Privacy Policy
Last updated: September 26, 2026
This policy explains how VIAROO.ME ("we", "us"), the operator of the viaroo website builder at viaroo.me, handles personal data. We collect only what we need to run the Service, we don't sell personal data, and we don't use it for advertising.
Controller and contact: VIAROO.ME — [email protected]. Write to this address for any privacy question or to exercise your rights.
1. Data we process
Your account
Name, email address and password (stored only as a secure hash), plus technical session data — IP address, browser user agent and the time of your last activity — while you are signed in. Why: to provide the Service you signed up for (performance of a contract) and to keep accounts secure (legitimate interest).
What you tell us about your business
The business description you enter when creating a site — name, type of business, location, services, and any contact details you choose to show (phone, email, address, opening hours). Why: to generate and publish your site (performance of a contract). Business contact details you enter are published on your site because you ask us to.
Your site
The pages, posts, images and settings of your WordPress site, and your WordPress user account on it. Your site is public on the internet, so anything you publish there is visible to everyone.
Messages from your site's visitors
When someone uses the contact form on a site built with viaroo, we store their message and the details they enter (for example name, email, phone and the page it was sent from) and deliver it to the site owner in their viaroo account and by email. For these messages the site owner is the controller and we process them on the owner's behalf. Forms are protected against spam; this may involve checking technical data such as the sender's IP address. Visitors who want their message deleted can ask the site owner or write to us.
Security and server logs
Our servers and the sites we host record technical logs (IP address, time, requested address, browser user agent) and failed login attempts, to protect against abuse and to fix problems (legitimate interest).
Analytics on viaroo.me
Only if you allow it in the cookie banner, our home page uses Google Analytics to count visits and see which pages are useful (consent). You can change your choice at any time with "Cookie settings" at the bottom of the home page. Sites built with viaroo don't include our analytics.
2. Who processes data for us
We use these service providers. Each receives only the data it needs for its task.
| Provider | What for | Data involved |
|---|---|---|
| Contabo (Germany) | Servers that host the Service and all sites | All data described above |
| Cloudflare | Domain name service, secure connections (HTTPS), protection against attacks | Visitors' IP addresses and request data |
| OpenAI | Writing the texts of your site and blog posts | Your business description; no account data |
| Pexels | Stock photo search | Search keywords only (no personal data); photos are downloaded by our servers |
| Brevo | Sending emails (contact-form messages, password resets, notifications) | Recipient address and email content |
| Analytics on our home page (only with consent); web fonts on our home page | IP address and browser data of home-page visitors |
Some providers process data outside the European Economic Area (for example in the United States). Where they do, the transfer is covered by appropriate safeguards such as the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.
3. How long we keep data
- Account data — while your account exists; deleted when you ask us to delete the account.
- Sites and business descriptions — until you delete the site or your account.
- Contact-form messages — until the site owner deletes them, or the site is deleted.
- Logs — kept for a short period (generally no more than 30 days), longer only when needed to investigate abuse.
- Backups — expire automatically within about 30 days.
4. Cookies
- Necessary cookies keep you signed in to your viaroo account and to WordPress, and protect forms against forgery. They don't need consent and are removed when you sign out or they expire.
- Analytics cookies (Google Analytics, names starting with
_ga) are set on our home page only after you accept them. We remember your choice in your browser's local storage.
5. Your rights
Depending on where you live (for example under the EU/UK GDPR), you can ask us to:
- give you a copy of your personal data, or send it to another provider (access, portability);
- correct it (rectification) or delete it (erasure);
- restrict or object to how we use it;
- withdraw consent you gave — this doesn't affect processing before you withdrew it.
Write to [email protected]; we answer within one month. You also have the right to complain to a data protection supervisory authority, in particular in the country where you live or work.
6. Security
All connections use HTTPS. Passwords are stored as secure hashes, access to servers is restricted, WordPress and its plugins are kept up to date, sites are protected against brute-force logins and spam, and data is backed up regularly.
7. Children
The Service is not intended for children under 16, and we don't knowingly collect their data.
8. Changes
We will post any changes to this policy here with a new date and, for material changes, notify account holders by email or in their account.