Home › Privacy Policy
Effective date: August 27, 2026
Last updated: August 27, 2026
WyzeBiz, operated by Wyze Business Solutions ("WyzeBiz," "we," "us," or "our"), builds CRM and customer-follow-up software for independent businesses. The platform is sold under four product names, all running on shared infrastructure and covered by this policy:
The editions differ in wording and defaults. The application, the account system, and the data handling described here are the same for all of them.
For business customer data we act as a controller. For contact data we act as a processor on behalf of the business customer who provided it, and that business customer decides what is collected and who is contacted.
From business customers: name, email, phone, company name, business address, billing details, account credentials (passwords are hashed and never stored in readable form), and the content of the campaigns they create.
From contacts, on a business customer's behalf: name, email address, phone number, city/location, and engagement data (opens, clicks, replies, and where the edition supports it, call and SMS records) generated by interacting with a campaign.
From connected Google services and social accounts, where a business customer turns them on: message content needed to detect replies and create leads, appointment details for events the application creates or updates on a connected calendar, reviews and replies for connected Google Business Profile locations, and the videos, images, and captions a customer schedules for publication to a connected YouTube, Facebook, Instagram, or TikTok account. The Google user data section below governs the Google portion of this and takes precedence.
Automatically, when a business customer uses the application: IP address and approximate city-level location, browser type and operating system, pages and features accessed, timestamps, session duration, and API request logs.
At signup, for fraud prevention: email domain, normalized phone number, IP address, and a hash derived from browser characteristics. This is used only to detect trial abuse and duplicate-account fraud, is never used for advertising, and is retained for up to 12 months after an account closes.
Cookies. We use cookies only for authentication and session management. We do not use advertising cookies, behavioral tracking cookies, or third-party tracking pixels. Rejecting cookies in your browser will prevent you from signing in.
We do not sell contact data.
This section governs data obtained through Google APIs and takes precedence over anything more general elsewhere in this policy.
Connecting a Google account is optional. Where a business customer chooses to connect one, we request only the scopes needed to operate the features they turned on:
gmail.send). Used solely to deliver the campaigns and replies that the business customer composed and approved. We do not send anything the customer did not configure.gmail.readonly). Used solely to detect replies to campaigns and, where the customer enables lead capture, to create a lead when a new inquiry arrives at a mailbox they nominated. Automated and bulk mail is filtered out rather than captured.gmail.modify). Write access, which we name explicitly because it is broader than reading and sending. The application uses it for a single operation: removing the unread marker from a message it has already processed, so the mailbox reflects what has been handled. It does not label, archive, move, or delete mail. The scope itself cannot permanently delete mail or bypass Trash.https://www.googleapis.com/auth/calendar). Used solely to create, update, and cancel the appointments a business customer books through the application, so that those appointments appear on the calendar they connected. We read existing events only to check availability for that scheduling. We do not read calendar data for any other purpose. This scope applies only where the customer connects a calendar, and the feature can be left off.https://www.googleapis.com/auth/business.manage). Used solely to read customer reviews for the business locations the customer connects and to post replies that the customer wrote or approved. It applies only to the locations they configure. We do not create, edit, or delete any other part of their Business Profile, and we do not post anything the customer has not approved. This scope applies only where the customer connects a location, and the feature can be left off.https://www.googleapis.com/auth/youtube.upload). Used solely to upload a video that the business customer created and scheduled through the application to the YouTube channel they connected. We upload nothing the customer did not schedule.https://www.googleapis.com/auth/youtube.readonly). Used solely to identify the channel the customer connected and to confirm that an upload succeeded. We do not read analytics, comments, or any channel the customer has not connected.How that data is handled:
| Purpose | Data used | Basis |
|---|---|---|
| Providing and operating the application | Account data, contact data, usage data | Performance of contract |
| Sending the emails and texts a customer configured | Contact data, campaign content, connected mailbox | Performance of contract |
| Detecting replies and capturing leads | Connected mailbox content | Performance of contract / consent |
| Measuring deliverability and engagement | Opens, clicks, replies, bounce data | Performance of contract |
| Suppressing bounced, unsubscribed, and undeliverable addresses | Contact data, suppression records | Legal obligation / legitimate interest |
| Authentication and account security | Credentials, session tokens, IP address | Legitimate interest / contract |
| Billing and subscription management | Billing details (via Stripe) | Performance of contract |
| Customer support | Account data, support correspondence | Legitimate interest |
| Fraud and abuse prevention | Email domain, phone, IP, device signals | Legitimate interest |
| Service improvement and debugging | Usage logs, anonymized error reports | Legitimate interest |
| Legal compliance | As required by law | Legal obligation |
We do not use business customer data or contact data for advertising, and we do not sell, rent, or trade personal information to third parties for their own marketing purposes.
We share information only in the circumstances below.
Sub-processors. Depending on the edition and the features a customer enables:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase Inc. | Database and file storage | All stored application data | United States |
| Cloudflare, Inc. | Website delivery, TLS termination, and CDN for our public sites | Web request data, IP address | United States |
| Railway Corp. | Application hosting | Web request data | United States |
| Google LLC | Gmail send, reply detection and mailbox organisation; calendar scheduling; Business Profile review management; and YouTube publishing, where the customer enables them | OAuth tokens, message content, appointment details, review and reply content, uploaded video and channel identifiers | United States |
| Stripe Inc. | Payment processing | Billing information, subscription data | United States |
| Resend Inc. | Transactional email | Recipient address, message content | United States |
| Meta Platforms, Inc. | Publishing to a connected Facebook Page or Instagram account, where enabled | OAuth tokens, post content and media | United States |
| TikTok Inc. | Publishing to a connected TikTok account, where enabled | OAuth tokens, video content | United States |
| Twilio Inc. | SMS and MMS delivery, where enabled | Phone numbers, message content | United States |
| Anthropic PBC | AI assistance features, where enabled | Content submitted to that feature | United States |
Each provider is contractually obligated to protect the data and use it only for the stated purpose. We update this list when we add or remove a provider.
Legal requirements. We may disclose information where required by law, subpoena, court order, or governmental authority.
Business transfers. In a merger, acquisition, or sale of assets, information may transfer to the successor entity. We will give notice before data becomes subject to a different privacy policy.
With your consent. For any other purpose, with your explicit consent.
We do not share, sell, or disclose personal information to data brokers, advertising networks, or any third party for their independent commercial use.
The business customer is the sender of record for every message sent through the platform. As a business customer, you are responsible for obtaining and maintaining any consent applicable law requires before contacting a person, including prior express written consent for SMS marketing under the TCPA. We provide the sending infrastructure, one-click unsubscribe, and suppression tooling; we do not send marketing messages to your contacts on our own behalf. See the Terms of Service for the full allocation of responsibility.
| Data type | Retention |
|---|---|
| Active account data | Duration of the subscription |
| Contact data, campaign history, engagement records | Duration of the subscription, plus 90 days after cancellation |
| Connected-mailbox OAuth credentials | Deleted immediately on disconnection or cancellation |
| Financial and billing records | 7 years, for accounting and tax purposes |
| Suppression and unsubscribe records | Indefinitely. Deleting them is what would let someone be contacted again after opting out |
| Server and usage logs | 90 days, rolling |
| Support correspondence | 3 years |
| Fraud-prevention signals | 12 months after an account closes |
| Encrypted backup copies | Purged on natural rotation, typically within 60 days of deletion from production |
A deletion request removes the identifying email from financial records rather than deleting the transaction record itself, because the underlying record is required for tax and accounting purposes. After the applicable period, data is permanently deleted from production systems.
We use:
No system is perfectly secure. In the event of a breach likely to create risk to your rights, we will notify you as required by applicable law, including California Civil Code §1798.29 and §1798.82.
California residents (CCPA/CPRA). You have the right to know what personal information we hold and how it is used, to request deletion, to request correction, to opt out of sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising, so no opt-out is required, but you may contact us to confirm.
Other states. Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana) have comparable rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising and profiling. We do not conduct targeted advertising or automated profiling that produces legal effects.
How to make a request. Email support@wyzebiz.com. We respond within 45 days and will tell you if we need more time. We may need to verify your identity first. If your data was provided to us by a business customer, we will refer the request to that business customer and assist them in fulfilling it.
The platform is not directed to anyone under 18, and we do not knowingly collect personal information from minors. If we learn we have, we delete it promptly.
WyzeBiz is operated from the United States and intended for US-based businesses. All data is stored and processed in the United States. We do not currently target users in the European Union or other international jurisdictions.
When we make material changes we will post the updated policy with a new effective date and notify active business customers by email at least 14 days before the changes take effect. Continued use after the effective date constitutes acceptance.
Wyze Business Solutions, 1555 Simi Town Center Way, Simi Valley, CA 93065