Privacy Policy
Last updated: [[DATE]]
Who we are
Barber Voice ("we") provides an AI phone receptionist that answers calls for barbershops and books appointments on their behalf. This policy explains what we collect and how we use it. You can reach us at [[CONTACT EMAIL]].
Information we collect
- Shop account data. Your name, email address, and the shop details you enter, such as business name, address, phone number, staff names, services and prices.
- Customer booking data. The phone number of people who call your shop, the name they give, and their appointment details. This belongs to your shop; we process it on your behalf.
- Call data. Audio is streamed to our AI provider to conduct the conversation in real time. We retain the resulting booking actions and, where enabled, a transcript so you can review what the AI agreed to.
- Google Calendar data. Described in its own section below.
Google user data
If you connect a Google Calendar, we request the calendar.events scope. We use it only to:
- read existing events so we know when a barber is unavailable;
- create an event when an appointment is booked;
- update or delete that event when it is rescheduled or cancelled.
We store the calendar identifier you select, an encrypted Google refresh token, and the start and end times of events that block availability. We do not read, store, or use the contents of unrelated calendar events beyond the times they occupy.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not use it to train generalized AI models.
Who we share data with
We share data only with service providers needed to run the product: our hosting and database provider, our telephony provider for placing and receiving calls and messages, our AI provider for conducting conversations, and our payment processor for billing. We do not sell personal information.
Retention and deletion
You can disconnect Google Calendar at any time from your dashboard, which deletes the stored refresh token and stops all calendar access. You may also revoke access directly at your Google account permissions page. To delete your account and associated data, email us at [[CONTACT EMAIL]] and we will remove it within [[N]] days.
Security
Data is stored in an access-controlled Postgres database with per-shop row-level isolation, so one shop cannot access another shop's records. Google refresh tokens are encrypted and are never exposed to the browser.