Privacy Policy
Last updated: May 14, 2026
1. Who We Are
Web Work (webwork.bg) is a website builder. This policy explains what personal data we collect, why, and how we protect it.
2. Data We Collect
Account data: email address and a securely hashed password (bcrypt). We also store the date you registered.
Payment data: payments are processed by Stripe. We store your Stripe customer ID but never see or store your card number. Please see Stripe's Privacy Policy.
Project data: the website content and source files you create through Web Work, including text, images you upload, product listings, blog posts, and configuration.
Chat messages: your conversations with the planning assistant are stored so you can return to them.
Email data: if you use the transactional email feature, we store sender configuration, templates, and delivery logs (recipient address, status, timestamps).
3. Analytics & Tracking
A. Visitor analytics on websites you build with Web Work. When visitors browse a site hosted on Web Work, we collect:
- Page path and referrer URL
- Device type (desktop, mobile, tablet) derived from the user agent string
- A daily visitor identifier — a truncated SHA-256 hash of the visitor's IP address combined with the project ID and the current date. The raw IP address is never stored.
This data helps site owners understand traffic patterns. It is cookieless and is never used for advertising or cross-site tracking.
B. Analytics on the Web Work platform itself (webwork.bg). With your consent — given via the cookie banner — we use the following tools to understand how the platform is used and to measure our advertising:
- PostHog (EU-hosted, eu.posthog.com) — product analytics, heatmaps, and session recordings. Session recordings are video-like replays of your interaction with the platform. Form inputs (passwords, emails) and the contents of your chat with the planning assistant are masked in recordings. Recordings are retained for 30 days.
- Meta Pixel (Meta Platforms, Inc.) — measures conversions from the advertising campaigns we run on Facebook and Instagram. It sets cookies (
_fbp,_fbc) and shares pseudonymous event data (page view, registration) with Meta. Meta is established outside the EEA; transfers rely on the EU-US Data Privacy Framework and Standard Contractual Clauses.
Neither tool loads before you accept the cookie banner. You can withdraw consent at any time by clearing your browser's site data for webwork.bg — the banner will reappear on your next visit.
Cookies and local storage set by the platform: a cookie-consent entry in local storage (your consent choice), ph_* (PostHog, only after consent), and _fbp / _fbc (Meta, only after consent). Authentication uses a JWT token stored in local storage — this is strictly necessary and is not subject to consent.
4. Third-Party Services
- Stripe — payment processing (privacy policy)
- Anthropic (Claude) and OpenAI — content generation. Your planning conversation and project description are sent to these providers to generate your website. See Anthropic's and OpenAI's privacy policies.
- Resend — transactional email delivery (privacy policy)
- Cloudflare — DNS and TLS certificates for custom domains
- PostHog — product analytics, heatmaps, and session recording on the Web Work platform (EU cloud) — only with your consent (privacy policy)
- Meta Platforms (Meta Pixel) — advertising performance measurement on the Web Work platform — only with your consent (privacy policy)
5. How We Use Your Data
- To create and maintain your account
- To generate, build, and host your website
- To process payments and manage subscriptions
- To send transactional emails (verification codes, order notifications) to you and your customers
- To provide analytics about visitors to your hosted site
- To detect and prevent abuse of the platform
- With your consent: to understand how the Web Work platform is used (PostHog) and to measure the performance of our advertising campaigns (Meta Pixel)
We do not sell your data. We do not use it for targeted advertising beyond measuring conversions from ads we run.
6. Data Retention & Deletion
Your account data and project files are retained for as long as your account is active.
- Account deletion (soft delete). You can mark your account as deleted from Settings. Your user record is kept in a deleted state so the email cannot be reused, and your project files are preserved so support can restore the account on request.
- Before deleting your account you must cancel any active improvement plan and hosting subscription via the Stripe customer portal so we never continue billing a deleted account. When you mark the account deleted, all hosted projects are stopped and pending email/password change requests are cleared.
- Permanent deletion. To have your account record and all associated project files permanently erased, email us at support@webwork.bg. We will action the request within 30 days, except for records we are legally required to keep.
- When a project is permanently deleted, its analytics page views and email logs are removed automatically (cascade delete).
- Stripe retains its own payment records independently according to their retention policies.
7. Data Security
Passwords are hashed with bcrypt. Sensitive environment variables (e.g. connected Stripe keys for your project) are encrypted with AES-256-GCM at rest. All traffic is served over HTTPS. We follow industry-standard practices, but no system can guarantee absolute security.
8. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to access, correct, or delete your personal data, restrict or object to processing, and data portability. To exercise these rights, contact us at the email below. We will respond within 30 days.
9. Children
Web Work is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, please contact us so we can delete it.
10. Contact
For privacy questions or data requests, email us at support@webwork.bg.