WeHearYou

Privacy Policy

What personal information WeHearYou collects, why, who it is shared with, and the choices you have. It covers the people who use WeHearYou and the customers those businesses contact through it.

Version
2026-09-29
Effective
29 September 2026

1. Who this policy covers

WeHearYou ("we", "us") provides software that helps businesses ask their customers for reviews, collect feedback and video testimonials, reply to reviews, and show reviews on their websites. This policy applies to wehearyou.online, wehearyou.app, and the review request, feedback and recording pages we host for businesses.

It covers two groups of people:

  • Account users — the business owners, staff and agency users who sign up for and use WeHearYou.
  • Recipients — the customers a business contacts through WeHearYou, including anyone who opens a review request, leaves feedback, or records a video testimonial.

2. Our role for recipients' information

When a business uploads or adds its customers and sends them requests, that business decides whom to contact and why. For that information we act as a service provider (a processor) on the business's behalf, and we use it only to run the service for that business.

If you received a message from a business through WeHearYou and want to know why, or want your information removed, the quickest route is to contact that business directly. You can also contact us, and we will pass your request on and help where we can.

Where the business is a healthcare provider covered by HIPAA, our handling of that information is also governed by the Business Associate Agreement between us and that provider.

3. Information we collect

From account users:

  • Account details — name, email address, a hashed password, your organisation and its locations, and your role.
  • Billing details — billing contact and subscription information. Card details are collected and held by Stripe, not by us.
  • Connected accounts — when you connect a Google Business Profile or Facebook Page, access tokens (stored encrypted) and the public business, review and rating information those platforms provide.
  • Content you create — campaigns, message templates, widget settings, replies, notes, and uploaded logos or images.
  • Security and usage records — sign-in events, actions taken in your account, and the IP address of requests, used for the audit trail and to prevent abuse.

3a. Information about recipients

Provided by the business, or by the recipient when they respond:

  • Contact details — name, email address and mobile number.
  • Responses — star ratings, written feedback, and reviews submitted through our pages.
  • Video testimonials — the recording, including image and voice, and anything said in it.
  • Message history — which requests were sent, when, by which channel, and whether they were delivered, opened or answered.
  • Opt-out status — if you reply STOP or unsubscribe, we keep a record so you are not contacted again.

4. How we use it

We use personal information only to:

  • Provide the service — send review requests by email and text, route responses, publish reviews a business chooses to show, and sync reviews from connected platforms.
  • Operate accounts — authentication, billing, customer support, and service announcements.
  • Keep the service safe — rate limiting, fraud and spam prevention, protecting shared sending infrastructure, and investigating misuse.
  • Generate AI assistance a business asks for — review summaries, suggested replies, and rewording of feedback (see section 5).
  • Meet legal obligations and enforce our Terms of Service.

5. Artificial intelligence features

When a business uses AI features, the relevant review or feedback text is sent to Google's Gemini API to produce a draft. The output is a suggestion for the business to review before anything is published.

We do not use review content, private feedback or video testimonials to train machine learning models, our own or anyone else's.

6. Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

We share it only with the service providers listed in the schedule below, each of which receives only what its function requires and is bound by written terms; with the business that sent a request (for recipients' information); when required by law or to protect rights and safety; and with a successor if WeHearYou is merged or sold, under the same protections.

Reviews and testimonials are shown publicly only where the business chooses to display them, for example in a website widget or on its review page.

7. Text messages

Text messages are sent on behalf of the business named in the message, to people that business says have agreed to be contacted. Message frequency varies, usually one request with at most a reminder or two per visit. Message and data rates may apply.

Reply STOP to any message to stop receiving texts from that business, or HELP for help. Opting out of texts does not opt you out of email, and the reverse is also true.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party, except the SMS provider that delivers the messages.

8. Cookies

The WeHearYou app uses essential cookies to keep you signed in and to protect forms against forgery. It does not use advertising or cross-site tracking cookies.

Our marketing site at wehearyou.online does not set advertising cookies. Its fonts are loaded from Google Fonts, which receives your IP address when the page loads.

9. How long we keep it

Account information is kept while the account is active. After an account ends, its data remains available for export for thirty days and is then deleted or de-identified within ninety days, except where the law requires us to keep it longer.

A business can delete individual contacts, feedback and testimonials at any time. Opt-out records are kept for as long as needed to honour them. Information may persist in routine backups until those backups expire.

10. Security

All connections to the service are encrypted, the database is encrypted at rest, third-party access tokens are encrypted by the application, each organisation's data is restricted to its own users, and sign-ins and account actions are logged. No system is perfectly secure; if an incident affects your information, we will notify you or the business responsible as the law requires.

11. Your choices and rights

You can ask to access, correct, export or delete your personal information, and you can withdraw consent to being contacted at any time. Depending on where you live, including California and other US states with privacy laws, you may have additional rights, and you will not be treated differently for using them.

Account users can update most information in their account settings. For anything else, email us at the address below or follow the steps on our data deletion page at wehearyou.app/data-deletion. We will verify the request before acting on it. If your information was added by a business, we may refer your request to that business, as it controls that information.

12. Children

WeHearYou is a business service and is not directed to children under 13. We do not knowingly collect personal information from them. If you believe a child has submitted information through a WeHearYou page, contact us and we will delete it.

13. Where information is stored

WeHearYou is operated from the United States, and information is stored and processed in the United States. If you use the service from elsewhere, your information will be transferred to the United States.

14. Changes to this policy

We will update this policy when our practices change. Each version is dated. If a change materially affects how we use personal information, we will notify account holders by email or in the app before it takes effect.

15. Contact

Questions or requests about privacy: info@novaadvertising.com. WeHearYou is made in Fairfax, Virginia, by NOVA Advertising.

Schedule — subprocessors

Third parties that receive customer or patient data in the normal operation of the service.

SubprocessorPurposeData received
NeonPrimary database hosting (US-East-1)All stored customer and patient records
VercelApplication hosting and file storageAll request traffic; uploaded logos, images and recorded video testimonials
ResendTransactional email deliveryPatient name and email address, message content
TwilioSMS deliveryPatient name and mobile number, message content
Google (Business Profile API)Review synchronisation and reply publishingPublic review content, reply text, business identifiers
Google (Gemini API)Review summaries, suggested replies, feedback rewritingReview text and private feedback text submitted for processing
MetaFacebook page rating synchronisationPublic recommendation content
StripeSubscription billingBilling contact and payment details only — no patient data

Version 2026-09-29. Earlier versions are available on request.