This Privacy Policy explains how VeyraOps LLC ("VeyraOps," "we," "us") collects, uses, and shares information when a business ("you," the "Customer") uses VeyraOps to run an AI-assisted front desk — receiving messages from your clients, qualifying requests, booking appointments, and collecting deposits.
This policy is written for two audiences: the salon/business owner who signs up for VeyraOps (the "Customer"), and the end clients of that business who message the Customer's WhatsApp/SMS number and are handled in part by our software ("End Clients"). Where something applies only to one group, we say so.
1. What we collect
In order to operate the service, we collect and store:
- Customer account data — your name, email, business (salon) profile, services, pricing, and hours, provided during sign-up and onboarding.
- End Client contact data — the name and phone number of anyone who messages your business number, stored so we can hold a conversation and a booking history with them.
- Message content — the full text (and, where applicable, media) of messages exchanged between End Clients and your business across supported channels (WhatsApp, SMS), so our AI assistant and your staff can read and respond to them.
- Booking and appointment data — requested services, dates/times, booking status, and related notes.
- Deposit/payment status — whether a deposit was requested, its amount, and whether it was paid, refunded, or is pending. We do not collect or store card numbers or other raw payment card data. Deposits are collected through Stripe's own hosted Checkout page — the End Client enters their card details directly on a Stripe-operated page, and VeyraOps only receives Stripe's confirmation that a payment succeeded (an identifier and amount), never the card itself.
- Language/formality signals — our AI detects the language and tone a client is writing in (e.g., French vs. English, formal vs. casual) so it can reply appropriately. This is stored as a small technical profile attached to the client record; it is not a demographic or protected-characteristic profile, and no such categories are inferred or stored.
- Consent and opt-out records — whether an End Client has opted in, opted out (e.g., by replying STOP), and when, so we can honor that choice going forward.
- Audit and security logs — logins, changes to business settings, booking approvals, refunds, and other sensitive actions, kept for security and accountability.
2. Why we collect it
We use this data solely to:
- Operate the AI-driven booking assistant on behalf of the Customer;
- Schedule, confirm, and manage appointments and deposits;
- Give the Customer visibility into their own conversations and bookings via the VeyraOps dashboard;
- Secure the service, detect abuse, and maintain an audit trail of sensitive actions;
- Comply with our legal obligations (e.g., honoring opt-out requests under TCPA/CASL-style rules).
We do not sell End Client data, and we do not use it for advertising or for any purpose unrelated to operating the service for the Customer whose number the End Client messaged.
3. Who we share it with
VeyraOps is built on top of a small number of specialized providers ("sub-processors"). Each one only receives the data it needs to perform its specific function:
- Anthropic (Claude API) — receives conversation text so our AI can generate replies and qualify requests. Anthropic processes this on our behalf as our AI provider.
- WAHA (self-hosted WhatsApp bridge) and Meta (WhatsApp infrastructure) — WhatsApp messages currently flow through WAHA, a self-hosted bridge to WhatsApp that we operate, rather than Meta's Cloud API directly. Because WAHA connects to WhatsApp, messages sent and received still necessarily pass through Meta's underlying WhatsApp infrastructure, so we list Meta as a sub-processor as well. We may migrate to Meta's Cloud API directly in the future; this section will be updated if and when that changes the data flow.
- Twilio — used for SMS messaging (sending and receiving text messages and, where enabled, handling missed-call notifications).
- Stripe — processes deposit payments via its own hosted Checkout. As described above, card details are entered directly on Stripe's page and never pass through VeyraOps servers.
- Supabase — our database and application-hosting provider; it stores the data described in Section 1 on our behalf, secured with per-business access controls.
- Vercel — hosts the VeyraOps web application (the dashboard and other pages you and your clients may load in a browser); pages are rendered on Vercel's infrastructure and may pass through data displayed on those pages as part of serving them to you.
We do not have signed Data Processing Agreements in place with all of the above providers as of this writing (this is tracked internally as a pre-Gate-2 requirement). We do not share data with any party beyond the providers listed here except where required by law.
4. Data retention
We have not yet finalized a specific retention period for message content, client records, and booking history — this is a business decision that needs sign-off from VeyraOps leadership, not something we can commit to here without that review. Until a specific period is published, we retain this data for as long as the Customer's account is active, plus a reasonable period afterward for legal, security, and accounting purposes, and we will update this section once a concrete retention schedule is adopted.
5. Your rights (End Clients)
If you are an End Client — someone who has messaged a VeyraOps-powered business — you can ask to see what data we hold about you, or ask us to delete it, by contacting us at privacy@veyraops.com or by contacting the business you messaged directly. At this time, this is handled as a manual request rather than a self-serve tool in the product — we do not yet have an in-app "delete my data" control, so we are describing the process honestly as it exists today rather than promising a mechanism we haven't built.
Opting out of messages: replying STOP (or UNSUBSCRIBE, CANCEL, END, QUIT) to any message from a VeyraOps-powered business number is a real, honored opt-out mechanism: it marks your record as opted out, stops all further automated outbound messages to you, and is logged as a compliance record, in line with TCPA (US) and CASL (Canada)-style opt-out requirements. If you ever continue to receive automated messages after replying STOP, contact us at privacy@veyraops.com so we can resolve it directly. If you change your mind, replying START resumes messaging.
6. Your rights (Customers)
As the business using VeyraOps, you retain ownership of your account and business data. You can request an export or deletion of your account data by contacting privacy@veyraops.com. Closing your account does not automatically delete historical records we are required to keep for legal or accounting purposes.
7. Security
Data is stored in a Postgres database with row-level security enforced per business (tenant), so one Customer's data is never visible to another. Sensitive actions (logins, refunds, consent/opt-out changes, booking approvals) are recorded in an audit log. No secrets or credentials are stored in application code.
8. Changes to this policy
We may update this policy as the product and our provider relationships evolve (including once outstanding items above — retention period, signed DPAs, a self-serve deletion tool — are finalized). Material changes will be reflected by updating the "Last updated" date above.
9. Contact
Questions about this policy or your data: privacy@veyraops.com