Privacy Policy
Effective date: June 5, 2026
Last updated: June 5, 2026
Canonical URL: /privacy/
1. Introduction
Welcome to We’ll Do It LLC. We are committed to protecting your personal information and being transparent about what we do with it. This Privacy Policy explains how we collect, use, share, and protect your data when you use welldoit.solutions, our WooCommerce store, our marketplaces, our consulting and support services, and related WDI services. That includes access to Monocle and other WDI software when it is included in your plan.
Who we are. We’ll Do It LLC, 2321 E. University Dr., Phoenix, AZ 85034, United States. For most of the processing described here, we are the data controller.
When we are a processor. When we resell or set up technology on a client’s behalf, we may act as a data processor. In that case, our processing is governed by our agreement with the client (the controller).
Related documents: Terms & Conditions, Data Protection, Third-Party Processors.
2. Legal reasons we use your information
We process personal information only when we have a valid legal reason.
- Contract. To deliver the services you purchase, manage your account, and process payments.
- Legal obligation. Tax, accounting, and regulatory requirements (including PTIN and ETIN identifiers where applicable).
- Legitimate interests. Security, fraud prevention, service improvement, and customer support, balanced against your rights.
- Consent. Optional marketing, non-essential cookies, and similar choices you can withdraw at any time.
3. Information we collect
We collect information directly from you, automatically on our sites, and from partners.
| Category | Examples |
|---|---|
| Identifiers | Name, email, phone, billing and shipping address, IP address, account username |
| Commercial | Purchases, subscriptions, quotes, transaction history |
| Internet and device activity | Pages viewed, referral URLs, cookies, analytics events |
| Professional | Job title, company, industry (for consulting and B2B services) |
| Sensitive or high-risk | SSN, EIN, TIN (for tax services only); payment card and bank data; delegated credentials for managed services |
Delegated access data
When you give us logins or financial access so we can do the work you hired us for, we treat that as high-trust data. We store it encrypted, restrict access on a need-to-know basis, prefer OAuth or API tokens over raw passwords, use the access only for the contracted purpose, and delete it when the service ends.
Health information
We do not routinely process protected health information (PHI). If a project requires it, we will use a separate, HIPAA-aligned agreement first.
4. How we use information
| Purpose | Typical data | Legal reason |
|---|---|---|
| Provide services and accounts | Identifiers, commercial, professional, delegated access (where needed) | Contract |
| Payments and fraud prevention | Identifiers, commercial, financial, device data | Contract; legitimate interests |
| Legal and regulatory compliance | Identifiers, tax identifiers | Legal obligation |
| Marketing (optional) | Identifiers, activity | Consent |
| Analytics and improvement | Activity, cookies | Consent (non-essential cookies); legitimate interests for server-side aggregates |
| Customer support | Information you provide | Legitimate interests |
5. Sharing and third parties
We do not sell personal information. We share data with service providers who process it on our behalf under contract. See the Third-Party Processors appendix for the current list (payments, CRM, analytics, hosting, marketplace tools, and more).
We may also share information with:
- Professional advisors (legal, accounting) under confidentiality.
- Government or law enforcement when required by valid legal process.
- A successor in a merger or acquisition (with notice where required).
Monocle and WDI software
Monocle (for example, monocle.welldoit.solutions) is a WDI-owned product suite. When your plan includes Monocle, we may sync account, order, and workplace-scoped data between WordPress/WooCommerce and Monocle through WDI plugins such as internal-wdi-monocle. Monocle data is processed under this policy and our Terms. Permissions are scoped to your active workplace memberships.
6. Cookies and similar technologies
We use cookies and similar technologies in the following categories.
For visitors in the EEA, UK, and California, non-essential cookies and trackers are blocked from loading until you give consent through our banner or a recognized global privacy signal.
| Category | Examples | Purpose | Consent |
|---|---|---|---|
| Strictly necessary | Cart, checkout, account login session, and security checks (for example, bot-protection challenges) | Operate the site and process transactions | Not required |
| Analytics | Google Analytics / Site Kit (_ga, _ga_*); HubSpot (hubspotutk, __hssc) |
Measure traffic and improve content | Consent (opt-in) |
| Marketing | Meta Pixel (_fbp, fr); TikTok Pixel; Kliken Meta tags; HubSpot marketing |
Measure ad campaigns and serve relevant ads | Consent (opt-in) |
| Functional | Affiliate or sales-agent referral attribution (ref_id); preference cookies |
Remember non-essential choices | Context-dependent |
A full per-vendor cookie list (name, purpose, provider, duration, and transfer destination) is available at /cookies/ and is linked from the cookie banner before consent.
Managing your choices. You can change your preferences at any time through Cookie Settings in the site footer. We honor Global Privacy Control (GPC) signals as a valid opt-out of sale and sharing under California law, and as a request to suppress non-essential storage and access under UK PECR.
California Your Privacy Choices. A persistent footer link labeled “Your Privacy Choices” with the CPPA-approved icon gives you a one-click way to opt out of sale and sharing and, where it applies, to limit the use of sensitive personal information.
7. Security, retention, and transfers
Security. We use a layered set of safeguards designed to keep your data confidential and intact.
- Encryption in transit (TLS) for site, account, and form traffic.
- Access controls that restrict systems to a need-to-know basis and require strong authentication for staff accounts.
- Vendor due diligence before we grant a service provider access to personal data.
- PCI DSS aligned payment handling through our payment processors (we do not store full card numbers on our own systems).
- Edge protection through a content delivery network and web application firewall.
- Application hardening, patching, and monitoring on our WordPress, WooCommerce, and Monocle environments.
We don’t publish the specific tools we use, because doing so would help attackers. We are happy to share our security overview under a non-disclosure agreement with enterprise clients on request.
Retention (summary).
- Client and transaction records: up to 10 years where required for tax and accounting.
- Analytics: up to 1 year.
- Support inquiries: up to 6 months.
- Marketing: until you unsubscribe (we retain a suppression list).
International transfers. We operate from the United States and may use service providers globally. For personal data transferred from the EEA or UK to the United States, we rely on:
- (a) the EU–US Data Privacy Framework adequacy decision and its UK Extension where the recipient is actively self-certified to the Framework; or
- (b) the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, supplemented by a transfer-risk assessment, where no adequacy mechanism applies.
8. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object, port your data, and withdraw consent. California residents may also opt out of sale and sharing and limit the use of sensitive personal information.
How to make a request. Email specialist@welldoit.solutions with the subject “Privacy Request”, or submit through the Your Privacy Choices link in our footer.
How long it takes. We aim to respond to California requests within 45 days (with one 45-day extension on notice). We respond to EEA and UK requests within one month (with up to two extra months on notice for complex requests), in each case as permitted by law. If a request involves data held by a partner processor, additional time may be needed and we will keep you informed.
How we verify you. Before we fulfill a request, we verify your identity using information already on file.
- For requests to know the categories of personal information we collect, or to delete it, we require at least two matching data points.
- For requests to know the specific pieces of personal information we hold, we require at least three matching pieces and a signed statement under penalty of perjury.
- We do not require verification for opt-out, opt-in, or “limit the use of sensitive personal information” requests.
Authorized agents (California). California residents may use an authorized agent. We may require either (a) the agent’s signed written permission from you plus verification of your own identity, or (b) a valid power of attorney executed under California Probate Code §§ 4121–4130.
Quick contacts for California rights:
- Do Not Sell or Share: specialist@welldoit.solutions
- Limit the Use of Sensitive Personal Information: specialist@welldoit.solutions
- One-click: the Your Privacy Choices link in our footer.
9. Notices for specific places
California (CCPA and CPRA)
The rights and notices above apply. We do not sell personal information in the traditional sense. We do not knowingly sell or share the personal information of consumers under 16.
EEA / UK / Canada
Controller: We’ll Do It LLC.
Contact: specialist@welldoit.solutions · 480-631-4324.
EEA and UK contact. If you are in the EEA or the UK, you may contact We’ll Do It LLC directly at specialist@welldoit.solutions or by mail at the address above.
Right to lodge a complaint.
- UK users may complain to the Information Commissioner’s Office (ICO) at https://ico.org.uk/make-a-complaint/.
- EEA users may complain to their local data protection authority. The full list is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
Mexico (LFPDPPP)
You may exercise ARCO rights (Access, Rectification, Cancellation, Opposition) through Section 8.
10. Children
Our services are not directed to children under 16, or to the lower age set by law where you live (no younger than 13). If we find out that a California user is between 13 and 15, we will not sell or share their personal information without their affirmative opt-in. For users under 13, we will not process personal information without verifiable parental consent under the methods recognized by California regulators.
11. Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with a new effective date and, where appropriate, emailed to registered customers.
12. Contact us
We’ll Do It LLC
2321 E. University Dr., Phoenix, AZ 85034, United States
Email: specialist@welldoit.solutions
General: mgmt@welldoit.solutions
For EU, UK, and Canada inquiries: specialist@welldoit.solutions · 480-631-4324
Appendix: Third-party processors
Controller: We’ll Do It LLC (Arizona, USA)
Last reviewed: 2026-06-05
We do not sell personal information. We share data with service providers who process it on our behalf under contract. “Providers” here include both WordPress and WooCommerce plugins and vendors connected to your account through a Monocle workplace integration.
Tier 1: customer data, payments, and marketing
| Service | Purpose | Data categories | Privacy policy |
|---|---|---|---|
| Stripe | Card payments; WCFM vendor Connect payouts | Payment identifiers, transaction metadata, contact info | https://stripe.com/privacy |
| Intuit QuickBooks Payments | Payment processing (QBMS gateway) | Payment and billing data | https://www.intuit.com/privacy/ |
| PayPal | Sales-agent and vendor payout credentials | PayPal account email, payout metadata | https://www.paypal.com/us/webapps/mpp/ua/privacy-full |
| HubSpot (Leadin + HubSpot for WooCommerce) | CRM, forms, chat, meetings, order/customer sync | Contact info, order history, communications | https://legal.hubspot.com/privacy-policy |
| Google (Site Kit, Listings & Ads) | Analytics, Search Console, Merchant Center / ads | Usage data, device identifiers, commerce events | https://policies.google.com/privacy |
| Meta (Facebook for WooCommerce, Kliken pixel) | Catalog sync, conversion tracking | Commerce events, device identifiers | https://www.facebook.com/privacy/policy/ |
| TikTok for Business | Advertising / event pixels | Usage and commerce events | https://www.tiktok.com/legal/privacy-policy |
| Cloudflare | CDN, web application firewall, and bot protection | IP address, request metadata | https://www.cloudflare.com/privacypolicy/ |
| Twilio | WooCommerce SMS order notifications | Phone number, order status messages | https://www.twilio.com/legal/privacy |
| RingCentral | Business phone, SMS, IVR, and call routing | Caller phone number, call/SMS metadata, voicemail recordings | https://www.ringcentral.com/legal/privacy-notice.html |
| GoDaddy (Reseller Store) | Hosting/domain reseller provisioning | Account and domain registration data | https://www.godaddy.com/legal/agreements/privacy-policy |
| Nextend Social Login | OAuth social sign-in | Profile data from connected providers | https://nextendweb.com/privacy-policy/ |
| AutomateWoo | Marketing automation, cart recovery | Email, order and cart activity | https://woocommerce.com/document/automatewoo-privacy/ |
| Push Lap Growth | Affiliate tracking | Referral cookies, order attribution | Vendor documentation maintained on file at WDI |
| Metricool | Social scheduling / analytics | Connected social account metadata | https://metricool.com/privacy-policy/ |
| Yext AI Search | On-site search | Search queries, session data | https://www.yext.com/privacy-policy |
| MyWorks QuickBooks sync | Accounting sync (customers, orders, payments) | Financial and customer records | https://myworks.software/privacy-policy/ |
| WP Mail SMTP | Outbound email delivery | Email addresses, message content (routed to configured provider) | Provider-specific (e.g. SendGrid, Google) |
| WCFM (WC Frontend Manager / Marketplace) | Multi-vendor marketplace operations | Vendor profiles, store and order data | Plugin vendor terms; vendors are separate controllers for their sales |
Tier 1b: Monocle workplace integrations
When your plan includes Monocle, additional third-party services may receive your data only when you connect them to your Monocle workplace through Settings → Integrations. Each connection is scoped to the workplace it was authorized in, and credentials are stored encrypted under the canonical vendor_integration_catalog / workplace_vendor_connections / connector_credentials pattern. Disconnecting an integration revokes Monocle’s access and stops further data exchange.
| Integration | Purpose | Data categories | Privacy policy |
|---|---|---|---|
| Google Workspace | Gmail, Calendar, Drive, Docs sync (per-workplace OAuth) | Email subjects, calendar events, file metadata as authorized | https://policies.google.com/privacy |
| Microsoft 365 | Outlook mail, Calendar, OneDrive, Teams sync | Email/calendar metadata, file metadata as authorized | https://privacy.microsoft.com/privacystatement |
| HubSpot CRM | Contacts, deals, tickets sync to Monocle workplace | CRM records, communications metadata | https://legal.hubspot.com/privacy-policy |
| Salesforce | Accounts, opportunities, tasks sync | CRM records, user identifiers | https://www.salesforce.com/company/privacy/ |
| Stripe | Connected-account billing, marketplace payouts, invoicing surfaces | Payment identifiers, transaction metadata, payout details | https://stripe.com/privacy |
| QuickBooks Online | Accounting sync (customers, invoices, journal entries) | Financial and customer records | https://www.intuit.com/privacy/ |
| Slack | Channel messages, files, and notifications routed to workplace | Message content, channel metadata, user identifiers | https://slack.com/trust/privacy/privacy-policy |
| Zoom | Meeting metadata, recordings, transcripts surfaced in workplace | Meeting metadata, recording artifacts as authorized | https://www.zoom.com/en/trust/privacy/ |
| ClickUp | Tasks, lists, comments mirrored in Monocle | Task metadata, comments, attachments as authorized | https://clickup.com/terms/privacy-policy |
| Linear / Jira | Issue tracking sync | Issue metadata, comments, status | https://linear.app/privacy · https://www.atlassian.com/legal/privacy-policy |
| Notion / Confluence | Workspace pages, comments, and database content | Page content, comments, file references as authorized | https://www.notion.com/privacy · https://www.atlassian.com/legal/privacy-policy |
| Asana | Tasks, projects, comments | Task metadata, comments, user identifiers | https://www.asana.com/terms#privacy-policy |
| HubSpot Marketing | Campaign analytics, asset metrics, contact attribution | Campaign engagement and contact metadata | https://legal.hubspot.com/privacy-policy |
| DocuSign | Contract signature workflows | Document content, signer identifiers, audit trail | https://www.docusign.com/trust/privacy |
| Figma | Design files, comments, code-connect mappings | File metadata and comments as authorized | https://www.figma.com/legal/privacy-policy/ |
| GitHub | Repository metadata, issues, PRs, deployments | Repo metadata, issue/PR content, identities | https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement |
| Datadog / PagerDuty | Logs, traces, alerts, on-call schedules surfaced to Monocle | Telemetry metadata, alert payloads | https://www.datadoghq.com/legal/privacy/ · https://www.pagerduty.com/privacy-policy/ |
| BigQuery / Supabase | Data-warehouse and DB integrations | Schema and row-level data as authorized | https://cloud.google.com/terms/cloud-privacy-notice · https://supabase.com/privacy |
| Apollo / Outreach / Clay | Sales prospecting and outreach orchestration | Prospect contact info, engagement metrics | https://www.apollo.io/privacy-policy · https://www.outreach.io/legal/privacy · https://www.clay.com/legal/privacy-policy |
| Twilio (Monocle channel) | Outbound SMS / voice from a Monocle workplace | Phone numbers, message content, call metadata | https://www.twilio.com/legal/privacy |
| Other | Additional vendors connected through the Monocle integration catalog | As described at the connection screen at time of OAuth | Vendor-specific; linked in your Monocle Settings → Integrations panel |
Authorization model. Every Monocle integration is workplace-scoped and consent-gated. You see the exact scopes requested at OAuth time, you can review active connections in Settings → Integrations, and you can disconnect at any time. We store no plaintext credentials; tokens are encrypted at rest under the canonical Monocle connector-credentials pattern.
Tier 2: infrastructure
We use a hosting provider that hosts our WordPress, WooCommerce, and Monocle environments and retains standard server logs.
| Service | Purpose | Privacy policy |
|---|---|---|
| GoDaddy (Managed WordPress) | Platform hosting and server logs (the hosting provider is a sub-processor of any personal data we store) | https://www.godaddy.com/legal/agreements/privacy-policy |
We also use commercial caching, image optimization, comment spam filtering, login protection, and WordPress security hardening tools to operate the site. These tools run on our own infrastructure and do not have independent access to personal data outside the hosting environment. We do not publish the specific products or versions we use, because doing so would help attackers. Enterprise clients may request a security overview under a non-disclosure agreement.
Affiliated WDI services (not third-party processors)
| Service | Role |
|---|---|
Monocle (monocle.welldoit.solutions) |
WDI-owned SaaS; workplace-scoped CRM/task data synced via internal-wdi-monocle bridge when included in your plan |
WDI custom plugins (internal-wdi-monocle, customer-monocle-connector) |
WDI-owned; extend WordPress/WooCommerce to Monocle under the same controller |
For Monocle-specific processing, see Section: Monocle and WDI software in the Privacy Policy.