Privacy Policy

This policy describes how Wetail handles data and privacy controls.

# Wetail Privacy Policy **Effective Date:** December 8, 2025 **Last Updated:** December 14, 2025 **Document Version:** 1.1 --- ## 1. Introduction This Privacy Policy describes how Wetail, Inc. ("Wetail," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use our e-commerce marketplace platform at wetail.co and related services (collectively, the "Platform"). **Your privacy is important to us.** We are committed to protecting your personal information and being transparent about our data practices. By using the Platform, you consent to the data practices described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Platform. --- ## 2. Information We Collect ### 2.1 Information You Provide Directly **Account Registration Information:** - Full name - Email address (required, must be unique) - Username and password - Phone number - Date of birth - Profile picture (optional) - User type selection (Customer, Seller, Supplier, Admin) **Business Information (for Sellers and Suppliers):** - Business name and legal entity information - Business address and physical location - Tax identification number (stored in encrypted/hashed format) - Business registration documents - Professional licenses and certifications - Business insurance information - Bank account details for payments **Payment Information:** - Credit/debit card information (processed and stored by Stripe, not on our servers) - Billing address - Payment method preferences - Transaction history - Refund and chargeback records **Shipping Information:** - Delivery addresses (primary and additional addresses) - Shipping preferences - Delivery instructions - Tracking preferences and notification settings **Communications:** - Messages sent through our platform messaging system - Customer support inquiries and tickets - Survey responses and feedback - Communications with other users (buyers, sellers, suppliers) - Email correspondence with Wetail **Product and Listing Information:** - Product descriptions, titles, and specifications - Product images and videos - Pricing information - Inventory levels - Product categories and tags - SKU and barcode data ### 2.2 Information Collected Automatically **Usage Data:** - Pages visited and features used - Products viewed, searched, and purchased - Time spent on pages - Click patterns and navigation paths - Shopping cart additions and abandonments - Search queries and filters used - Browsing history on our Platform **Device and Browser Information:** - IP address - Device type, model, and operating system - Browser type and version - Screen resolution and display settings - Device identifiers (advertising IDs, device IDs) - Language preferences - Time zone and location settings **Location Information:** - IP-based approximate location (city, state, country) - GPS location (with your explicit consent) - Shipping and billing address locations - Time zone derived from device settings **Cookies and Similar Technologies:** - Session cookies (essential for platform functionality) - Persistent cookies (for preferences and authentication) - Analytics cookies (to understand usage patterns) - Advertising cookies (for targeted marketing) - Local storage data - Web beacons and pixel tags **Transaction Data:** - Order details and purchase history - Payment amounts and methods - Refund and return history - Dispute and resolution records - Seller performance metrics - Supplier fulfillment data - Shipping carrier and tracking information - Lock-In Deal participation and deposit information - Group buying (Wetail Sales) participation records ### 2.3 Information from Third Parties **Third-Party Integrations:** - Payment data from Stripe (transaction status, fraud indicators) - Shipping data from Shippo (tracking, delivery confirmation) - Product data from AutoDS/Doba (backend inventory and pricing for AI-generated deals) - Authentication data from social login providers (if used) - Analytics data from Google Analytics - Advertising data from marketing partners **Note:** AutoDS and Doba are backend systems used by Wetail's AI to source products and create deals automatically. Customer data is not shared with these services; they only provide product catalog information to the platform. **Verification Services:** - Business verification data from commercial databases - Identity verification results - Credit check results (for net-terms accounts) - Fraud prevention signals from security services **Public Sources:** - Business registry information - Professional licenses and certifications - Court records and legal filings (when relevant) - Social media profile information (if linked) --- ## 3. How We Use Your Information ### 3.1 Platform Operations **Account Management:** - Create and manage user accounts - Authenticate users and maintain session security - Verify user identity and business credentials - Enforce subscription tier features and limits - Process upgrades, downgrades, and cancellations **Transaction Processing:** - Process orders, payments, and refunds - Coordinate order fulfillment and shipping - Track delivery status and provide updates - Handle returns, exchanges, and disputes - Generate invoices and receipts - Process subscription billing **Platform Features:** - Display personalized product recommendations - Show relevant search results - Maintain shopping carts across sessions - Save user preferences and settings - Provide analytics dashboards to sellers/suppliers - Enable messaging between users ### 3.2 Communication **Transactional Communications:** - Order confirmations and shipping notifications - Payment receipts and billing statements - Account verification and password resets - Security alerts and fraud warnings - Dispute notifications and resolution updates - Subscription renewal reminders **Marketing Communications (with consent):** - Promotional emails about sales, deals, and new products - Newsletter subscriptions - Personalized product recommendations - Flash sale notifications - Wetail Sales (group buying) opportunities - Lock-In Deal availability and expiration notices - Platform updates and new feature announcements **Customer Support:** - Respond to inquiries and support tickets - Resolve technical issues and account problems - Handle complaints and disputes - Provide platform usage assistance ### 3.3 Business Operations **Analytics and Insights:** - Analyze platform usage and user behavior - Generate aggregate statistics and trends - Create performance reports for sellers/suppliers - Identify popular products and categories - Measure marketing campaign effectiveness - Optimize platform features and user experience **Fraud Prevention and Security:** - Detect and prevent fraudulent transactions - Identify suspicious account activity - Prevent unauthorized access and data breaches - Enforce platform policies and terms - Investigate violations and abuse - Protect against security threats **AI and Machine Learning:** - Train and improve recommendation algorithms - Optimize pricing and inventory management tools - Enhance search relevance and ranking - Improve fraud detection models - Automate content moderation - Generate marketing content and product descriptions - Predict demand and trends **Legal and Compliance:** - Comply with legal obligations and regulations - Respond to law enforcement requests - Enforce contracts and agreements - Resolve disputes and legal claims - Maintain records for tax and accounting purposes - Conduct internal audits and investigations ### 3.4 Platform Improvement **Product Development:** - Test and improve existing features - Develop new features and services - A/B test different user experiences - Optimize platform performance and speed - Fix bugs and technical issues - Enhance mobile and web applications **Quality Assurance:** - Monitor system performance and uptime - Identify and resolve technical problems - Test new releases and updates - Ensure data accuracy and integrity - Maintain service level agreements --- ## 4. How We Share Your Information ### 4.1 Sharing with Other Users **Public Profile Information:** - Sellers and Suppliers: Business name, profile picture, ratings, reviews, response times - Customers: Username, profile picture (if provided), public reviews **Transaction-Related Sharing:** - Sellers receive buyer's name, shipping address, and contact information for order fulfillment - Buyers receive seller's business name and customer service contact information - Suppliers receive order details from sellers for fulfillment - Platform facilitates communication between parties for transaction support ### 4.2 Service Providers and Partners **Payment Processing:** - Stripe: Payment card information, transaction amounts, billing addresses - Purpose: Process payments, detect fraud, issue refunds **Shipping and Logistics:** - Shippo and shipping carriers: Recipient name, delivery address, package details - Purpose: Generate shipping labels, track packages, coordinate delivery **Product Sourcing (Backend Only):** - AutoDS/Doba: Product catalog data, inventory availability, wholesale pricing - Purpose: Enable AI to automatically source and create deals for the marketplace - Data Flow: One-way from AutoDS/Doba to Wetail (no customer data shared with these services) - Customer Interaction: None - customers only see and purchase from AI-generated deals **Analytics and Marketing:** - Google Analytics: Usage data, device information, page views - Email service providers: Email addresses, communication preferences - SMS providers: Phone numbers for transaction notifications - Purpose: Analyze platform usage, send communications, measure marketing effectiveness **Cloud Infrastructure:** - Amazon Web Services (AWS), DigitalOcean, or similar: All platform data - Purpose: Host platform, store data, ensure availability and performance **Security and Fraud Prevention:** - Fraud detection services: Transaction data, device information, behavioral signals - Identity verification services: Identity documents, business verification data - Purpose: Prevent fraud, verify identities, protect platform security ### 4.3 Business Transfers In the event of a merger, acquisition, sale of assets, or bankruptcy: - Your information may be transferred to acquiring entity - You will be notified via email and platform notice - New entity must honor commitments in this Privacy Policy - You may request account deletion if you object to transfer ### 4.4 Legal Requirements We may disclose your information when required by law or when we believe disclosure is necessary to: - Comply with legal process (subpoenas, court orders, warrants) - Enforce our Terms of Service and other agreements - Protect our rights, property, or safety - Protect the rights, property, or safety of our users or others - Investigate fraud, security issues, or policy violations - Respond to government requests or law enforcement inquiries ### 4.5 Aggregate and De-Identified Data We may share aggregate or de-identified data that cannot reasonably identify you: - Industry benchmarks and trends - Platform usage statistics - Market research and insights - Academic research and studies - Business intelligence and reporting --- ## 5. Data Retention ### 5.1 Retention Periods **Active Accounts:** - Account data: Retained while account is active - Transaction records: Retained for 7 years for tax and legal compliance - Communication logs: Retained for 3 years for dispute resolution - Analytics data: Retained for 2 years for business insights **Closed Accounts:** - Personal data: Deleted or anonymized within 90 days of account closure - Transaction records: Retained for 7 years for legal compliance - Dispute records: Retained until resolution + 3 years - Legal hold data: Retained until legal matter is resolved **Cookies and Tracking Data:** - Session cookies: Deleted when browser is closed - Persistent cookies: Expire after 12 months - Analytics data: Retained for 26 months (Google Analytics default) - Advertising cookies: Expire after 90 days ### 5.2 Legal and Regulatory Requirements Some data must be retained longer to comply with: - Tax regulations (7 years for financial records) - Consumer protection laws (varies by jurisdiction) - Contract law (statute of limitations periods) - Anti-money laundering regulations - Data breach notification requirements ### 5.3 Data Deletion Requests Users can request data deletion: - Account closure deletes most personal data within 90 days - Some data retained for legal compliance (see above) - Data in backups may take up to 6 months to fully delete - Anonymized data may be retained indefinitely - Active disputes or legal holds prevent deletion until resolved --- ## 6. Your Privacy Rights and Choices ### 6.1 Access and Portability **Right to Access:** - Request copy of personal data we hold about you - Review account information in account dashboard - Request detailed data export in portable format (JSON, CSV) - Access transaction history and order details **How to Exercise:** - Access most data through account settings - Submit data access request: [email protected] - Response within 30 days (may extend to 60 days for complex requests) - Identity verification required for security ### 6.2 Correction and Update **Right to Correct:** - Update inaccurate or incomplete personal data - Modify account information, preferences, and settings - Correct business information and payment details - Update shipping addresses and contact information **How to Exercise:** - Update most information through account settings - Contact [email protected] for assistance - Some corrections may require verification ### 6.3 Deletion and Erasure **Right to Delete:** - Request deletion of your personal data (subject to legal exceptions) - Close account and remove associated data - Request removal of specific data elements **Exceptions:** - Data required for legal compliance cannot be deleted - Transaction records retained for tax purposes - Dispute records retained until resolution - Data under legal hold or investigation **How to Exercise:** - Close account through account settings - Submit deletion request: [email protected] - Confirm identity for security purposes - Deletion completed within 90 days (except legal exceptions) ### 6.4 Marketing Opt-Out **Right to Opt-Out:** - Unsubscribe from marketing emails (transactional emails still sent) - Opt-out of SMS marketing messages - Disable push notifications on mobile devices - Limit targeted advertising **How to Exercise:** - Click "Unsubscribe" link in marketing emails - Reply "STOP" to SMS marketing messages - Adjust notification preferences in account settings - Opt-out of interest-based advertising through industry tools: - NAI Opt-Out: optout.networkadvertising.org - DAA Opt-Out: optout.aboutads.info - Cookie settings on our website ### 6.5 Cookie Management **Cookie Controls:** - Accept or reject non-essential cookies through cookie banner - Manage cookie preferences in account settings - Use browser settings to block or delete cookies - Enable "Do Not Track" browser settings (we honor DNT signals) **Impact of Cookie Restrictions:** - Essential cookies required for platform functionality - Disabling cookies may limit features or functionality - Analytics cookies improve platform performance - Advertising cookies enable personalized recommendations ### 6.6 Object to Processing **Right to Object:** - Object to processing of your data for direct marketing - Object to automated decision-making (including profiling) - Object to processing based on legitimate interests **How to Exercise:** - Contact [email protected] with specific objection - We will cease processing unless we have compelling legitimate grounds - Response provided within 30 days ### 6.7 Data Portability **Right to Export:** - Receive your data in structured, commonly used format - Transfer data to another service provider - Export includes: account data, transaction history, messages, listings **How to Exercise:** - Request data export: [email protected] - Specify desired format (JSON, CSV, XML) - Receive export within 30 days - Identity verification required ### 6.8 Withdraw Consent **Right to Withdraw:** - Withdraw consent for optional data processing - Opt-out of AI feature usage - Disable location tracking - Revoke third-party data sharing permissions **How to Exercise:** - Adjust privacy settings in account settings - Contact [email protected] - Withdrawal does not affect lawfulness of prior processing - Some services may become unavailable after withdrawal --- ## 7. International Data Transfers ### 7.1 Cross-Border Transfers **Data Location:** - Primary servers located in United States (California) - Backup servers located in United States and European Union - Content delivery network nodes in multiple countries - Service providers may process data in various locations **Transfer Mechanisms:** - Standard Contractual Clauses (SCCs) for EU data transfers - Privacy Shield successor frameworks (when available) - Adequacy decisions by regulatory authorities - Explicit consent for transfers (when required) ### 7.2 Regional Compliance **European Union (GDPR):** - Lawful basis for processing: Contract, consent, legitimate interests - Data Protection Officer contact: [email protected] - Right to lodge complaint with supervisory authority - Additional rights under GDPR honored **California (CCPA/CPRA):** - California residents have enhanced privacy rights - Right to know what data is collected and shared - Right to opt-out of sale of personal information - Right to non-discrimination for exercising privacy rights - We do NOT sell personal information for monetary consideration **Canada (PIPEDA):** - Consent obtained for collection, use, and disclosure - Accountability for data in third-party possession - Access to personal information upon request - Privacy Commissioner complaints accepted **United Kingdom (UK GDPR):** - Same rights as EU GDPR - ICO (Information Commissioner's Office) oversight - Representative contact: [email protected] **Australia (Privacy Act):** - Australian Privacy Principles (APPs) compliance - Notification of overseas disclosures - OAIC (Office of the Australian Information Commissioner) complaints - Representative contact: [email protected] --- ## 8. Data Security ### 8.1 Technical Safeguards **Encryption:** - SSL/TLS encryption for data in transit (HTTPS everywhere) - AES-256 encryption for data at rest (sensitive data) - End-to-end encryption for payment information - Hashing of passwords (bcrypt with salt) - Encryption of sensitive identifiers (tax IDs, SSNs) **Access Controls:** - Role-based access control (RBAC) for employees - Multi-factor authentication (MFA) for administrative accounts - Principle of least privilege for data access - Regular access reviews and revocation of unnecessary permissions - Segregation of duties for sensitive operations **Network Security:** - Firewalls and intrusion detection systems (IDS) - DDoS protection and rate limiting - Web application firewall (WAF) - Regular security scanning and vulnerability assessments - Isolated production and development environments ### 8.2 Operational Safeguards **Employee Training:** - Regular security awareness training - Data privacy and protection training - Incident response procedures - Confidentiality agreements and NDAs - Background checks for employees with data access **Third-Party Management:** - Vendor security assessments - Data processing agreements (DPAs) - Regular audits of service providers - Contractual security requirements - Incident notification obligations **Monitoring and Response:** - 24/7 security monitoring and logging - Automated threat detection and alerting - Security information and event management (SIEM) - Regular security audits and penetration testing - Incident response plan and team ### 8.3 Physical Safeguards **Data Center Security:** - Physical access controls and surveillance - Biometric authentication for entry - Environmental controls (fire suppression, climate control) - Redundant power and network connectivity - Geographic redundancy and disaster recovery ### 8.4 Incident Response **Data Breach Procedures:** - Immediate containment and investigation - Assessment of scope and impact - Notification to affected users within 72 hours (or as required by law) - Notification to regulatory authorities (as required) - Remediation and corrective actions - Post-incident review and improvement **Breach Notification:** If a data breach occurs, we will: - Notify affected users via email and platform notification - Describe the nature of the breach and data affected - Provide steps users can take to protect themselves - Offer credit monitoring or identity protection services (if appropriate) - Report to relevant authorities within required timeframes --- ## 9. Children's Privacy ### 9.1 Age Requirements **Minimum Age:** - Platform is not intended for children under 18 years old - Users must be 18+ or age of majority in their jurisdiction - We do not knowingly collect data from children under 13 (COPPA compliance) - Parental consent required for users aged 13-17 (where permitted by law) ### 9.2 Compliance with COPPA **Children's Online Privacy Protection Act (US):** - We do not knowingly collect personal information from children under 13 - No accounts created for children under 13 - If we discover data from child under 13, we will delete it promptly - Parents can contact us to review or delete child's information ### 9.3 Reporting Underage Accounts **How to Report:** - Email [email protected] with subject "Underage Account" - Provide username or email address of underage user - We will investigate and take appropriate action - Account will be suspended or deleted if user is underage --- ## 10. Third-Party Links and Services ### 10.1 External Links **Third-Party Websites:** - Platform may contain links to external websites and services - We are not responsible for privacy practices of third parties - Third-party sites have their own privacy policies - We encourage you to review third-party privacy policies **Examples:** - Seller websites or stores - Social media platforms - Payment processors (Stripe) - Shipping carriers - Product manufacturers ### 10.2 Third-Party Integrations **Integrated Services:** We integrate with third-party services for platform functionality: - Stripe for payment processing - Shippo for shipping labels and tracking - AutoDS/Doba for dropshipping automation - Google Analytics for usage analytics - Email service providers for communications **Data Sharing:** - Data shared only as necessary for service functionality - Third parties must comply with data protection agreements - Review third-party privacy policies for their practices - Contact us to opt-out of specific integrations (may limit functionality) ### 10.3 Social Media **Social Login:** - Optional social login (Google, Facebook, Apple) - Requires permission to access basic profile information - We do not post to social media without your permission - Social platforms have separate privacy policies **Social Sharing:** - Users may share products or content on social media - Shared content subject to social platform privacy policies - Public shares visible to social media audiences - We cannot control data collected by social platforms --- ## 11. Cookies and Tracking Technologies ### 11.1 Types of Cookies **Essential Cookies:** - Required for platform functionality - Enable authentication and security - Maintain shopping cart contents - Remember user preferences - Cannot be disabled without breaking platform **Analytics Cookies:** - Understand how users interact with platform - Measure page performance and load times - Identify popular content and features - Improve user experience - Can be disabled in cookie settings **Advertising Cookies:** - Display relevant advertisements - Measure ad campaign effectiveness - Limit ad frequency - Provide personalized recommendations - Can be opted out via cookie settings or industry tools **Functional Cookies:** - Remember user preferences and settings - Enable enhanced features - Provide personalized experience - Can be disabled in cookie settings ### 11.2 Other Tracking Technologies **Web Beacons (Pixels):** - Small images embedded in emails or web pages - Track email opens and link clicks - Measure campaign effectiveness - Can be blocked by email clients or browser extensions **Local Storage:** - HTML5 local storage for enhanced functionality - Stores preferences and cached data - Improves platform performance - Can be cleared through browser settings **Device Fingerprinting:** - Collect device and browser characteristics - Fraud prevention and security - Identify returning users - Less invasive than cookies ### 11.3 Managing Cookies **Cookie Consent:** - Cookie banner displayed on first visit - Options to accept all, reject optional, or customize - Preferences saved and respected on future visits - Can be changed anytime in account settings **Browser Controls:** - Most browsers allow cookie management in settings - Block all cookies, third-party cookies, or specific sites - Delete cookies periodically or on browser close - Enable private/incognito mode to prevent cookie storage **Do Not Track:** - We honor Do Not Track (DNT) browser signals - DNT limits behavioral tracking and targeted ads - Essential cookies still used for functionality - May limit personalization and recommendations --- ## 12. AI and Automated Decision-Making ### 12.1 Use of Artificial Intelligence We use artificial intelligence and machine learning technologies to enhance your experience, improve platform functionality, and maintain security. AI-powered features include: - Product recommendations and personalization - Search ranking and relevance - Fraud detection and prevention - Content moderation and filtering - Customer support assistance ### 12.2 Data Used for AI **AI Training and Improvement:** We use data collected through your use of the platform to train and improve our AI systems. This helps us provide better service, enhanced security, and improved features for all users. **Data Categories Used:** - Browsing and interaction patterns - Purchase history and transaction data - Search queries and preferences - Product interactions and reviews - Account activity information - Communications and feedback - Device and technical information **Processing Method:** Data is processed to train AI models that improve platform functionality. After initial training, personally identifiable information is anonymized or removed from production models, though behavioral patterns learned from the data remain in the system. **Data Retention:** Training data may be retained for the duration necessary to improve and maintain AI systems, typically up to 3 years. Anonymized data may be retained indefinitely for research and model validation purposes. ### 12.3 Your Rights Regarding AI **Control Options:** - Disable personalized recommendations in account settings - Opt-out of personalized content and targeted advertising - Request explanation of automated decisions affecting you - Request human review of automated decisions - Appeal decisions made by AI systems **Limitations:** Certain AI processing is necessary for platform operation and security (such as fraud detection and content moderation) and cannot be disabled while using the platform. **Account Deletion:** You may delete your account at any time. Note that some data may be retained in anonymized form for AI model validation and legal compliance purposes. ### 12.4 Automated Decision-Making **Human Oversight:** Critical decisions affecting your account (such as suspension or permanent restrictions) are reviewed by human staff. You have the right to request human review of any automated decision and to receive an explanation of the logic involved. **AI Accuracy Disclaimer:** AI systems may occasionally produce inaccurate, incomplete, or unexpected results. We do not guarantee the accuracy of AI-generated recommendations, content, or decisions. Users should verify important information independently and exercise their own judgment when relying on AI-assisted features. **Contact:** For questions about AI processing or to exercise your rights, contact [email protected] --- ## 13. Changes to Privacy Policy ### 13.1 Policy Updates **Right to Modify:** - We reserve the right to modify this Privacy Policy at any time - Material changes will be communicated via email and platform notifications - "Last Updated" date at top of policy reflects most recent changes - Continued use after changes constitutes acceptance **Notice Period:** - Material changes: 30-day notice before effective date - Non-material changes: Effective immediately upon posting - Emergency changes (security, legal): Effective immediately with notice ### 13.2 Notification Methods **How We Notify:** - Email to address on file - Prominent notice on platform homepage - In-account notification banner - Pop-up or modal on login (for significant changes) **Your Options:** - Review changes and continue using platform (acceptance) - Contact us with questions or concerns - Close account if you disagree with changes - Exercise opt-out rights for new processing activities --- ## 14. Contact Us ### 14.1 Privacy Inquiries **General Privacy Questions:** - Email: [email protected] - Phone: 1-855-WETAIL-6 (1-855-938-2456) - Mail: Wetail Privacy Team, 123 Commerce Street, Suite 500, San Francisco, CA 94105, USA **Data Subject Requests:** - Access, correction, deletion, portability requests - Online portal: wetail.co/privacy/request - Email: [email protected] with "Data Request" in subject - Response within 30 days (may extend to 60 days for complex requests) ### 14.2 Data Protection Officer **EU/UK Data Protection Officer:** - Email: [email protected] - Mail: Data Protection Officer, Wetail, Inc., 123 Commerce Street, Suite 500, San Francisco, CA 94105, USA **Regional Representatives:** - EU Representative: [email protected] - UK Representative: [email protected] - Australia Representative: [email protected] ### 14.3 Regulatory Authorities **Right to Complaint:** You have the right to lodge a complaint with your local data protection authority: **European Union:** - Contact your national supervisory authority - List available at: edpb.europa.eu **United Kingdom:** - Information Commissioner's Office (ICO) - Website: ico.org.uk - Phone: 0303 123 1113 **California (USA):** - California Attorney General - Website: oag.ca.gov - Privacy Rights complaint form available online **Canada:** - Office of the Privacy Commissioner of Canada - Website: priv.gc.ca - Phone: 1-800-282-1376 **Australia:** - Office of the Australian Information Commissioner (OAIC) - Website: oaic.gov.au - Phone: 1300 363 992 --- ## 15. Additional Information for Specific Jurisdictions ### 15.1 California Residents (CCPA/CPRA) **Your California Rights:** **Right to Know:** - Categories of personal information collected - Sources of personal information - Business/commercial purposes for collection - Categories of third parties with whom we share - Specific pieces of personal information collected about you **Right to Delete:** - Request deletion of personal information (subject to exceptions) - Exceptions: Legal compliance, fraud prevention, service provision **Right to Opt-Out:** - We do NOT sell personal information for monetary consideration - We may share data for targeted advertising (can opt-out) - Do Not Sell My Personal Information: [email protected] **Right to Non-Discrimination:** - No discrimination for exercising CCPA rights - Same prices, services, and quality regardless of privacy choices **Shine the Light:** - Annual request for list of personal information shared with third parties for direct marketing - Contact: [email protected] **How to Exercise Rights:** - Submit request: wetail.co/privacy/ccpa or [email protected] - Verify identity for security - Response within 45 days (may extend to 90 days) - No charge for up to 2 requests per 12 months ### 15.2 European Union Residents (GDPR) **Your GDPR Rights:** **Right to Access:** - Confirm whether we process your personal data - Obtain copy of personal data - Receive supplementary information about processing **Right to Rectification:** - Correct inaccurate personal data - Complete incomplete personal data **Right to Erasure (Right to be Forgotten):** - Request deletion of personal data (subject to legal exceptions) **Right to Restriction:** - Limit how we use your personal data in certain circumstances **Right to Data Portability:** - Receive personal data in structured, machine-readable format - Transfer data to another controller **Right to Object:** - Object to processing based on legitimate interests or direct marketing - Object to automated decision-making and profiling **Legal Basis for Processing:** - Contract: Necessary to fulfill our agreement with you - Consent: You have given clear consent for specific purpose - Legitimate Interests: Processing necessary for our legitimate interests - Legal Obligation: Necessary to comply with legal requirements **International Transfers:** - Standard Contractual Clauses (SCCs) for transfers outside EEA - Adequacy decisions recognized - Additional safeguards implemented **Data Protection Officer:** - Contact: [email protected] - EU Representative: [email protected] **Supervisory Authority:** - Right to lodge complaint with lead supervisory authority - Irish Data Protection Commission (our lead authority in EU) - Contact your national authority in your country ### 15.3 United Kingdom Residents (UK GDPR) **Your UK Rights:** - Same rights as EU GDPR (see above) - UK ICO as supervisory authority - Contact: [email protected] - ICO complaints: ico.org.uk ### 15.4 Canadian Residents (PIPEDA) **Your Canadian Rights:** **Access:** - Request access to personal information - Receive information about how data is used **Correction:** - Request correction of inaccurate information - Challenge accuracy of information **Consent:** - Withdraw consent for optional processing - Opt-out of marketing communications **Complaint:** - Lodge complaint with Privacy Commissioner of Canada - Website: priv.gc.ca **Contact:** - Canadian Privacy Officer: [email protected] ### 15.5 Australian Residents (Privacy Act) **Your Australian Rights:** **Access and Correction:** - Request access to personal information - Request correction of inaccurate or out-of-date information **Complaints:** - Lodge complaint with us first - Escalate to OAIC if unresolved - Website: oaic.gov.au **Overseas Disclosure:** - Personal information may be disclosed to overseas recipients (US, EU) - Standard Contractual Clauses and safeguards applied **Contact:** - Australian Privacy Officer: [email protected] --- ## 16. Glossary **Personal Information/Personal Data:** Information that identifies or can be used to identify an individual. **Processing:** Any operation performed on personal data, including collection, storage, use, and deletion. **Controller:** Entity that determines purposes and means of processing personal data (Wetail is the controller). **Processor:** Entity that processes personal data on behalf of controller (our service providers). **Consent:** Freely given, specific, informed, and unambiguous indication of agreement to processing. **Legitimate Interests:** Processing necessary for legitimate business purposes that do not override individual rights. **Data Subject:** Individual whose personal data is processed. **Supervisory Authority:** Independent public authority that monitors GDPR compliance. --- ## 17. Document Information **Document Control:** - **Prepared by:** Wetail Privacy and Legal Teams - **Approved by:** [TO BE UPDATED BY LEGAL COUNSEL] - **Next Review Date:** Quarterly review scheduled - **Version History:** Available upon request - **Effective Date:** December 8, 2025 - **Last Updated:** December 8, 2025 **Language:** This Privacy Policy is provided in English. Translations may be provided for convenience, but the English version governs in case of conflicts or discrepancies. **Questions:** If you have questions about this Privacy Policy or our privacy practices, please contact us at [email protected] --- **BY USING THE WETAIL PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THIS PRIVACY POLICY.** **IF YOU DO NOT AGREE TO THIS PRIVACY POLICY, YOU MUST NOT ACCESS OR USE THE WETAIL PLATFORM.**