Legal
Privacy Policy
Effective date: August 8, 2026 · Last updated: August 8, 2026
On this page
This Privacy Policy explains how WoEngage AI Inc. ("WoEngage," "we," "us," or "our") collects, uses, discloses, and protects personal data when you visit our website, create an account, or use our AI-agentic customer engagement platform (collectively, the "Service"). It should be read together with our Terms & Conditions.
1. Overview & Scope
This Policy applies to personal data we collect: (a) about visitors to our marketing website; (b) about our customers and their authorized users ("Account Data"); and (c) that our customers submit to the Service about their own end users through connected databases, files, or integrations, in order to run engagement campaigns ("Customer Data"). Section 2 explains how these categories are treated differently.
2. Our Role: Controller vs. Processor
For Account Data (e.g., the information you provide when you sign up, your billing details, and your usage of the Service), WoEngage acts as a data controller and this Policy describes that processing in full.
For Customer Data that our customers connect to the Service (for example, records from a SQL/NoSQL database or CSV file containing our customers' own end users, or campaign delivery data sent through connected email/SMS/push providers), WoEngage acts as a data processor (or "service provider"/"processor" under applicable law) acting only on our customer's documented instructions. If you are an end user who received a message sent using WoEngage on behalf of one of our customers, please direct privacy requests to that business directly; we will assist our customer in responding to your request as required by law and any applicable Data Processing Addendum.
3. Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account & profile data | Name, work email, password hash, company name, role | You, at sign-up |
| Billing data | Billing address, plan, transaction history (payment card details are handled by our payment processor and are not stored on our servers) | You, our payment processor |
| Connection credentials | Encrypted database connection strings, API keys/tokens for messaging providers you configure | You |
| Customer Data | Records from your connected SQL/NoSQL databases or CSV files, audience segments, campaign content, delivery/engagement events (opens, clicks, bounces, opt-outs) | You / your connected data sources |
| Usage & device data | Log data, IP address, browser type, pages viewed, feature usage, timestamps | Automatically, via cookies and similar technologies |
| Support communications | Messages, attachments, and metadata when you contact support | You |
4. How We Use Data
We use Account Data and usage data to:
- Provide, operate, maintain, and improve the Service;
- Authenticate you and secure your account;
- Process payments and manage subscriptions;
- Provide customer support and respond to inquiries;
- Send administrative communications (e.g., security alerts, service updates);
- Send product and marketing communications, where you have opted in or as otherwise permitted by law, and which you may opt out of at any time;
- Monitor for fraud, abuse, and violations of our Terms;
- Analyze aggregated, de-identified usage trends to improve product features, including AI/model performance;
- Comply with legal obligations and enforce our agreements.
We process Customer Data solely as necessary to provide the Service functionality you configure — for example, to execute the audience queries, prompts, and campaigns you define, and to deliver messages through the channels you connect. We do not sell Customer Data, and we do not use Customer Data to train models for the benefit of other customers.
5. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area, the UK, or another jurisdiction with similar requirements, we rely on the following legal bases:
- Contractual necessity — to provide the Service you signed up for;
- Legitimate interests — for security, fraud prevention, product improvement, and direct marketing to existing business customers, balanced against your rights;
- Consent — for non-essential cookies and certain marketing communications, which you may withdraw at any time;
- Legal obligation — where processing is required to comply with law.
Where WoEngage processes Customer Data as a processor, the applicable legal basis is determined by our customer as the controller.
8. Data Retention
We retain Account Data for as long as your account is active and for a reasonable period afterward to comply with legal, tax, or accounting obligations, resolve disputes, and enforce our agreements. We retain Customer Data for the duration of your subscription and delete or return it within a reasonable period after termination, in accordance with your instructions and our Terms, unless a longer retention period is required by law. Backups are purged on a rolling schedule.
9. Security
We implement administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction, including encryption in transit (TLS) and at rest for sensitive fields, role-based access controls, least-privilege internal access, audit logging, and regular security reviews. No system is completely secure; if you believe your account has been compromised, contact security@woengage.com immediately.
10. International Data Transfers
We may transfer, store, and process personal data in countries other than your own, including the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on recognized transfer mechanisms such as the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum, together with supplementary technical and organizational measures as appropriate.
11. Your Privacy Rights
Depending on your location, you may have the right to: access the personal data we hold about you; correct inaccurate data; delete your data; restrict or object to certain processing; receive a portable copy of your data; and withdraw consent at any time where processing is based on consent. To exercise these rights, contact us at privacy@woengage.com. We will verify your request and respond within the timeframe required by applicable law. If we process your data as a processor on behalf of a WoEngage customer, we will direct your request to that customer or assist them in responding, as required by our agreement with them.
You also have the right to lodge a complaint with your local data protection supervisory authority.
12. Notice for California Residents
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), California residents have the right to know what personal information is collected, request deletion, correct inaccurate information, opt out of "sale" or "sharing" of personal information (we do not sell or share personal information for cross-context behavioral advertising), and to non-discrimination for exercising these rights. To submit a request, email privacy@woengage.com. We may need to verify your identity before completing a request.
13. Children's Privacy
The Service is intended for business use and is not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@woengage.com and we will take steps to delete it.
14. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and/or a prominent notice on the Service prior to the change becoming effective. The "Last updated" date above reflects the most recent revision.
15. Contact Us & Data Protection Officer
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:
WoEngage AI Inc.
Attn: Privacy Team / Data Protection Officer
Email: privacy@woengage.com