1. Who we are
WeWidget (“we”, “us”, “our”) provides an embeddable Google Reviews widget service. This policy explains what personal data we collect, how we use it, and your rights.
2. Data we collect
- Account data: name and email address provided at sign-up.
- Google account data: when you connect your Google Business Profile, we store an encrypted OAuth refresh token to fetch your public reviews. We do not store your Google password.
- Review data: publicly visible Google reviews fetched from your Business Profile are cached in our database to serve your widget.
- Payment data: billing is handled by Stripe. We store only a Stripe customer ID — no card numbers are held by us.
- Usage data: basic analytics on widget impressions (page origin only, no visitor PII).
3. How we use your data
- To provide the widget service and sync your Google reviews.
- To process payments and manage your subscription.
- To send transactional emails (account, billing, review sync status).
- To improve the service based on aggregate usage.
4. Third parties
- Google: review data is fetched via the Google Business Profile API under their Terms of Service.
- Stripe: payment processing. Stripe's privacy policy governs card data.
- Supabase: database and authentication hosting.
5. Data retention
Your data is retained while your account is active. You may delete your account at any time by contacting us, which removes your profile, cached reviews, and Google connection. Stripe billing records are retained as required by law.
6. Your rights
Under UK GDPR you have the right to access, correct, or delete your personal data. Contact us at hello@wewidget.app for any data request.