Last updated: 2026-08-04
Data controller:
Wibigo OÜ — Osaühing (private limited company)
Registry code: 17567662
Narva mnt 5, 10117 Tallinn, Estonia
Email: privacy@wibigo.com
Wibigo is a website builder and business platform for small businesses. This Privacy Policy explains what personal information we collect, why we collect it, how long we keep it, who we share it with, and how you can access or delete it. It applies to wibigo.com, to the Wibigo application, and to the websites you publish with Wibigo.
We collect information that you provide directly to us, including:
We also collect data from third-party platforms, but only for the platforms you explicitly choose to connect. Google connections are described in detail in section 9.
We do not sell, trade or rent your personal information. We share it only in these situations:
We apply appropriate technical and organisational measures to protect personal information. Third-party access tokens are encrypted at rest, and access to production data is restricted to the personnel who need it. No method of transmission over the internet is completely secure, so we cannot guarantee absolute security.
We keep personal information only for as long as we need it. These periods are enforced by an automated daily job, not applied on request:
Under the GDPR and comparable laws you have the right to:
To exercise any of these rights, email privacy@wibigo.com.
We use cookies and similar technologies to keep you signed in, to remember your preferences and to measure how the service is used. You can manage non-essential cookies from the cookie settings link in our footer, or configure your browser to refuse cookies.
Wibigo integrates with third-party platforms only when you choose to connect them. When you connect an account we request only the permissions the feature needs, and we store the resulting access tokens encrypted at rest:
If you connect a Facebook Page we store your Facebook user and business identifiers, the connected Page's id and name, the product catalog's id and name, the linked Instagram account id, the Pixel id, and a long-lived access token with its expiry and the permissions you granted. For Instagram we store the Instagram user id and username with the same token details. For WhatsApp Business we store the WhatsApp Business Account and phone number identifiers, the display phone number and verified name, the access token, and the webhook verification secrets. We also record when each sync ran and whether it failed.
We use this to publish your catalog to your storefront, to receive and answer messages in your Wibigo inbox, and to capture leads from your Page. Every access token is encrypted at rest. Message and catalog data is kept while the connection is active. When you remove Wibigo from your Facebook settings, Meta calls our deletion endpoint and the connection and its data are deleted automatically; you can also disconnect from inside Wibigo at any time.
If you connect Outlook we store the connected account's email, an encrypted access and refresh token with their expiry and granted scopes, the calendar identifier, and your synchronisation settings and timestamps. We use it only to create, update and read the calendar events that correspond to your Wibigo appointments. Disconnecting deletes the stored connection and its tokens. The Google Calendar connection works identically and is described in section 9.
Stripe and Paddle process payments for you. We store the connected account's identifier and whether it is able to accept charges — we never receive or store full card numbers, which stay with the payment provider. Shopify supplies product and order data for the storefront features you enable. Etsy supplies your listings only — Wibigo does not read your Etsy sales. OpenProvider handles domain registration and business email.
Each provider processes data under its own privacy policy; we encourage you to review them.
This section describes exactly how Wibigo handles data obtained through Google APIs. Connecting a Google account is always optional, and Wibigo is fully usable without it.
Only what the permission you granted covers. For the
Google Business Profile connection we request the scopes
openid, email and
https://www.googleapis.com/auth/business.manage, and we store:
For the Google Calendar connection we request openid,
email, profile and
https://www.googleapis.com/auth/calendar, and use them only to read and write the
calendar events that correspond to your Wibigo appointments.
To deliver the specific features you switched on: pre-filling your website with your verified business details instead of making you retype them, showing your Google reviews inside Wibigo, helping you reply to those reviews, publishing the replies you approve back to Google, and keeping your appointments in sync with your calendar.
Inside your Wibigo account only. Business details are used to populate your own website; reviews and metrics appear in your Wibigo control panel; calendar data is used to create and update your appointment events. When you ask Wibigo to draft a reply to a review, the review text is sent to our AI text provider (currently Google Gemini, with a fallback provider if it is unavailable) solely to generate that draft. Every draft is shown to you and is published to Google only after you approve it.
For as long as the connection is active. Tokens are refreshed while the connection lives, and cached reviews and business details are kept so the panel keeps working between syncs. When you disconnect, or when you delete your account, the connection and the Google data cached against it — including tokens and cached reviews — are deleted. Backups are rotated automatically and expire within 30 days.
Nobody, beyond the processors needed to run the feature. Wibigo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not sell Google user data, do not use it for advertising, do not use it to train generalised AI or machine-learning models, and do not transfer it to others except as necessary to provide the feature you enabled, to comply with applicable law, or as part of a merger or acquisition of which you would be notified.
In Wibigo, open your site's control panel, go to the Google Business Profile (or Calendar) connection and choose Disconnect. Wibigo revokes the token with Google and deletes the stored connection and the Google data cached against it. You can also revoke Wibigo's access at any time directly from your Google Account permissions page; revoking there stops all further access immediately.
Disconnecting already deletes it. If you would like written confirmation, or want data removed without signing in, email privacy@wibigo.com from the address on your Wibigo account, or use our Data Deletion page. We complete these requests within 30 days and confirm by email when they are done.
You can delete your data at any time. Removing the Wibigo app from your Facebook or Instagram settings automatically deletes the data tied to that connection. To delete your account and all associated data, visit our Data Deletion page or email privacy@wibigo.com. Requests are processed within 30 days.
Our service is not intended for children under the age of 16 (or the minimum age of digital consent in your jurisdiction). We do not knowingly collect personal information from children.
We are established in Estonia and process data primarily within the European Economic Area. Where a provider processes data outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses or another approved safeguard.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date above.
Privacy and data requests: privacy@wibigo.com
General & support: support@wibigo.com
Legal: legal@wibigo.com
Website: https://wibigo.com
Additional notices for users in Türkiye (KVKK): Aydınlatma Metni · Açık Rıza Metni
Wibigo is operated by Wibigo OÜ, a private limited company registered in Estonia under registry code 17567662. Registered address: Narva mnt 5, 10117 Tallinn, Estonia.