Privacy Policy
Privacy Policy
Last updated: 17 June 2026
This Privacy Policy explains how Weavely Ltd ("Weavely", "we", "us", or "our") collects, uses, shares, and protects personal data in connection with our website and our software-as-a-service product (the "Service"). Weavely Ltd is a company registered in England and Wales with company number 16331589.
Weavely is an automated data pipeline that moves marketing and advertising data from connected platforms (for example Google Ads, Google Analytics 4, Google Search Console, Meta, TikTok, LinkedIn, and Amazon Ads) directly into a data warehouse owned and controlled by our customer (typically a Google BigQuery project inside the customer's own Google Cloud account).
We are committed to handling personal data lawfully, transparently, and securely, in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, the EU General Data Protection Regulation ("EU GDPR") where it applies, and other applicable data protection laws including, where relevant, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
Please also review our Limited Use disclosure in Section 5, which describes how we comply with the Google API Services User Data Policy.
1. The two roles we play: controller and processor
Because of how Weavely works, we handle personal data in two distinct capacities. Understanding which capacity applies is important to your rights and to our obligations.
Where we act as a data controller. We determine the purposes and means of processing for:
personal data about visitors to our website;
personal data about the individuals who register for, administer, or use a Weavely account ("Account Users"), such as names, work email addresses, and login credentials;
personal data about business contacts, prospects, and partners; and
marketing and communications data.
For this data, this Privacy Policy is the primary description of how we handle it, and you can exercise your rights directly with us.
Where we act as a data processor. When Weavely connects to a customer's advertising and analytics platforms and pipes the resulting data into the customer's own warehouse, that data ("Customer Data") may contain personal data. For Customer Data, our customer is the controller and decides what data is processed and why; we process it only on the customer's documented instructions, under a Data Processing Addendum ("DPA") that forms part of our customer agreement.
If you are an individual whose personal data appears in Customer Data (for example because you interacted with a customer's advertising) and you wish to exercise your rights, please contact the relevant customer, who is the controller. We will assist that customer in responding to your request as required by law. The remainder of this Privacy Policy focuses mainly on the data for which we are the controller; Section 6 describes the Customer Data we process and our role in that processing.
2. Who we are and how to contact us
The controller of your personal data, and the entity behind the Service, is:
Weavely Ltd (registered in England and Wales, company number 16331589) 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom Email: privacy@weavely.io (or info@weavely.io)
We have not appointed a statutory Data Protection Officer because we are not required to do so; however, you can direct any privacy question to the contact above.
You have the right to lodge a complaint with the UK Information Commissioner's Office ("ICO"), the UK supervisory authority (www.ico.org.uk), or with your local EU/EEA supervisory authority. We would appreciate the chance to address your concerns first, so please contact us before approaching a regulator.
3. The personal data we collect (controller role)
We may collect and process the following categories of personal data:
Account and identity data: first and last name, job title, employer or agency name, and the email address used to create or administer a Weavely account.
Authentication and credential data: login credentials for the Service, and the access tokens and refresh tokens issued when you connect a third-party data source to Weavely via OAuth. We treat these tokens as confidential and use them only to operate the pipeline you have configured.
Contact data: business email address, telephone number, and postal or business address.
Usage and technical data: information about how you use the Service and our website, including IP address, browser type and version, device information, log data, time zone setting, pages viewed, and actions taken within the Service.
Billing data: information needed to bill and collect payment for the Service. Card payments are handled by our payment processor; we do not store full payment card numbers.
Marketing and communications data: your preferences for receiving marketing from us and your communications with us.
We do not intentionally collect special category data (such as data revealing racial or ethnic origin, religious beliefs, health, sexual orientation, or political opinions), and we do not collect data about criminal convictions. Please do not configure the Service to send special category data through the pipeline unless you have confirmed you have a lawful basis to do so and have agreed appropriate terms with us.
4. Children
The Service is intended for business use and is not directed at children. You must be at least 16 years old to use the Service. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
5. Third-party platform connections and Google API Limited Use
To operate Weavely, you connect third-party advertising and analytics platforms to the Service. Your use of those connections is also governed by the terms and privacy policies of the relevant platform.
Google API Services User Data Policy and Limited Use. Weavely's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
we access Google user data (for example from Google Ads, Google Analytics 4, and Google Search Console) only to provide and improve the user-facing features of Weavely, namely to move that data into the warehouse you control;
we do not use Google user data for serving advertising;
we do not sell Google user data; and
we do not allow humans to read this data unless we have your affirmative agreement for specific messages, it is necessary for security purposes or to comply with applicable law, or the data has been aggregated and anonymised.
Amazon Selling Partner API. Weavely's use and transfer of information received from the Amazon Selling Partner API ("Amazon Information") adheres to Amazon's Acceptable Use Policy and Data Protection Policy. Specifically:
we access Amazon Information solely to provide the user-facing features of Weavely, namely to deliver that data into the Google BigQuery warehouse you control;
Weavely operates as a pass-through pipeline: Amazon Information is not persisted in any Weavely-owned data store. It is transmitted directly into the customer's own Google BigQuery instance and the only state Weavely retains is encrypted OAuth refresh tokens and minimal operational metadata;
we do not use Amazon Information to train, fine-tune, or improve any artificial intelligence or machine learning models;
we do not allow human review of Amazon Information except where required for security incident response or to comply with applicable law;
we do not sell Amazon Information or share it with any party other than the customer's own warehouse and the infrastructure sub-processors disclosed in Section 8;
you may revoke Weavely's access to your Amazon Seller Central account at any time via your account's authorized applications settings.
Other platforms. Similar principles apply to other connected platforms. We process data obtained from Meta, TikTok, LinkedIn, Amazon Ads, and other connectors solely to deliver the pipeline functionality you have configured, in accordance with each platform's applicable developer and platform terms. We do not use this data to build independent profiles, to retarget, or for any purpose unrelated to delivering the Service to you.
6. Customer Data we process (processor role)
When you configure Weavely, the Service extracts data from your connected platforms and loads it into your warehouse. This Customer Data is determined by you and may include advertising performance metrics, campaign and account identifiers, and, depending on your configuration and the platforms involved, limited personal data.
A defining feature of Weavely is that Customer Data lands in your own cloud project. You retain ownership and control of that warehouse and of the historical data in it. If you stop using Weavely, the data already loaded into your warehouse remains yours.
For Customer Data we act only as your processor and we will:
process it only on your documented instructions, including with regard to international transfers;
ensure that personnel authorised to process it are bound by confidentiality;
implement appropriate technical and organisational security measures (see Section 10);
engage sub-processors only as described in Section 8 and under written terms no less protective than our DPA;
assist you, taking into account the nature of processing, in responding to data subject requests and in meeting your security, breach-notification, and data protection impact assessment obligations;
notify you without undue delay after becoming aware of a personal data breach affecting Customer Data; and
at your choice, delete or return Customer Data held in our systems at the end of the engagement, subject to legal retention requirements. Note that data already loaded into your own warehouse is within your control to retain or delete.
The full terms governing this processing are set out in our DPA.
7. How we use personal data, and our legal bases (controller role)
We use the personal data for which we are the controller only where the law allows. The legal bases we rely on are:
Performance of a contract. To create and administer your account, operate and maintain the pipeline you configure, provide customer support, and bill for the Service.
Legitimate interests. To secure, monitor, and improve the Service; to understand how the Service is used; to communicate with business contacts; and to pursue and grow our business, provided your interests and fundamental rights do not override those interests. You can object to processing based on legitimate interests (see Section 11).
Consent. Where required, for example to send certain marketing communications or to set non-essential cookies. You can withdraw consent at any time.
Legal obligation. To comply with applicable law, including tax, accounting, and lawful requests from authorities.
We will not use your personal data for a new, incompatible purpose without notifying you and, where required, obtaining your consent.
8. Sharing of personal data and sub-processors
We do not sell personal data. We share personal data only as described below.
Service providers and sub-processors. We use trusted third parties to help us run the Service and our business. They process personal data on our behalf under written terms and only as needed to provide their services. Our principal sub-processors include:
Sub-processor | Purpose | Location |
|---|---|---|
Google Cloud Platform (Google LLC / Google Ireland Ltd) | Cloud infrastructure and data processing | EU / US, region as configured |
Anthropic (Claude) | AI-powered features within the Service | United States |
OpenAI (ChatGPT) | AI-powered features within the Service | United States |
HubSpot, Inc. | CRM, customer and marketing communications | United States |
monday.com Ltd | Internal work and project management | EU |
Google Analytics (Google LLC / Google Ireland Ltd) | Website analytics | EU / US |
We maintain a current list of sub-processors and will make it available to customers. Where required by the DPA, we will give customers notice of new sub-processors and an opportunity to object.
Professional advisers and authorities. We may disclose personal data to our advisers, or to regulators, courts, or law enforcement, where required to comply with the law, to enforce our agreements, or to protect our rights, property, or safety.
Corporate transactions. If Weavely is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. We will require any acquirer to honour commitments made in this Privacy Policy or notify you of any material change.
9. International transfers of data
We are based in the United Kingdom. Some of the parties we work with, and some of the regions in which data may be stored, are located outside the UK and the EEA, including the United States.
Where we transfer personal data outside the UK or the EEA, we ensure an appropriate safeguard is in place, which may include:
a transfer to a country covered by UK or EU adequacy regulations;
the UK International Data Transfer Agreement ("IDTA") or the UK Addendum to the EU Standard Contractual Clauses;
the EU Standard Contractual Clauses for transfers from the EEA; and
where applicable, transfer to a recipient certified under the EU-US Data Privacy Framework and its UK extension (the UK-US data bridge), such as our cloud infrastructure provider.
Data residency for Customer Data. Because Customer Data is loaded into your own cloud project, you choose the region in which it is stored. For example, EU or German customers can select an EU region for their warehouse so that pipeline data remains within the EU. We process Customer Data in transit only to the extent necessary to deliver it to the destination you have configured.
You may contact us for more information about the safeguards applied to a specific transfer.
10. How we keep data secure
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, or disclosure. These include encryption of data in transit and at rest, access controls and least-privilege permissions, secure handling and storage of OAuth tokens, network and infrastructure security, logging and monitoring, and regular review of our security practices. Access to personal data is limited to personnel who need it and who are bound by confidentiality obligations. You can read more about our security practices on our Security page: https://www.weavely.io/legal/security.
No method of transmission over the internet or method of storage is completely secure. While we work to protect personal data, we cannot guarantee absolute security. If you believe your interaction with us is no longer secure, please contact us immediately.
11. Your rights
Subject to applicable law, you have the following rights in relation to personal data for which we are the controller:
the right to be informed about how we use your data;
the right of access to your data;
the right to rectification of inaccurate or incomplete data;
the right to erasure in certain circumstances;
the right to restrict processing in certain circumstances;
the right to data portability;
the right to object to processing based on legitimate interests, and to direct marketing at any time; and
rights in relation to automated decision-making and profiling. We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing.
To exercise any of these rights, contact us at privacy@weavely.io. We will not charge a fee unless your request is clearly unfounded or excessive. We may ask you to verify your identity before we act, to protect your data. We will respond within the time limits set by applicable law.
Where the personal data is Customer Data and we act as a processor, please direct your request to the relevant customer (the controller), and we will assist them as required.
California residents. If you are a California resident, you have rights under the CCPA/CPRA, including the right to know what personal information we collect and how we use and disclose it, the right to access and delete it, the right to correct inaccurate information, and the right to opt out of any sale or sharing of personal information. We do not sell personal information and we do not share it for cross-context behavioural advertising. We do not discriminate against you for exercising your rights. To make a request, contact us using the details above; you may use an authorised agent where permitted.
12. Cookies
Our website uses cookies and similar technologies for essential functionality, and, with your consent where required, for analytics and marketing. You can manage your preferences through our cookie banner or your browser settings. For more detail on the cookies we use, see our Cookie Policy: https://www.weavely.io/legal/cookie-policy.
13. How long we keep data
We keep personal data only for as long as necessary for the purposes for which we collected it, including to satisfy legal, accounting, or reporting requirements. Account and contract data is generally retained for the duration of the customer relationship and for a defined period afterwards to meet legal and operational needs. We may retain data for longer where there is an ongoing or anticipated complaint or legal claim. OAuth tokens are retained only while the relevant connection is active and are revoked or deleted when you disconnect a source or close your account.
For Amazon Information specifically, we do not retain it in any Weavely-owned store beyond the duration of a single pipeline run, in line with Amazon's Data Protection Policy retention requirements. Data already delivered to a customer's own warehouse is subject to that customer's own retention policies.
14. Marketing
You will receive marketing communications from us only where you have consented or where we are otherwise permitted to contact you. You can opt out at any time by using the unsubscribe link in our emails or by contacting us. Opting out of marketing does not affect data we hold for other purposes, such as administering your account.
15. Changes to this Privacy Policy
We keep this Privacy Policy under review and will post any updates on this page with a revised "Last updated" date. Where changes are material, we will take reasonable steps to notify you. Your continued use of the Service after an update constitutes acceptance of the revised policy.
16. Interpretation
References to "including" mean "including but not limited to". Email addresses provided in this policy may be used only for the purpose for which they are given. Defined terms have the meaning given to them in this policy or in our customer agreement and DPA.
Own your marketing data. Scale without limits.