Privacy Policy
Effective Date: 15 June 2026
1. Introduction
Welcome to Weave ("we", "us", or "our"). We operate the Weave web application, accessible at weave-app.io (the "Service").
This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information. We are committed to protecting your privacy and will never sell or share your personal data with third parties for marketing or commercial purposes.
By using Weave, you agree to the collection and use of information as described in this policy.
2. Who We Are
Weave is operated from Australia. If you have any questions about this policy, please contact us at:
Email: support@weave-app.io
As we grow, we intend to offer our Service to users in the United Kingdom, United States, European Union, and other regions. Where applicable, we comply with the relevant data protection laws of those jurisdictions, including the UK GDPR, EU GDPR, and applicable US state privacy laws.
3. Information We Collect
3.1 Information You Provide via Sign-In
When you create a Weave account, authentication is handled by Clerk (our identity management provider). Clerk supports sign-in via Google, Microsoft, or Apple as identity providers. Through this process we receive:
- Full name
- Email address
We do not receive or store your password.
3.2 Email Account Data
Separately from sign-in, you may connect your Google or Microsoft email account to Weave via OAuth. This connection is used solely to send emails to your contacts on your behalf using templates you create within the Service. The specific permissions we request are:
- Google:
gmail.send,gmail.settings.basic, anduserinfo.email— to send emails from your Gmail account, read your Gmail signature from your mailbox settings (so it can be appended to outgoing emails), and retrieve your Gmail address - Microsoft:
Mail.Send,User.Read, andoffline_access— to send emails from your Outlook account, retrieve your Microsoft account email, and maintain access without requiring you to reconnect each time
We do not read your inbox, access your contacts, or access your calendar through this integration. The gmail.settings.basic permission is used solely to retrieve your email signature; we do not modify your Gmail settings. You may revoke this access at any time via your Google or Microsoft account settings, or within Weave.
3.3 Meeting and Calendar Data
You may connect your Calendly account to Weave via OAuth. Through this integration we access and store:
- Scheduled event data (event titles, times, and meeting types)
- Invitee information (names and email addresses of meeting participants)
- Your Calendly event types and booking links
Weave also subscribes to Calendly webhooks to receive real-time booking notifications. We store invitee names and email addresses in encrypted form.
3.4 CRM Data
You may connect one or more CRM platforms to Weave to power automations and workflows. Supported platforms and their connection methods are:
- HubSpot and Pipedrive — connected via OAuth
- WorkSorted — connected via OAuth
- AdviserLogic — connected via API credentials (API key and password) that you provide directly within Weave
Through these integrations, we may access and store:
- Contact records — names, email addresses, and phone numbers
- Contact dates of birth (where available in your CRM) — used to surface upcoming birthday notifications
- Deal and pipeline data — deal names, values, stages, and close dates (where supported by the platform)
Depending on your connected platform and active workflows, Weave may also write data back to your CRM on your behalf, including notes and newly created client records. All contact PII stored by Weave (including names, emails, and dates of birth) is encrypted at rest. You may revoke CRM access at any time via your CRM provider's settings or within Weave.
3.5 Client Onboarding Forms
You may connect your Typeform account to Weave via OAuth as part of client onboarding workflows. Through this integration, Weave will:
- Create questionnaire forms in your Typeform account on your behalf, based on questions you configure within Weave
- Subscribe to Typeform webhooks to receive client responses when a form is completed
- Process those responses to create or update client records in your connected CRM
Form responses may contain personal information submitted by your clients (such as names, contact details, and any other information requested in the form). This data is processed and passed to your CRM as part of the onboarding workflow. You are responsible for ensuring you have appropriate authorisation from your clients to collect and process their information in this way.
You may revoke Typeform access at any time via your Typeform account settings or within Weave.
3.6 SMS Communications
Weave may send SMS messages to contacts on your behalf as part of workflow automations, using Twilio as our SMS provider. Phone numbers used for this purpose are sourced from your connected CRM data.
3.7 Automatically Collected Information
We may collect standard technical information when you use the Service, such as your IP address, browser type, device information, and usage logs. This information is used solely for operating, securing, and improving the Service.
3.8 Cookies & Analytics
We use cookies and similar technologies to operate and improve the Service. The cookies we use fall into the following categories:
- Essential cookies — required for the Service to function. These include authentication session cookies set by Clerk and a UI preference cookie (
sidebar_state) that remembers whether your sidebar is expanded or collapsed. You cannot opt out of these without losing core functionality. - Analytics — we use Vercel Analytics on our public website to understand aggregate traffic patterns (page views and navigation). Vercel Analytics is designed to be cookieless and does not collect personal identifiers or build individual user profiles.
- Product analytics — we may use PostHog to capture anonymised usage events within the application (such as feature interactions) to help us identify areas for improvement. PostHog data is not used for advertising.
You can clear cookies at any time via your browser settings. Removing essential cookies will require you to sign in again. Vercel Analytics and PostHog data collection can be blocked by browser extensions that restrict tracking scripts.
4. How We Use Your Information
We use the information we collect to:
- Authenticate you and maintain your account
- Provide, operate, and improve the Service
- Display and process your meeting, calendar, and CRM data as part of core features
- Send emails and SMS messages to your contacts on your behalf
- Create client onboarding forms and process completed form responses on your behalf
- Create and update records in your connected CRM as part of workflow automations
- Respond to your support requests
- Ensure the security and integrity of the Service
- Comply with our legal obligations
We do not use your personal data for advertising or sell it to any third party.
5. How We Store and Protect Your Data
We take data security seriously. Your data is protected using the following measures:
- All data is encrypted at rest using double encryption: a master encryption key and a unique per-user encryption key.
- All data in transit is encrypted using TLS (HTTPS).
- Authentication and identity management is handled by Clerk, a trusted third-party identity platform.
While we take all reasonable steps to protect your data, no method of transmission or storage is 100% secure. We will notify you promptly if a data breach occurs that affects your personal information, as required by applicable law.
6. Third-Party Services
We use the following third-party services to operate Weave:
- Clerk — identity and authentication management for sign-in and sign-up
- Google (via OAuth) — sending emails from your Gmail account on your behalf
- Microsoft (via OAuth) — sending emails from your Outlook account on your behalf
- Calendly (via OAuth) — accessing your meeting and scheduling data
- HubSpot (via OAuth) — accessing and updating your CRM contacts, deals, and related data
- Pipedrive (via OAuth) — accessing and updating your CRM contacts, deals, and related data
- WorkSorted (via OAuth) — accessing and updating your CRM clients and related data
- AdviserLogic (via API credentials) — accessing your CRM client data
- Typeform (via OAuth) — creating onboarding forms and receiving form responses on your behalf
- Twilio — sending SMS messages to your contacts on your behalf
- Google Gemini — used to help summarise and structure client onboarding form responses before they are saved to your CRM (this feature is planned and not yet active)
Google API Services User Data Policy:Weave's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Where Weave uses AI services, such as Google Gemini, to process data obtained via Google Workspace APIs, that data is used solely to provide or improve the specific user-facing feature for which it was collected. It is not used to develop, improve, or train generalised or non-personalised AI or machine learning models, and it is not used for advertising purposes.
These providers have their own privacy policies and data practices. We encourage you to review them:
- Google Privacy Policy: https://policies.google.com/privacy
- Microsoft Privacy Statement: https://privacy.microsoft.com
- Clerk Privacy Policy: https://clerk.com/legal/privacy
We do not share your personal data with any other third parties, except as required by law.
7. Data Retention
We retain your personal data for as long as your account is active, or as necessary to provide you with the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required by law to retain it for longer.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you
- Correction — request that inaccurate data be corrected
- Deletion — request that we delete your personal data
- Portability — request your data in a portable format
- Objection — object to certain types of processing
- Withdrawal of consent — revoke OAuth permissions at any time via your Google, Microsoft, Apple, Calendly, HubSpot, Pipedrive, WorkSorted, or Typeform account settings; AdviserLogic credentials may be removed within Weave
To exercise any of these rights, please contact us at support@weave-app.io. We will respond within 30 days.
If you are located in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.
9. Children's Privacy
Weave is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at support@weave-app.io and we will delete it promptly.
10. International Data Transfers
Your data may be processed and stored outside of your home country, including in Australia and the countries where our third-party service providers operate. Where such transfers occur, we ensure appropriate safeguards are in place in accordance with applicable data protection law.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this document and, where appropriate, notify you by email or via the Service. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us at:
Weave
Email: support@weave-app.io
— End of Privacy Policy —