Privacy Policy.

How Wensity Private Limited collects, uses, stores, and deletes your data. Written in plain English, with every processor named and every retention period stated. No buried clauses.

Last updated · Applies to ui.wensity.com, the Wensity CLI, and Wensity UI

1. Who we are

Wensity Private Limited is a private limited company incorporated in India under CIN U62013UW2026PTC256410, with its registered office in Noida, Uttar Pradesh, India. In this policy “we”, “us” and “Wensity” mean that company. We are the data controller for ui.wensity.com, for the Wensity UI component library and CLI, and for the design and engineering services we deliver under contract.

This policy covers what we collect, why we collect it, who else touches it, how long we keep it, and how you get it back or get rid of it. It is written to be read once and understood, not to be technically accurate and practically useless. If something here is unclear, email hey@wensity.com and we will explain it in writing. You can also read more about the company.

2. The short version

If you read nothing else on this page, read this. Four commitments govern everything below, and the rest of the policy is just the detail of how we keep them.

  • We never sell, rent, or trade your personal data. There is no arrangement under which a third party pays us for information about you, and there never will be.
  • We collect the minimum that makes the product work. If a field is not required to deliver something you bought or to keep your account secure, we do not ask for it.
  • We do not run advertising trackers, cross-site ad pixels, or fingerprinting scripts. Nothing on this site follows you to another site.
  • You can get a copy of your data or have it deleted at any time by sending one email. No forms, no retention team, no attempt to talk you out of it.

3. What we collect

What we hold depends entirely on how you use Wensity. Browsing the component gallery creates almost nothing. Buying a template creates a purchase record. Here is the full list.

  • Account data. Your email address, the identifier returned by your OAuth provider if you signed in with GitHub or Google, and your display name and avatar where the provider supplies them. We never receive or store your password for those providers.
  • Session data. BetterAuth session records that keep you signed in, including a session token, creation and expiry timestamps, and the IP address and user agent the session was created from. That last pair exists so you can spot a session you did not start.
  • Licence and purchase data. Which component plan or templates you own, when the licence was granted, its current state, and a reference ID issued by our payment processor. We use that reference to look a payment up. We do not store your card number, expiry, or CVV, and those never reach our servers.
  • CLI and API data. A hash of each API token you create, the token label and creation date, and a record of which components or templates were downloaded and when. The hash lets us check a token without being able to read it back, so a copy of our database does not hand anyone your token.
  • Support and enquiry data. Whatever you put in an email or a contact form: your address, your message, and any project detail you choose to include so we can answer properly.
  • Usage analytics. Counts of page views, referrers, rough country-level location, and device class, plus product events such as starting a checkout, downloading a template, or creating an API token. Traffic counts are aggregated and not tied to you. Product events are tied to your account when you are signed in. We use this to see which components people actually reach for and which docs pages leave them stuck.

We do not knowingly collect data from anyone under 16, and Wensity UI is not directed at children. If you believe a child has given us personal data, email us and we will delete it.

4. Why we use it

Every category above maps to a specific job. Nothing is collected on the theory that it might be useful later.

  • To deliver what you bought. Account, licence, and purchase records are what let the site and the CLI confirm you are entitled to a given component or template and hand you the source.
  • To keep accounts secure. Session and token records let you stay signed in, let you revoke access you no longer want, and let us detect a token being used in a way that suggests it has leaked.
  • To support you. Email and enquiry data are used to answer your question, resolve a billing problem, or scope an engagement and write you a proposal.
  • To meet legal duties. Payment references and invoice records are retained because tax and accounting law requires it, not because we want them.
  • To improve the product. Analytics inform what we build next. This data is not used to target you with advertising or to make any automated decision that affects you.

Where the GDPR applies, our legal bases are performance of a contract for account, licence, purchase, and delivery data; legitimate interest for security, abuse prevention, and aggregate analytics; legal obligation for financial records; and consent for anything optional, such as a mailing list you asked to join. You can withdraw consent at any time without affecting anything we did before you withdrew it.

5. Who else handles it

Running this product means using infrastructure we did not build. Each provider below processes data on our instructions under its own contractual security and privacy commitments. We name them so you can check them yourself rather than take our word for it.

  • Vercel for hosting, the CDN, and edge delivery. Handles request metadata and server logs.
  • Supabase and PostgreSQL for the product database holding accounts, licences, purchases, and token hashes.
  • BetterAuth for authentication and session management.
  • Lemon Squeezy as merchant of record and payment processor. Card details go to Lemon Squeezy directly and are never held by us.
  • PostHog and Umami for analytics. Umami counts website traffic, is cookieless, and stores nothing in your browser. PostHog records product events and, when you are signed in, associates them with your account.
  • A transactional email provider for receipts, licence keys, password and sign-in mail, and replies to your support requests.

Some of these providers operate outside India, so your data may be processed in other countries, including in the United States and the European Union. Where required, transfers rely on standard contractual clauses or an equivalent approved mechanism. Beyond these processors, we disclose personal data only when the law compels it, and only to the extent it compels it. If we are ever served with a request for your data and we are legally permitted to tell you, we will.

6. Cookies and local storage

We use three kinds of browser storage, and none of them are for advertising.

  • Strictly necessary. Session cookies that keep you signed in and protect forms against cross-site request forgery. The site cannot work without these.
  • Preferences. Cookies or local storage entries that remember display choices such as your theme, so the interface looks the same when you return.
  • Analytics. Storage used by our product analytics. Our website traffic analytics is cookieless and writes nothing to your browser at all. None of this storage is shared with advertisers.

There are no advertising cookies, no cross-site ad pixels, no data broker integrations, and no fingerprinting. Blocking non-essential storage in your browser will not break anything except your saved preferences.

7. How long we keep it

Data has a lifespan here. We do not keep records indefinitely on the off chance they matter.

  • Account and licence records are kept while your account is open. Delete the account and they go within 30 days, apart from anything covered below.
  • Sessions and API tokens expire on their own schedule, and revoked tokens are removed within 30 days.
  • Invoices and payment references are retained for eight years because Indian tax and company law requires it. This is the one category we cannot delete on request.
  • Support email is kept for up to 24 months so we have the history of a recurring issue, then deleted.
  • Analytics data is retained for up to 14 months, then deleted.

8. How we protect it

All traffic to and from this site is encrypted in transit with TLS. Data at rest sits in a managed database with encryption enabled. API tokens are stored only as hashes, so nobody, including us, can read a token back out of the database. Access to production data is limited to the people who need it to run the service, which is currently a very short list, and administrative access requires multi-factor authentication.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data, we will notify affected users and the relevant authority without undue delay, and within 72 hours of becoming aware where the law requires it. The notice will say what happened, what data was involved, and what to do about it. If you think you have found a vulnerability, email hey@wensity.com and we will work with you on it in good faith.

9. Your rights

Wherever you live, you can exercise all of the following with us. We do not gate these behind a particular jurisdiction.

  • Access. Ask for a copy of the personal data we hold about you.
  • Correction. Ask us to fix anything inaccurate or incomplete.
  • Deletion. Ask us to erase your data, subject only to records we are legally required to retain.
  • Portability. Get your data in a structured, machine-readable format.
  • Objection. Object to processing based on legitimate interest, or opt out of any optional communication.
  • Complaint. Raise the matter with your local data protection authority if you are not satisfied with how we handled it.

To use any of these, email hey@wensity.com from the address on your account. We respond within 30 days, and usually much sooner. There is no charge. We will never make an account worse, slower, or more expensive because you exercised a right, which is what the GDPR, the CCPA, and India's Digital Personal Data Protection Act all require and what we would do regardless.

10. Changes to this policy

We update this page when the product changes or when a processor changes. Material updates are posted here and the “last updated” date at the top of the page moves. If a change meaningfully affects how we handle data you have already given us, we will also email account holders rather than rely on you noticing a date. Continuing to use Wensity after a change means you accept the revised policy. Older versions are available on request.

11. Contact

Privacy questions, data requests, and complaints all go to the same place: hey@wensity.com. Postal enquiries can be addressed to Wensity Private Limited, Noida, Uttar Pradesh, India; email us first and we will send the full registered address. You may also want the terms of service, which govern licensing and payment.