Privacy Policy

Last updated: 25 September 2026

This policy explains what personal data Impact Tech, a sole proprietorship registered in Mumbai, India that owns and operates Weaver ("Weaver", "we", "us"), collects, why we collect it, how long we keep it, who we share it with, and the choices you have. It covers our website at theweaverapp.com and demos.theweaverapp.com (the "Site") and the Weaver software service, including its web app, mobile app, and messaging integrations (the "Service").

1. Our two roles

We handle personal data in two different capacities, and your rights depend on which one applies.

2. Data we collect on the Site

Demo requests and contact forms

When you book a demo we collect your name, company, work email address, phone or WhatsApp number, company size, an optional message, and the page and button you used to reach the form. Submissions are checked by Cloudflare Turnstile to block bots, which processes your IP address and browser signals for that purpose. We also check that your email domain accepts mail. Submissions are stored in a Google Sheet accessible only to the Weaver team and used to follow up with you.

WhatsApp and email

If you message us on WhatsApp or email us, we receive your phone number or email address, your name as shown by that service, and the content of your messages. WhatsApp messages are also handled under Meta's own privacy terms.

Usage and device data

When you browse the Site we collect standard technical data: IP address, browser and device type, operating system, referring page, pages viewed, time on page, clicks and scroll depth, approximate location derived from your IP address, and campaign parameters (UTM tags) in the URL you arrived on. This is collected through Google Analytics, Google Ads conversion tracking and PostHog. See Cookies and analytics.

Short links

Links of the form theweaverapp.com/r/… redirect to a page on the Site. The redirect itself does not log your click. Once you land on the Site, normal analytics apply.

3. Data we collect in the Service

Account data

To create and run a Customer's Weaver app we hold the name, email address, phone number, role and login details of each user the Customer invites, plus the Customer's business name, plan and billing contact.

Customer Content

Whatever the Customer's team enters into their app: records, notes, attachments, comments, voice notes, and messages sent to or from the app through WhatsApp, Slack, Microsoft Teams or email. We process this as a processor, as described in section 1.

Connected services

When a Customer connects another system to Weaver (an existing CRM, a messaging platform, an email account, a webhook), we store the credentials or tokens needed for that connection, encrypted, and exchange data with that system as configured by the Customer.

Service logs

We keep technical logs of requests to the Service, including IP address, user id, timestamp, the action performed and any errors, to run, secure and debug the Service. We also keep an audit trail of changes to records so that Customers can see who changed what.

4. How we use data

We do not sell personal data. We do not use Customer Content to train AI models.

Where the EU or UK GDPR applies, we rely on: contract to provide the Service to Customers and their users; legitimate interests to run and secure the Site and Service, follow up on business enquiries, and measure how the Site is used; consent for non-essential cookies, advertising measurement and marketing messages, which you can withdraw at any time; and legal obligation where the law requires us to keep or disclose data.

Where India's Digital Personal Data Protection Act 2023 applies, we process personal data for the purposes you have consented to or for the legitimate uses the Act allows, such as fulfilling a service you have asked for.

6. AI features

Weaver includes AI features such as answering questions about your data in plain language, turning voice notes into record updates, drafting messages and running automations. To do this, the relevant parts of your prompt and Customer Content are sent to a large language model.

7. Who we share data with

We share personal data only with service providers that process it on our behalf, and only as needed to run the Site and Service:

We may also disclose data where required by law, to protect our rights or the safety of others, or as part of a merger, acquisition or sale of assets, in which case this policy will continue to apply to the data transferred.

8. Cookies and analytics

The Site uses cookies and similar technologies for:

You can block or delete cookies in your browser settings. You can opt out of Google Analytics with the browser add-on and manage Google ad settings at adssettings.google.com. The Service itself uses only the cookies and local storage needed to keep you signed in and remember your preferences.

9. How long we keep data

10. Security

Data is encrypted in transit (TLS) and at rest. Each Customer's data is logically isolated within our multi-tenant runtime. Access to production systems is limited to named team members using multi-factor authentication, and integration credentials are stored encrypted. We keep audit logs of changes to Customer records. No system is completely secure, and if we become aware of a breach affecting your data we will notify you and any regulator as the law requires.

11. Where data is stored

The Service runs on AWS data centres in the United States and India, and the Site and app front end are served through Cloudflare's global network. Our service providers may process data in other countries. Where data leaves the EU, UK or another jurisdiction with transfer rules, we rely on the providers' standard contractual clauses or equivalent safeguards.

12. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive a copy in a portable format, and withdraw consent. To exercise any of these, email us at [email protected]. We will respond within 30 days. You can also complain to your local data protection authority.

If your data sits inside a Customer's Weaver app, we will pass your request to that Customer and assist them, since they control that data.

To unsubscribe from marketing messages, use the link in the message or reply "stop" on WhatsApp.

13. Children

The Site and Service are for businesses and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the Service changes. We will post the new version here with a new "last updated" date, and for material changes we will notify Customers by email or inside the app before they take effect.

15. Contact

Impact Tech (proprietor: Sagar Jagdeep Sodah)
Mumbai, Maharashtra, India
GSTIN: 27ENDPS5256Q1Z2
Email: [email protected]