Privacy Policy
Last updated: August 2026
Who we are
Hadeya (“we”, “us”) provides an appointment booking platform that lets service businesses accept bookings and payments through a booking chat link that customers open in a web browser. A business may share that link wherever it likes — including as an automated reply from its own WhatsApp Business account — but the booking conversation itself always takes place in the web chat. Hadeya has no access to a business's WhatsApp account, and neither sends nor receives WhatsApp messages. This policy explains what data we collect, why we collect it, and how it is handled — for both business owners who use Hadeya and their customers who book through the chat.
For customer booking and conversation data, Hadeya processes information on behalf of the business the customer is interacting with. That business determines the purposes for which its customer information is used; Hadeya processes it solely to provide the booking, messaging, and payment services the business has requested, and solely for the benefit of that business. For business account information (sign-up details, billing, service administration), Hadeya acts on its own behalf to operate, secure, and administer the service.
Data we collect
- Business account data — name, email address, business name, business hours, services, and logo provided when a business signs up.
- Customer booking data — name, phone number, and email address shared by customers during a booking conversation, along with appointment details (service, date, time).
- Conversation data — messages exchanged with the booking assistant in the booking chat, retained to maintain conversation context and booking history.
- Booking chat data — a randomly generated session identifier and your recent messages, stored in your own browser so the conversation survives a page refresh. You can remove them at any time by clearing site data in your browser. We also record that session identifier and the network (IP) address messages arrive from, in order to apply the rate limits that keep the booking chat from being abused.
- Verification codes — if a chat visitor asks about an appointment booked earlier, we send a one-time code to the email address or phone number already held for that booking. Only a hashed form of the code is stored, and it expires shortly after being sent.
- Technical and messaging metadata — message identifiers, timestamps, the delivery status of the SMS and email notifications we send, payment webhook metadata, and system, authentication, and error logs necessary to operate and secure the service.
- Payment status— whether a booking's payment succeeded, failed, or was refunded. Payments are processed by Safepay; we never see or store card numbers or bank credentials.
How we use data
- To create and confirm appointments requested by customers.
- To send booking confirmations and appointment reminders by SMS and email. Customers receive these transactional messages only in connection with a booking they initiated, and can opt out of reminders at any time — by replying “STOP” to a reminder message or by contacting the business or us.
- To collect booking payments through Safepay.
- To show businesses their own appointments, customers, and payment records on their dashboard.
We do not sell personal data, and we do not use customer data for advertising. Customer data is logically isolated between business accounts, so one business cannot access another business's customer records.
AI assistant
Booking conversations are handled by an AI assistant powered by OpenAI. OpenAI processes limited conversation content solely to generate the responses needed to take and manage bookings. Conversation data — including anonymized, aggregated, or derived forms of it — is not used to create, develop, train, or improve artificial intelligence models, by us or by our providers.
Third-party services
We rely on the following processors to run the service: Supabase (database and authentication), Safepay (payment processing), Twilio (SMS reminders and verification codes), Resend (email), OpenAI (AI responses in booking conversations), Sentry (error monitoring), and Vercel (hosting). Each provider receives only the data required to perform its function, processes it on our instructions for that purpose only — not for its own purposes — and is bound by written terms requiring appropriate security safeguards.
Data retention & deletion
- Conversation transcripts are retained for up to 12 months from the last message, then deleted.
- Appointment and customer recordsare retained while the business's account is active, so the business has an accurate booking history.
- Business account datais retained while the account is active. When a business closes its account, we delete its data — including its customers' booking and conversation data — within 30 days, except for records we are legally required to keep (such as payment records). Residual copies in encrypted backups expire within a further 30 days.
To request deletion of your data — whether you are a business owner or a customer who booked through the booking chat — email admin@hadeya.online from the affected account, phone number, or email address. We will delete the associated personal data within 30 days and confirm once done.
Sensitive information
The booking assistant only needs your name, contact details, and appointment preferences. Please do not share sensitive information in the conversation — such as full payment card numbers, bank account details, government identification numbers, or health information. Payments are always collected through a secure Safepay link, never by message.
International processing
The providers listed above operate cloud infrastructure that may store or process data outside your country of residence. We transfer data to them only under the contractual safeguards described in this policy.
Security
All traffic is encrypted in transit (HTTPS), database access is restricted per business via row-level security, and payment webhooks are verified with cryptographic signatures. The booking chat is rate limited per session and per network address, one-time verification codes are stored only as hashes, and a chat visitor can reach appointment details only for the booking made in that conversation or after passing a one-time code check.
Contact
Questions about this policy or your data: admin@hadeya.online.