Privacy Policy
This policy explains how PayCovay, LocalOps, BookITnow, WALO command workflows, and related AMH tools collect, use, protect, and share information.
We do not sell your customer lists, lead data, private business records, connected-account tokens, food-photo data, or project files.
1. Information we collect
- Account information: name, email, phone number, business name, login details, preferences, team members, and workspace settings.
- Business and content data: websites, leads, customers, jobs, bookings, calendar records, messages, articles, files, invoices, quotes, domains, repositories, analytics, campaigns, and SEO reports you provide or connect.
- Connected-account data: account IDs, OAuth tokens or refresh tokens, scopes, connection status, metadata, logs, and API responses from providers you authorize.
- Usage and device data: browser, device, IP address, approximate location, pages visited, features used, timestamps, diagnostics, security events, and error reports.
- Communications: support requests, emails, WhatsApp/SMS messages, call notes, and responses you send through the service.
2. How we use information
- Provide, operate, secure, troubleshoot, and improve the service.
- Run requested workflows such as scans, reports, automations, publishing, indexing, routing, reminders, quotes, invoices, bookings, and customer follow-up.
- Authenticate users, maintain sessions, enforce approvals, and prevent fraud or abuse.
- Send transactional messages, alerts, reminders, confirmations, login links, and support responses.
- Comply with legal, tax, security, and platform obligations.
3. Connected apps and service providers
We may use or connect with Cloudflare, Supabase, Stripe, Resend, Twilio, Meta/WhatsApp, Google, Microsoft, Yahoo, GitHub, Vercel, OpenAI, Anthropic, Google Gemini, Cloudflare AI, Ollama/local models, browser verification tools such as Playwright, maps/geocoding providers, analytics tools, and similar providers selected for the product or workflow.
When you connect a third-party account, we process only what is needed for the features you enable. We do not store third-party account passwords. You can disconnect provider access or request token rotation when supported.
4. AI processing
When you ask for AI features, relevant prompts, files, pages, messages, images, business records, or logs may be processed by AI providers or local models. AI results may be stored with task history so you can review, reuse, correct, or audit them. AI outputs can be wrong and should be reviewed before important use.
5. Cookies, pixels, and tracking choices
We use essential cookies or browser storage for login, security, preferences, accessibility settings, and feature state. If analytics, pixels, ads, or measurement tools are enabled, they may use cookies, device data, referral data, page events, and similar technologies. You can manage cookies in your browser and through any cookie controls we provide.
6. Location, sensitive data, payments, and uploads
Some features use approximate or permission-based location for maps, local SEO, job routing, delivery, rental, field-service, or nearby-provider workflows. Precise device location is used only when a feature asks and you grant permission.
Do not upload Social Security numbers, medical records, government IDs, passwords, private keys, or other highly sensitive information unless a feature explicitly asks for it and you understand the risk. Payment details are handled by payment processors such as Stripe; we do not store full card or bank credentials on our own servers.
7. Privacy choices and rights
Depending on where you live, you may request access, correction, export, deletion, restriction, objection, or opt-out of sale/sharing if applicable. We may need to verify your identity before fulfilling a request. We will not discriminate against you for exercising privacy rights.
You may unsubscribe from marketing emails, reply STOP to supported promotional SMS workflows, disconnect integrations, or request deletion where legally available. Transactional, security, and account messages may still be sent where needed to operate the service.
8. Data retention and security
We keep account and business data while your account is active or as needed to provide the service. Some data may be retained for backup, fraud prevention, dispute handling, legal, tax, security, or audit reasons. We use HTTPS, access controls, environment secrets, provider security controls, logs, and tenant separation, but no internet service can guarantee absolute security.
9. Children
The service is not directed to children under 13, and business-account features are intended for users 18 and older.
10. Official privacy and compliance references
These links are official regulator references we use to keep policy language grounded. They are provided for transparency and are not legal advice.
- FTC - CAN-SPAM compliance guide
- FCC - unwanted calls and texts
- FCC - accessibility complaint categories
- California Attorney General - CCPA
- European Data Protection Board - data subject rights
11. Contact
Privacy questions or requests can be sent to [email protected].