Legal · Wix apps
Privacy Policy for the Wix apps
Effective September 25, 2026
The short version
These apps run inside your Wix site and keep their data there, in the app’s own collections. Nothing is copied to a server of ours, no visitor is tracked, and there are no analytics, advertising or tracking services embedded in any of them. Wix handles billing, so we never see payment details. If you email us for support, we keep that correspondence for as long as it takes to help you, and nothing more.
Who is responsible
The apps listed below are developed and published by Builds By Luke, based in Canada. For the purposes of Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and the EU/UK General Data Protection Regulation (GDPR), Builds By Luke is accountable for the handling described in this policy.
The person accountable for this policy is the Privacy Contact at Builds By Luke. Questions, access requests and complaints all go to one place:
support@buildsbyluke.com
Which apps this covers
This policy covers the following apps, available through the Wix App Market:
- Site Search & Product Search — Instant search for products, pages and posts that is never out of date — results come from the live catalog, not a stale copy.
- Bundles & Volume Discounts — Buy-more-save-more pricing and bundle deals, applied automatically at checkout — no coupon codes, no checkout plugin.
- Product Add-ons & Extras — Gift wrapping, engraving text and paid extras on the product page you already have, charged at checkout as named fees.
- Comments & Moderation — Comment threads on any page, with a spam filter that explains itself and an approval queue you actually control.
- FAQ Sections & Search — A separate FAQ for every page, with search that stays inside the section it is on and nothing ever added to a page for you.
- Tables & Charts — Tables that fit every screen, from a Google Sheet or typed in, with a chart drawn from the same rows.
- Testimonials Wall — Testimonials that never vanish, collected on your site and shown in the layout you choose.
- Pricing Tables & Comparison — Pricing tables that stay saved, with a yearly toggle, comparison rows and a request-a-quote mode.
- Countdown Timers — Countdowns that show up, count the right moment, and stay exactly where you put them.
- Announcement Bars — One bar across your whole site — on a phone as well as a desktop, pushing your page down instead of covering it.
- Content Protection — Right-click, dragging and the phone long press blocked on every page — and never inside your own forms.
- Podcast Player — A podcast player fed by your RSS feed, with episodes, show notes and subscribe links, in your fonts.
- Polls & Surveys — A live poll or a short survey on any page, with unlimited votes on the free plan.
- Timeline & Milestones — A timeline of anything, with any date at all — a year, a month, a span of years, BC, or your own words — in the order you choose.
- Recipe Cards & Cookbook — A cookbook on any page of your site, with ten recipes free, a real print view and share links that open the recipe they name.
- Video Gallery & Playlists — A video gallery with five arrangements and every design control free, that loads nothing from YouTube until a visitor presses play.
- Audio Player & Playlists — A real audio player for any page — fifteen tracks and every control free, and it runs on Wix Studio, where the built-in music player does not.
- Portfolio & Project Showcase — A portfolio that carries documents as well as photographs — ten projects, four arrangements and every design control, free.
- Downloads & Document Library — Files your visitors open in one press — no account, no sign-up and no sign-in, on any page you like.
- Jobs & Careers Board — Ten open roles free, an Apply button that actually works, and a job advert that is never cut off.
- News Ticker & Live Updates — A real ticker — as thin as 28 pixels — with no cap on your updates on the free plan, and no badge on any plan, ever.
- Quote & Price Calculator — An instant price on any page, with every line of the sum shown — and a free plan, where the app it replaces has none.
- Real Estate Property Listings — A property board on any page — twelve properties free, every filter free, and a price written the way your market writes it.
- Team & Staff Directory — Your team on any page — twelve people free, four times the best free plan in this category, with every arrangement and a Read more that actually opens.
- Class & Event Timetable — The week your studio actually runs — no cap on classes on the free plan, and three days a week is one entry, not three.
- PDF & Document Viewer — Your PDFs on your own page, with no watermark on any plan and no storage limit of ours, ever — because your files never leave your own media.
- Before & After Comparison — Drag a handle across a photograph and it becomes the other photograph — unlimited comparisons on the free plan, and no watermark on any plan, ever.
- Course & Programme Catalogue — A catalogue of your courses on a page you designed, with the modules and lessons published free — and no cap on courses, on any plan.
- Services & Price List — Every price you actually charge — junior, senior, 30 or 90 minutes — free on every plan, with no cart, no order total and no badge.
- Opening Hours & Open Now — Open, closing soon or closed — worked out on your own clock, with holidays free and no watermark on any plan, ever.
- Stats & Impact Counters — Numbers that count up on your page — any size of figure in the same second, with no cap on how many and no watermark on any plan, ever.
- Logo, Client & Partner Strip — The logos of the businesses you work with, balanced by eye so a long wordmark and a square badge look the same size — with no cap on how many and no watermark on any plan, ever.
- Image Hotspots & Labels — Clickable points on any picture, each with as much to say as you like — and a panel that stays on the picture wherever the point is, with no cap on points and no watermark on any plan, ever.
- Knowledge Base & Help Centre — Help articles with headings, steps and pictures — searched in the visitor’s own browser, with no cap on articles and no badge on any plan, ever.
- Vehicle & Equipment Listings — Cars, vans, boats and plant on any page of your site — with no cap on vehicles, on any plan, ever, and no watermark or badge anywhere.
- Discussion Forum & Boards — A real forum on your own site — boards, topics and replies, where anybody can post with just a name, and the whole moderation queue is free.
- Mega Menu & Site Navigation — A bar across the top, panels with as many columns as you like, and levels as deep as your site goes — none of it rationed, on any plan.
- Member Profiles & Directory — A directory of your members that they keep up to date themselves — no cap on how many, and nothing appears until you approve it.
- Client Portal & File Delivery — Files for one client, that only that client can open — by a private link nobody needs an account for, or as a site member you name.
- Gallery, Slideshow & Lightbox — Five arrangements, a real lightbox, and every tile asking for a picture its own size — with no cap on pictures and no badge, on any plan.
- Appointment & Enquiry Request — It takes the request; you keep the diary. No calendar of availability to keep working, no cap on requests, and no badge on your website, ever.
- Visitor Counter & Page Views — An honest number on your own site: page views and unique visitors, counted where they happen. No invented traffic, no badge, and nothing stored about anybody.
- Blog Contents & Reading Time — A contents list built from the headings already on the page, a reading time counted from the article itself, and related posts that never need a permission into your blog.
- Photo Wall & Social Grid — A wall of your own pictures, captions and dates on any page — one that connects to nothing, so there is nothing that can disconnect.
- Document Request & File Upload — Ask each client for the documents you need, and watch them arrive against a checklist with their name on it — with no cap on anything, because nothing is stored by the app.
- Event List & What’s On — A clear page of what is coming up — gigs, markets, fairs, quiz nights — in the order they happen. It is a list, not a ticketing platform: it never sells a ticket and never takes a cut of your gate.
- Membership Cards & Renewals — Your members already exist. This shows each of them their own membership the moment they sign in — their tier, what it includes, and how long is left. It never takes a payment and never charges a percentage of anything.
- Hover Effects & Tooltips — A treatment on a button, a hint on a word, an effect on a picture — and all three work on a phone as well as a desktop. Every effect is on the free plan.
- Help Desk & Support Tickets — Somebody asks you something and gets a reference on the screen. They come back, type it in, and read your answer. It never sends an email, so nothing can land in spam.
- Sports Club: Fixtures, Results & League Table — Your club’s fixtures and results on any page — and the league table works itself out from the scores you type, so the one thing you never have to keep up to date is the table.
- Classifieds & Noticeboard — Small ads and notices your own visitors put up — no seller accounts, no commission, no checkout, and every ad comes down on its own.
- Service Times & Sermons — Your service times where somebody looking for them will find them, and every sermon in one place — with no donation engine, no uploads and no badge.
- Members Only Content Blocks — Hide part of a page behind a sign-in or an access code — and the hidden words are not in the page at all until the door opens.
- Tours, Trips & Itineraries — Your tours with the itinerary on every one — the stops, in order, with times. It is a page, not a booking engine.
- Postcode & Delivery Checker — A postcode box that answers “do you deliver to me?” on the spot. No search credits, no shop needed, and it is not a map.
- Coming Soon & Launch Page — A countdown, a launch page and a list of people to tell — and it takes itself down at the moment you set. No badge on any plan.
- Events Calendar & Google Sync — Your Google Calendar on your website, kept in sync on its own — no cap on events on any plan, and nobody ever logs in to Google.
- Seasonal & Celebration Effects — Snow, autumn leaves, hearts, fireworks and confetti that switch themselves on for each holiday, only on the pages you choose — every effect free, and no badge on any plan.
It covers the apps only. The buildsbyluke.com website itself, including its contact form and chat, is covered by the site privacy policy.
Two roles, stated plainly
If you are a site owner who installs one of these apps, the data the app stores is stored inside your own Wix site and belongs to you. You decide what the app is configured to do, and you are responsible to your own visitors and shoppers for the data your site collects. The app processes that data on your behalf, in your site, to do the job you installed it for.
If you are a visitor or shopper on a site that uses one of these apps, the site owner is your point of contact for anything about that site. We do not receive your personal information from the app; see “What every app has in common” below.
What every app has in common
- Each app stores what it needs in collections it creates inside the site owner’s Wix site. That data lives on Wix’s infrastructure, under the site owner’s Wix account, and is not copied to any server operated by Builds By Luke.
- The apps’ servers call Wix’s own APIs, with one kind of exception that never involves a visitor: where the site owner gives an app an address to read — a podcast feed, an RSS or Atom feed, a published Google Sheet, a calendar’s iCal address, or a page, channel or feed to import from — the app’s backend, on Wix’s infrastructure, reads that address. Those requests carry nothing about the site’s visitors, and no third-party service receives personal information about a visitor from the apps.
- A visitor’s browser reaches outside the site only for content the owner chose to show: a video or a virtual tour loads from its host when the visitor asks for it, audio streams from the owner’s podcast host, and a file or picture comes from wherever the owner keeps it. That host sees the request as it would for any embedded content. Each case is set out below.
- The apps set no cookies of their own and do not fingerprint or track visitors.
- As at the effective date above, no analytics, advertising or visitor-measurement tool is embedded in any of the apps. If that ever changes, this policy will be updated to describe it before it is switched on.
- The only information about a site that reaches us automatically is what Wix sends any app developer: the app-instance identifier and which plan the site is on, so paid features can be unlocked. Wix does not send us your payment details.
- Uninstalling an app removes the collections it created. One exception is noted under Bundles & Volume Discounts below.
What each app processes
The short answer first, because it differs by app and the difference matters. Unless an app is named in this list, it collects no personal information about your visitors at all. It stores the site owner’s own content in collections inside the owner’s site, sets no cookies and writes nothing to a visitor’s browser. Where such an app offers counting, what it writes is a total against the owner’s own item — the file that was opened, the role whose Apply button was pressed, the property or session somebody asked about — carrying no name, address, cookie or other identifier of any kind. And where an app stores anything personal about a visitor at all, it is only ever what that visitor chose to type into it. These are the apps that do anything beyond the rule, and exactly what each of them does:
- Site Search & Product Search — nothing about a visitor. It logs the search text with no identifier attached to it.
- Bundles & Volume Discounts — nothing about a shopper. It stores the offers you create, and Wix’s own cart does the rest.
- FAQ Sections & Search — nothing about a visitor. There is nothing for one to fill in, and the two helpfulness counters are plain totals with no identifier attached.
- Tables & Charts — nothing about a visitor. It stores the tables you build and, if you link a Google Sheet, the link you pasted. It sets no cookies.
- Testimonials Wall — nothing about a visitor who only reads the page. If a visitor sends a testimonial through the form, what they typed is stored: their name, the testimonial and, if the owner asks, a role, company, rating and email address. The email is never shown on the site.
- Discussion Forum & Boards — nothing about a visitor who only reads the forum. If a visitor posts, what they typed is stored: the name they chose and the words they wrote, both of which are then published on the owner’s page, because that is what a forum is. No email address is ever asked for or kept, no account is made, and nothing is written to the visitor’s browser.
- Classifieds & Noticeboard — nothing about a visitor who only reads the board. If a visitor puts an ad up, what they typed is stored: the name they chose, the ad itself, and how they would like to be contacted — an email address, a telephone number, or a line of their own. The contact detail is never included in the read that draws the board, and on the stricter of the two settings it is never sent to a page at all. No account is made and nothing is written to the visitor’s browser.
- Member Profiles & Directory — nothing about a reader. A signed-in member who writes a profile is storing what they typed about themselves, with a switch on every field saying whether it may be shown. No password, no email address and nothing uploaded — a photograph is a web address they pasted — and they can delete the whole profile themselves at any time.
- Document Request & File Upload — nothing about a visitor who only looks at the page. If a client sends a document, the document itself goes straight into the site owner’s own private storage and never passes through the app; what the app stores is a reference to it, plus the name the owner typed and an email address if the owner asked for one. It never asks a client to make an account and never sends an email to anybody.
- Appointment & Enquiry Request — nothing about a visitor who only looks at the form. If a visitor sends a request, what they typed is stored: a name, one way to reach them, what they want and roughly when. It never asks for a postal address, never takes a payment, and never sends an email to anybody — the owner answers from their own address.
- Coming Soon & Launch Page — nothing about a visitor who only reads the launch page. If a visitor asks to be told when the site opens, what they typed is stored: their email address, and a name and one answer if the owner asked for those. No email is ever sent by the app — the owner writes to their own list — and nothing is written to the visitor's browser. The one exception is the owner's own preview key, kept for that tab only by somebody who arrived holding one.
- Events Calendar & Google Sync — nothing about a visitor who only reads the calendar. On the Business plan, and only if the site owner switches suggestions on, a visitor who suggests an event is storing what they typed: the event itself, and a name and one line saying how to reach them, both optional. The suggestion is deleted once the owner approves or declines it, and the name and contact line never reach the calendar. Nothing is written to the visitor’s browser.
- Seasonal & Celebration Effects — nothing about a visitor. The effects are chosen and drawn in the visitor’s own browser, from the owner’s settings, which arrive inside the page. The one thing it ever keeps is a visitor’s own press of the Stop button, remembered for that tab only and gone when the tab closes; it is never sent anywhere and identifies nobody.
- Visitor Counter & Page Views — the one app here that uses a visitor’s browser to count them, and it is two dates: the day they first arrived and the day they were last counted, so a first visit can be told from a return. No cookie is set and no identifier of any kind is created; the only thing that ever leaves the browser is two yes-or-no answers. What is recorded on the owner’s site is a page address with its query string cut off, a day, an instant and those two flags — no IP address, no country, no device, no referrer and no session. The site owner can switch the two dates off entirely, and then page views are still counted and unique visitors are not.
- Every other app covered by this policy — the ones that publish the site owner’s own content, whatever shape that content takes — stores nothing about a visitor. They set no cookies, write nothing to a visitor’s browser, and load no font, script or tracker from anywhere. Four of them are worth being exact about, because the claim is stronger than the rule: Video Gallery & Playlists makes no request to YouTube or Vimeo at all — not even for a thumbnail — until a visitor presses play, unless the site owner switches that off; Quote & Price Calculator works the price out in the visitor’s own browser and keeps a shared quote’s answers in the fragment of the address, which a browser never sends to any server; and Jobs & Careers Board and Real Estate Property Listings never receive an application or an enquiry — the button hands the visitor straight to the owner’s own page, inbox or system. Full detail below.
- An app that displays a file — a document, a PDF, a picture — is the one case in which a visitor’s browser reaches outside the site: it fetches that file from wherever the site owner keeps it, and the file itself holds whatever the owner put in it. Full detail below.
- Countdown Timers, Announcement Bars, Polls & Surveys and Audio Player & Playlists — nothing that identifies a visitor. Each may keep one value in the visitor’s own browser (a countdown’s start time, a closed bar, a vote already cast, where a listener stopped) so the page behaves sensibly on the next visit; nothing is sent to us or tied to a person. Any app that needs the page to behave sensibly on a visitor’s next visit is in this position, and the rule is the same for all of them: one value, kept in that browser, never sent to us and never tied to a person, and only where the site’s cookie banner allows functional storage.
- Product Add-ons & Extras — no contact details, but whatever a shopper types into a text extra is stored, such as an engraving message. That is the point of the feature, and it may contain personal details if they choose to put them there.
- Comments & Moderation — this one does. A comment carries a display name, the comment itself, and a guest’s email address. Full detail below.
Site Search & Product Search
When a visitor searches, the app reads the site’s own public content (products, pages, blog posts, services and events) through Wix APIs and returns matching results. It writes a search log to a collection inside the site: the query, its normalised form, the number of results, the day, and whether the search came from the floating button or the inline bar. No name, email, account, IP address, cookie or other visitor identifier is stored with it. The site owner’s settings (which content is searchable, colours, text, synonyms, hidden pages) are stored in a settings collection in the same site.
The search log is kept for 7 days on the Free plan, 90 days on Pro and 365 days on Business, and the site owner can clear it from the app’s dashboard at any time. The app never reads orders, members or contacts.
Bundles & Volume Discounts
The app stores the offers a store owner creates (names, products or collections, quantities, percentages, schedule, status) in a collection inside the store, and reads product names, prices, images and collections from the store’s catalog to display them. Each offer is compiled into automatic discount rules that live in the store itself, under Marketing → Discounts, exactly like discounts created by hand.
No shopper data is collected by the app. Adding a bundle to the cart uses Wix’s own cart, under Wix’s privacy policy. Uninstalling removes the offers collection; the discount rules remain visible in the store until the owner deletes them, so nothing keeps applying silently.
Product Add-ons & Extras
The app stores the extras a store owner defines (names, prices, choices, products) in a collection inside the store. When a shopper adds a product with extras to the cart, the app stores which extras were chosen and any text the shopper typed (an engraving message, for example) in a second, privileged collection, keyed to the cart’s purchase-flow identifier and the cart line, so the fee can be calculated at checkout and shown on the order. Only the app’s own backend can read that collection.
A shopper may choose to type personal details into a text extra; that text is stored in the store owner’s site and shown to the store owner on the order, which is the purpose of the feature. No names, emails, addresses or payment details are collected by the app; those stay with Wix. Selections for abandoned carts remain in the collection until the site owner clears them or uninstalls the app.
Comments & Moderation
This is one of only two apps that store personal information about a site’s visitors (the other is Testimonials Wall, below), so it is worth being exact. When a visitor posts a comment, the app stores in a collection inside the site owner’s site: the comment text, the display name given, the page the comment belongs to, the time it was posted, its status, and a spam score with the reasons behind it. If the visitor was a logged-in member of that site, their Wix member ID is stored instead of contact details, and no email is collected at all. If the visitor was a guest, the email address they typed is stored alongside the comment.
A guest’s email is stored for the site owner’s reference only. It is never shown to other visitors, never returned by the public thread, and never used to send anything — the app sends no email whatsoever. The site owner can see it in their dashboard and in a CSV export. The comment text and display name are public by design: that is what posting a comment means.
Spam scoring happens entirely inside the site. No comment, name or email is sent to any external classification service, ours included. The filter scores behaviour only — link stuffing, sales vocabulary, capitals, punctuation floods, repeated characters, an email hidden in the body, a suspicious author name and duplicate text across pages. It does not score language or writing system, so a comment in any language is judged the same way. The site owner’s settings (moderation mode, members-only, blocked words, heading, colour, sort order) are stored in a second collection in the same site.
Comments are kept until the site owner deletes them; deleting a comment in the dashboard removes the row and the email with it. A visitor who wants their comment removed should contact the owner of the site they commented on, who can delete it immediately. Uninstalling removes both collections.
FAQ Sections & Search
This app collects no personal information about visitors at all. There is nothing for a visitor to fill in: no form, no comment, no account. It stores the site owner’s own content — the FAQ sections and the questions and answers written into them — in collections inside the owner’s site.
Two counters are kept against each question: how many times it was opened, and how many people marked the answer helpful or unhelpful. They are plain totals with nothing attached. No name, email, account, IP address, cookie or other identifier is recorded with them, so they cannot be traced to a person and are not personal data.
On the paid plans the app also adds a machine-readable copy of the questions on a page, as schema.org FAQPage structured data. It contains only the questions and answers the site owner wrote, and nothing about whoever is reading the page.
Tables & Charts
This app collects no personal information about visitors at all. There is nothing for a visitor to fill in: no form, no comment, no account, and the app sets no cookies. It stores the site owner’s own content — each table’s name, columns, display and chart settings, and the rows the owner typed, pasted, uploaded or imported — in collections inside the owner’s site.
If the owner links a Google Sheet, the link they pasted is stored with the table and the sheet’s published CSV export is read by the app’s backend, which runs on Wix’s infrastructure. That request carries nothing about the site’s visitors, and the app refuses any address that is not docs.google.com. Whatever is in the sheet becomes rows on the owner’s page, so a sheet that contains personal details will publish them; that is the owner’s choice and responsibility, exactly as it would be for any page they write.
Sorting, searching and paging happen in the visitor’s browser against rows already on the page. No search text, click or view is recorded anywhere.
Testimonials Wall
A visitor who only reads a wall of testimonials is not recorded in any way; the app sets no cookies. The testimonials the site owner types in or imports are the owner’s own content, stored in collections inside the owner’s site.
If the owner switches on the form (a paid feature), a visitor can send a testimonial. The app then stores what the visitor typed: their name, the testimonial, and, if the owner asks for them, a role, company, star rating and email address, together with the time it was sent. The visitor ticks a consent line before sending. The submission waits for the owner to publish, hide or delete it, and the email address is kept for the owner alone; it is never included in what the page loads. A visitor who wants a testimonial removed asks the site owner, who deletes it in the dashboard. The app caps submissions per hour and uses a hidden field to discard automated senders; it does not record IP addresses or device identifiers.
Every app that publishes the site owner’s own content
Most of the apps covered by this policy do one job: they take content the site owner types in or uploads and put it on the owner’s own page. A pricing table, a protection setting, a podcast feed, a timeline, a recipe, a video gallery, a portfolio, a document library, a news ticker, a quote calculator, a careers board, a property board, a class timetable — and every app of the same shape added to the list above after this policy’s effective date. For all of them the answer is the same, and it does not vary:
- They collect no personal information about visitors at all, and set no cookies.
- They write nothing to a visitor’s browser — no cookie, no local storage, no identifier.
- They store the owner’s own content in collections inside the owner’s site, and uninstalling removes those collections.
- Where the owner switches counting on, the app writes one row naming only the owner’s own item — the file that was downloaded, the headline or the update that was pressed, the role, property, session or item somebody asked about. No name, email, address, cookie or other visitor identifier is stored with it, and nothing at all is written to the visitor’s browser.
- Where such an app has a button that sends a visitor somewhere — Apply, Enquire, Book, Enrol, Contact — the app never receives what the visitor then says. The button hands them straight to the page, inbox, link or system the owner chose. There is no application, no enquiry, no lead record and no mail server of ours anywhere in it.
Some of them reach outside the site, always on the owner’s or the visitor’s behalf and never to us. Podcast Player reads the owner’s feed from the app’s backend on Wix’s infrastructure — asking Apple’s public podcast directory for the feed’s address when the owner pastes an Apple Podcasts link — and a visitor’s browser streams the audio from the owner’s podcast host, as it would from any player. News Ticker & Live Updates can read one RSS or Atom address the owner names, keeping only the headline, its link and its time. Recipe Cards & Cookbook can import a recipe from a page address the owner gives it, reading the recipe data that page already publishes for search engines, and Video Gallery & Playlists asks YouTube or Vimeo for a video’s title when the owner adds one, and can import from a YouTube channel or playlist the owner names. These reads happen from the app’s backend, when the owner asks, and carry nothing about the site’s visitors.
Where an app shows a video or a virtual tour, nothing is requested from YouTube, Vimeo or the tour’s host — not even a thumbnail — until a visitor presses play, and YouTube plays through its no-cookie player: Video Gallery & Playlists (unless the site owner switches that off), Course & Programme Catalogue, Services & Price List, Real Estate Property Listings, Vehicle & Equipment Listings, Recipe Cards & Cookbook and Timeline & Milestones. Portfolio & Project Showcase loads the same no-cookie player when a visitor opens a project that has a video in it.
Documents, files and pictures an app displays
Some of these apps do not describe a file, they show it — a PDF, a document, a picture. Three things follow, and they are worth stating rather than leaving to be discovered.
- The file is fetched by the visitor’s browser, from wherever the site owner keeps it. Normally that is the owner’s own Wix Media Manager, which is the same place every other picture on the page comes from. If the owner instead points the app at a file hosted somewhere else, the visitor’s browser fetches it from that host, and that host sees the request as it would for any link the owner put on the page. The apps store the address of a file and the words around it, never a copy.
- The file is read in the visitor’s own browser. Everything needed to draw a document on the page is part of the app’s own bundle — nothing is loaded from a content delivery network at the moment of reading, no page is sent anywhere to be converted, and no server of ours ever receives the document or anything inside it. A search inside a document runs on the visitor’s own machine, and what they searched for is not recorded.
- The file holds whatever the owner put in it. A document can contain personal information about identifiable people — a staff list, a newsletter, a price list naming who does the work. Publishing it is the owner’s decision and the owner is the controller of it; the app’s job is to display it. Removing a document from the app removes it from the page immediately.
Where the owner switches counting on, these apps count in the same way as every other app above: one row naming only the document, with no visitor identifier of any kind, and nothing written to the visitor’s browser.
Countdown Timers, Announcement Bars, Polls & Surveys, Audio Player
These apps store the owner’s timers, bars, polls and survey questions in collections inside the owner’s site, and they keep one small value in the visitor’s own browser where the feature needs it: an evergreen countdown remembers when it started and a closed countdown bar stays closed for that browsing session (both only when the site’s cookie banner allows functional storage — if it does not, nothing is stored and the countdown simply starts again on each page), a closed announcement bar stays closed for the session, and a poll remembers that the visitor has voted so it shows results instead of the form. None of these values is sent to us or linked to a person. Poll votes are stored as totals per option; survey answers are stored as given, with no IP address or device identifier, and an announcement bar’s impressions and clicks are daily totals.
Audio Player & Playlists stores the owner’s tracks, playlists and player settings in collections inside the owner’s site. It writes one value to a visitor’s browser and only when the owner switches “pick up where you left off” on: how far through a track that browser had listened, and then only when the site’s cookie banner allows functional storage. Where it does not, tracks simply start at the beginning. Plays and downloads are counted as two numbers on a row named by the track and the date — no visitor identifier is received, derived or written, so an owner can leave counting on without owing anybody a consent prompt. The audio itself streams from wherever the owner keeps it, as it would from any player.
Team & Staff Directory
This app collects nothing at all about a site’s visitors — no form, no account, no cookie, no local storage, no identifier of any kind. It is worth being exact about the other side of it, because this is the one app on this list whose ordinary content is personal information about identifiable people: the site owner types in their colleagues’ names, photographs, roles, departments, locations, pronouns, biographies, work email addresses, work telephone numbers and links, and all of it is stored in collections inside the owner’s own site and published on the owner’s own page, because publishing it is the entire purpose of a staff directory.
The site owner is the controller of that information and is responsible for having told the people in it. The app is built to keep the scope narrow: there is nowhere to put a home address, a salary, a date of birth or a national insurance number, a joining date is published as a year only, and a profile can be removed by the owner at any time — nothing the app does ever deletes a row on its own. Somebody who wants their profile changed or taken down should ask the owner of the site it appears on, who can do it immediately. Uninstalling removes the collections.
If the owner switches counting on, the app keeps one number against a person saying how many times the Contact button was pressed. Nothing about who pressed it is received, derived or written. The Contact button hands the visitor straight to the address, telephone number, page or link the owner chose; the app never receives a message, so there is no enquiry, no lead record and no mail server of ours anywhere in it.
The same reasoning applies, more lightly, to any app on the list above whose ordinary content can name an identifiable person — who performs a service, who teaches a course, who to ask about a property or a listing, whose name is on a document. In every such case the site owner is the controller of that information and is responsible for having told the person; the field exists because a visitor needs to know who they are dealing with, not so that a record can be built about anybody. None of these apps has anywhere to put a home address, a salary, a date of birth or a national identifier, none of them ever adds a person the owner did not type in, and removing the entry removes it from the page immediately.
Discussion Forum & Boards
This app is the one on the list whose ordinary content is written by visitors rather than by the site owner, so it is worth being exact. A visitor who only reads a forum leaves nothing at all: no cookie, no local storage, no session, no identifier, and no request to anybody but the owner’s own site. A visitor who posts gives a name and a message, and that is the whole of it — there is nowhere to put an email address, no account is created, no confirmation is sent, and nothing is written to their browser. Both are then published on the owner’s page, because publishing them is what a forum is for. Where the site has members and somebody is signed in, the app also stores the site member identifier Wix already holds, so that owner can see which posts are theirs.
The site owner is the controller of everything posted on their forum. They can edit, hide, move or delete any topic or reply at any moment, on every plan including the free one, and deleting a topic deletes its replies with it. Somebody who wants their post removed should ask the owner of the site it appears on, who can do it immediately. The whole forum is ordinary rows in the owner’s own content manager and can be exported to a spreadsheet at any time; uninstalling removes the collections.
This app sends no email to anybody, ever — not to the owner, not to a member, not when a topic is started or a reply is posted. There is no mail server of ours anywhere in it, so there is no notification to switch off and nobody can be sent a mailing by it. The spam filter is arithmetic on the text itself, performed inside the owner’s own site: no post is ever sent to a third-party service to be scored. A “helpful” press, and on the Business plan a topic being opened, are each recorded as one row naming the topic and nothing else — no address, no cookie, no fingerprint, nothing about the person at all.
Classifieds & Noticeboard
This is the other app whose ordinary content is written by visitors, and unlike a forum post an ad usually carries a way of reaching the person who wrote it — so it is worth being exact. A visitor who only reads a board leaves nothing at all: no cookie, no local storage, no session, no identifier, and no request to anybody but the owner’s own site. A visitor who puts an ad up gives a name, the ad, and how they would like to be contacted. Where the site has members and somebody is signed in, the app also stores the site member identifier Wix already holds, so the owner can see which ads are theirs.
The contact detail is treated differently from everything else, and the site owner chooses how. On the default setting it is never part of the read that draws the board — the shape a page receives has no field to put one in — and is fetched for a single ad, by name, only when a reader presses Show contact. That is an obstacle to anybody harvesting a page rather than encryption, and the app says so in those words in the dashboard. The second setting is the guarantee: with contacts kept in the dashboard, no contact detail is sent to a page at all, by any request, and the owner passes them on themselves. A board set that way publishes a name and an ad, and nothing else.
The site owner is the controller of everything on their board. They can edit, hide, move or delete any ad at any moment, on every plan including the free one. Somebody who wants their ad removed should ask the owner of the site it appears on, who can do it immediately — and in the ordinary course every ad comes down by itself when its run ends, which is arithmetic done at the moment somebody reads it rather than a sweep that could be missed. The whole board is ordinary rows in the owner’s own content manager and can be exported to a spreadsheet at any time; uninstalling removes the collections.
No picture is ever uploaded and none is stored: a picture on an ad is a web
address the poster typed, checked to be http or https before it is
kept, and drawn with no referrer sent to whoever is hosting it.
This app sends no email to anybody, ever — not to the owner, not to a poster,
not when an ad goes up. There is no mail server of ours anywhere in it. The spam filter is
arithmetic on the text itself, performed inside the owner’s own site:
no ad is ever sent to a third-party service to be scored. On the Business
plan, an ad being opened is recorded as one row naming the ad and nothing else
— no address, no cookie, no fingerprint, nothing about the person at all.
Document Request & File Upload
This is the app on the list that handles the most sensitive thing anybody will put through any of them — a client’s identity document — so it is worth being exact about where it goes. It goes nowhere near us. When a client presses a file, this app’s server asks Wix for a signed, one-shot upload address and hands it to the client’s browser; the browser sends the file directly to Wix, into the site owner’s own media library, in a folder named for that client. Not one byte of any document passes through this app, and there is no copy of it anywhere but the owner’s own site.
Every document is stored private, which means it has no public web address at all — not even an unlisted one that could be forwarded or guessed. The only way to open one is from the owner’s own dashboard, as that site’s own staff, over a link this app mints at the moment it is pressed and which stops working ten minutes later. The signed upload address the client’s browser is given carries the destination, the filename and the privacy setting baked into it, so a client holding one cannot change where their file goes, what it is called, or make it public.
What the app itself stores is a reference, not a file: the media identifier, the filename, the size, the type and the time it arrived. Beside it sits the request — the name the site owner typed for that client, an email address if the owner chose to ask for one, and whatever the sender wrote in a message box. There is nowhere in this app to put a home address, a date of birth, a national identifier or a payment detail, because it never asks for one. A request link is a long random token, and the owner may add a short code on top of it; a locked request gives up nothing at all — not even the name on it — until that code is given.
Nothing whatsoever is stored about the person sending. No cookie, no local storage, no session, no identifier and no address — a client needs no account, no password and nothing installed. The optional activity record, which only a Business site can read, is a line saying what happened and when; “opened” means this request’s page was drawn, not that a particular person was there, and the dashboard says so in those words rather than letting an owner read it as a receipt.
The site owner is the controller of everything in their requests and is responsible for having told their clients what the documents are for and how long they will be kept. They can delete any request at any moment on every plan, and deleting a request leaves the documents exactly where they are in their own media library — this app will not throw away somebody’s signed contract because a row was tidied. Uninstalling removes the app’s collections and touches no document at all.
This app sends no email to anybody, ever — not to the owner, not to a client. Where a rival charges to remind somebody, this app writes the owner a message to paste into their own email, from their own address. And receiving a document is free on every plan, including a lapsed one: a subscription ending must never be the reason a client’s file does not arrive.
Member Profiles & Directory
This is the app on the list whose ordinary content is personal information that the people it is about wrote themselves, so it is worth being exact. A visitor who only reads a directory leaves nothing at all: no cookie, no local storage, no session, no identifier, and no request to anybody but the owner’s own site. A signed-in member who writes a profile is storing what they chose to say about themselves — a name, a line under it, something about themselves, where they are, a photograph and a few links — and it is then published on the owner’s page, because publishing it is what a member directory is for.
Every one of those fields has its own switch, and the member owns it. Anything switched off is removed before the page is sent, so it is not in the page for anybody to read and it cannot be found by searching either; it stays in the owner’s own records, and in the exported spreadsheet, which is the owner’s copy rather than a copy of the page. The app holds no password, no email address, no telephone number and no home address, because it never asks for one: a member is identified only by the pseudonymous site-member identifier Wix already holds, taken from the token Wix signs, and never from anything the browser says about itself.
Nothing is ever uploaded to this app. A photograph is a web address the member pastes, checked before it is accepted; there is no upload path at all. No profile is ever emitted as structured data, and every link a member publishes is marked so that it passes no ranking to anybody — these are private people who joined a club, not a business advertising its staff.
The site owner is the controller of everything in their directory and is responsible for having told the people in it what it is for. They can edit, take down or remove any profile at any moment, on every plan including the free one, and nothing appears on the page until they approve it. A member can also remove their own profile at any time, in two presses, and that deletes the row — it is not merely hidden. The whole directory is ordinary rows in the owner’s own content manager, exportable to a spreadsheet at any time; uninstalling removes the collections.
This app sends no email to anybody, ever — not to the owner, not to a member, not when a profile is written or approved. There is no mail server of ours anywhere in it. On the Business plan a profile being opened is recorded as one row naming the profile and the time, and nothing about the reader at all; on every other plan that request is not even made.
Appointment & Enquiry Request
This is the app on the list whose ordinary content is a visitor asking to be contacted back, so it is worth being exact. A visitor who only looks at the form leaves nothing at all: no cookie, no local storage, no session, no identifier, and no request to anybody but the owner’s own site. A visitor who sends a request is giving the business a name, one way to reach them — an email address or a telephone number, whichever the owner asks for — what they want, roughly when would suit them, and anything else they chose to type. That is the whole of it, and it is the whole point: a request nobody can answer is worse than no request.
It never asks anybody for a postal address, and it never takes a payment. There is no cart, no order total, no checkout and no card field anywhere in it, so there is nothing of that kind to store, lose or hand to anybody. No IP address is recorded, nothing is written to the sender’s browser, and the app makes no request to any third party at all. The spam check is arithmetic performed inside the owner’s own site: no request is ever sent to an outside service to be scored, and a request the check finds suspicious is stored and marked for the owner rather than discarded.
This app sends no email to anybody, ever — not to the sender, not to the owner, not to a third party. There is no mail server of ours anywhere in it, and no outbound channel of any kind. The owner answers from their own address, out of their own email client. Where a site is on the Business plan and the owner has switched it on, the sender can be given a private link to look up their own request; the secret half of that link is stored beside the request, is never shown in any list, and is never included in an exported spreadsheet. Looking it up returns the state of that one request and nothing else — never the owner’s private note, never their tags, and never anybody else’s request.
The site owner is the controller of every request their form receives and is responsible for telling people what they will do with it. They can read, answer, export or delete any request at any moment, on every plan including the free one. Everything is ordinary rows in the owner’s own content manager and can be exported to a spreadsheet at any time; uninstalling removes the collections.
Visitor Counter & Page Views
This is the only app on this list that uses a visitor’s browser to count them, so it is worth being exact about what it keeps there. To tell a first visit from a return it keeps two dates in the visitor’s own browser storage — the day they first arrived and the day they were last counted. It is not a cookie, it is never sent anywhere, and it is not an identifier: nothing about it is unique to a person, nothing can be joined to anything else, and the only thing that ever leaves that browser is two yes-or-no answers, is this a first visit and is this a new day. Every read and write of it is wrapped, so a private window or a browser with site data blocked simply counts the view and claims no visitor. The site owner can switch it off entirely in their dashboard; page views are then still counted and unique visitors are not, because a nought there would be a guess rather than a figure.
What is written down on the owner’s own site for a counted view is a page address, a day, an instant and those two flags — and nothing else. There is no IP address, no country, no city, no device, no browser, no referrer, no search term, no session and no identifier of any kind. The page address has its query string and fragment removed before anything is stored, because a query string is where a site puts a search term, a discount code, an email address in a sign-up link or a marketing identifier, and none of that is any business of a counter.
Nothing is loaded from any third party — no script, no tracker, no analytics service, no font and no icon set — and a placement makes exactly one request, to the owner’s own site. The app also never invents a view: there is no simulated traffic in it, and the only number ever added to a count is a figure the owner typed in as the one they carried over from whatever they were counting with before, which their dashboard always shows separately from what was actually counted.
The site owner is the controller of their own figures. They are ordinary rows in the owner’s own content manager, exportable to a spreadsheet at any time on every plan including the free one, and uninstalling removes the collections.
Coming Soon & Launch Page
This app stores nothing at all about a visitor who only reads the launch page — no cookie, no local storage, no identifier, no counting of any kind. Its ordinary content is the owner's own: a moment, a headline, a message and a design.
It is worth being exact about the other side of it, because this app does collect information about identifiable people: a visitor who asks to be told when the site opens is giving the site owner their email address, and, if the owner has switched those fields on, a name and one answer to one question of the owner's own. That is the whole of it. What is written down is the address, the name and answer if they were asked for, the instant, and the path of the page the form was on — and the path has its query string and fragment removed before anything is stored, because a query string is where a site puts a search term, a discount code or a marketing identifier, and none of that is any business of a sign-up form. There is no network-address column, no reader-identifier column, no browser column and no referrer column on that collection, so there is nowhere for one to be added by accident.
The site owner is the controller of that list and is responsible for what they do with it. This app never sends anybody anything: there is no mail server in it, no confirmation message, no double opt-in and no connection to anybody else's mail service. It collects the addresses; the owner writes to their list from whatever they already use. No address is ever passed on, sold or used for anything else. The owner can remove somebody from the list on any plan, the moment they ask, and the rows are ordinary rows in the owner's own content manager, exportable to a spreadsheet at any time on every plan including the free one. Deleting a launch deletes its list with it, rather than leaving addresses behind with nobody to answer for them. Uninstalling removes the collections.
The app can also draw a curtain over the owner's published site until the moment they set. That curtain is a courtesy, not a lock: it is not a password and it is not security, and the app says so in the owner's dashboard in those words — search engines and anybody reading the page source can still see what is behind it. The only thing this app ever writes to a browser is the owner's own preview key, and only for somebody who arrived holding one: it is kept for that tab only, it is gone when the tab closes, it identifies nobody, and every read and write of it is wrapped so that a private window or a browser with site data blocked simply carries on. A site that is not behind a curtain carries none of the curtain’s code.
Events Calendar & Google Sync
This app stores nothing at all about a visitor who only reads the calendar — no cookie, no local storage, no identifier, no counting of any kind — and nothing is loaded from anybody else: no font, no script, no tracker. The map, Google and Outlook buttons are ordinary links that carry only the event and go nowhere until they are pressed, and the calendar file for everything else is built in the visitor’s own browser. Its ordinary content is the owner’s own: their calendars, their events, a design and some wording.
If the owner syncs a calendar — a Google, Outlook or other iCal calendar — the address they pasted is stored in their own site and the calendar is read from that address by the app’s backend, which runs on Wix’s infrastructure. That request carries nothing about the site’s visitors, and a visitor’s browser never contacts Google or any other calendar provider. A Google “secret address” is a password shaped like a link, so it is never sent to a page, on any plan. The app never asks for a Google login and holds no Google permission. Whatever is in the synced calendar becomes events on the owner’s page, so a calendar that names people will publish their names; that is the owner’s choice and responsibility, exactly as it would be for any page they write. Attendee and organiser lists in a synced calendar are never read.
It is worth being exact about the one place this app holds anything about an identifiable person. On the Business plan, and only if the owner switches suggestions on, a visitor can suggest an event through a short form. What is written down is the event they described — a title, a date, times, a place, a description and a link — and, only if they choose to give them, a name and one line saying how to reach them. There is no network-address column, no reader-identifier column and no browser column on that collection, so there is nowhere for one to be added by accident. Nothing a visitor sends appears on the owner’s page until the owner approves it, and an approved event carries only the event: the name and the contact line never reach the calendar. A suggestion is deleted as soon as it is approved or declined, and deleting one works on every plan, including after a Business plan ends. The rows are ordinary rows in the owner’s own content manager, and uninstalling removes the collections.
Seasonal & Celebration Effects
This app stores nothing at all about a visitor — no cookie, no identifier, no counting of any kind — and nothing is loaded from anybody else: no font, no script, no tracker. Which effect runs, on which page and on which day is decided in the visitor’s own browser from the owner’s settings, which Wix places inside the page itself, so an ordinary page view asks nobody anything. The drawing code is fetched from the app’s own address on Wix’s infrastructure, and only on a page that is about to draw something. A page with nothing to draw fetches none of it, and with every effect switched off the app’s site-wide script comes off the site altogether. If the owner uses a picture of their own as the effect, the visitor’s browser loads that picture from wherever the owner keeps it.
Two requests are worth being exact about, and neither carries anything about the visitor. Where the owner has placed the app’s invisible effects layer on their pages, the page asks the app, once, for that site’s own settings. And now and then — at most one visit in twenty, once the settings are more than three days old — a page asks the app to refresh them with the site’s current plan. Neither request sends anything from the page: the only thing the app learns from either is which site is asking, which Wix tells it.
The one thing this app ever writes to a browser is a visitor’s own press of the Stop button, so the animation stays stopped as they move around the site. It is kept for that tab only, it is gone when the tab closes, it is never sent anywhere and it identifies nobody. Every read and write of it is wrapped, so a private window or a browser with site data blocked simply shows the effect again on the next page. The app also honours a visitor’s reduced-motion setting: nothing falls and nothing bursts for them, and a decoration stands still.
Its ordinary content is the owner’s own: which effects, on which dates and pages, in which colours. It is kept in the app’s own setting on the owner’s site, with a backup copy in a collection in their content manager. A record of the owner’s changes, the newest 200, is kept there too, on every plan. It names the effect that changed and never anybody who visited. Uninstalling removes the collections.
Plans and billing
Paid plans are sold and billed by Wix through the Wix App Market. Wix collects and handles your payment and billing details under its own terms and privacy policy; we receive only the plan level for each installation, never the payment details.
Support correspondence
If you email us, we receive your email address, your name if you include it, and the message you wrote, and we use them for one purpose: to reply and resolve your question. Support correspondence is kept for as long as it takes to resolve the matter and for a reasonable period afterwards in case it comes up again, and is never used for marketing. We only reply to people who contact us first.
Legal basis for processing (GDPR)
Where the GDPR applies to you, the legal bases are:
- Performance of a contract (Art. 6(1)(b)): providing the app you installed, with the features of the plan you chose.
- Legitimate interests (Art. 6(1)(f)): answering support requests, and keeping the apps secure and working. That interest is balanced against yours by collecting the minimum and keeping data inside your own site.
We do not rely on consent for any processing described here, so there is no consent for you to withdraw from us. Where a site owner’s own use of an app depends on their visitors’ consent, that is the site owner’s responsibility under their own policy.
Where the data lives, and international transfers
Data the apps store stays inside your Wix site, wherever Wix keeps it, and we do not move it. Support correspondence is handled in Canada, which the European Commission recognises as providing adequate protection for commercial organisations subject to PIPEDA, so no additional transfer safeguard is required for it.
Your rights
Under PIPEDA you may ask what personal information we hold about you, ask for it to be corrected, and challenge our compliance with this policy. Where the GDPR applies, you also have the rights of access, rectification, erasure, restriction, portability and objection.
- Site owners control the app’s data directly: clear it from the app’s dashboard, or uninstall the app to remove its collections.
- Visitors and shoppers should contact the owner of the site they used, who holds the data.
- For anything we hold ourselves (support correspondence), email the Privacy Contact. Requests are answered within 30 days. Deletion is honoured except where a record must be kept for tax, accounting or legal reasons.
You also have the right to complain to the privacy regulator in your country if you believe your information has been mishandled, though we would ask for the chance to resolve it first.
Children
The apps are business tools for site owners and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has sent us information, email us and we will delete it.
Changes to this policy
If this policy changes in any material way, the revised version will be posted on this page with a new effective date at the top, and the change will take effect when it is posted. Material changes will never be applied retroactively to information already collected without telling you.
Contact
Privacy Contact, Builds By Luke, Canada
support@buildsbyluke.com