This policy explains what personal data Widgetjoy handles, why, how long we keep it, who else sees it, and your rights. It uses the words defined in our Terms.
Who we are
Widgetjoy ("we", "us") runs widgetjoy.com. Write to us at [email protected].
- For our own purposes we are the controller: the accounts of our Customers, people who try Widgetjoy without an account, visitors to widgetjoy.com, and people who write to us. This policy covers that data.
- For what Visitors send through a Customer's Widgets we are a processor. The Customer decides what their Widgets ask for and what happens to the answers, under our Data Processing Addendum. If you sent something through a widget on somebody else's website, please contact that website first.
What we collect, and why
| What | Why | Legal basis |
|---|---|---|
| Your name, email address and password (stored only as a hash), and whether you confirmed the address | To create your account, sign you in and write to you about it | Contract |
| Your Workspace: its Sites, Widgets and their published versions, settings, agent tokens (stored only as a hash), the addresses of websites where your Widgets appeared, and a history of who changed what | This is the service you use; the history lets you and us look into problems | Contract; legitimate interests (security) |
| Monthly usage totals: views and messages | To run the service and, later, to apply plan limits | Contract |
| A session while you are signed in, without your IP address or browser | To keep you signed in | Contract |
| A widget you build before you have an account, or before you have added your website, with the template it started from, under a random code only your browser holds | So you can try Widgetjoy and keep what you made when you sign up or publish | Steps before a contract; legitimate interests |
| Counts of sign-in, sign-up and similar attempts, under a keyed hash of your IP or email address, never the address itself | To stop abuse | Legitimate interests (security) |
| Emails you send us | To answer you | Legitimate interests |
On widgetjoy.com we run no analytics or advertising, and our pages load nothing from other companies. Our application does not store your IP address or write it to its logs; it holds it briefly to limit abuse. A click on the "Made with Widgetjoy" badge, and a widget started after it, are added to daily counts that hold nothing about you. The editor on our widget pages keeps what you build in it as a widget built without an account, described above, and you can create your account from it. The example forms on our pages are demonstrations, and what you type into them is not kept.
On a Customer's website, a Visitor's browser asks our server for the Widget, so we receive the Visitor's IP address, browser details and the page's address. IP addresses are used only to limit abuse and are never stored. Page views are counted for the Customer's usage totals, with no identifier stored in the Visitor's browser. What a Visitor sends, with the path of the page it was sent from, is Customer Data, processed as the DPA describes. We do not profile Visitors or follow anybody across websites.
Cookies and browser storage
We use only what is needed for what you asked for, so we show no consent banner.
| Name | Where | What it does | How long |
|---|---|---|---|
__Host-wj_session cookie | Dashboard and widgetjoy.com | Keeps you signed in | Up to 7 days after you last used it |
wj_signed_in cookie | Dashboard and widgetjoy.com | Says "signed in", with no identifier, so our website offers you the Dashboard | 30 days, removed when you sign out |
widgetjoy-theme, widgetjoy-sidebar, widgetjoy-site | Dashboard and widgetjoy.com | Remember your theme, a folded sidebar and the website you chose to look at | Until you change or clear them |
widgetjoy:, widgetjoy:, widgetjoy:, widgetjoy: | Dashboard and widgetjoy.com | Keep a widget you are building without an account, edits not saved yet, and where you were in its editor | Until you publish or save them, the draft expires, or you close the tab |
widgetjoy: | A Customer's website | Keeps an announcement bar or a countdown closed after a Visitor closes it | Until the Visitor clears it |
The script that loads Widgets on a Customer's website sets no cookies.
How long we keep it
- Your account and Workspace
- Until you delete them in Settings
- What Visitors sent
- Until the Customer deletes it or the Workspace. Deleting a Site or a Widget does not delete its messages
- A widget built without an account
- 30 days after the last change, or a day after it joins a Workspace
- Sessions
- Up to 7 days after you last used one
- Technical records: one-time links, abuse counters, page-view counts, and messages and emails waiting to be sent
- Deleted automatically, most within a day and all within 40 days
- Daily view counts for each Widget, which hold nothing about Visitors
- 400 days, or until the Workspace is deleted
- Emails you send us
- No more than two years after the conversation ends
Who else sees it
Our hosting provider, and Cloudflare, which carries our network traffic and delivers our email, process personal data for us only to provide their service; see the sub-processors page. Cloudflare is based in the United States, and transfers to it rely on the EU–US Data Privacy Framework and the European Commission's Standard Contractual Clauses.
We also share personal data with a Customer when it is their Customer Data; with an agent a Customer connects, which acts with the access of the person who connected it; when the law requires it; and with a new owner if Widgetjoy is sold or merged, who is bound by this policy.
We do not sell personal data, share it for advertising, or use what Visitors send to train AI models.
How we protect it
Connections are encrypted, passwords and tokens are stored only as hashes, and every request is checked against the Workspace it belongs to. If a breach affects your personal data, we will tell you without undue delay, and the authorities where the law requires it.
Your rights
You may access, correct, delete or download your personal data, restrict or object to how we use it, and complain to your data protection authority. Most of it you can do yourself in Settings → General: Download everything gives you one file with your Workspace, and Delete your account erases it with your Workspace. For anything else, write to [email protected]; we answer within one month. Visitors should first contact the website they sent their information to.
We make no decisions about anybody by automated means alone.
Children
Widgetjoy is for businesses and not meant for anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.
Emails and changes
We only email you about your account and Workspace: confirming your address, resetting your password, new messages from Visitors (which you can turn off in Settings) and confirming a deletion. No newsletters, no marketing.
When we change this policy, we update the date at the top, and tell you before a change that matters takes effect.