Weblevate

Privacy Policy

Last updated: July 9, 2026

Who we are

Weblevate ("we", "us") provides websites, lead capture, and online booking for local service businesses. This policy explains what we collect, how we use it, and the choices you have. It applies to weblevate.com, app.weblevate.com, and every business site we host on our subdomains.

What we collect

Account data: your email address and, if you sign in with Google, your name and profile picture. Business data: the details you enter about your business — name, address, phone, services, hours, photos. Customer data submitted to hosted business sites: when a visitor requests a quote or books an appointment, we store the name, contact details, and message they provide so the business can serve them. Usage data: standard server logs (IP address, browser, pages visited) used for security and reliability.

How we use it

To operate the service: build and host your website, deliver leads and booking notifications to you, and process subscription payments (handled by Stripe — we never see full card numbers). We do not sell personal information, and we do not use it for third-party advertising.

Google user data

If you sign in with Google, we receive your name, email address, and profile picture, and use them only to create and identify your account. If you connect Google Calendar, we request permission to create and edit events on your calendars (the "calendar.events" scope). We use that access for exactly one purpose: when a customer books, reschedules, or cancels an appointment on your Weblevate site, we create, update, or delete the matching event on your calendar. We store an encrypted refresh token to do this; we do not read, store, or analyze your other calendar events, and we never share Google user data with third parties or use it for advertising. Weblevate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Google Calendar at any time from your Appointments page, or revoke access at myaccount.google.com/permissions; disconnecting deletes our stored token.

Who we share data with

Service providers that run the platform on our behalf: Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (transactional email), and Google (sign-in and calendar sync, when you enable them). Each receives only what it needs to provide its function. We may disclose information if required by law.

Retention and deletion

We keep your data while your account is active. Cancel your subscription and request deletion at any time by emailing us; we delete your account, business sites, leads, and appointments, and stored Google tokens, within 30 days.

Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to the operator of the service. Calendar refresh tokens are stored in a locked-down table that application users cannot read.

Contact

Questions or requests: email techurgencysaas@gmail.com.