Skip to content

Legal

Privacy Policy

Last updated: September 11, 2026

Who we are and what this policy covers

Phooey Labs is the software and AI brand of Phooey Brands LLC. This policy applies to three services we operate:

  • This website, phooeylabs.com.
  • Wooshie Order Sheet Automation, a WordPress plugin that sends WooCommerce order data to Google Sheets.
  • Phooey Labs Connector, our hosted service that handles Google authorization for Wooshie. This is the application name you see on the Google consent screen when you connect your Google account through Wooshie.

FileDropper is a separate product with its own terms and privacy policy. Nothing here describes FileDropper's data practices.

For any privacy question, contact support@phooeylabs.com.

Website: contact form, analytics, and cookies

If you submit the contact form, we receive your name, email address, an optional company or website, the inquiry type you selected, and your message. We use that information to read your inquiry, assess fit, and reply. We do not sell it, use it for advertising, or add you to a marketing list.

The contact form uses Google reCAPTCHA to distinguish people from automated submissions. It loads only when you submit the form, and Google's Privacy Policy and Terms of Service apply to that use. reCAPTCHA is not analytics and is not covered by your analytics cookie choice.

We use Google Analytics 4 to understand site usage in aggregate. No analytics script, request, or cookie loads until you accept analytics cookies. If you reject or later withdraw consent, analytics stays off and we remove first-party analytics cookies where technically possible. Form contents, names, and email addresses are never sent to analytics. You can change your choice at any time with . See the Cookie Policy for detail.

We use third parties to host this website, deliver contact form email, and protect the form from automated abuse. Each provider processes only what is needed to perform its function.

Wooshie and Phooey Labs Connector: where data lives

It helps to separate three places data can sit:

  • Your WordPress site. Wooshie stores its configuration, such as field mappings and the selected spreadsheet and tab, plus transmission history, inside your own WordPress installation. Your Google access and refresh tokens are also stored there, in encrypted form, in your WordPress database. That data is under your control and your hosting provider's.
  • Your Google spreadsheet. Order rows are written to the spreadsheet and tab you select. That file lives in your Google account, under your Google settings and sharing choices.
  • Our hosted connector. Phooey Labs Connector processes Google authorization and token-refresh requests for your installation. It temporarily stores authorization results in encrypted form while handling those requests, and it keeps the operational records needed to run and support the service, such as installation and request records.

Order-row payloads travel directly from your WordPress installation to Google Sheets. They do not pass through the hosted connector. We do hold installation and operational records, so we do not claim that Phooey Labs stores nothing.

Customer information in mapped fields

You choose which WooCommerce order fields Wooshie sends. Depending on that configuration, those fields may contain customer information such as names, email addresses, phone numbers, or addresses. You decide what is mapped, and you are responsible for having the right basis to send that information to your spreadsheet and to anyone you share it with.

Google data we access and why

When you connect Google through Wooshie, you authorize Phooey Labs Connector using Google's OAuth flow. We request the https://www.googleapis.com/auth/drive.file permission and use the Google Picker so you can choose or create the spreadsheet yourself.

  • What this permission means. Access is limited to files you select or that the application creates. It does not give us access to the rest of your Google Drive.
  • What we read. Spreadsheet information needed to set up and maintain the destination, such as the tab list and existing header row.
  • What we write. Column headings and the order data you configured, added as rows in the tab you chose.
  • What we do not request. The flow does not request your Google profile or email scopes. Authorization is associated with your registered plugin installation, not with personal profile information from your Google account.

Google API Services User Data Policy and Limited Use

Phooey Labs' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the features you are using in Wooshie.
  • We do not use Google user data for advertising of any kind.
  • We do not sell Google user data or transfer it for advertising purposes.
  • We do not use Google user data, or data derived from it, to develop, train, or improve AI or machine learning models. This applies regardless of any other AI work Phooey Labs does.
  • Humans do not read your Google data except with your explicit permission for a support request you raise, where required for security or to comply with applicable law, or where the data has been aggregated and anonymized for operational purposes.

Phooey Labs is an independent developer. We do not claim any Google approval, certification, endorsement, or guaranteed verification status.

Sharing and service providers

We share information only with service providers that operate our services, such as hosting, email delivery, and spam protection. We also disclose information where required by applicable law. We do not sell personal information.

Wooshie bundles the Freemius SDK for licensing and commerce. Freemius may process the merchant's information, such as account and license details, plugin installation identifiers, your site URL, software versions, and diagnostic information the SDK is permitted to collect. This concerns you as the merchant. Your shoppers' WooCommerce order data is not sent to Freemius; order rows travel only from your WordPress site to your Google spreadsheet.

Storage, security, and access

Google tokens stored by Wooshie in your WordPress database, and authorization results temporarily stored by the connector, are held in encrypted form. Encryption reduces risk; it is not a guarantee on its own.

As an organizational policy, access to operational systems and records is limited to the people who run and support the service. Human access to information connected to your installation is permitted only where needed for a support request you raise, for security, or to comply with applicable law.

Retention periods differ by the type of record:

  • Logs. Logs stored in our Google Cloud Logging _Default bucket are retained for 30 days.
  • Audit logs. Audit logs stored in the Google Cloud Logging _Required bucket are retained for 400 days.
  • Temporary Google authorization records. These records carry expiration timestamps and are removed by an automatic cleanup policy. Cleanup runs in the background, so expiration does not mean immediate physical deletion.
  • Hosted installation records. These records have no automatic expiration policy. They can remain after Google access is revoked or the plugin is uninstalled. You can contact support@phooeylabs.com to request deletion of the installation and related records we hold.

Google tokens stored by Wooshie in your WordPress database remain under your control on your site. Google spreadsheet content remains in your Google account until you delete it.

Disconnecting and deleting data

Revoking Google access and deleting stored information are separate actions. Doing one does not automatically do the others, and installation records can remain after authorization is revoked.

  • Disconnect inside the plugin. Disconnecting in Wooshie removes the Google tokens stored locally on your site and attempts to revoke the authorization through Google. If remote revocation cannot be confirmed, you may also need to remove access through your Google Account.
  • Revoke Google access yourself. Remove Phooey Labs Connector at myaccount.google.com/connections. After revocation the credential stops working, though a request already in progress may still finish.
  • Uninstall the plugin. Wooshie retains its data by default so you do not lose your configuration accidentally. Local configuration and transmission history are removed only if you enable the "Delete Wooshie data when the plugin is deleted" setting and then delete the plugin. Uninstalling does not delete content in your Google spreadsheet or automatically erase records held by the hosted service.
  • Request deletion of hosted records. Email support@phooeylabs.com to ask us to delete the installation and related records we hold.
  • Delete spreadsheet content. Rows already written stay in your Google spreadsheet until you delete them yourself.

External links

This site links to external destinations, including filedropper.io and phooeybrands.com. Once you follow a link, the privacy practices of that destination apply.

Privacy inquiries and updates to this policy

To ask what information we hold, request deletion, or raise any other privacy question, write to support@phooeylabs.com. We may update this policy as our services change. The date at the top of this page reflects the current version.