Legal
Privacy Policy
Who we are, what personal data we collect and why, who processes it and where, how long we keep it, and how to get a copy of it or have it erased.
Last updated: October 2026 · Joorus Inc. (Best Webby) · Controller for account data · Processor for merchant customer data
Who we are
BestWebby is operated by Joorus Inc., trading as Best Webby (“we”, “us”, “our”), 250 Consumers Road, Suite 908, Toronto, Ontario M2J 4V6, Canada. You can reach us about anything in this policy at [email protected].
We are the controller of the personal data described in this policy: data about the businesses that hold a BestWebby account and the people who use it, visitors to bestwebby.com and the dashboard, and people who contact us or ask about the platform.
For the data merchants hold about their own customers — shoppers, orders, messages — the merchant is the controller and we are their processor, acting on their instructions under our Data Processing Agreement. If you bought from a store that runs on BestWebby, that store's privacy notice explains how it uses your data, and requests about it go to the store first.
Privacy officer
Our Privacy Officer is accountable for how we handle personal data and for this policy. Write to the Privacy Officer at [email protected], or by post to Joorus Inc., 250 Consumers Road, Suite 908, Toronto, Ontario M2J 4V6, Canada, marked “Privacy Officer”.
What we collect
We collect information you provide directly:
- Account registration information (name, email, phone number, business name and address)
- Payment and billing information (processed by Stripe — we do not store card data)
- Business and product information uploaded to the Platform
- Messages you send us, including through the contact form, and sales enquiries
We collect automatically:
- Usage and analytics data in the dashboard (pages visited, features used)
- Technical information (browser, device, IP address) in server and security logs
- Cookies, as described below
How we use your data, and the legal basis
We use personal data only for the purposes below. For people in the EEA, the UK or Switzerland, each purpose has the legal basis shown.
- Providing your account and the platform, including support — performance of our contract with you (GDPR Art. 6(1)(b)).
- Billing, invoices, tax and accounting records — our contract with you, and our legal obligations (Art. 6(1)(b) and (c)).
- Service and security messages, such as sign-in alerts, invoices and notices about your account — our contract with you, and our legitimate interest in keeping accounts secure (Art. 6(1)(b) and (f)).
- Answering contact-form messages and sales enquiries, and preparing quotes — steps you ask us to take before entering a contract, and our legitimate interest in answering enquiries (Art. 6(1)(b) and (f)).
- Security, fraud and abuse prevention, including screening product listings and investigating abuse reports — our legitimate interest in protecting the platform, merchants and shoppers, and our legal obligations where they apply (Art. 6(1)(f) and (c)).
- Understanding how the dashboard is used, to improve it — our legitimate interest in improving the product (Art. 6(1)(f)).
- News about BestWebby by email — only with your consent, or where the law allows it for existing customers (Art. 6(1)(a) or (f)). Every such email lets you unsubscribe.
- Meeting legal requirements and defending legal claims — our legal obligations and legitimate interests (Art. 6(1)(c) and (f)).
In Canada, we collect, use and disclose personal information for these purposes with your consent, which you can withdraw subject to legal and contractual limits. We do not sell personal data.
Automated suggestions and analysis
Some features draft or analyse text and images using language and image models run by outside providers — for example suggested replies to customer messages and reviews, support and dispute assistance, listing screening, reading invoices and images, and image generation. When a feature is used, the text or image it needs is sent to one of the model providers listed under who processes your data to produce the result.
Storefront voice search works the same way: when a shopper uses the microphone, the voice clip is sent to our speech-to-text provider to be turned into text, and is not kept by us.
We do not use your data, or your customers' data, to train models. A model's output is a suggestion: nothing that has a legal or similarly significant effect on you is decided by a model alone, and a listing held by screening is decided by a person.
Who processes your data
We use the following service providers, who process personal data for us under contract and only on our instructions:
- Hetzner Online GmbH (Germany) — Hosting. Platform data, including databases, files and backups, is stored in its EU data centres.
- Cloudflare, Inc. (United States, with a global edge network) — DNS, CDN, bot protection and DDoS mitigation. Traffic to the platform and to storefronts passes through it.
- Stripe, Inc. (United States) — Billing for the platform itself. Your customers pay into your own Stripe account, which you contract with directly.
- Google LLC (Gemini API) (United States and other countries where Google operates) — Language and image models behind suggested replies to customer messages and reviews, support and dispute assistance, listing screening, reading invoices and images, and image generation. It receives the text or image the feature needs.
- Groq, Inc. (United States) — Language models for the same features, and speech-to-text for storefront voice search. It receives the text a feature needs, or the voice clip a shopper records to search.
The same list, with the transfer safeguard for each provider, is kept up to date on our security page. We also disclose personal data to professional advisers, to authorities where the law requires it, and to a buyer or successor if our business is transferred, subject to this policy.
International transfers
Platform data is stored in the European Union, in Germany. Joorus Inc. is established in Canada, which the European Commission and the UK recognise as providing adequate protection for organisations subject to PIPEDA. Some providers above process data in the United States. For those, we rely on the EU-U.S. Data Privacy Framework (with its UK Extension and the Swiss-U.S. framework) where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses with the UK International Data Transfer Addendum. You can ask us for a copy of the safeguards at [email protected].
Cookies
bestwebby.com uses no analytics or advertising cookies. Our network provider may set a strictly necessary security cookie to tell people from bots.
The dashboard (dashboard.bestwebby.com) uses strictly necessary cookies to keep you signed in and to protect your account. With your permission, it also measures how the dashboard is used, with product-analytics software we host on our own servers, so that data does not go to a third party. The dashboard asks first, and the analytics does not load unless you allow it. We keep your answer in one cookie for 12 months, then ask again. You can change it at any time with “Cookie choice” in the dashboard menu. When you allow it, the analytics keeps a random visitor number in a cookie and in your browser’s local storage, so it can recognise a returning visit; it lasts up to 12 months. If you withdraw, or your answer lapses, both are deleted. It never runs on our legal pages or on payment and feedback links.
Storefronts are run by the merchants who own them. Each store asks its visitors for their cookie choices and decides which analytics or advertising tools it uses.
Data retention
We retain account data for the duration of your subscription plus 90 days after cancellation. If you close your account yourself, you can restore it within those 90 days; after that it is deleted. You may request immediate erasure at any time, except for the billing and legal records described below.
If an invoice is still unpaid 15 days after we send its payment link, your account is disabled. You can still sign in to pay and to export your data while it is disabled. An account that stays disabled is deleted 30 days after it was disabled. We warn you 14, 7 and 2 days before deletion, and we do not delete the account until each of those warnings has been sent. Deleted data cannot be recovered.
After an account is deleted, for either reason, we keep its invoices, payment records, records of acceptance of our terms, and records of the notices we sent, for 6 years. We keep them as the law requires and so we can show what happened. They do not include your store content or your customers' data, and we do not use them for anything else.
Contact-form messages and sales enquiries that do not lead to an account are kept for up to 24 months after our last exchange with you. Server and security logs are kept for up to 12 months. Dashboard analytics data is kept for up to 24 months.
How we protect your data
We use technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2 or higher), encryption of sensitive credentials, separation of each merchant's data at the database level, least-privilege access with a second factor for platform administration, and regular backups. The status of each of our controls is published on our Trust page.
No method of sending or storing data over the internet is completely secure, so we cannot guarantee that personal data will never be accessed, disclosed, altered or lost without authorisation. You can help by keeping your sign-in codes, devices and email account secure.
If a breach of our security safeguards involving your personal data creates a real risk of significant harm to you, or a risk to your rights and freedoms, we will notify you and the relevant regulator as the law requires, and take steps to contain it and limit its effects.
Your rights
If you are in the EEA, the UK or Switzerland, you have the right to access your data, correct inaccurate data, erase your data, restrict processing, data portability, and object to processing — including, at any time, to processing based on our legitimate interests and to direct marketing. Where we rely on your consent, you can withdraw it at any time. In Canada, you can access and correct the personal information we hold about you and withdraw consent.
Send requests to [email protected] or through our contact form. We answer within one month, and may need to confirm who you are first.
You also have the right to complain to a data protection supervisory authority: in the EEA, the authority where you live or work, or where you think the problem happened; in the UK, the Information Commissioner's Office; in Canada, the Office of the Privacy Commissioner of Canada. We would appreciate the chance to deal with your concern first.
Where we offer the platform
Best Webby is offered to businesses established outside the European Union, the European Economic Area, the United Kingdom and Switzerland. We do not offer it to businesses established in those places, and we have not appointed a representative there.
Anyone, wherever they are, can contact the controller directly: Joorus Inc., 250 Consumers Road, Suite 908, Toronto, Ontario M2J 4V6, Canada, [email protected].
Changes to this policy
When we change this policy we publish the new version here with a new date. If a change materially affects how we use your data, we tell account holders by email before it takes effect.
Contact
Data protection inquiries: [email protected], by post to Joorus Inc., 250 Consumers Road, Suite 908, Toronto, Ontario M2J 4V6, Canada, or through our contact form.