SMS messages, replies, opt-out requests, support messages, delivery status, provider message IDs, and outreach logs.
    • Public business lead data, including publicly available business listing information, contact details, ratings, review counts, website signals, and audit signals.
    • Authentication, admin, error, rate-limit, security, and diagnostic data used to protect and operate the service.

    We do not store your full payment card number.

    2. How We Collect Information

    We collect information when you submit forms, complete checkout, upload files, use the website, communicate with us, interact with emails or SMS, or when we gather publicly available business information for outreach and service delivery.

    3. How We Use Information

    We use information to:

    • provide and deliver Webistry services;
    • process checkout, verify payment, create orders, and send receipts;
    • collect post-payment intake and project assets;
    • build websites, dashboards, automations, and related systems;
    • communicate about projects, support, billing, and updates;
    • send and manage email or SMS outreach where applicable;
    • honor unsubscribe, STOP, and suppression requests;
    • measure website traffic, conversions, and marketing performance;
    • improve our website, offers, designs, and operations;
    • secure the site, prevent abuse, rate-limit requests, and debug errors;
    • comply with legal, tax, accounting, and dispute obligations.

    4. AI-Assisted Processing

    We may use AI-assisted tools to help draft copy, generate ideas, analyze websites, summarize information, write code, or support project work. Information you submit may be included in prompts or processing where needed to provide the service. We do not intentionally submit payment card numbers, government IDs, or unnecessary secrets to AI tools.

    5. Vendors and Service Providers

    We may share information with vendors that help us operate the business, including:

    • Stripe for checkout, payments, invoices, receipts, and payment verification;
    • Supabase for database, authentication, storage, edge functions, logs, and backend processing;
    • Cloudflare for hosting, security, DNS, and site delivery;
    • Brevo for transactional and outreach email;
    • communication providers for outreach, delivery status, and opt-out handling where applicable;
    • Meta Pixel for advertising and conversion measurement;
    • Anthropic or other AI providers for AI-assisted service work;
    • Calendly for scheduling where used;
    • Cloudinary for image delivery and optimization where used;
    • search, scraping, validation, enrichment, analytics, professional advisor, contractor, legal, and accounting providers where needed.

    6. Cookies, Session Storage, and Local Storage

    We use browser storage to keep the checkout and intake flow working, remember session and UTM data, prevent duplicate analytics events, manage authenticated sessions, and support admin tools. Meta Pixel and other third-party tools may use cookies or similar technologies. You can control cookies and tracking through your browser or provider settings, but some features may not work correctly if storage is disabled.

    7. Analytics and Advertising

    We use first-party analytics and Meta Pixel to understand traffic, conversions, and marketing performance. This may include page views, conversion events, session IDs, referrers, UTM parameters, device data, approximate location, and purchase or booking events. We do not use analytics to collect full payment card details.

    8. Email and SMS

    We may send transactional emails about purchases, receipts, onboarding, project updates, and support. We may also send marketing or outreach emails or SMS where permitted. You can unsubscribe from marketing email using the link provided or by contacting us. You can opt out of SMS by replying STOP, UNSUBSCRIBE, CANCEL, END, QUIT, OPTOUT, or REMOVE.

    9. Public Business Outreach

    Webistry may collect and use publicly available business contact information to contact businesses about Webistry services. We honor opt-out requests and maintain suppression or deletion records as needed to avoid future contact.

    10. Uploaded Files

    Uploaded logos, photos, and project files are used to provide services. Files may be stored with Supabase and processed or delivered through image and storage providers. Do not upload files you are not authorized to use or files containing sensitive personal information unless necessary.

    11. Data Retention

    We keep information for as long as reasonably needed to provide services, maintain records, resolve disputes, improve operations, comply with legal, tax, and accounting obligations, and honor opt-outs. Order, payment, invoice, and business records may be retained longer where required. Outreach suppression records may be retained so we do not contact opted-out recipients again. Uploaded files may be retained during the project and support period unless deletion is requested and no legal or business reason requires retention.

    12. Deletion, Access, and Correction

    You may request access, correction, or deletion of personal information by contacting [email protected]. We may need to verify your request. We may decline or limit deletion when retention is required for payment records, legal compliance, dispute defense, security, fraud prevention, or honoring opt-outs.

    13. Security

    We use reasonable technical and organizational safeguards, including server-side payment verification, access controls, storage rules, and rate limits. No system can be guaranteed completely secure.

    14. Do Not Sell

    We do not sell personal information for money. Some analytics or advertising tools may be considered "sharing" under certain privacy laws. Contact us if you want to opt out of non-essential advertising or analytics use where applicable.

    15. Children's Privacy / COPPA

    Webistry is intended for businesses and adults. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Do not submit information about children under 13 through our website, checkout, intake forms, uploads, chat, email, SMS, or project materials. If you believe a child under 13 has provided information to us, contact [email protected] and we will take appropriate steps to delete it unless retention is required by law, security, fraud prevention, or dispute records.

    16. Accessibility Requests

    If you need this Privacy Policy or any Webistry content in an alternative format, contact [email protected].

    17. Changes

    We may update this Privacy Policy from time to time. The posted version applies going forward.

    18. Contact

    Privacy questions or requests: [email protected]