Privacy Policy

Last updated:

This Privacy Policy explains how Webrenew LLC ("Webrenew," "we," "us," or "our") collects, uses, discloses, and protects personal information. It also explains the choices and rights available to you. This policy is a notice, not a request to waive any privacy right.

1. Scope and our role

This policy applies to webrenew.com, Webrenew Agency, Webrenew Tools, Design Studio, our template store and domain marketplace, and any other Webrenew service that links directly to it. A product-specific privacy notice controls for a service that publishes one.

Webrenew LLC is the controller or "business" for personal information we collect for our own services. When an agency customer gives us personal information solely to process on its instructions, that customer may be the controller and Webrenew its processor or service provider; the applicable service agreement and data processing terms then govern that processing.

You can contact the controller at privacy@webrenew.io. Webrenew LLC is based in the United States.

2. Personal information we collect

2.1 Information you provide

  • Account and profile data: name, email address, profile image, account identifiers, authentication method, and credentials processed by our authentication provider.
  • Contact and professional data: name, email, phone, company, role, website, project goals, form responses, and messages you send us.
  • Transaction and contract data: purchases, subscription or fulfillment status, billing address, Stripe customer and transaction identifiers, signed-document data, and related records. Stripe processes full payment-card details; we do not store full card numbers.
  • Content and project data: designs, strategy answers you choose to save, prompts, files, brand assets, code, support communications, and other material you submit or ask us to process.

2.2 Information collected automatically

  • Technical and activity data: IP address, browser, operating system, device type, pages and features used, referrer, filtered query or UTM parameters, access times, and approximate country, region, or city inferred from your network connection.
  • Security and diagnostics: request, rate-limit, bot-detection, error, and performance information needed to protect and troubleshoot the services.
  • Cookies and local storage: authentication, consent choices, settings, on-device tool data, and, after marketing consent, advertising attribution identifiers. Section 6 provides more detail.

2.3 Information from other sources

We may receive information from authentication providers such as Google, GitHub, or Slack; Stripe; Cal.com; contract and signature providers; a business customer that authorizes us to work with its data; and advertising partners when you have consented. We receive only the information made available under your settings, the transaction, or the applicable business relationship.

Please do not submit health information, government identifiers, precise geolocation, information about children, or other special or highly sensitive data unless we expressly request it under an appropriate agreement.

3. Why we process information and our legal bases

Where the GDPR or UK GDPR applies, we rely on the following legal bases. A basis applies only where the processing is necessary and proportionate for the stated purpose.

  • Provide requested services and take pre-contract steps (Article 6(1)(b)): create accounts, answer service inquiries, schedule calls, process purchases, deliver downloads, save requested content, and perform agency agreements.
  • Comply with law (Article 6(1)(c)): keep required tax and transaction records, respond to valid legal process, and meet legal security, consumer-protection, and accounting duties.
  • Our legitimate interests (Article 6(1)(f)): secure the services, prevent fraud and spam, diagnose errors, maintain business records, improve features using aggregate usage patterns, respond to non-contractual communications, and establish or defend legal claims. Our interests are reliable services, network and information security, effective customer support, and responsible business operation. We balance these interests against your rights and do not use this basis where those rights override them.
  • Your consent (Article 6(1)(a)): load the X advertising pixel and Apollo website-visitor tracker, send advertising conversions or audience data, identify interested business visitors, and send consent-based marketing. You may withdraw consent as easily as you gave it, without affecting earlier lawful processing.

Account, contact, and transaction fields marked as required are needed to provide the requested account, response, or purchase. If you do not provide them, we may be unable to fulfill the request. Optional fields are voluntary. Basic request and security data is collected automatically when you use an online service.

We do not use identifiable customer content to train a general AI model unless a service-specific notice and valid legal basis clearly permit it. We may use information that has been aggregated or deidentified so it is no longer personal information, and we do not attempt to reidentify it.

4. Browser processing and saved content

Many free tools process inputs entirely in your browser. Design Studio strategy answers remain on your device by default and are not included in analytics, share links, or layout saves. If you sign in and choose "Save to portal," we upload the named copy you selected so it is available in your account. Files or content sent to a server-powered feature are processed as the feature explains.

5. Recipients and disclosures

We do not sell personal information for money. We disclose only what is reasonably necessary for the purpose, including to these recipient categories:

  • Infrastructure and security: Vercel for hosting, bot protection, aggregate analytics, and performance data; Supabase for authentication, databases, and storage; Upstash for rate limiting; Cloudflare R2 for protected file delivery; and Sentry for error monitoring.
  • Business operations: Stripe for payments; Resend for transactional email; Slack for internal lead and service notifications; Cal.com for scheduling; and contract, signature, accounting, and professional advisers as needed.
  • Connected and AI services: authentication or integration providers you choose and, when a feature requires it, the AI processor identified by that feature or a service-specific notice.
  • Advertising and lead intelligence: X and Apollo receive the limited information described in Section 6 only after marketing consent. California law may call this "sharing" for cross-context behavioral advertising even when no money changes hands.
  • Legal and corporate events: courts, regulators, law enforcement, advisers, or a transaction counterparty when legally required or reasonably necessary to protect rights, safety, and the services, or in a merger, financing, reorganization, or sale subject to appropriate safeguards.

Processors act under agreements and instructions appropriate to their role. Some connected providers, X, and Apollo may act as independent controllers for their own services.

6. Cookies, local storage, analytics, and advertising

6.1 Essential storage and privacy-focused analytics

  • Authentication cookies keep signed-in users secure. Consent and preference records remember choices and settings. On-device tool data stays in your browser unless you choose to upload it.
  • To demonstrate and honor your privacy choice, we keep an anonymous consent receipt containing c15t's random browser subject ID, decision time, category choices, policy ID and fingerprint, GPC status, and page path. It does not include your IP address, user-agent, email address, or form content. If delivery is interrupted, an anonymous pending copy remains in local storage only until our server confirms receipt.
  • Vercel Web Analytics provides aggregate, cookie-free usage data; Vercel Speed Insights supplies performance measurements. We do not put form text, email addresses, or saved strategy answers in analytics events.
  • Sentry receives error diagnostics when the application fails. Session replay is disabled; we do not intentionally record a video-like replay of your browsing session.

6.2 Consent choices, advertising, and visitor identification

Marketing is off unless you opt in. If you consent, the X pixel may record website visits and ad interactions, and we may send X:

  • Lead, booking, and customer conversion events, with your normalized email transformed using SHA-256 before transmission.
  • An X click identifier, and for server conversion matching the IP address and user-agent associated with the consented conversion.
  • Hashed email addresses for a consented X audience and similar audience targeting.

If you consent, Apollo's website-visitor tracker also loads and uses local storage and may use cookies. It receives IP address, device and browser identifiers, referrer, pages viewed, visit timing and frequency, and related website interactions. The Apollo tracker may invoke identity-resolution technology supplied through Apollo and store hashed email identifiers returned by that service. Apollo may match activity with company, location, industry, and professional data in its services. We use the resulting company-level and, where available for United States visitors, contact-level identification to understand business interest, prioritize leads, and conduct sales follow-up.

If you decline, neither marketing tracker loads, and we do not send X conversions or audience records. As a second layer, c15t blocks known X and Apollo fetch or XMLHttpRequest destinations until marketing consent is active. Your browser stores its consent record for up to 365 days. You can change or withdraw your choice at any time through . We stop future reporting and schedule removal of associated email addresses from our X audience. If you cleared site data or changed browsers, email privacy@webrenew.io. The consent-controlled reload removes known first-party X cookies and Apollo local-storage identifiers and stops future tracking in that browser. To request deletion or opt out of previously matched Apollo data, contact us or use Apollo's privacy center. X and Apollo handle information they receive under their own privacy terms.

We recognize Global Privacy Control (GPC) signals. A GPC signal disables marketing for that browser and device and withdraws an earlier browser-stored marketing choice. Where that browser holds the limited lead identifiers needed to carry out the withdrawal, we also propagate it to our audience records. Use the email above for an account-wide or cross-device request.

7. Retention

We keep personal information only as long as reasonably necessary for the purpose described above, then delete, deidentify, or isolate it unless law permits or requires longer retention. The criteria we apply include:

  • Account and deliberately saved content: for the account and service relationship, subject to deletion requests, backup cycles, and legal exceptions.
  • Inquiries, support, and agency records: for the active relationship and a reasonable period for follow-up, quality, security, disputes, and applicable limitation periods.
  • Purchases, contracts, and billing metadata: for fulfillment, access rights, tax, accounting, fraud, chargeback, and other legal record requirements.
  • Request, security, error, and performance data: for short operational and diagnostic cycles appropriate to the risk, or in aggregate form that does not identify you.
  • Browser consent: up to 365 days. A consented X click identifier in session storage ends with the browser session. Anonymous consent receipts are kept for up to 400 days. Other server-side consent and conversion records are kept while needed to honor the choice, prevent duplicate reporting, demonstrate compliance, and manage the customer relationship.

Deletion may be delayed where information is needed to complete a transaction, protect security, comply with law, exercise legal claims, or preserve an immutable backup until its ordinary deletion cycle. We do not use isolated information for a new purpose.

8. Security and incident response

We use reasonable technical, administrative, and organizational measures designed for the nature and risk of the information, including encrypted transport, access controls, authentication, restricted service-role access, monitoring, and vendor safeguards. No system is completely secure. If an incident triggers a legal notification duty, we will notify affected people and authorities as required by applicable law.

9. Your privacy rights

Depending on where you live and subject to legal exceptions, you may have rights to:

  • Know whether and how we process your personal information.
  • Access personal information and receive a copy of it.
  • Correct inaccurate or incomplete information.
  • Delete information that we no longer have a lawful reason to keep.
  • Restrict certain processing or object to it.
  • Receive information you provided in a structured, commonly used, machine-readable format and transmit it to another controller where portability applies.
  • Withdraw consent at any time and object at any time to direct marketing. Withdrawal does not affect processing that was lawful before it.
  • Receive human review where a decision based solely on automated processing has a legal or similarly significant effect, if such a decision is ever used.
  • Complain to a data protection or privacy authority.

To exercise a right, email privacy@webrenew.io from the address associated with your request and describe the service and right involved. We may ask for information reasonably necessary to verify identity and authority, and use it only for that purpose. We generally do not charge a fee, but may decline or charge where law permits for manifestly unfounded or excessive requests.

We respond within the period required by applicable law. Under the GDPR this is generally one month, subject to a permitted extension for complex or numerous requests. If we cannot fulfill a request, we will explain why and identify available complaint or appeal options. EEA residents may complain to the supervisory authority where they live, work, or believe an infringement occurred; UK residents may complain to the Information Commissioner's Office. We encourage you to contact us first so we can address the concern.

10. California notice at collection and privacy rights

This section supplements the rest of this policy for California residents and serves as our notice at collection. It describes the categories of personal information we collected in the preceding 12 months, sources, purposes, service-provider disclosures, retention criteria, and sale or sharing practices. We collect a category only when you use a feature that requires it.

10.1 Categories collected in the preceding 12 months

  • Identifiers

    Examples:
    Name, email address, phone number, account and authentication-provider identifiers, IP address, company, and advertising click or conversion identifiers.
    Sources:
    You, your browser or device, authentication providers, payment providers, scheduling providers, and business customers that authorize us to receive the information.
    Purposes and service-provider disclosures:
    Account access, responding to inquiries, service delivery, transactions, security, fraud prevention, and consented advertising measurement. Disclosed as needed to hosting, authentication, communications, scheduling, payment, security, and advertising providers.
    Retention:
    For the account or customer relationship, transaction and legal-record periods, security and support needs, or until a valid deletion request applies. Advertising identifiers are removed or disabled after withdrawal as described below.
    Sale or sharing:
    Not sold for money. After opt-in consent, hashed email, IP address, and advertising identifiers may be shared with X for advertising measurement and audience services, and identifiers may be shared with Apollo for website-visitor identification and lead intelligence.
  • California customer-record information

    Examples:
    Contact details, billing address, signature or contract information, and limited payment and transaction metadata. Stripe, not Webrenew, handles full payment-card numbers.
    Sources:
    You, Stripe, contract and signature providers, and business customers.
    Purposes and service-provider disclosures:
    Purchases, invoicing, contracts, fulfillment, customer support, tax, accounting, and legal compliance. Disclosed to payment, contract, accounting, hosting, and professional-service providers as needed.
    Retention:
    For the transaction or contract relationship and the applicable tax, accounting, warranty, dispute, and legal-limitation periods.
    Sale or sharing:
    Not sold or shared for cross-context behavioral advertising.
  • Commercial information

    Examples:
    Products, templates, subscriptions, domains, or agency services considered or purchased; purchase status; and download or fulfillment records.
    Sources:
    You, Stripe, and our service records.
    Purposes and service-provider disclosures:
    Checkout, delivery, entitlement management, customer support, accounting, and service planning. Disclosed to payment, email-delivery, storage, and hosting providers as needed.
    Retention:
    For fulfillment and access rights, the customer relationship, and applicable transaction-record obligations.
    Sale or sharing:
    Not sold or shared for cross-context behavioral advertising.
  • Internet or other electronic network activity

    Examples:
    Pages and features used, referrer and UTM data, browser and device details, approximate location, request and error logs, performance data, security signals, and interactions with consented advertising.
    Sources:
    Your browser or device and our hosting, analytics, security, and advertising providers.
    Purposes and service-provider disclosures:
    Operate and secure the services, prevent abuse, diagnose errors, understand aggregate usage, and measure consented advertising. Disclosed to hosting, analytics, performance, error-monitoring, security, and advertising providers as needed.
    Retention:
    For short operational, security, and diagnostic cycles or in aggregated form. Anonymous consent receipts are retained for up to 400 days. Vendor retention may vary by service configuration; we keep identifiable records only while reasonably necessary for the stated purpose.
    Sale or sharing:
    Not sold for money. After opt-in consent, website visits, browser details, IP address, and ad interactions may be shared with X, and website activity and device or browser identifiers may be shared with Apollo for visitor identification and lead intelligence.
  • Approximate geolocation

    Examples:
    Country, region, or city inferred from an IP address. We do not intentionally collect precise geolocation through these services.
    Sources:
    Your network connection and hosting or analytics providers.
    Purposes and service-provider disclosures:
    Security, country-based abuse controls, aggregate analytics, and regional service operation. Disclosed to hosting, analytics, and security providers as needed.
    Retention:
    For the associated request-log, security, or aggregate-analytics period.
    Sale or sharing:
    Not sold or shared for cross-context behavioral advertising.
  • Professional or employment-related information

    Examples:
    Company name, role, business website, project requirements, and other professional details you include in an inquiry or agency engagement.
    Sources:
    You, your organization, an authorized business contact, and, after marketing consent, Apollo's company and professional data.
    Purposes and service-provider disclosures:
    Respond to business inquiries, identify business interest, scope and deliver agency work, and maintain customer relationships. Disclosed to communications, collaboration, contract, hosting, and consented lead-intelligence providers as needed.
    Retention:
    For the inquiry, customer, or agency relationship and applicable contract, dispute, and legal-record periods.
    Sale or sharing:
    Not sold for money. After opt-in consent, professional information associated with a website visitor may be shared with or received from Apollo for lead intelligence and sales follow-up.
  • Inferences

    Examples:
    Likely service interests or project needs inferred from the pages, forms, and service choices with which you interact.
    Sources:
    The information and activity described above.
    Purposes and service-provider disclosures:
    Respond to requests, tailor service recommendations, understand demand, and, after marketing consent, prioritize business leads. Disclosed to service providers only as needed to support those purposes.
    Retention:
    For the associated inquiry or customer relationship, or in aggregated form for service planning.
    Sale or sharing:
    Not sold for money. After opt-in consent, interest or company-profile inferences may be shared with or received from Apollo for lead intelligence and sales follow-up.
  • Sensitive personal information

    Examples:
    Account login credentials and, only when an agency customer chooses to provide them, credentials needed to access customer systems. Authentication and payment providers process credentials within their systems.
    Sources:
    You and authentication providers.
    Purposes and service-provider disclosures:
    Only to authenticate, secure accounts, or perform requested agency work. Disclosed to authentication, hosting, or specifically authorized project providers as necessary.
    Retention:
    For account authentication or the authorized project need, then deleted, rotated, or deactivated under the applicable service process.
    Sale or sharing:
    Not sold or shared for cross-context behavioral advertising.

10.2 Sale, sharing, sensitive information, and minors

We do not sell personal information for money. In the preceding 12 months, after opt-in marketing consent, we shared identifiers and internet or network activity with X for advertising measurement, audience matching, and cross-context behavioral advertising. Beginning August 24, 2026, opt-in marketing consent also permits us to share identifiers, internet or network activity, professional data, and inferences with Apollo for website-visitor identification and lead intelligence. We do not have actual knowledge that we sell or share personal information of consumers under 16.

We use and disclose sensitive personal information only for permitted purposes such as authentication, account security, and providing a specifically requested service. We do not use it to infer characteristics. Because we do not use or disclose it outside those permitted purposes, we do not currently provide a separate right-to-limit mechanism. If our practices change, we will provide the required notice and choice before that use begins.

10.3 California rights and how to exercise them

Subject to exceptions, California residents have rights to know the categories, sources, purposes, recipients, and specific pieces of personal information collected; delete information; correct inaccuracies; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service and pricing without retaliation for exercising a right.

  • Know, access, delete, or correct: email privacy@webrenew.io. We may verify your request by matching account, email, transaction, or service details already maintained by us. We aim to confirm and respond within the CCPA deadlines, generally 45 days for a verified request, subject to a permitted extension.
  • Do not sell or share: use , send a GPC signal, or email us. No account or identity verification is required for an opt-out. We process it as soon as feasibly possible and no later than the period required by law. We will not ask you to opt back in for at least 12 months.
  • GPC scope: the signal applies to the browser and device that sends it. If we can associate that browser with limited lead identifiers stored there for consent withdrawal, we also apply the opt-out to those audience records. Email us to extend a request across browsers, devices, or offline records.
  • Authorized agents: an agent may submit a request by email and identify the resident represented. We may require signed permission, proof of registration with the California Secretary of State where applicable, direct confirmation from the resident, or other legally permitted verification. We do not require verification for an opt-out beyond information needed to identify the affected records.

11. International transfers

Webrenew is based in the United States, and we and our providers may process information in the United States and other countries. Where EU, EEA, Swiss, or UK transfer rules apply, we use an applicable mechanism such as an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and supplementary safeguards as appropriate. Contact us to ask about the mechanism relevant to your information or to request an available copy, subject to lawful redactions.

12. Automated processing and AI

We use automated rate limits, bot detection, spam rules, and country-based abuse controls to protect forms and services. These controls may silently reject a submission but do not make decisions producing legal or similarly significant effects. If a legitimate form is not accepted, contact us by email. AI-powered features may generate content at your direction; they are not used by this service to make solely automated decisions about your legal rights, employment, credit, housing, insurance, education, or access to an essential service.

13. Children

The services are not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided information, contact us so we can investigate and delete it where required. We do not knowingly sell or share personal information of anyone under 16.

14. Changes to this policy

We may update this policy to reflect changes in law, technology, or our practices. We will post the revised policy and update its date. If a change materially affects how we use information already collected, we will provide additional notice and obtain consent where required before the change applies.

15. Contact us

For privacy questions, rights requests, or complaints, contact Webrenew LLC at privacy@webrenew.io. For general service questions, email contact@webrenew.io. Include the Webrenew service involved, but do not send passwords, full payment-card details, or other unnecessary sensitive data.

Webrenew

Ready to build something great?