Privacy Policy
1. Introduction and who we are
This Privacy Policy explains how Alovibe ("Alovibe", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the Alovibe platform, websites, applications, and related services (together, the "Service"). It applies to the businesses that hold an Alovibe account ("Account Owners" or "tenants"), the staff and team members they invite, the people who visit our marketing site or join our notify-me waitlist, and — in the limited respects described below — the end customers of those businesses.
Alovibe is a multi-tenant, AI-assisted booking, CRM, and commerce platform. Each Account Owner operates an isolated workspace ("tenant") in which they manage their own services, staff, bookings, customer relationships, messaging across connected channels, and online commerce.
The Service is operated by NEXGEN SKYLINEX, S.L., a company registered at Paseo Virgen del Puerto 51, 28005 Madrid, Spain (referred to in this Policy as "Alovibe"). For questions about this Policy or to exercise your rights, use the contact details in Section 16.
2. Our two roles: controller and processor
Alovibe handles personal data in two distinct capacities, and it is important to understand which applies to you.
(a) Alovibe as controller. For data about the Service itself and about the people who hold or administer an account — Account Owner and team member identity, login credentials, security settings, billing identifiers, usage and technical data, and marketing-site and waitlist interactions — Alovibe is the data controller. We decide why and how that data is processed, and this Policy governs it.
(b) Alovibe as processor. For the personal data that an Account Owner brings into the Service about their own end customers — including customer contact records, message and conversation content, booking and order data, and related material — the Account Owner is the controller and Alovibe acts as a processor on the Account Owner's behalf. We process that data only on the Account Owner's documented instructions, as configured through their use of the product and as set out in our Data Processing Agreement (the "DPA"). The Account Owner is responsible for having a lawful basis to collect and use their customers' data and for honouring their customers' privacy rights.
(c) Account Owner's customers and staff. End customers and the Account Owner's own staff are the data subjects in the processor relationship. If you are an end customer and you wish to exercise privacy rights over data a business holds about you, please contact that business directly; it is the controller of that data. We will assist the business in responding (see Section 11).
Multi-tenancy is enforced both in our application logic (every data query is scoped to a single tenant) and at the database layer (tenant-linking integrity constraints, composite tenant foreign keys, and partial unique indexes), so one business cannot access another business's data.
3. The personal data we collect
We collect the categories of personal data described below. Some we collect directly; some is provided by Account Owners about their customers; and some is generated automatically as you use the Service.
3.1 Account Owner and team member data (Alovibe as controller).
- Identity and account details: name, business name, email address, chosen interface language, theme, timezone, and currency.
- Authentication and security data: a hashed password (we never store passwords in plain text); two-factor authentication secrets stored in encrypted form; recovery codes stored only as one-way hashes; and last-login and email-verification timestamps.
- Team and staff records: names, email addresses, hashed passwords, tenant-scoped roles (owner, manager, front desk), and staff working profiles (role, colour label, commission percentage, and working days and hours).
- Billing and subscription data: subscription status and the identifiers our payment processor assigns to your account, subscription, and payments. We do not store full payment card numbers.
3.2 End-customer and commerce data (Alovibe as processor, on the Account Owner's behalf).
- Customer identity and CRM records: name, phone number, email address, preferred channel, language, free-text notes, tags, and customer-since year.
- Delivery and shipping details: recipient name, phone, street, city, state, postal code, and country, where an Account Owner uses the commerce features.
- Channel identities: the external identifiers and display names that link a customer to a connected messaging channel (for example, a WhatsApp, Telegram, Instagram, or Facebook handle).
- Conversation content across all channels (WhatsApp, Telegram, Instagram, Facebook, website chat, and voice): full inbound and outbound message bodies, message direction, author, language, and channel message identifiers.
- Message attachments: inbound customer photos and documents and outbound reply images, with their file type, name, and size.
- Booking and appointment data: the customer, staff member, resource, times, party size, price, paid status, notes, recurrence, and any linked calendar event identifier.
- Customer verification records: where a customer is asked to confirm control of an email or phone before a booking is confirmed, we hold the email, phone, a one-way hash of the verification code, its expiry, and attempt counts.
- Commerce and CRM growth data: product orders, line items, quantities, totals, discount codes, gift cards (including, for gifted cards, the recipient name and email, sender name, and message), loyalty cards and stamps, refunds (with reason and any internal note), memberships, service packages, waitlist entries (including preference and channel), reviews (rating and text), campaign audiences, and a marketing opt-out flag.
- Payment and order metadata: the identifiers our payment processor assigns for a tenant's customer, payment, checkout, and connected-account flows, and deposit, balance, and no-show amounts and paid flags. We do not store full card numbers.
- Business knowledge base content: titles and content an Account Owner adds to power the AI assistant, which may contain personal data in free text.
3.3 AI and voice processing metadata.
- For each AI-generated reply we record operational metadata: the model used, prompt and completion token counts, processing duration, reply language, and a trace of the tools the assistant invoked with their inputs and results, together with cross-turn assistant state for a conversation.
- For the optional web-voice feature we record an anonymous visitor identifier, the linked customer or conversation, billed seconds, and per-session and per-day usage.
3.4 Connected-integration credentials.
- Where an Account Owner connects a channel or integration, the associated access tokens and OAuth refresh tokens (for example, messaging-platform tokens, bot tokens, and calendar and email refresh tokens) are stored in encrypted form at rest.
3.5 Technical, operational, and notification data.
- IP address, device and browser information, server logs, and an internal audit log of administrative actions (recording the acting user, the action, and related metadata).
- Web push subscription details (endpoint, keys, and user-agent string) where push notifications are enabled.
- Raw inbound webhook payloads, retained for a short period for crash recovery; these can contain message text, phone numbers, and names.
- System alerts and health and monitoring data.
3.6 Marketing-site and waitlist data.
- Where you ask us to be notified about a plan or feature that is coming soon, we collect your email, the plan of interest, and your locale.
4. Sources of personal data
We obtain personal data from the following sources: (a) directly from you when you create an account, configure the Service, communicate with us, or use product features; (b) from Account Owners, who provide and generate data about their customers and staff through their use of the Service; (c) from the connected channels and integrations an Account Owner enables, through which messages and related data flow into the Service; (d) from our payment processor, which returns payment and subscription metadata; and (e) automatically, from your interactions with the Service (technical, log, and usage data).
5. How we use personal data, and our lawful bases
Where the EU or UK GDPR or comparable laws apply, we rely on the lawful bases noted below. Where Alovibe acts as a processor (Section 2(b)), the relevant lawful basis is determined by the Account Owner as controller, and we process on their instructions.
| Purpose | Lawful basis |
|---|---|
| Providing, operating, and maintaining the Service and your account | Performance of a contract |
| Processing bookings and orders and sending transactional messages (confirmations, reminders, receipts) | Performance of a contract |
| Powering the "Alo" AI assistant and the optional voice feature where enabled | Performance of a contract; the Account Owner's instructions |
| Billing, subscription management, and fraud prevention | Performance of a contract; legal obligation; legitimate interests |
| Securing the Service, preventing abuse and spam, and protecting our and our users' systems | Legitimate interests; legal obligation |
| Providing support and communicating about the Service | Performance of a contract; legitimate interests |
| Sending marketing communications, where you operate them or where we contact you about our own products | Consent, or legitimate interests, depending on the communication and applicable law |
| Improving and developing the Service and producing aggregated, non-identifying analytics | Legitimate interests |
| Complying with legal and regulatory obligations | Legal obligation |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms; you may object as described in Section 11. Where we rely on consent (for example, certain marketing), you may withdraw it at any time, without affecting processing already carried out. We do not sell personal data.
6. The "Alo" AI assistant and voice feature
Alovibe includes an AI assistant ("Alo") and an optional web-voice feature, both powered by OpenAI.
What is sent and when. When an Account Owner enables the assistant, relevant conversation context and the business's knowledge base content are sent to OpenAI to generate replies, and short text snippets are sent to generate the embeddings that let the assistant search the knowledge base. When the voice feature is enabled, the customer's audio is sent from the customer's browser to our own servers, which relay it to OpenAI, which transcribes the speech to text, generates a reply, and synthesizes that reply back into speech (a cascade of speech-to-text, reply generation, and text-to-speech). The customer's audio is not streamed directly between the browser and OpenAI, and our credentials are never exposed in the browser.
Owner control and defaults. The assistant operates per tenant and is controlled by the Account Owner. The AI assistant (including autopilot) and the voice feature are enabled by default for new accounts, and the Account Owner can turn either of them off in their settings.
Provider data handling. OpenAI processes this data as a sub-processor in order to return a response. OpenAI processes Service data submitted through its API under its applicable API data-use terms, which (at the date of this Policy) provide that data submitted through the API is not used to train its models. We rely on OpenAI's API data-use policy for this default; we do not undertake that we set any additional, separate "no-training" flag beyond it.
A note on free-text content. Because conversation and knowledge base fields are free-text, Account Owners should avoid placing special-category or unnecessary sensitive personal data into them.
7. How we share personal data and our sub-processors
We share personal data only as needed to run the Service, comply with law, or protect rights. We do not sell personal data and do not share it for cross-context behavioural advertising.
7.1 Sub-processors. We engage the following sub-processors. Each processes personal data only to perform its function and under contractual data-protection terms. Some of these are active only where an Account Owner enables the relevant feature or integration.
- OpenAI — powers the "Alo" AI assistant (chat replies and knowledge base embeddings) and the optional voice feature, as described in Section 6.
- Stripe — payments. Stripe is used in two ways: (i) Stripe Billing processes Account Owners' subscription payments to Alovibe; and (ii) through Stripe Connect, each Account Owner connects their own Stripe account into which their end customers' payments (booking deposits and balances, product orders, gift-card purchases, and no-show fees) are paid directly. Alovibe stores only Stripe identifiers and metadata, never full card numbers.
- Resend — delivery of transactional and marketing email (for example, login links, verification and password emails, booking confirmations and reminders, order and gift-card emails, and marketing campaigns).
- Meta (WhatsApp, Instagram, Facebook) — inbound and outbound messaging on the Meta-owned channels an Account Owner connects. The Account Owner connects their own Meta or WhatsApp Business account; Meta processes that data under its own terms as the Account Owner's provider, and any Meta or WhatsApp messaging fees are billed by Meta directly to the Account Owner, not by Alovibe.
- Telegram — inbound and outbound messaging through the Account Owner's own Telegram bot; the bot token is stored encrypted.
- Google (Calendar and Gmail) — optional, per-tenant integrations. Calendar sync pushes booking events one way to a connected calendar; the Gmail connector, if enabled, is send-only for support replies. These are inactive unless the Account Owner enables them.
- Sentry — optional error and exception monitoring for our application servers and browser app, which may capture error context and stack traces. Inactive unless configured by Alovibe.
- Hosting and infrastructure (operator-run) — the Service is self-hosted by Alovibe on dedicated server infrastructure running our database (the primary datastore), an in-memory store for sessions and locks, a reverse proxy providing automatic TLS, our application containers, a backup process, and a file store. Where configured, encrypted backups may be uploaded to an operator-controlled off-site storage location. We do not use a managed third-party cloud database provider.
The channels and integrations an Account Owner connects are the Account Owner's own third-party accounts; those providers act as the Account Owner's providers or sub-processors and may bill the Account Owner directly.
7.2 Other recipients. We may also disclose personal data: to professional advisers and auditors under confidentiality; to authorities or other parties where required by law, legal process, or to establish, exercise, or defend legal claims; and in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this Policy or provide notice as required.
7.3 Sub-processor changes. We may update our sub-processors as the Service evolves. We will make information about current sub-processors available and provide a means for Account Owners to be informed of material changes so they can object on reasonable data-protection grounds, as set out in the DPA.
8. International data transfers
Alovibe operates internationally, and personal data may be processed in, or accessed from, countries other than the one in which you are located, including countries that may not provide the same level of data-protection law as your home country. Some of our sub-processors are located outside the European Economic Area and the United Kingdom.
Where we transfer personal data internationally and the law requires a safeguard, we put one in place — in particular, the European Commission's and the UK's Standard Contractual Clauses (with the UK Addendum or International Data Transfer Agreement as applicable), or another lawful transfer mechanism, together with supplementary measures where appropriate. You may request information about the safeguards that apply by contacting us (Section 16).
9. Data retention and deletion
We keep personal data only for as long as needed for the purposes described in this Policy, and our retention is enforced by automated processes, not merely by policy. Key retention rules:
- Active account. We retain account and tenant data for as long as your account is active and as needed to provide the Service.
- Account deletion and purge. When an Account Owner requests account deletion in Settings, we cancel the subscription, mark the tenant as cancelled and blocked, revoke all active sessions, and log the request. A scheduled job then permanently deletes all of that tenant's data after a 30-day wind-down window, recording the purge in our audit log.
- Webhook and token hygiene. Raw inbound webhook payloads kept for crash recovery, short-lived deduplication records, and expired one-time tokens (such as login, reset, verification, and order-portal tokens) are deleted automatically once they are older than approximately seven days.
- Web voice-call audio. Where the optional web-voice feature is used, the raw audio of each caller's turn is stored in our database (as a message attachment) so the recording is available in the inbox alongside the transcript. An automated daily process permanently deletes this raw audio once it is older than 30 days; the text transcript and any non-audio attachments are kept, so the conversation record remains without the recording.
- Abandoned checkouts. Unpaid, never-charged orders are deleted after about 48 hours, and any reserved gift-card or loyalty value is released.
- Sessions. Sign-in sessions are stored with a 30-day lifetime (or a shorter, browser-session or 24-hour lifetime where "remember me" is not selected) and are revoked on logout, password change, or account deletion.
- Backups. We take daily, verified database backups and retain a rolling set of recent backups; after data is deleted from the live system, residual copies in backups are overwritten on the normal backup-rotation cycle and are not used for any other purpose in the meantime.
We may retain limited data for longer where required to comply with legal obligations, resolve disputes, or enforce our agreements.
10. How we protect personal data
We apply technical and organisational security measures appropriate to the risk, including:
- Encryption of secrets at rest using strong authenticated encryption (AES-256-GCM) for connected-channel credentials, OAuth refresh tokens, the platform AI key, two-factor secrets, and other platform secrets.
- Password hashing using bcrypt; passwords are never stored in plain text.
- One-way hashing of tokens and one-time codes (such as login, reset, verification, order-portal, and loyalty codes), generated with cryptographically secure randomness and compared in constant time; raw tokens are never persisted.
- Encryption in transit via TLS, enforced by our reverse proxy with automatic certificates and HTTP Strict Transport Security, together with security headers (content-type, framing, referrer, and permissions policies).
- Secure sessions using HTTP-only, same-site, secure cookies bound to opaque session identifiers, with per-user revocation.
- Access control and tenant isolation enforced server-side on every request and backstopped at the database layer (composite tenant foreign keys and partial unique indexes), role-based access control (owner, manager, front desk), an optional administrative IP allowlist, verification of incoming webhooks, rate limiting and an automated anti-abuse mechanism, and re-authentication before sensitive or irreversible actions.
- Backups and monitoring, including verified daily backups with rotation and optional off-site copies, optional error monitoring, a system-alert facility, and a deep health-check endpoint.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security; however, we work continuously to protect personal data against unauthorised access, loss, or misuse.
11. Your data-protection rights
Depending on your location and on whether Alovibe acts as controller or processor for the data in question, you may have the following rights:
- Access — to obtain confirmation of whether we process your personal data and a copy of it.
- Rectification — to have inaccurate or incomplete data corrected.
- Erasure — to have your personal data deleted in certain circumstances.
- Portability — to receive your personal data in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller.
- Restriction — to limit how we process your data in certain circumstances.
- Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time.
- Withdrawal of consent — to withdraw consent where we rely on it, without affecting prior processing.
- Complaint — to lodge a complaint with your local supervisory authority (in the EEA, your data protection authority; in the UK, the Information Commissioner's Office). We would appreciate the chance to address your concerns first.
If you are a resident of California or another US state with comparable rights, you may have rights to know, access, correct, delete, and obtain a copy of your personal information, and to opt out of any "sale" or "sharing" or of targeted advertising — and not to be discriminated against for exercising these rights. As noted, we do not sell personal data or share it for cross-context behavioural advertising.
How to exercise your rights — in product.
- Account Owners (data we control): you can manage and exercise most rights directly in the Service. Use Settings to export your tenant's full data as a downloadable file (covering your business profile, hours, services, staff, customers, bookings, conversations, messages, reviews, knowledge base, waitlist, loyalty, memberships, commissions, campaigns, and audit log; provider credentials are excluded and large collections may be capped, with truncation flagged). You can correct business, customer, staff, and booking data inline as you work. You can delete your account from Settings, which triggers the cancellation and 30-day purge described in Section 9. Re-authentication is required for export and deletion.
- Marketing recipients: every marketing email includes a one-click unsubscribe link and a standards-based list-unsubscribe header; unsubscribing immediately excludes that contact from future campaigns. Account Owners can also block a customer, which stops automated replies and excludes them from campaigns and offers.
- End customers of a business using Alovibe: Alovibe is a processor for your data, so please direct access, correction, deletion, and other requests to the business you interacted with — it is the controller. Alovibe provides Account Owners with the export and deletion tooling needed to honour your request and will assist the business as required.
To exercise rights over data we control, or if you cannot use the in-product tools, contact us using Section 16. We may need to verify your identity, and we will respond within the timeframes required by applicable law.
12. Cookies and similar technologies
Alovibe uses a single strictly necessary session cookie to keep signed-in users authenticated, and browser local storage to remember interface preferences (language, currency, theme) and your cookie-banner choice. We do not use advertising or cross-site tracking cookies, and non-essential analytics and tracking are off by default and are not loaded. Our payment processor may set its own cookies on its own payment pages. For full details, see our Cookie Policy.
13. Children's data
The Service is intended for businesses and the people who run them; it is not directed to children, and we do not knowingly collect personal data directly from children. Account Owners are responsible for the data they process about their own customers and for any age-related obligations that apply to them. If you believe a child has provided us with personal data in our capacity as controller, contact us and we will take appropriate steps to delete it.
14. Automated decision-making
We do not use your personal data to make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. The "Alo" assistant generates messages and suggestions, but it operates under the Account Owner's configuration and control.
15. Changes to this Policy
We may update this Policy from time to time to reflect changes in the Service, our practices, or the law. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice (for example, in-product or by email). Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by law.
16. Contact us and Data Protection Officer
If you have questions about this Policy, wish to exercise your rights, or want information about our safeguards or sub-processors, contact us at:
- Email: privacy@alovibe.com (or support@alovibe.app)
- Postal address: NEXGEN SKYLINEX, S.L., Paseo Virgen del Puerto 51, 28005 Madrid, Spain
Where we are required to appoint a Data Protection Officer or an EU/UK representative, their contact details will be published here and made available on request.
17. Governing law
This Policy and any dispute arising out of or relating to it are governed by the laws of Spain, without prejudice to any mandatory data-protection rights you have under the laws of your country of residence.