Last Updated: January 21, 2026
This Privacy Policy explains how Hey Wav, Inc. ("Hey Wav," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use our website, applications, and services (the "Service").
By using the Service, you consent to the practices described in this Privacy Policy.
See our Cookie Policy for more details.
If you sign in via third-party providers (when available), we receive basic profile information they provide
When invited to a workspace, we receive your email address from the inviting user
For our product catalog feature (Radar), we collect publicly available information from brand and product websites:
This information is used to maintain an accurate product database for discovery purposes. We do not collect personal information about individuals from public sources.
For brands: If you represent a brand and wish to request correction, removal, or claim your brand profile, please contact us at support@heywav.com.
During account registration, you may choose to opt in to receive marketing emails by checking the marketing consent checkbox. This is not pre-checked; you must actively consent.
You can unsubscribe from marketing emails at any time by:
Opting out of marketing does not affect transactional emails necessary for the Service.
We share information when you direct us to, such as:
Within a workspace, members can see:
Workspace administrators have additional access to workspace settings and data.
The following may be publicly visible:
We share information with third-party service providers who assist in operating the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication, file storage | All account and content data |
| Stripe | Payment processing, subscriptions | Email, name, payment method details, billing address |
| PostHog | Product analytics (US-hosted) | With consent: user ID, email, name, workspace info, behavior events, page views, device info |
| Resend | Email delivery | Email addresses, email content |
| Cloudflare | Security, CAPTCHA, DDOS protection | IP address, browser characteristics, request patterns for bot detection and firewall |
| Vercel | Website hosting, CDN, DDOS/firewall protection | IP address, device info, browser type, location (city/country from IP), request data |
| Anthropic (Claude) | AI-powered content enrichment | Product/brand information from public sources (admin use only, not user data) |
These providers are contractually obligated to protect your data and use it only for the services they provide to us.
Note on AI services: We use Anthropic's Claude API for enriching product catalog data. Per Anthropic's commercial API terms, inputs and outputs are not used for model training.
If you configure webhooks to send data to external URLs:
We may disclose information if required by law or if we believe disclosure is necessary to:
If Hey Wav is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any change in ownership or use of your personal information.
We retain your data as long as your account is active and as needed to provide the Service.
When you delete content:
When you delete your account:
Usage analytics are retained according to our analytics provider's policies:
You can access your personal data through:
You can update your personal information in:
You can delete:
You can export your data by:
You can request that we limit how we process your data in certain circumstances.
You can object to processing based on legitimate interests.
You can request your data in a portable format (JSON).
Where processing is based on consent, you can withdraw consent at any time.
To exercise any of these rights, contact us at support@heywav.com. We will respond within 30 days.
We implement appropriate technical and organizational measures to protect your data, including:
While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
Your data is primarily processed in the United States. Our service providers also process data in the United States.
| Provider | Location | Transfer Mechanism |
|---|---|---|
| Supabase | United States | Standard Contractual Clauses (SCCs) |
| Stripe | United States | EU-US Data Privacy Framework, SCCs |
| PostHog | United States | Standard Contractual Clauses (SCCs) |
| Resend | United States | Standard Contractual Clauses (SCCs) |
| Cloudflare | Global (CDN) | Standard Contractual Clauses (SCCs) |
| Vercel | Global (US primary) | EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs) |
For international transfers from the EEA, UK, or Switzerland, we rely on:
The Service is not intended for children under 18. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
You can request information about:
You can request deletion of your personal information, subject to certain exceptions.
We do not sell personal information in the traditional sense. However, sharing data with analytics providers may constitute "sharing" under CPRA. You can opt out using our cookie preferences or by enabling Global Privacy Control (GPC) in your browser.
We will not discriminate against you for exercising your privacy rights.
If you are in the European Economic Area (EEA), UK, or Switzerland:
We process your data based on the following legal bases under GDPR Article 6:
| Processing Activity | Legal Basis | Details |
|---|---|---|
| Account creation and management | Contract (Art. 6(1)(b)) | Necessary to provide the Service you requested |
| Storing your content | Contract (Art. 6(1)(b)) | Core functionality you signed up for |
| Transactional emails | Contract (Art. 6(1)(b)) | Necessary for service delivery |
| Analytics (with consent) | Consent (Art. 6(1)(a)) | Only after explicit opt-in; you can withdraw anytime |
| User identification in analytics | Consent (Art. 6(1)(a)) | Separate, explicit consent required |
| Marketing communications | Consent (Art. 6(1)(a)) | Opt-in during registration; you can unsubscribe anytime |
| Security and fraud prevention | Legitimate interest (Art. 6(1)(f)) | Protecting users and the Service from abuse |
| Service improvement | Legitimate interest (Art. 6(1)(f)) | Improving features based on aggregated usage |
| Payment processing | Contract (Art. 6(1)(b)) | Necessary to process your payments |
| Tax and financial records | Legal obligation (Art. 6(1)(c)) | Required by applicable tax laws |
In addition to the rights in Section 6, you have the right to:
You have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or place of the alleged infringement if you believe our processing of your personal data violates the GDPR.
For data protection inquiries, contact us at privacy@heywav.com.
If you are in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD):
We process your data based on:
Contact us at support@heywav.com. We will respond within 15 days as required by LGPD.
If you are in Canada, you have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):
We obtain meaningful consent for the collection, use, and disclosure of your personal information. You may withdraw consent at any time, subject to legal or contractual restrictions.
Contact us at support@heywav.com. We will respond within 30 days.
If you are in South Africa, you have rights under the Protection of Personal Information Act (POPIA):
Contact us at support@heywav.com. We will respond within 30 days.
If you are in Australia, you have rights under the Privacy Act 1988 and Australian Privacy Principles (APPs):
Contact us at support@heywav.com. We will respond within 30 days.
The Service may contain links to third-party websites. We are not responsible for their privacy practices. We encourage you to review their privacy policies.
We may update this Privacy Policy from time to time. When we do:
Continued use of the Service after changes constitutes acceptance.
If you have questions about this Privacy Policy or our data practices, contact us at:
| Category | Examples | Purpose |
|---|---|---|
| Identifiers | Email, name, user ID | Account management, authentication |
| Contact info | Email address | Communications, notifications |
| Profile data | Photo, bio, links | Display on profile, personalization |
| Content | Projects, songs, contacts | Core service functionality |
| Usage data | Page views, clicks, features used | Analytics, improvement |
| Device data | Browser, OS, IP address | Security, optimization |
| Location | Timezone, stated location | Personalization, scheduling |
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Content (active) | Until deleted by user |
| Content (trash) | Until permanently deleted + 30 day backup period |
| Usage analytics | 90 days |
| Security logs | 90 days |
| Payment records | 7 years (tax compliance) |
This Privacy Policy was last updated on January 20, 2026.