Privacy Policy

Effective: July 23, 2026

Webie, Inc. ("Webie") operates webie.app, Webie mobile apps, and NFC hardware (cards, wristbands, rings). This policy explains how we handle your data.

1. What We Collect

Account info you provide (name, email, phone, job title, company, social links, card content). Imported contacts are processed on-device with your consent. Payments are handled by Stripe—we never store full card numbers. We automatically collect usage data, device info, NFC tap logs (timestamp, city-level location if enabled), and cookies. If you use OAuth (Google/Apple), we receive your name, email, and photo.

Approximate location. So that members can find each other, we work out a rough location from your IP address and show it on the member map. We never read your device GPS and never ask for location permission. Before storing the coordinate we shift it by up to roughly 15 kilometres, so the point on the map is never where you actually are—only the general area. It refreshes at most once a day, which means it follows you if you travel or relocate. You can remove yourself from the map at any time in your privacy settings; we then stop showing you to anyone.

2. How We Use It

To operate the Services, process orders, enable networking features (sharing, groups, tags, the member map), track referrals, send service updates, improve the product, and prevent fraud. Marketing emails require consent and include unsubscribe.

3. Who We Share With

Your card content is public to anyone who views it. We share data with service providers (Vercel, Supabase, Stripe, Cloudflare) bound by contract. Team Plan admins can access team card content and analytics. We disclose data when legally required or in a business transfer (with notice). We do not sell your personal information.

4. Retention & Deletion

Data is kept while your account is active. After deletion, personal data is removed within 30 days. Aggregated analytics are retained indefinitely.

5. Your Rights

You can access, update, or delete your account anytime. California (CCPA) and EEA/UK (GDPR) residents have additional rights. Contact support@webie.app.

6. Security

We use TLS encryption, encryption at rest, and role-based access controls. No system is 100% secure.

7. Team Plan & NFC

Under a Team Plan, your organization is the data controller; Webie is the processor. DPA available on request. NFC hardware stores only a URL—no personal data on the chip.

8. Google User Data & Limited Use

When you connect your Gmail account, Webie requests only the gmail.send scope — the minimum permission required to send follow-up emails on your behalf. We never read, search, modify, label, or delete any messages in your Gmail account.

  • Google user data is used solely to send emails you explicitly initiate in Webie.
  • We do not use Google user data for advertising or marketing targeting.
  • We do not sell, transfer, or share Google user data with third parties.
  • We do not use Google user data to train AI or machine learning models.
  • OAuth tokens are AES-256 encrypted at rest; only the minimum necessary access is stored.
  • You can revoke Gmail access at any time from Settings → Integrations → Gmail, or from your Google Account → Security → Third-party apps.

Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

9. Changes & Contact

We may update this policy and will post changes with a new date. Continued use means acceptance. The Services are not for anyone under 13 (16 in EEA).

Webie, Inc. — support@webie.app — Winter Garden, Orlando, FL

← Back to home