Privacy policy
Last updated: 1 October 2026
1. Who we are
Wizeply helps small businesses in Israel automate WhatsApp conversations with their customers, through the official WhatsApp Business Platform. Wizeply is operated by WEBSMITH (Ran Koli), Israel ("we"). This policy covers the Wizeply service and this website.
2. What we collect
2.1 From businesses that use Wizeply (account data)
- The account holder's name and email address.
- A password, stored only as a one-way hash. If you sign in with Google instead, the basic profile Google shares (name, email, picture) and the sign-in tokens Google issues.
- Sign-in session records, including IP address and browser type.
- Your business settings, the automations you build and the message text you approve.
- Your conversations with the setup assistant.
- The identifiers of the WhatsApp Business Account, phone number, Facebook Page and lead forms you connect, and the access tokens Meta issues for them (stored encrypted).
- If you turn on notifications, your browser's notification subscription.
- Records of how the service ran for your account, such as events and errors.
2.2 On behalf of businesses, about their customers
We process this data only to run the business's automations, on the business's instructions.
- WhatsApp: customers' phone numbers, the text of the messages exchanged with the business (for a photo, video or file a customer sends, only its caption), their delivery status, and the media files the business uploads for its own messages.
- Consent: when a customer agreed to receive messages, from which source and with what wording, and every opt-out, such as a customer replying "STOP".
- Meta Lead Ads: if the business connects a lead form, the lead, form, Page and ad identifiers, and only the answers the business maps for its automation, such as name and phone number. We do not keep the other answers.
2.3 This website
This website sets no cookies and uses no analytics or advertising trackers. Our hosting provider may keep standard server logs, such as IP addresses, to operate and secure it.
3. Why we use it
- to provide the service: run automations, send and receive the WhatsApp messages the business set up, and handle its leads;
- to apply consent and opt-outs before messages are sent;
- to secure, maintain and fix the service;
- to contact account holders about the service, including support and alerts;
- to meet our legal duties.
We do not sell personal data, use it for advertising, or use it to train AI models.
4. Our role
- For account data, we decide how it is used and are responsible for it.
- For a business's customer data, the business decides how it is used, and we process it on the business's behalf and only on its instructions. Customers who want to exercise their rights over this data should contact the business. If a request reaches us, we pass it on and help the business respond.
- The business is responsible for having the consent it needs to message its customers (see the terms of service).
5. Service providers and data locations
No provider we use has a data region in Israel. We keep our main data in the EU, in Frankfurt, Germany. Some providers process data elsewhere, including in the United States. We share data with them only to run the service. Some of them are being set up now for the production service.
Vercel
Hosts the Wizeply web app and this website
Where: Not pinned to a region; may include the United States
Neon
Database
Where: EU (Frankfurt, Germany)
Temporal Cloud
Runs automation workflows
Where: EU (Frankfurt, Germany)
Fly.io
Runs our servers
Where: EU (Frankfurt, Germany)
Cloudflare R2
Stores media files
Where: EU
Anthropic
The AI model behind the setup assistant. It receives your conversation with the assistant and your automation settings, not your customers’ messages or leads
Where: United States or global; inputs deleted promptly, except what the law requires us to keep, and except copies held by our service providers under their own policies — including our AI provider, which may keep content flagged in its safety review for longer
Google
Sign-in with Google, if you use it; our own email
Where: Global
Your browser’s push service (for example Google, Apple, Mozilla or Microsoft)
Delivers service alerts to account holders who turn on notifications
Where: Set by the browser vendor
PostHog
Product analytics about how account holders use the app; never customer messages or phone numbers
Where: EU storage; may pass through servers outside the EU
Sentry
Error reports
Where: Chosen at account setup; may be outside the EU
Better Stack
Uptime monitoring and alerts
Where: Chosen at account setup; may be outside the EU
Meta is not our service provider. The business connects its own WhatsApp Business Account and Facebook Page to Wizeply, and Meta processes those messages and leads under its own terms and privacy policy.
6. How long we keep data
- We keep account data and the business's customer data while the business's account is active.
- We do not yet delete data automatically on a schedule. We delete it on request: when a business closes its account or asks us to, we delete its data promptly, as described on the data deletion page.
- Copies in our providers' backups and system logs are removed on their schedules, except what the law requires us to keep, and except copies held by our service providers under their own policies — including our AI provider, which may keep content flagged in its safety review for longer.
- When a business deletes its account, we delete all its data, including consent and opt-out records.
- When a person asks us to delete their data while the business's account is active, we keep only a minimal record that this number asked not to receive messages, so it isn't contacted again.
- We keep records the law requires, such as accounting records, only as long as required.
7. Security
- Connections to the service are encrypted.
- The access tokens Meta issues for your accounts are stored encrypted.
- We verify the signature of every notification Meta sends us before we act on it.
- Each business's data is kept separate. Only that business's account can see it, and the operator only when needed to run or support the service.
- No system is perfectly secure. If a security incident affects your data, we will act and notify as the law requires.
8. Your rights
Under Israel's Privacy Protection Law
- to review the information about you held in a database;
- to ask us to correct or delete information about you that is incorrect, incomplete, unclear or out of date;
- if you receive direct mailing, to ask to be removed from the mailing list.
Under the EU's GDPR, where it applies to you
Access, correction, deletion, restriction, objection and portability, and the right to complain to a data protection authority.
How to use them
- Email us from the address connected to your request. We will reply promptly. For account deletion, see the data deletion page.
- If you are a customer of a business that uses Wizeply, contact the business first; we will help it respond.
- To stop WhatsApp messages from a business, reply "STOP", or block the business in WhatsApp.
- In Israel you can also complain to the Privacy Protection Authority.
9. Data from Meta's platforms
Data we receive from Meta's platforms (the WhatsApp Business Platform, Facebook Pages and Lead Ads) is used only to provide Wizeply to the business that connected it.
- We do not sell or license it, or give it to data brokers.
- We do not use it for advertising or to build profiles of people.
- We do not use it to train AI models.
- We share it only with the service providers above, only to run the service.
- We delete it as described in section 6 and on request.
10. Changes
We will post changes to this policy on this page with a new date. If a change is material, we will email account holders.