Privacy Policy

Last updated April 28, 2026 · Terms →

Webinly (“we”, “us”) is a webinar hosting platform run by an independent operator. This page explains what data we collect when you use app.webinly.com, what we do with it, and the rights you have over it. We aim for plain English, not legalese — if anything is unclear, email contact@webinly.com.

Who this applies to

Hosts — people who sign up at /sign-up to create webinars.

Attendees — people who register on a host's public webinar page (e.g. /w/some-slug).

What we collect

From hosts

  • Account info — name, email, profile image (provided via your sign-in method — email + password or Google sign-in).
  • Webinar content — titles, descriptions, schedules, video files you upload, and any offer / CTA copy you configure.

From attendees

  • Registration info — the name and email you enter on the host's public page, plus optional UTM parameters from the link you clicked.
  • Attendance signals — when you joined the watch room, how long you watched, and whether you reached the end. Used to show the host attendance + drop-off analytics.
  • Chat messages and questions — anything you type in the watch room sidebar (including the “Ask a question” tab) is stored so the host can reply later.
  • IP address — captured by our hosting providers' standard logs for security and abuse prevention; not associated with your registration record.

Cookies

Strictly necessary (always on): signing in sets two essential cookies (an access token and a refresh token). On webinar pages that use a host-set password gate, we may set one additional short-lived cookie that records the password was entered (so you don't have to type it on every page-load). These can't be turned off without breaking the service.

Analytics (your choice): we use a privacy-friendly product analytics tool (which pages people open, which buttons confuse them, where they drop off in the host flow). It only fires after you click Accept on the cookie banner; if you click Reject, no analytics cookies are set and no events are sent.

Advertising (your choice): a host can connect their own advertising pixels — Meta (Facebook), TikTok, and Google — to their public webinar pages so their ad platforms can measure the registrations and sales those ads drive. When a host has enabled them, these third-party pixels load on that host's webinar and checkout pages only after you click Accept — the same choice that gates analytics. Click Reject and no advertising pixels load. The host (not Webinly) chooses whether to run them and is the data controller for that choice.

You can change your mind any time — reopen the cookie banner.

How we use it

  • To run your webinars (host the page, stream the video, deliver chat).
  • To send emails on the host's behalf (registration confirmations, reminders, replay links).
  • To compute the analytics shown on the host dashboard.
  • To detect abuse and keep the service up (rate-limiting, bot detection, spam handling).
  • To respond when you contact us.

We do not sell your data, and we do not use the content of your webinars (videos, chat, questions) to train AI models.

Who we share it with

Webinly relies on a small set of infrastructure sub-processors, grouped here by function. Each one only handles the data it needs to do its job:

FunctionWhat they handleWhere
Authentication & real-time chatSign-in, session security, and live webinar chatEU
Database hostingYour account, webinars, registrations, and messagesEU / USA
Email deliveryRegistration confirmations and reminder emailsUSA
Background job processingScheduled sends (reminders and follow-ups)USA
Application hosting & CDNServing the app and static assetsGlobal
Host advertising pixels (host's choice, consent-gated)Meta, TikTok & Google receive page-view and conversion events on a host's webinar pages when that host enables their own pixel and you accept cookiesGlobal
WhatsApp messaging (host's choice)When a host connects their own WhatsApp Business number, Meta receives the phone numbers we message on that host's behalf, the message contents, and delivery and read receiptsGlobal

WhatsApp, in plain terms. A host can connect their own WhatsApp Business number to Webinly. When they do, we act only on that host's instructions: we send the messages they configure, we store the replies so the conversation is readable later, and we keep our own copy of any photo, voice note or document exchanged — because WhatsApp itself deletes those within days. We never use a host's WhatsApp data for our own purposes, never message their contacts on our own behalf, and never move data between hosts. Replying with a stop word (in Arabic or English) unsubscribes you immediately, and you can ask a host to delete your conversation at any time.

When EU/UK personal data flows outside those regions we rely on standard contractual clauses with the relevant sub-processor. Aside from the sub-processors above — and any advertising pixels an individual host chooses to run on their own webinar pages, which load only with your consent — we do not share your data with third parties unless required by law.

Your rights

No matter where you live, you can:

  • Access a copy of your data — email contact@webinly.com.
  • Correct inaccurate data (hosts can edit most fields directly in the dashboard).
  • Delete your account and all the data tied to it.
  • Export your data in a portable format on request.
  • Object to processing or restrict it. We will comply unless we have a legal reason to keep the data (e.g. an ongoing abuse investigation).
  • Unsubscribe from any email by clicking the link at the bottom of every email we send.

If you are in the EU/UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

How long we keep it

We keep your data for as long as your account is active. When you delete your account, we delete (or irreversibly anonymize) your webinars, registrations, and chat history within 30 days, except where we are required to keep records for legal reasons.

Hosts: when you delete a webinar, the registrants attached to it are deleted at the same time. Backups are purged on a 30-day rolling cycle.

Children

Webinly is not intended for children under 16. We do not knowingly collect personal data from anyone under that age. If you believe a child has signed up, please email us so we can remove their account.

Changes to this policy

We may update this page as the product changes. If the change is material we will email registered hosts at least 14 days before it takes effect. The “Last updated” date at the top always reflects the current version.

Contact

Questions, requests, or complaints — email contact@webinly.com. We aim to reply within 5 business days.