Privacy Policy
Effective date: 1 May 2025 · Last updated: 13 July 2026
1. Who We Are
Wiro (“Wiro”, “we”, “our”, or “us”) is a software-as-a-service platform designed for creative and communications agencies operating in the Gulf region. Our platform helps agencies manage clients, campaigns, PR coverage, finances, scheduling, communications, and social media.
For any privacy-related questions, contact us at admin@wiro.ae.
2. What Data We Collect
We collect data in the following categories:
Account & Agency Data
- Your name, email address, and profile information
- Your agency name, logo, and configuration settings
- Team member profiles and role assignments
Client & Business Data
- Client contact details, contracts, and billing information
- Campaign and project data you enter into the platform
- PR coverage items, media contacts, and coverage reports
- Invoices, expenses, and financial records
Google Account Data (when you connect Google)
- Your primary Google Account email address
- Google Calendar list and event data (titles, times, locations, attendees, Meet links)
- Google OAuth access token, refresh token, and expiry information
Scheduling Data (Calendly and Cal.com)
- Your connected scheduling account email and profile information
- Event types and booking page URLs
- Booking details including attendee name, email, meeting time, and duration
- OAuth access and refresh tokens for each connected scheduling provider
Messaging Data (Slack, Telegram, WhatsApp)
- Slack: workspace name, channel names, message history from connected channels and DMs
- Telegram: bot token, bot ID, and bot username — no user message content is stored server-side
- WhatsApp Business: WhatsApp Business Account ID, phone number ID, and message logs from your business number
Social Media & Content Data (Meta, TikTok, YouTube, Threads)
- Meta (Facebook and Instagram): connected Facebook Page IDs and names, linked Instagram Business Account IDs, page access tokens, published and scheduled post data, and account insights
- TikTok: OpenID, handle, and avatar for connected TikTok accounts used for content publishing
- YouTube: channel identifier for connected YouTube accounts
- Threads: account identifier for connected Threads accounts
Advertising Data (Meta Ads, TikTok Ads, Google Ads)
- Connected ad account IDs and names
- Campaign, ad set, and ad performance metrics fetched on your behalf
- OAuth access tokens for each ad platform connection
Cloud Storage Data (Dropbox, OneDrive)
- OAuth access and refresh tokens for your connected storage account
- File and folder metadata (names, paths, modified dates) displayed in Wiro
- File contents are accessed only when you explicitly open or import a file
Influencer Research Data
- Public profile data fetched from Instagram and TikTok via the Apify service
- This data is publicly available and is not scraped from private accounts
Usage Data
- Log data, IP addresses, browser type, and access timestamps
- Feature usage patterns to improve the platform
3. How We Use Your Data
We use your data solely to provide and improve Wiro:
- Delivering the features of the platform you have signed up for
- Authenticating your identity and protecting your account
- Sending transactional emails (account activity, invoices, reminders)
- Syncing data from connected third-party services on your behalf and at your direction
- Displaying your scheduling events, messages, social media content, and files in the Wiro interface
- Improving platform reliability, performance, and new features
- Complying with applicable laws and responding to lawful requests
We do not sell, rent, or share your data with third parties for advertising or marketing purposes. We do not use your data — including any data received from third-party integrations — to train AI or machine-learning models.
4. Third-Party Services and Integrations
Wiro integrates with the following services. All integrations are optional. You connect each service yourself and can disconnect at any time from Settings.
Infrastructure
- Supabase — database, file storage, and authentication (hosted in the EU)
- Google APIs — Calendar (calendar.readonly, calendar.events) and Meet (via Calendar conferenceData)
- Google Ads API — read and manage connected Google Ads accounts (adwords scope)
Scheduling
- Calendly — read your event types and sync booked meetings into the Wiro Scheduler
- Cal.com — read your event types and sync booked meetings; create and manage bookings and webhooks on your behalf
Messaging
- Slack — read messages from connected channels and DMs, send messages on your behalf
- Telegram — receive and relay messages via your connected Telegram bot
- WhatsApp Business Cloud API (Meta) — send and receive messages via your WhatsApp Business number
Social Media & Content
- Meta (Facebook & Instagram) — read and publish posts to connected Facebook Pages and Instagram Business accounts; read account insights
- TikTok — read connected account profile; draft and publish video content
- YouTube — read connected channel identifier
- Threads — read connected account identifier
Advertising
- Meta Ads (Facebook Ads Manager) — read ad account, campaign, ad set, and ad performance data
- TikTok for Business — read ad account and campaign performance data
Cloud Storage
- Dropbox — read and display your Dropbox files in Wiro
- Microsoft OneDrive — read, display, and optionally write files in your OneDrive
Data & Research
- Apify — fetch publicly available influencer profile data from Instagram and TikTok
Each of these services has its own privacy policy. We configure integrations with least-privilege access wherever possible and store credentials encrypted.
5. Google API Services and Google User Data
Wiro’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google OAuth Scopes Requested
When you connect your Google account, Wiro requests only the following three OAuth scopes. Connecting Google is entirely optional. Wiro does not request any restricted Google scope.
- userinfo.email — used to identify which Google account you connected.
- calendar.readonly — used to list your calendars and display existing Google Calendar events in Wiro's Scheduler.
- calendar.events — used when you create, edit, or delete Google Calendar events through Wiro. Google Meet links are generated through the Calendar API's conferenceData feature; no separate Meet permission is required.
Wiro does not request Gmail access, Drive access, or the full calendar scope. Wiro cannot read, send, or otherwise access your Gmail, and cannot access any file in your Google Drive.
Google Calendar — Limitations
Calendar access is used only to power the Wiro Scheduler. Wiro does not use Google data for:
- Advertising or building advertising profiles
- Selling or sharing data with third parties
- Sending unsolicited bulk or marketing email
- Training general-purpose AI or machine-learning models
Wiro has no access to Gmail or Google Drive. It cannot read, compose, or send email from your Gmail account, and it cannot list, open, or download any file in your Google Drive.
AI and Model Training
Google Calendar data is not used to train Wiro’s or any third party’s AI or machine-learning models. Google user data is not transferred to AI providers for model training.
Data Stored
- Google account email address
- Google OAuth access token, refresh token, and token expiry
- Google Calendar event data synced to the Scheduler (title, time, location, attendees, Meet link)
- Limited Calendar metadata cached in your browser's localStorage for performance
Wiro does not access Google Drive or Gmail at all.
Disconnecting Google
When you disconnect Google from Settings, Wiro will:
- Revoke your Google OAuth authorisation via Google's token revocation endpoint
- Delete your stored access and refresh tokens from Wiro's database
- Clear your Calendar browser caches from localStorage
- Stop all future access to Google services
Google Calendar events previously synced into Wiro’s Scheduler remain in the database after disconnect. They are no longer refreshed. Email admin@wiro.ae to request deletion. You can also revoke access independently at myaccount.google.com/permissions.
User Control
- Connecting Google is optional
- You can disconnect Google at any time from Settings
- You can revoke access through your Google Account security settings
- You can request deletion of stored Google data by emailing admin@wiro.ae
6. Scheduler Integrations (Calendly and Cal.com)
Wiro’s Scheduler can display events from your Calendly and Cal.com booking accounts alongside Google Calendar events, Wiro-native events, and Google Meet links. Each connection is optional and separate.
Calendly
When you connect Calendly, Wiro requests OAuth access to:
- Read your Calendly user profile and email address
- Read your event types (booking page URLs and configurations)
- Sync booked meetings into the Wiro Scheduler via webhooks
Wiro stores your Calendly access token, refresh token, user ID, and synced event data in its database. Wiro does not create, modify, or cancel Calendly bookings on your behalf. You can disconnect Calendly from Settings at any time, which deletes stored tokens and stops future syncing.
Cal.com
When you connect Cal.com, Wiro requests OAuth access to:
- Read your Cal.com profile
- Read your event types
- Read existing bookings and sync them to the Scheduler
- Create and manage webhooks so new bookings appear in Wiro automatically
Wiro stores your Cal.com access token, refresh token, and synced booking data. Webhooks are registered on your Cal.com account to receive real-time booking notifications. You can disconnect Cal.com from Settings, which deletes stored tokens and removes the registered webhook from Cal.com.
Data Retention After Disconnect
Booking events previously synced from Calendly or Cal.com remain in Wiro’s Scheduler database after disconnect. They are no longer refreshed or updated. Email admin@wiro.ae to request deletion of synced booking data.
7. Messaging Integrations (Slack, Telegram, WhatsApp)
Wiro’s unified inbox can aggregate messages from Slack, Telegram, and WhatsApp Business. Each connection is optional, separate, and can be disconnected at any time from Settings.
Slack
When you connect Slack, Wiro requests OAuth access with the following scopes:
- channels:read and channels:history — to list and read messages from public channels you select
- im:read and im:history — to read direct messages in your Slack workspace
- chat:write — to send messages on your behalf from within Wiro
- users:read — to resolve user display names in conversations
Wiro stores your Slack access token, workspace (Team) ID, and bot ID. Message content is fetched when you view a conversation and is not permanently stored in Wiro’s database.
Telegram
Wiro connects to Telegram via a Bot Token you create through Telegram’s BotFather and enter manually in Settings. Wiro does not use OAuth for Telegram. Wiro stores your bot token, bot ID, and bot username. Wiro registers a webhook with Telegram so incoming messages to your bot are relayed to the Wiro inbox. Wiro does not store Telegram message history server-side beyond active session delivery.
WhatsApp Business
Wiro connects to WhatsApp via the Meta WhatsApp Business Cloud API. When you connect a WhatsApp Business number, Wiro stores your WhatsApp Business Account (WABA) ID, phone number ID, and access token. Wiro can send and receive messages on behalf of your WhatsApp Business number and logs message content in its database to support your inbox history. Wiro does not use WhatsApp message data for advertising or for any purpose other than operating your connected inbox.
Disconnect
Disconnecting a messaging integration from Settings will delete stored tokens and account identifiers and stop future message processing. Message history already displayed in Wiro may be retained until you request account deletion.
8. Social Media and Content Integrations
Wiro’s Planner supports content scheduling and publishing to social platforms. All connections are optional.
Meta (Facebook Pages and Instagram)
When you connect Meta, Wiro requests the following permissions:
- pages_show_list — to list your manageable Facebook Pages
- pages_read_engagement and pages_manage_metadata — to read page details and insights
- pages_manage_posts — to publish and schedule posts to connected Facebook Pages on your behalf
- instagram_basic and instagram_content_publish — to read your linked Instagram Business accounts and publish content
Wiro stores long-lived Page Access Tokens and Instagram Business Account IDs. Post content you schedule or publish through Wiro is sent to Meta on your behalf. Wiro does not access your personal Facebook profile, private messages, or data beyond the pages and accounts you explicitly connect.
TikTok
When you connect TikTok for content, Wiro requests access to read your account profile (OpenID, handle, avatar) and to draft and publish video content on your behalf. Wiro stores your TikTok access token and account identifier. Wiro only publishes content you explicitly create and submit through the platform.
YouTube
Wiro connects to YouTube using the youtube.readonly scope to identify your connected channel, and youtube.upload to publish videos you create in Wiro. Wiro uploads only the video, title, description, tags, and visibility you set on a post, and reads back the resulting video’s status to confirm it published. No watch history, analytics, or other channel content is accessed, and Wiro cannot edit or delete videos once uploaded.
Threads
Wiro connects to Threads using the threads_basic scope to identify your connected Threads account, and threads_content_publish to post the text and media you create in Wiro. Wiro publishes only content you explicitly create and schedule through the platform, and stores the resulting post identifier and link. Your Threads feed, followers, and engagement data are not accessed.
General
Social media data is used only to operate the publishing and planning features you use. Wiro does not use social content, engagement data, or audience information for advertising, profiling, or AI model training.
9. Advertising Platform Integrations
Wiro can display advertising performance data from Meta Ads, TikTok Ads, and Google Ads. These connections are read-focused and are used to surface campaign metrics inside Wiro.
Meta Ads
Wiro requests ads_read, ads_management, and business_management permissions to read your Meta ad account details, campaigns, ad sets, ad performance metrics, and spend data. Wiro does not create, modify, or delete ad campaigns through this connection unless you explicitly use a campaign management feature.
TikTok Ads
Wiro connects to TikTok for Business via OAuth to read your TikTok Ads account details and campaign performance metrics. No ad creation or modification is performed without your explicit action.
Google Ads
Wiro requests the adwords scope to read your Google Ads account hierarchy and campaign performance data. This is a separate connection from the Wiro Google integration and uses a separate OAuth client.
Advertising tokens are stored in Wiro’s database. Campaign performance data is fetched on demand and synced on a scheduled basis. Wiro does not use advertising data for any purpose other than displaying it to you inside the platform.
10. Cloud Storage Integrations (Dropbox and OneDrive)
Wiro can display files from Dropbox and Microsoft OneDrive. Wiro does not access Google Drive.
Dropbox
When you connect Dropbox, Wiro uses standard Dropbox OAuth to read your file and folder metadata and list files in Wiro. Wiro stores your Dropbox access and refresh tokens. File contents are accessed only when you explicitly open or import a file.
Microsoft OneDrive
When you connect OneDrive, Wiro requests Files.ReadWrite, offline_access, and User.Read from Microsoft. Wiro uses this to list and display your OneDrive files in Wiro. The Files.ReadWrite scope is requested to support optional file operations. Wiro stores your OneDrive access and refresh tokens.
Disconnect
Disconnecting a storage integration from Settings deletes stored tokens and stops future file access. No file contents are permanently stored in Wiro’s database.
11. Data Retention
We retain your data for as long as your account is active. If you close your account, we will delete your personal data within 30 days, except where retention is required by applicable law (e.g., financial records required under UAE commercial law).
Synced event data from Google Calendar, Calendly, and Cal.com remains in Wiro’s database after you disconnect the relevant integration. It is no longer refreshed once disconnected. You may request deletion by emailing admin@wiro.ae.
You may request deletion of your account and all associated data at any time by emailing admin@wiro.ae.
12. Security
We use industry-standard security practices including TLS encryption in transit, encrypted storage at rest, and role-based access controls. OAuth tokens for all third-party services are stored encrypted and are never exposed in client-side code or public API responses.
Despite these measures, no system is completely secure. You are responsible for maintaining the security of your login credentials and any integration tokens you configure.
13. Data Sharing
Wiro does not sell your data. Your data is not shared with third parties except:
- Service providers necessary to operate Wiro (such as Supabase for database hosting), who process data only to provide services to Wiro and are required to protect it appropriately
- The third-party platforms you explicitly connect (e.g., data sent to Meta when you publish a post, or to Google when you create a calendar event)
- Where required by applicable law or a lawful government request
Your data is not shared with advertising platforms for targeting purposes. Integration data (social posts, messages, bookings) is transmitted to the relevant third-party service only when you initiate the action.
14. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Data portability (receive your data in a machine-readable format)
To exercise any of these rights, contact admin@wiro.ae. We will respond within 30 days.
15. Cookies and Local Storage
Wiro uses session cookies strictly necessary for authentication. We do not use third-party tracking cookies or advertising cookies.
Wiro uses your browser’s localStorage to cache limited Calendar metadata for performance. These caches are cleared when you disconnect Google or when you clear your browser’s site data.
16. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by email or by displaying a notice in the platform. Continued use of Wiro after changes are posted constitutes your acceptance of the updated policy.
17. Contact
For all privacy enquiries, data-deletion requests, or questions about this policy: