Privacy
What we hold about you, what a widget collects from the people who fill it in, and everyone else who touches either.
Last updated 6 September 2026
1.Two different things, kept apart
Widgio handles personal data in two situations that are not the same, and the rest of this page follows that split:
- You, using Widgio. We decide what is collected and why. In data-protection language we are the controller, and sections 2 and 5 to 10 are about that.
- Your visitors, filling in your widget. That is your data, collected for you, on your website. You decide what to ask and what to do with the answers; we store it and show it to you. You are the controller and we are the processor - section 3.
2.What we hold about you
- Your email address. It is your account - you sign in with a link sent to it - and it is how we reach you about the service.
- What you build. The widgets, their wording and their settings, and the description you typed to make them.
- Payment records. Which plan you are on and when it renews. Paddle takes the payment and holds the card details; we never see them and we could not charge your card if we wanted to.
- Ordinary server logs - requests, errors, IP addresses - kept briefly, to keep the service up and to see what broke.
We do not sell any of it, we do not advertise, and we do not build a profile of you. The site itself sets no advertising or analytics cookies.
3.What a widget collects from your visitors
When somebody completes a widget on your site, this is exactly what arrives in your leads, and nothing else:
- the answers they gave, and anything they typed into a contact field you asked for;
- the estimate or result the widget produced for them, where it produces one;
- the address of the page they were on, the page that referred them, their browser language and screen size;
- how long they took, which is used to tell a person from a bot and for nothing else;
- their IP address, recorded to limit abuse of the form - a public form with no such limit becomes a spam relay within days.
The widget sets no cookies and does not track anybody across sites. It stores one thing in the browser and only for the visit: whether a banner or a floating widget was dismissed, so that dismissing it means something. It does not read cookies belonging to your site.
We use this data only to store it, show it to you and let you export it. We do not use it to market to anybody, we do not sell it, and we do not use it to train AI models - the AI that writes a widget’s wording sees the description you type, never a lead.
Because it is your data collected on your site, telling your visitors about it and having a lawful reason to collect it is yours to do. Your own privacy notice should cover the widget, and if you ask for anything beyond a name and a way to reply, it should say so.
4.Counting how often a widget is seen
Separately from the answers above, a widget tells us when it has appeared on a page, so that you can see whether your snippet is working and how many people it reached. This is the only other thing it ever sends.
It is a count, not a record of a visit. We keep one running total per widget, per day, per website - and nothing else. No address, no page, no referrer, no identifier, no cookie. There is no visitor in what is stored, because there is nowhere in it to put one: a thousand people opening your page and one person opening it a thousand times leave the same single number behind, and neither can be told apart from the other or followed anywhere.
5.Who else touches it
As short a list as we can keep it. Each one does one job:
| Who | What for | Where |
|---|---|---|
| Vercel | Runs the website and the API | United States, European Union |
| Supabase | Stores accounts, widgets and leads | European Union |
| Writes the wording of a widget from the description you type. Leads are never sent to it | United States | |
| Resend | Delivers the email telling you an enquiry arrived | United States |
| Paddle | Takes payment and is the seller of record | United Kingdom |
Some of them are outside the European Economic Area, which means data reaches countries with different laws. Where that happens it is covered by the standard contractual clauses those companies publish. We will add to this list only when a new service is genuinely needed, and this page changes when it does.
6.How long it is kept
- Leads: until you delete them. Every lead has a Delete on it, and deleting removes the row rather than hiding it.
- Your account and widgets: while the account is open. Close it and they go, along with the leads in it.
- View counts: for as long as the widget exists. They are totals with nobody in them, so there is nothing in one that could expire.
- Server logs: a short rolling window, then gone.
- Records of payments: kept as long as tax law requires, which is not up to us.
7.What you can ask for
You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. Write to widgio.ai@gmail.com and we will answer within a month, in practice much sooner.
If you filled in a widget on somebody’s website and want your data removed, ask the owner of that website - it is theirs, and they can delete it themselves. If you cannot reach them, write to us and we will help.
If you think we have handled your data badly you can complain to the data protection authority where you live.
8.Security
Everything travels over HTTPS. Leads are stored in a database where the rules are enforced by the database itself, not only by our code, so one account cannot read another’s - and the key our server uses to save a lead cannot read, change or delete anybody’s. Nothing a widget writes onto your page is ever inserted as HTML, which is the way an embedded script usually becomes a security problem for the site hosting it.
No system is perfect. If something goes wrong in a way that affects you, we will tell you rather than hope you do not notice.
9.Children
Widgio is a tool for businesses and is not meant for children. We do not knowingly collect data from anybody under 16 through our own site, and you should not use a widget to collect data from children either.
10.Changes, and who to write to
When this notice changes we update the date at the top, and if the change matters we email you. The person responsible for it is Tetiana Korolova - see the terms for the full details.