HelloWave

Privacy Policy

Effective August 31, 2026

1. Overview

This policy explains what information HelloWave collects, why, and how it's used. It covers two kinds of people: account holders (you, if you sign up for HelloWave to build widgets) and visitors (people who see or interact with a widget an account holder has embedded on their own website).

2. Information We Collect from Account Holders

  • Account information: name, email address, company, and password (stored hashed, never in plain text).
  • Billing information: handled directly by our payment processor, Stripe — we do not store your full card number.
  • Widget configuration: the content, targeting rules, and domains you set up for each widget.
  • Usage data: aggregate view/click analytics for your own widgets, and standard technical logs (IP address, browser, timestamps) for security and troubleshooting.

3. Information We Collect from Website Visitors

When someone visits a website that has a HelloWave widget embedded, our script may collect:

  • Device and browsing signals: device type, referring page, current URL path, and UTM parameters, used to decide whether a widget's targeting rules match.
  • Approximate location and weather: when a widget uses location- or weather-based targeting or personalization, we derive an approximate country/city/region from IP address (via MaxMind) and current weather conditions for that location (via OpenWeather). We do not collect precise GPS location.
  • A session identifier: a randomly generated token stored in the visitor's browser (via localStorage) so we don't count the same visitor's view or click more than once, and so a widget the visitor already dismissed or completed doesn't reappear.
  • Submitted content: if a visitor fills out a lead capture form, answers a text-input question, or completes a quiz, we store what they submitted (for example, an email address and name, a free-text answer, or quiz answers and score) on behalf of the account holder who owns that widget.

For this visitor data, the account holder who created the widget is the party responsible for deciding what's collected and why; HelloWave processes it on their behalf to operate the Service. If you're a website visitor with questions about a specific widget, please contact the website you saw it on.

4. How We Use Information

  • To operate the Service: serving widgets, evaluating targeting rules, and recording analytics;
  • To provide account holders with the leads, responses, and quiz results their widgets collect;
  • To bill for paid plans and enforce plan limits;
  • To secure the Service, prevent abuse, and debug issues;
  • To communicate with account holders about their account, billing, or material changes to the Service.

5. Cookies and Local Storage

Our dashboard uses standard session cookies to keep you logged in. Our embeddable widget script uses browser localStorage (not cookies) on the websites it's embedded on, to generate a session token and to remember whether a visitor has already dismissed, submitted, or completed a given widget.

6. Third Parties We Work With

  • Stripe — payment processing for paid plans;
  • MaxMind — IP-based geolocation lookups;
  • OpenWeather — weather data used for weather-based targeting and personalization;
  • Our infrastructure and email providers, who process data solely to help us run the Service.

We do not sell personal information.

7. Data Retention

We retain account data for as long as an account is active, and widget analytics/submissions for as long as the widget or account exists, unless an account holder deletes them sooner. You can delete your account and its data from your account settings, or by contacting us.

8. Your Rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Account holders can exercise these rights for their own account directly from their dashboard, or by emailing us. Website visitors with a request about data collected through a specific widget should start with the website that widget appeared on, since they control that widget's content and targeting; we're glad to assist them as needed.

9. Children's Privacy

The Service is not directed to children, and we don't knowingly collect personal information from children.

10. Changes to This Policy

We may update this policy from time to time. If we make material changes, we'll take reasonable steps to notify account holders, such as posting a notice on our site or emailing the address on file.

11. Contact

Questions about this policy or your data? Email us at[email protected].