Privacy Policy
Effective · Version 2026-10-04
What’s changed
Changes since the April 17, 2026 version, newest first. Each one links to its section below.
The complete, current list of services that process your data is now our Subprocessors page, which this section points to. It names services the old table here left out: Planning Center (only when you connect it), Google (sign-in and calendar when you connect them, plus website icons, fonts and video thumbnails), OpenAI (document search), Groq (transcribing videos and voice), Google Maps, OpenStreetMap and Esri (maps and address lookups), Bunny.net (video hosting) and Calendly (booking the setup call).
This used to say we might train our AI features on anonymized, aggregated data. We don't train AI models on your data at all, and the AI providers we use don't either; this now says so.
Privacy questions, data requests and the EU data protection contact all go to help@getwisehq.com. Our mailing address is available on request.
This used to say you could manage cookies through our cookie banner. There is no banner yet: you manage cookies in your browser settings, and analytics cookies are not set without an explicit action from you until the banner for EU visitors is in place.
1. Introduction
WiseHQ ("we," "us," "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
2. Information We Collect
Information you provide
- Account information: name, email, password (hashed), organization name
- Profile information: avatar, phone number, job title
- Organization data: work orders, events, assets, vendors, documents, photos, etc.
- Payment information: processed by Stripe (we do not store card details)
- Communications: support tickets, emails, in-app messages
Information collected automatically
- Device information: browser, OS, IP address, device type
- Usage data: pages visited, features used, timestamps, session duration
- Cookies and similar technologies (see Cookie Policy section)
Information from third parties
- OAuth providers (Google) if you sign in with them
- Integration data (Google Drive, Dropbox) if you connect them
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To process payments and manage subscriptions
- To send transactional emails (verification, receipts, invites, security alerts)
- To send product updates and marketing (you can opt out)
- To provide customer support
- To detect and prevent fraud, abuse, and security issues
- To comply with legal obligations
- To analyze usage patterns and improve product decisions
- To improve our features, including AI features. We do not use your data to train AI models, and the AI providers we use don’t either.
4. Third-Party Subprocessors
We use trusted service providers (“subprocessors”) to operate the Service: hosting and our database (Supabase, Vercel, Cloudflare), payments (Stripe), email (Resend), AI features (Anthropic, OpenAI, Groq), maps and address lookups (Google Maps, OpenStreetMap, Esri), video hosting (Bunny.net), booking our setup call (Calendly), website icons, fonts and video thumbnails (Google) and the integrations you choose to connect (Planning Center, Google). Each processes only what it needs for its job and is bound by its own data processing terms (for public services we use without an agreement — the OpenStreetMap and Esri maps, and Google’s website icons, fonts and YouTube thumbnails — their published privacy and usage policies).
The complete, current list — what each one does, the data it handles and where — is on our Subprocessors page. Before a new subprocessor handles your data, we add it there and announce it in What’s New.
5. Data Sharing
We do not sell your data. We may share data:
- With the subprocessors on our Subprocessors page, to operate the Service
- With your organization administrators (if you're part of a multi-user org)
- With your explicit consent
- To comply with legal process (subpoena, court order)
- To protect our rights, property, or safety of users
- In connection with a merger, acquisition, or asset sale (with notice to you)
6. Your Rights (GDPR / CCPA / Similar Laws)
Depending on your location, you have rights including:
- Access: Request a copy of all personal data we hold about you
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your account and personal data
- Portability: Export your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Opt out of marketing communications
- Withdrawal of consent: Revoke previously granted permissions
To exercise these rights: use the export and delete buttons in Settings → Privacy, or email us at help@getwisehq.com. We respond within 30 days.
7. Data Security
We implement industry-standard security measures including:
- TLS/HTTPS encryption in transit
- AES-256 encryption at rest (via Supabase)
- Row-level security isolation between organizations
- Access controls and role-based permissions
- Regular security audits and backups
- Password hashing with industry-standard algorithms
No system is perfectly secure. In the event of a data breach affecting your personal data, we will notify you within 72 hours in accordance with applicable law.
8. Data Retention
We retain your data for as long as your account is active. After account deletion:
- Personal data is deleted within 30 days
- Anonymized usage data may be retained for analytics
- Legal records (invoices, tax records) retained per applicable law (typically 7 years)
- Backups are rotated out within 90 days
9. Cookies and Tracking
We use cookies for:
- Essential: Authentication, security, session management (always on)
- Preferences: Theme, language, view settings (stored locally)
- Analytics: Usage tracking (requires consent for EU visitors)
You can manage cookie preferences via your browser settings. A cookie consent banner is planned for EU visitors; until then, analytics cookies are not set without an explicit user action.
10. Children's Privacy
WiseHQ is not intended for children under 13 (or 16 in EU). We do not knowingly collect data from children. If you believe a child has provided personal data, contact us and we will delete it.
11. International Data Transfers
Your data may be processed in the United States or other countries where our subprocessors operate. By using the Service, you consent to these transfers. For EU customers, we rely on Standard Contractual Clauses and other legal mechanisms for lawful transfer.
12. Religious and Denominational Content
WiseHQ does not review, endorse, or moderate religious or denominational content uploaded by customers. User-uploaded documents and messages are not scanned for theological content.
13. California Privacy Rights (CCPA)
California residents have specific rights under the CCPA, including the right to know what personal information we collect, the right to delete it, and the right to opt out of sale (we do not sell your data). See "Your Rights" above.
14. Changes to This Policy
We may update this Privacy Policy. Material changes will be announced by email and in-app notice at least 30 days before taking effect. Current version: 2026-10-04.
15. Contact
Privacy inquiries: help@getwisehq.com
Data Protection Officer (for EU): help@getwisehq.com
Mailing address: available on request — email help@getwisehq.com
Questions? help@getwisehq.com