Privacy policy.
Plain language for what Folowise collects, what we never collect, and how you can ask us to delete it. Last updated June 4, 2026.
-
01Scope
What this covers, and who is responsible for what.
This policy applies to FoloEngine and any related services provided by Folowise: this marketing site, the licensing relationship with you, and the control plane your licensed site connects to. FoloEngine is a business service; we deal with companies and their teams, not consumers directly.
It does not cover the websites you run on top of FoloEngine. For your shop's customers, you are the data controller and your own privacy policy applies. Their data lives in your database, on your infrastructure, and never reaches us, so we are neither controller nor processor of it. For the data described below (your account, this site's visitors, and telemetry), we are the data controller.
-
02What we collect
The data that touches our systems.
From licensees: company name, contact name and email, billing details, the URL of each licensed site, the package version it runs, and an activation record created when a site first connects (site URL, package version, timestamp, and the connecting IP address, kept for security auditing).
From visitors to this marketing site: standard server logs (IP address, user agent, page URL, referrer) and anything you voluntarily submit through the contact form (name, email, company, message).
From connected sites: signed telemetry ("heartbeats", roughly every fifteen minutes) containing aggregate counts (for example product, order, and pending-review counts), operational statuses, package version, and technical health metrics such as queue and error-rate summaries. Telemetry identifies your site, never your customers.
-
03What we never collect
Your customers' data does not reach us. By design.
The control plane must never receive: product rows, order line items, customer names, emails, phone numbers, addresses, payment instruments, review text, uploaded files, or payment proof documents. This is enforced by the architecture, not by policy alone: the telemetry message format has no fields for such data and oversized or malformed payloads are rejected before processing. We cannot access your customers' data because it is not on our systems, and any future exception would require a documented architecture change, not a quiet edit to this page.
-
04How we use it
What we do with the data.
We use the data described above to: issue and validate licenses; deliver feature grants to your site; monitor site health and alert you to outages or problems; respond to your messages; process payments and send invoices; secure the service against abuse; debug reported issues; and comply with legal obligations. We do not sell personal data. We do not show ads. We do not use your data to train AI models.
-
05Legal bases
Why we are allowed to process it.
Where data protection law requires a legal basis, ours are: performance of a contract (licensing, telemetry, support, billing); legitimate interest (securing the service, preventing abuse, improving the engine); consent (contact form submissions); and legal obligation (tax and accounting records). Telemetry is necessary to operate the licensing service and is part of the contract between us.
-
06Sharing
Who else sees the data.
We share data only with sub-processors required to run the service (hosting providers, email infrastructure, payment processing for invoices) and only the minimum needed. Each sub-processor is bound by data protection terms. We do not sell or rent personal data to third parties. We disclose data to authorities only when legally compelled, and we will tell you when the law allows us to. A current list of sub-processors is available on request.
-
07Cookies and local storage
What this site stores in your browser.
This marketing site sets only essential first-party cookies: a session cookie and a CSRF protection cookie. Your language choice (English or Arabic) is kept in that session, and your light or dark theme preference is kept in your browser's local storage and never sent to us. We use no third-party analytics, no advertising cookies, and no tracking pixels. Storefronts built on FoloEngine set their own cookies under their own policies.
-
08Retention
How long we keep it.
Account and billing data: the duration of the license plus the period required by tax and accounting law. Contact form submissions: up to twelve months for reply and follow-up. Server logs: up to ninety days. Heartbeat records and health snapshots: a bounded rolling window sized for operational diagnostics, after which they are pruned. Activation and security audit records: the duration of the license plus three years.
Your commerce data is in your own database; we hold none of it, so there is nothing for us to return or delete when a license ends.
-
09Security
How we protect it.
Commerce data stays on your infrastructure by construction, which removes the largest possible breach surface from our side. For everything else: all traffic is encrypted in transit (TLS). Every message between your site and the control plane is signed with HMAC-SHA256, carries a timestamp, and uses single-use values so replayed messages are rejected. License keys are shown once at issuance and stored only as cryptographic hashes; we cannot read them back. Signing secrets are encrypted at rest. Administrative actions inside the control plane are audit-logged, and production access is limited to a small set of named operators. We will notify you promptly of any material security incident affecting your site or your data.
-
10Your rights
What you can ask us to do.
You can ask us to: provide a copy of the personal data we hold about you; correct it if it is wrong; delete it where we no longer need it; restrict or object to how we process it; or hand it over in a portable format. Send a request to info@folowise.com with "Privacy request" in the subject. We respond within thirty days. If you believe we have mishandled your data, you may also complain to your local data protection authority.
-
11International transfers
Where data may live.
The data we hold (account, billing, telemetry, logs) may be processed on infrastructure located outside your country. We use reputable hosting providers with appropriate security and data protection standards, and where the law requires, we put recognized transfer safeguards in place. On request we will tell you where your data is hosted and what safeguards apply. Your commerce data is not affected by any of this: it stays wherever you host your own site.
-
12Changes
How this policy can change.
We may update this policy. Material changes will be announced to your account contact by email before they take effect, and the "last updated" date at the top of this page always reflects the current version. We will never weaken the "what we never collect" commitments in section 03 by policy update alone; that boundary is part of the product's architecture.
-
13Contact
Reach our privacy team.
Privacy questions, data requests, or concerns: info@folowise.com with "Privacy" in the subject. We respond within one business day for routine requests and within thirty days for formal data subject requests.
Also read the terms of service.
License, your responsibilities, telemetry, billing, updates, intellectual property, governing law.