Privacy Policy
Last Updated: October 7, 2024
Introduction
Welcome to WaitHub, a comprehensive waitlist management application for service-based businesses. This Privacy Policy explains how we collect, use, and protect your information and your clients' information when you use our service.
Information We Collect
Business Account Data
- Account Information: Business name, contact details, billing information
- User Profiles: Staff member names, roles, and access permissions
- Location Data: Business addresses for multi-location features
- Subscription Data: Plan type, billing history, payment methods
Client Information
- Waitlist Data: Client names, phone numbers, party size, service preferences
- Communication Records: SMS message history and delivery status
- Visit History: Previous waitlist entries and service patterns
Usage Analytics
- App Usage: Feature usage, session duration, device information
- Performance Data: Error logs, crash reports, system performance
- Business Metrics: Wait times, service turnover, client satisfaction scores
How We Collect Information
Direct Collection
- Account Registration: Information you provide when signing up
- Waitlist Management: Client data entered by your staff
- Settings Configuration: Preferences and customizations you set
Automatic Collection
- Firebase Integration: Real-time data synchronization
- Mobile Apps: iOS and Android app usage data
- Location Services: GPS data for multi-location businesses (with permission)
How We Use Your Information
Service Delivery
- Provide real-time waitlist management
- Send automated SMS notifications to clients
- Synchronize data across devices and locations
- Generate wait time estimates and analytics
Business Operations
- Process subscription payments and billing
- Provide customer support and training
- Improve service quality and add new features
- Ensure system security and prevent fraud
Communication
- Send service updates and maintenance notifications
- Provide technical support and troubleshooting
- Share product updates and new feature announcements
Data Storage and Security
Cloud Infrastructure
We use Google Firebase and other enterprise-grade cloud services to store and process data. All data is encrypted in transit and at rest using industry-standard encryption protocols.
Security Measures
- End-to-end encryption for all data transmission
- Multi-factor authentication for admin accounts
- Regular security audits and penetration testing
- SOC 2 Type II compliance for data handling
- Role-based access controls for staff members
Data Retention
- Active Accounts: Data retained while subscription is active
- Cancelled Accounts: Data deleted within 30 days of cancellation
- Guest Data: Automatically purged after 12 months of inactivity
- Billing Records: Retained for 7 years for tax and legal compliance
SMS and Communication
Client Consent
We only send SMS messages to clients who have provided explicit consent. You are responsible for obtaining this consent and maintaining records of opt-ins.
Message Content
- Wait time updates and service ready notifications
- Customizable message templates with your branding
- Opt-out instructions included in every message
- Compliance with TCPA and other messaging regulations
Third-Party Integrations
Service Providers
- Google Firebase: Real-time database and authentication
- Twilio: SMS messaging services
- Stripe: Payment processing and billing
- Apple/Google: Mobile app distribution and push notifications
Data Sharing
We do not sell or rent your data to third parties. We only share data with service providers necessary to deliver our service, and they are bound by strict confidentiality agreements.
Your Rights and Controls
Account Management
- Access and download your account data
- Update or correct inaccurate information
- Delete your account and associated data
- Export client data in standard formats
Client Rights
- Clients can request removal from waitlists
- Opt-out of SMS communications at any time
- Request deletion of their personal information
Compliance and Regulations
Privacy Laws
WaitHub complies with applicable privacy laws including GDPR, CCPA, and other regional data protection regulations. We serve as a data processor for client information, while you remain the data controller.
Industry Standards
- PCI DSS compliance for payment data
- HIPAA-ready infrastructure (upon request)
- SOC 2 Type II certification
- Regular third-party security assessments
International Data Transfers
Your data may be processed in various countries where our service providers operate. We ensure appropriate safeguards are in place for international data transfers.
Children's Privacy
WaitHub is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the service. Your continued use of WaitHub after changes constitutes acceptance of the updated policy.
Contact Us
For questions about this Privacy Policy or to exercise your privacy rights, please use our contact form on the website.