Privacy Policy

Version 1.0

Effective Date: May 11, 2026  ·  Last Updated: May 11, 2026

Welcome to Wezard, a B2B SaaS platform (the "Service," "Platform," or "System"). This Privacy Policy describes how Wezard ("Company," "we," "us," or "our") collects, uses, and discloses information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular consumer or household ("Personal Information").

This Policy applies to all users of our Service, including employees of our corporate customers ("Customer Users"), visitors to our website, and any individuals whose information is processed via our feedback-capturing and routing tools.

1Introduction and Scope

1.1 Wezard as a Service Provider

For the majority of the data we process — specifically the bug reports, product feedback, and metadata routed to third-party issue trackers — Wezard acts as a Service Provider (as defined by the CCPA/CPRA) or Data Processor. In these instances, our Customer (the business that purchased the subscription) is the Business or Data Controller.

If you are an individual providing feedback to one of our Customers, your information is governed by that Customer's privacy policy.

2Categories of Information We Collect

In the preceding 12 months, we may have collected the following categories of Personal Information:

2.1 Identifiers

  • Direct Identifiers: Name, business email address, and job title provided during account creation.
  • Communication Identifiers: Mobile phone numbers for users who opt-in to SMS/text alerts regarding bug status updates or system notifications.
  • Online Identifiers: IP addresses, unique device identifiers, and account usernames.

2.2 Commercial Information

  • Subscription Records: Records of products or services purchased, obtained, or considered, and other consuming histories or tendencies related to the Wezard Platform.
  • Billing Information: Payment metadata (note: we use third-party payment processors and do not store full credit card numbers on our servers).

2.3 Internet or Other Electronic Network Activity

  • Usage Data: Information on the User's interaction with the Platform, including time spent on specific features, frequency of ticket routing, and logs of integrations with tools like Jira, ServiceNow, and Azure DevOps.
  • System Logs: Technical logs used to monitor system integrity, detect stress-testing attempts, and prevent unauthorized data access between tenants.

2.4 Professional or Employment-Related Information

Since Wezard is a B2B platform, we collect information regarding your employer and your role within the organization to facilitate the proper routing and ownership of bug reports.

3Sources of Information

We collect information from the following sources:

  • Directly from You: When you create an account, fill out a profile, or contact us for support.
  • From Our Customers: A business customer may provide your business contact information to grant you access to the Platform.
  • Automatically: Via cookies, web beacons, and server logs as you navigate the Platform.
  • Third-Party Integrations: If you link Wezard to Jira, ServiceNow, or Azure DevOps, we receive information from those services to facilitate the syncing and centralizing of fragmented bug reports.

4How We Use Your Information

Wezard uses Personal Information for the following business and commercial purposes:

4.1 Operational Purposes

  • Providing the Service: Capturing and structuring product feedback and routing it to the appropriate issue tracker.
  • Status Tracking: Providing real-time notifications and analytics on feedback volume and resolution trends.
  • Account Management: Authenticating users and providing access to centralized bug reports.

4.2 Security and System Integrity

  • Detection and Prevention: To detect, prevent, and respond to security incidents and fraudulent activity.
  • Strict Enforcement: To monitor for violations of our Terms of Service, specifically identifying unauthorized stress testing, penetration testing, or attempts to gather other tenant's data.
  • Violation Penalties: Information may be used to document breaches of the ToS that lead to account termination or legal action.

4.3 Analytics and Improvement

We use de-identified or aggregated data to analyze response times and resolution trends to improve our routing algorithms.

5Sharing and Disclosure of Information

Wezard does not sell your Personal Information to third parties. We share information only as described below.

5.1 With Third-Party Service Providers

We share information with vendors who perform services on our behalf, such as:

  • Cloud Hosting: Microsoft Azure is our primary cloud infrastructure provider. Customer Data is hosted in the following Azure regions based on customer type:
    • Commercial Customers: East US and East US 2.
    • Government Customers: USGov Virginia (Azure Government).
  • Communication: SMS/Text alert providers for opt-in user notifications.
  • Analytics: Third-party tools used to track Platform performance and product usage.
  • Payment Processing: PCI-compliant third-party payment processors.

5.2 With Third-Party Integrations

At the direction of the Customer, Wezard routes data to Jira, ServiceNow, and Azure DevOps. Once data is routed to these third-party platforms, it is subject to the privacy policies of those respective providers.

5.3 Legal Obligations

We may disclose information if required to do so by law or in the good faith belief that such action is necessary to:

  • Comply with a legal obligation or a court order.
  • Protect and defend the rights or property of Wezard.
  • Protect the personal safety of users or the public.
  • Protect against legal liability.

6Data Retention and Deletion

6.1 Standard Retention

We retain Personal Information for as long as the Customer's account is active or as needed to provide the Service.

6.2 Post-Termination Deletion (The "60-Day Rule")

Upon the termination or expiration of a subscription:

  • Storage Period: Wezard will store Customer Data for a period of sixty (60) days.
  • Customer Responsibility: During this window, Customers must export any bug reports, feedback analytics, or system logs they wish to keep directly from the Wezard portal.
  • Permanent Deletion: After 60 days, all such data is permanently purged from our active systems and backups (subject to standard rotation cycles). Wezard is not liable for data loss once this 60-day window has closed.

6.3 System Log Retention

System and application logs (including access logs, audit trails, and integration activity logs) are retained for a period of thirty (30) days from the date of generation, after which they are automatically purged from our active systems.

Customers requiring longer log retention for compliance or auditing purposes must export the relevant logs from the Wezard portal prior to the expiration of the 30-day window or prior to the termination of their subscription, whichever occurs first.

7Security Measures and System Exploitation

Wezard employs robust physical, electronic, and managerial procedures to safeguard and secure the information we collect.

7.1 Technical Safeguards

  • Encryption: All data is encrypted in transit using TLS 1.2+ and at rest using AES-256.
  • Multi-Tenancy Isolation: Our architecture is designed to ensure that one customer cannot access another customer's data.

7.2 User Access Controls

Wezard provides administrators and end users with the following controls to manage access to their accounts and data:

  • Role-Based Access Control (RBAC): Customer administrators can assign granular permissions to users, restricting access to bug reports, analytics, and configuration settings based on organizational role.
  • Single Sign-On (SSO): Wezard supports enterprise SSO integration, allowing Customers to manage authentication through their existing identity provider.
  • Multi-Factor Authentication (MFA): MFA is available to all users and may be enforced organization-wide by Customer administrators for an additional layer of account security.

7.3 Data Backups

Wezard maintains automated daily backups of Customer Data to safeguard against accidental loss, corruption, or system failure.

  • Database Architecture: Customer Data is stored within a PostgreSQL database hosted on a virtual machine in the applicable Azure region.
  • Backup Frequency: Backups are executed on a daily, automated schedule via scripted backup routines.
  • Backup Storage: Backup snapshots are written to Azure Blob Storage within the same regional boundary as the source database (i.e., commercial backups remain in East US/East US 2; government backups remain in USGov Virginia).
  • Backup Retention: Backups follow the same retention and deletion timelines outlined in Section 6.

7.4 Prohibited Conduct

As stated in our Terms of Service, users are strictly prohibited from:

  • Running stress testing or automated scripts intended to compromise system performance.
  • Attempting to breach or gather other tenant's data. Any information collected in relation to such activities will be retained for as long as necessary to facilitate legal proceedings or system remediation.

8California Privacy Rights (CCPA/CPRA)

This section applies solely to residents of the State of California.

8.1 Your Rights

Under the CCPA/CPRA, California residents have the following rights:

  • Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell.
  • Right to Delete: You have the right to request the deletion of your personal information, subject to legal exceptions (such as the need to complete a transaction or comply with a legal obligation).
  • Right to Correct: You have the right to request that we correct inaccurate personal information.
  • Right to Opt-Out of Sharing: We do not "sell" or "share" (for cross-contextual behavioral advertising) your personal information.

8.2 Exercising Your Rights

To exercise these rights, please email us at privacy@wezardapp.com. We will verify your request by asking for information sufficient to confirm your identity, such as your business email and a verification code.

9Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Keep you logged in.
  • Understand your preferences based on previous or current site activity.
  • Compile aggregate data about site traffic and site interaction.

9.1 Third-Party Tracking Partners

Wezard works with third-party analytics and product-experience providers to measure Platform performance, diagnose technical issues, and improve user experience. These providers may use cookies, page tags, session-replay scripts, and similar technologies to collect information such as page views, click events, browser type, device characteristics, and IP address.

These third-party tools are configured to process data on our behalf and are contractually restricted from using Platform data for their own independent purposes.

9.2 Your Cookie Choices

You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies through your browser settings. If you turn cookies off, some features of the Service may not function properly.

10Children's Privacy

The Wezard Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected such information, we will take steps to delete it immediately.

11International Data Transfers and Data Residency

11.1 Customers in the United States

Customer Data for commercial U.S. customers is processed and stored within the continental United States, specifically in the Microsoft Azure East US and East US 2 regions. Customer Data for U.S. government customers is processed and stored exclusively within the Azure Government USGov Virginia region, which is operated in compliance with applicable U.S. federal data residency requirements.

Wezard processes Personal Information in accordance with applicable U.S. federal and state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and other state-level privacy statutes where applicable.

11.2 Customers in the EEA and United Kingdom

By using our Service, customers outside the United States acknowledge that their information will be transferred to and processed in the U.S., where data protection laws may differ from those in their home jurisdiction. For customers in the European Economic Area (EEA) or United Kingdom, we utilize Standard Contractual Clauses (SCCs), together with supplementary technical and organizational measures, to ensure an adequate level of protection for international data transfers.

12Changes to This Policy

Wezard reserves the right to amend this Privacy Policy at any time. We will notify you of material changes by:

  • Posting a notice on our Platform dashboard.
  • Sending an email to the primary account administrator.
  • Updating the "Last Updated" date at the top of this policy.

Contact Us

If you have questions or concerns about this Privacy Policy or Wezard's data practices, please contact our Data Privacy Officer:

Wezard Privacy Team

2150 Association Drive, Ste 270

Okemos, MI 48864-4909, United States

Email: privacy@wezardapp.com

Important: By continuing to use Wezard, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you have any questions or concerns, please do not hesitate to contact us.