Privacy Policy
Last updated: 6 August 2026
Who we are
webMake is a website builder that lets small businesses generate, edit and publish a site. This policy explains what data we process and why. Questions: admin@webmake.uk.
Data we collect
Account data (email, hashed password), the content of the sites you create, and messages that visitors submit through your published sites (contact/newsletter leads). We also log AI generation activity (a short prompt snippet, timestamp) to enforce fair-use limits.
How we use it
To run the service: authenticate you, store and publish your sites, deliver visitor messages to you, prevent abuse, and improve the product.
Connected social accounts
If you connect Instagram or your Google Business Profile, we store an access token for that account, its id and its public handle. The token is encrypted at rest and is used for exactly two things: identifying which account to post to, and publishing a post you approved. Nothing is ever published without your approval.
We do NOT read your direct messages, your followers, or anyone else’s content; we do not follow, comment or send messages on your behalf; and we never receive your password — the connection is made through the platform’s own consent screen. We also read the reach and engagement figures of posts we published, so the calendar can show you how they did.
The token is kept until you disconnect the account or delete the site, and disconnecting deletes it from our database immediately. See Deleting your data.
Third-party processors
Hosting and database: our own server. CDN, DNS, email routing and privacy-first analytics: Cloudflare — its Web Analytics sets no cookies and stores no per-visitor identifier, and it measures the sites we host as well as our own so we can see whether they are fast. Transactional email: Resend. Payments: Shopier. SMS verification: NETGSM or Twilio. AI text generation: OpenRouter. Images: Pollinations, Pexels and Unsplash. Owner notifications: Telegram. Publishing, only for accounts you connect yourself: Meta (Instagram) and Google. Each processes data only to provide its part of the service, and your data is never sold.
Retention and security
Your data is kept while your account is active; deleting your account or a site removes the related data within a reasonable period. Passwords are stored only as an irreversible hash, access tokens for connected accounts are encrypted at rest, and everything is transmitted over HTTPS.
Cookies
A strictly-necessary session cookie keeps you signed in, and a preference cookie stores your language. We do not use advertising or tracking cookies.
Your rights & contact
You may request access, correction or deletion of your data at any time by writing to admin@webmake.uk. For step-by-step instructions, see Deleting your data.