Privacy Policy

Last updated: August 2026

Who we are

Hadeya (“we”, “us”) provides an appointment booking platform that lets service businesses accept bookings and payments through WhatsApp. This policy explains what data we collect, why we collect it, and how it is handled — for both business owners who use Hadeya and their customers who book through WhatsApp.

For customer booking and conversation data, Hadeya processes information on behalf of the business the customer is interacting with. That business determines the purposes for which its customer information is used; Hadeya processes it solely to provide the booking, messaging, and payment services the business has requested, and solely for the benefit of that business. For business account information (sign-up details, billing, service administration), Hadeya acts on its own behalf to operate, secure, and administer the service.

Data we collect

  • Business account data — name, email address, business name, business hours, services, and logo provided when a business signs up.
  • WhatsApp connection data— the WhatsApp Business Account ID, phone number ID, and access tokens needed to send and receive messages on the business's behalf. Access tokens are stored encrypted.
  • Customer booking data — name, phone number, and email address shared by customers during a booking conversation, along with appointment details (service, date, time).
  • Conversation data — WhatsApp messages exchanged with the booking assistant, retained to maintain conversation context and booking history.
  • Technical and messaging metadata — message identifiers, timestamps, delivery and read status, webhook payload metadata, and system, authentication, and error logs necessary to operate and secure the service.
  • Payment status— whether a booking's payment succeeded, failed, or was refunded. Payments are processed by Safepay; we never see or store card numbers or bank credentials.

How we use data

  • To create and confirm appointments requested by customers.
  • To send booking confirmations and appointment reminders via WhatsApp, SMS, and email. Customers receive these transactional messages only in connection with a booking they initiated, and can opt out of reminders at any time — by replying “STOP” in the conversation or by contacting the business or us.
  • To collect booking payments through Safepay.
  • To show businesses their own appointments, customers, and payment records on their dashboard.

We do not sell personal data, and we do not use customer data for advertising. Customer data is logically isolated between business accounts, so one business cannot access another business's customer records.

AI assistant

Booking conversations are handled by an AI assistant powered by OpenAI. OpenAI processes limited conversation content solely to generate the responses needed to take and manage bookings. WhatsApp-derived data — including anonymized, aggregated, or derived forms of it — is not used to create, develop, train, or improve artificial intelligence models, by us or by our providers.

Third-party services

We rely on the following processors to run the service: Meta (WhatsApp Business Platform messaging), Supabase (database and authentication), Safepay (payment processing), Twilio (SMS reminders), Resend (email), OpenAI (AI responses in booking conversations), and Vercel (hosting). Each provider receives only the data required to perform its function, processes it on our instructions for that purpose only — not for its own purposes — and is bound by written terms requiring appropriate security safeguards.

Data retention & deletion

  • Conversation transcripts are retained for up to 12 months from the last message, then deleted.
  • Appointment and customer recordsare retained while the business's account is active, so the business has an accurate booking history.
  • Business account datais retained while the account is active. When a business closes its account or disconnects from Hadeya, we delete its data — including its customers' booking and conversation data — within 30 days, except for records we are legally required to keep (such as payment records). Residual copies in encrypted backups expire within a further 30 days.

To request deletion of your data — whether you are a business owner or a customer who booked through WhatsApp — email admin@hadeya.online from the affected account or phone number. We will delete the associated personal data within 30 days and confirm once done.

Sensitive information

The booking assistant only needs your name, contact details, and appointment preferences. Please do not share sensitive information in the conversation — such as full payment card numbers, bank account details, government identification numbers, or health information. Payments are always collected through a secure Safepay link, never by message.

International processing

The providers listed above operate cloud infrastructure that may store or process data outside your country of residence. We transfer data to them only under the contractual safeguards described in this policy.

Security

All traffic is encrypted in transit (HTTPS). WhatsApp access tokens are stored encrypted at rest, database access is restricted per business via row-level security, and payment webhooks are verified with cryptographic signatures.

Contact

Questions about this policy or your data: admin@hadeya.online.