Privacy Policy

Last updated: September 2026

1. Who we are

WeWidget (“we”, “us”, “our”) provides an embeddable Google Reviews widget service. This policy explains what personal data we collect, how we use it, and your rights.

2. Data we collect

  • Account data: name and email address provided at sign-up.
  • Google account data: when you connect your Google Business Profile, we store an encrypted OAuth refresh token to fetch your public reviews. We do not store your Google password.
  • Review data: publicly visible Google reviews fetched from your Business Profile are cached in our database to serve your widget.
  • Payment data: billing is handled by Stripe. We store only a Stripe customer ID — no card numbers are held by us.
  • Usage data: basic analytics on widget impressions (page origin only, no visitor PII).
  • WordPress plugin setup data: if you set WeWidget up from inside our WordPress plugin, the plugin sends us what you type and choose during setup: the business name you search for, the Google Place ID and business name of the result you pick, the email address you enter, and your site’s address. This happens only when you use those setup controls — never automatically.
  • WordPress placement data: when you choose or change where the widget should appear on your WordPress site, the plugin sends us three things: which widget it was, the placement you chose (your homepage, every page, or placing it yourself with the shortcode), and a credential that authenticates your installation. That is the whole transmission — it does not include the plugin version or which screen you chose it on. It is sent only after you make that choice — not when the plugin is installed, activated, updated, or when you open your WordPress admin — and it is delivered shortly afterwards in the background. WeWidget then works out one further detail itself: the placement you had before, by comparing your new choice with the most recent placement already recorded for that widget. The plugin does not send us your previous placement, and we use the comparison to skip recording a change when nothing actually changed. We use all of this to see whether WordPress setup reaches the point where the widget actually has somewhere to appear, and to help when it does not.
  • The installation credential: the plugin also sends a credential we issued to that installation during setup, so we can confirm a placement report really came from it. It authenticates the widget installation and is linked to the WeWidget account that owns that widget. It contains no information about your site’s visitors. We do not store the credential itself — we check its signature mathematically each time a report arrives. No page or post content, page addresses, visitor activity, WordPress logins or Google credentials are sent with any of this.
  • Acquisition data: if you arrive from an advert or campaign link, we record the click identifier and campaign parameters from that link’s URL (such as Google’s gclid) so we can measure which channels bring visitors, and we may report those click identifiers back to the advertising platform to confirm a sign-up happened. This involves no cookies, no tracking scripts and no personal details — only the identifier the platform itself added to the link.

3. How we use your data

  • To provide the widget service and sync your Google reviews.
  • To process payments and manage your subscription.
  • To send transactional emails (account, billing, review sync status).
  • To improve the service based on aggregate usage.

4. Google user data & Limited Use

WeWidget's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • We access your Google Business Profile data solely to display your business's reviews and rating on websites you choose, at your direction.
  • We only read review and rating data — we never edit your listing, and never reply to, create, or delete reviews.
  • We do not sell Google user data, use it for advertising, or transfer it to third parties except as necessary to provide the service you requested or as required by law.
  • No humans read your Google data except with your explicit permission (e.g. a support request), for security purposes, or where required by law.
  • You can revoke WeWidget's access at any time from your dashboard or at myaccount.google.com/permissions. On disconnection we delete the stored refresh token; cached review data is removed when your account is deleted.

5. Third parties

  • Google: review data is fetched via the Google Business Profile API under their Terms of Service.
  • Stripe: payment processing. Stripe's privacy policy governs card data.
  • Supabase: database and authentication hosting.

6. Data retention

Your data is retained while your account is active. You may delete your account at any time by contacting us, which removes your profile, cached reviews, and Google connection. Stripe billing records are retained as required by law.

Setup and placement records from the WordPress plugin are kept in our internal event log. We have not set a fixed deletion period for that log, so it should be assumed to be kept indefinitely.

When an account is deleted, the direct link from these records to that profile is removed. The records themselves are kept, and are not anonymous: the details stored at the time remain, and can include your site address, the Google Place ID of your business, the widget identifier, the placement chosen and the date. Those details may still identify, or make it possible to identify, the site or business the record came from.

If you want these records deleted as well, email us and we will remove them. This is a manual job rather than an automatic one, so please ask explicitly — deleting your account on its own does not remove them. It is easiest for us if you ask before the account is deleted, or tell us your site address or widget ID afterwards, as those are what we search on.

7. Your rights

Under UK GDPR you have the right to access, correct, or delete your personal data. Contact us at hello@wewidget.app for any data request.

8. Contact

Questions about this policy: hello@wewidget.app