Privacy Policy
Last updated: July 9, 2026
Who we are
Weblevate ("we", "us") provides websites, lead capture, and online booking for local service businesses. This policy explains what we collect, how we use it, and the choices you have. It applies to weblevate.com, app.weblevate.com, and every business site we host on our subdomains.
What we collect
Account data: your email address and, if you sign in with Google, your name and profile picture. Business data: the details you enter about your business — name, address, phone, services, hours, photos. Customer data submitted to hosted business sites: when a visitor requests a quote or books an appointment, we store the name, contact details, and message they provide so the business can serve them. Usage data: standard server logs (IP address, browser, pages visited) used for security and reliability.
How we use it
To operate the service: build and host your website, deliver leads and booking notifications to you, and process subscription payments (handled by Stripe — we never see full card numbers). We do not sell personal information, and we do not use it for third-party advertising.
Google user data
If you sign in with Google, we receive your name, email address, and profile picture, and use them only to create and identify your account. If you connect Google Calendar, we request permission to create and edit events on your calendars (the "calendar.events" scope). We use that access for exactly one purpose: when a customer books, reschedules, or cancels an appointment on your Weblevate site, we create, update, or delete the matching event on your calendar. We store an encrypted refresh token to do this; we do not read, store, or analyze your other calendar events, and we never share Google user data with third parties or use it for advertising. Weblevate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Google Calendar at any time from your Appointments page, or revoke access at myaccount.google.com/permissions; disconnecting deletes our stored token.
If you connect Google Ads, we request read access to your Google Ads data (the "adwords" scope). We use it for exactly one purpose: reading the performance of your own advertising (spend, clicks, impressions, and conversions) and showing it to you on your private Weblevate dashboard next to the leads and bookings your site captured. We store an encrypted refresh token to refresh this report nightly. We do not modify your campaigns, we do not share or sell this data, and we never use it for our own or anyone else's advertising. The same Google API Services User Data Policy and Limited Use requirements above apply. You can disconnect Google Ads at any time from your dashboard; disconnecting deletes our stored token and cached report.
Text messages (SMS)
If you provide your phone number when booking an appointment on a business website hosted on Weblevate, we and that business use it to send appointment-related text messages, such as booking confirmations and reminders. Message frequency varies with your appointment activity. Message and data rates may apply.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
You can opt out at any time by replying STOP to any message. Reply HELP for help. For assistance you can also email techurgencysaas@gmail.com.
Who we share data with
Service providers that run the platform on our behalf: Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (transactional email), and Google (sign-in and calendar sync, when you enable them). Each receives only what it needs to provide its function. We may disclose information if required by law.
Retention and deletion
We keep your data while your account is active. Cancel your subscription and request deletion at any time by emailing us; we delete your account, business sites, leads, and appointments, and stored Google tokens, within 30 days.
Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is limited to the operator of the service. Calendar refresh tokens are stored in a locked-down table that application users cannot read.
Contact
Questions or requests: email techurgencysaas@gmail.com.