1. Introduction and Who We Are
Wiggle BOS ("Wiggle") is a business operating system for start-ups and small to medium businesses, built and run by Floof Digital LLC, doing business as Floof Digital Consulting ("Floof Digital," "we," "us," or "our"), based in Indiana, United States.
This Privacy Policy explains what information Wiggle collects when you use the app at wiggle.floofdigital.com, the product pages at floofdigital.com/wiggleos, and the proposal pages, booking pages, forms and websites that Wiggle hosts for its customers. It covers how we use that information, who we share it with, and the choices you have. The Floof Digital Privacy Policy covers the rest of floofdigital.com and our consulting services.
Your use of Wiggle is also governed by our Terms of Service.
2. Your Business Data Belongs to You
Wiggle is built on one promise: your business, your data, always. Everything your team enters or connects, and every insight Wiggle produces from it, belongs to your business. You can export all of it at any time, in open and documented formats, and take it to any other platform (see section 11).
That shapes two different roles we play:
- Your account. For the people who sign in to Wiggle and the business that pays for it, Floof Digital decides how that information is used. This policy tells you how.
- Your workspace content. For the information your business puts into Wiggle about its own customers, leads and contacts, your business decides how it is used and Floof Digital processes it only to run Wiggle for you. If you are one of a Wiggle customer's contacts, the business you deal with is responsible for your information, and requests about it are best sent to them first. We will help them respond.
3. Information We Collect
Account Information
When you are invited to or sign up for Wiggle, we collect your name, email address, business name, the role you hold in the workspace, and optionally your job title and phone number.
If you sign in with Google, Microsoft, Facebook or LinkedIn, we receive your name, your email address, whether that address is verified, and which service you used. We use these only to sign you in and to show your name in the workspace. We never receive your password for those services. Our sign-in provider may also receive a link to your profile picture from them; Wiggle does not use it.
Workspace Content
Wiggle stores what your team puts into it, which can include:
- Customers, leads, contacts and accounts, with their names, email addresses, phone numbers, job titles, company details and notes
- Deals, projects, tasks, meetings and the activity timeline
- Emails sent to and from your workspace inbox, including their contents and attachment names
- Email you forward or BCC to your workspace address: the message, its sender, recipients and attachments' names, filed against the matching contact, or held in your Inbox for review.
- Proposals, agreements, signed documents, uploaded files, images and the websites you build
- Your business profile, voice guide, scorecard, goals and business checkup answers
- Your conversations with Romey, the Wiggle AI assistant
Before You Have a Workspace
Free Business Checkup: the website address you enter, the answers you give, a coded form of your IP address to prevent abuse, and, only if you ask us to email the report, your email address and your agreement to hear from us. We read the public pages of that website the way a search engine does, following its robots.txt. Checkups that do not become a Wiggle workspace are deleted after 90 days.
Services You Connect
Wiggle only reaches into another service when someone in your workspace connects it, and each connection can be removed at any time from Settings, then Connections.
- Google Calendar: your email address and name, and the busy times on your primary calendar so the booking page offers only free slots. Wiggle adds meetings people book to your calendar and invites the attendees. It does not read the details of your other events.
- Microsoft 365: your profile, your calendar's busy times, and your mail. Every few minutes Wiggle checks your Inbox and Sent Items and files only the messages exchanged with customers and contacts already in your workspace onto their records, keeping the sender, recipients, subject and body. Every other message is ignored and is not stored. Mail filing can be switched off for each connection. Wiggle adds booked meetings to your calendar with a Teams link.
- Google Business Profile: the locations you choose, with their details, posts, reviews, reviewer names and search performance. Wiggle posts updates and review replies only when a person in your workspace approves them. Reviews are shown to you but not stored.
- Facebook Pages and Instagram: your Facebook user ID and name, the Pages you choose, the Instagram account linked to each, and follower and performance figures. Wiggle posts to a Page or Instagram account only when a person in your workspace approves it, or automatically when the workspace owner has turned on auto-sharing of the workspace's own published blog posts. Our Facebook data deletion page explains how to remove this.
- LinkedIn Pages: your LinkedIn member ID (and your name, when LinkedIn shares it), the company Pages you choose, and follower and post figures. Wiggle posts to a LinkedIn Page only when a person in your workspace approves it, or automatically when the workspace owner has turned on auto-sharing of the workspace's own published blog posts.
- QuickBooks and Xero: Wiggle creates the customer and records the sale or invoice when a customer pays you through Wiggle. If you use Financial health, Wiggle also reads your profit and loss, money owed to you, bank account balances and sales by customer, and keeps a summary in your workspace so you can see them next to your pipeline. Reading never changes anything in your books.
- Stripe, Square and PayPal: if you connect them, Wiggle reads your payments, refunds, customers, subscriptions and, for Stripe, your balance and payouts, and keeps a summary in your workspace next to your other figures. Wiggle only reads; it never moves money or changes anything in those accounts. Only people you allow to see finances can see these figures.
- DocuSign: your DocuSign account name and email, to link the account.
- Mailchimp and Klaviyo: the name and email address of contacts in your workspace who have agreed to receive marketing from your business, and which list they join. Wiggle adds only those contacts, and, when double opt-in is on, the service asks each one to confirm first.
- Slack, Zapier, Make and other webhooks: when you connect them, Wiggle sends the events you choose (for example a new lead or a won deal), with the deal title, value, the contact's name and email and, for webhooks, phone number, and a link back to Wiggle, to the channel or address you set.
- Zapier, Make and the Wiggle API: when you authorise Zapier or Make, or create an API key, the apps you connect can read and change the records the access you granted covers, such as contacts, deals and tasks, and receive the events you choose. Every change they make is recorded in your workspace, and you can remove their access at any time in Settings.
- Zoom: if you connect Zoom, Wiggle receives the transcript Zoom makes of your recorded meetings, with the meeting topic, time and participants' names and emails. Wiggle writes a summary and suggested next steps, files them against the matching customer, and discards the transcript unless you choose to keep full transcripts. Zoom only provides transcripts on its paid plans with cloud recording turned on. Participants in your meetings should be told that the meeting is recorded and summarised; your business is responsible for that notice.
- Calendly: the event types you choose and the name, email and answers of people who book, so each booking becomes a lead or a meeting in your workspace.
- SEO health: Wiggle reads the public pages of your website on the schedule you choose, and Google's PageSpeed Insights measures your homepage's speed. The findings are kept in your workspace.
- Google Search Console and Google Analytics: if you connect them, Wiggle reads your website's search and traffic figures, such as clicks, impressions, the searches and pages people find you through, visits and conversions, and keeps daily totals and top lists in your workspace. Wiggle only reads; it never changes your Google settings.
The access keys these services give Wiggle are stored in our database so the connection keeps working. They are never included in exports, and disconnecting deletes them.
Information About the People Your Business Works With
Some of Wiggle's pages are used by people who do not have a Wiggle account. When they use them, Wiggle collects the following on behalf of the business they are dealing with:
- Proposal pages: when a proposal is opened, the time, the browser and device type, and a coded, one way version of the IP address (not the address itself), so the business can see that it was read. Accepting or declining collects the name, email address and any reason given.
- Agreements and signed documents: the signer's typed name and email address, the exact consent wording they agreed to, the time, the browser and device type, and a coded, one way version of their IP address (not the address itself), kept as the record of the signature. Signed copies are stored privately and can be opened only by the business and by the signer through a link that expires.
- Booking pages and lead forms: the name, email address, phone number, company and message entered. Lead forms do not record the IP address.
- Websites Wiggle hosts: Wiggle adds no analytics, advertising trackers or cookies to the websites it publishes for its customers. The only cookie is set on a password protected proposal, after the right password is entered, so the visitor does not have to enter it again for 7 days.
Billing Information
Wiggle subscriptions, and payments your customers make through Wiggle, are handled by Stripe. Card details are entered on Stripe's own pages and never reach our servers. We keep the plan, billing status, invoice history and the Stripe customer reference.
Technical and Usage Information
Our hosting provider records technical details of requests to Wiggle, such as the IP address, browser type, time and page requested, to keep the service running and secure. Wiggle records how many AI actions each workspace uses, and their cost, to run the monthly AI allowance. The Wiggle app contains no advertising pixels, analytics trackers or session recording.
4. How We Use Your Information
We use information to:
- Run Wiggle and provide the features your workspace uses
- Sign you in and keep your account and workspace secure
- Send the emails you ask Wiggle to send, and service messages about your account, billing and security
- Provide support, fix problems and improve Wiggle
- Bill for subscriptions and apply the limits of your plan
- Detect and prevent fraud, abuse and security incidents
- Comply with legal obligations
We do not sell your information, we do not use your workspace content for advertising, and we do not market to the contacts your business keeps in Wiggle.
5. Romey and AI Features
Romey and Wiggle's other AI features send the information needed for each request to our AI model providers, and return the result to you. Depending on the feature, that can include account, contact and deal details, recent emails, your business profile and voice guide, review text, and the brief you typed. AI video creation sends only the written description of the video.
- AI drafts, people decide. Anything AI writes that could reach a customer or a public listing arrives as a draft for a person to approve. The one exception is auto-sharing: if a workspace owner turns it on, Wiggle shares a short recap of the workspace's own published blog posts to its connected Pages without a separate approval each time.
- No training on your data. Our AI model providers process your workspace information only to answer the request. Under our agreements with them, they do not use it to train their models. AI video creation receives only the description you write, never your workspace records.
- Your conversations are yours. Romey conversations are saved in your workspace so your team can pick up where they left off, and they are included in your export.
6. Google User Data
Wiggle's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Information from Google is used only to provide the features you connected it for, is not sold, is not used for advertising, is not read by people except with your permission, for security, or to comply with the law, and is not used to develop, improve or train generalized AI or machine learning models.
7. Cookies and Browser Storage
The Wiggle app keeps your sign-in session, and small preferences such as a collapsed menu or the last workspace you opened, in your browser's own storage. Your current Romey chat is kept in the browser tab until you close it. These are needed for Wiggle to work and are not used for tracking. The Wiggle app sets no advertising or analytics cookies.
Wiggle loads some code libraries and fonts from public content networks (jsDelivr, cdnjs and Google Fonts), which see your IP address when they deliver them. The Wiggle product pages on floofdigital.com follow the analytics practices in the Floof Digital Privacy Policy.
8. How We Share Information
We share information only in these circumstances:
- Service providers: companies that run parts of Wiggle for us, and may use the information only to provide their service:
- Supabase: database and sign-in
- Cloudflare: hosting, file storage, security, email routing and PDF creation
- Resend: delivering the emails Wiggle sends
- Stripe: subscriptions and payments
- AI model providers: Romey and the AI features (section 5)
- Services you connect: when your workspace connects a service in section 3, Wiggle sends it what that connection needs. Your use of those services is governed by their own privacy policies.
- Inside your workspace: workspace content is visible to the people your workspace owner invites, according to their role.
- Floof Digital staff: a small number of staff can access workspaces to provide support, fix problems, keep Wiggle secure, or comply with the law.
- Legal requirements: when required by law, subpoena or legal process, or to protect the rights, safety or property of our users, the public or Floof Digital.
- Business transfers: in connection with a merger, acquisition or sale of assets, your information may be transferred as part of that transaction, and this policy would continue to protect it.
9. Where Your Data Is Stored
Wiggle's database is hosted in the United States. Files and websites are stored with Cloudflare and delivered through its global network, and our service providers may process information in other countries. When information moves outside your country, we rely on our providers' contractual safeguards, such as the European Commission's Standard Contractual Clauses.
10. Data Retention
- Active workspaces: your workspace content is kept for as long as your workspace is open, unless you delete it sooner. Records you delete in Wiggle are removed.
- Ended subscriptions: if a subscription ends, the workspace becomes read only and your export stays available. We keep the workspace for 12 months after the subscription ends, remind you before it is deleted, and then delete it.
- Connected services: access keys are deleted as soon as you disconnect a service, or when the service tells us you removed Wiggle.
- Exports: export files are deleted once their download link expires, after 7 days.
- Billing and transaction records: kept for 7 years, as required for tax and accounting purposes.
- Technical logs: kept for the short periods set by our hosting provider.
- Backups: deleted data can remain in backups until they are overwritten on our providers' rolling schedule.
11. Exporting and Deleting Your Data
Export. The workspace owner can download everything in the workspace at any time from Settings: every record as JSON and CSV files, the files you uploaded, the websites you published, and a plain description of how it all fits together. The export is never locked behind a plan and stays available if your subscription ends. Passwords and access keys are left out.
Delete. To delete your workspace, your account, or a Facebook or other connection, email derek@floofdigital.com from the address on the account. We will confirm the request, give you the chance to take a final export, delete the data within 30 days, and write back when it is done. Records kept for legal reasons, such as billing records, are kept only for as long as the law requires. You can also remove single records, and disconnect any connected service, yourself at any time.
12. Data Security
We protect your information with encryption in transit (HTTPS everywhere), encryption at rest by our database and storage providers, role based access inside every workspace, private storage for signed agreements and documents, signed and verified connections for payments and webhooks, and by collecting only what Wiggle needs. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If a breach affects your information, we will notify you as the law requires.
13. Your Rights and Choices
Depending on where you live, you may have some or all of these rights over your personal information:
- Access: request a copy of the personal information we hold about you.
- Portability: receive your data in a portable format. For workspace content, the export does this at any time.
- Correction: correct inaccurate information. Most of it you can edit in Wiggle directly.
- Deletion: ask us to delete your personal information.
- Objection and restriction: object to, or ask us to limit, how we use it.
- Opt out: of any marketing email from Floof Digital at any time. Service messages about your account continue while it is open.
California residents have rights under the California Consumer Privacy Act, including the right to know what we collect and the right to opt out of the sale of personal information. We do not sell personal information. Residents of the European Union and the United Kingdom have rights under the GDPR, and can complain to their local data protection authority.
To exercise any of these rights, email derek@floofdigital.com. We will respond within 30 days. If your information is in a Wiggle customer's workspace, we will pass your request to that business and help them respond.
14. Responsibilities of Workspace Owners
Businesses using Wiggle are responsible for having the right to put their customers' and contacts' information into Wiggle, and for the permission needed before adding anyone to a marketing list through a connected service such as Mailchimp or Klaviyo.
15. Children's Privacy
Wiggle is built for businesses. It is not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we discover we have, we will delete it promptly.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last Updated" date. For material changes, we will also tell workspace owners by email or in Wiggle before the change takes effect.
17. Contact Us
If you have questions about this Privacy Policy or how Wiggle handles your information, contact us at:
Floof Digital LLC (doing business as Floof Digital Consulting)
Wiggle BOS
Email: derek@floofdigital.com
Web: floofdigital.com/wiggleos