Privacy Policy
Privacy Policy
Draft dated 2026-09-01. Not yet reviewed by a licensed attorney. Do not publish as final or rely on this to establish legal compliance.
Who this covers
Chakusa has two kinds of accounts: business accounts (business owners running their CRM, marketplace listing, bookings, and loyalty program) and customer accounts (people who discover, book, and message businesses through Chakusa). One person can hold both. This policy covers both, and this website.
Information we collect
From business accounts
Name, email, and business details when you sign up. If you sign in with Google or Apple, the basic profile information those providers share. If you use the CRM to track your own customers, the customer names, phone numbers, notes, message content, and review/feedback records you enter, that data is yours, not ours; you're responsible for having the right to collect and store it.
From customer accounts
Name, email, phone (optional), and a profile used across every business you interact with through Chakusa: booking history, loyalty points and redemptions, marketplace searches and favorites, reviews you leave, and messages and AI assistant conversations you send. Marketplace search recognizes your approximate location if you allow it, to show nearby businesses.
Bookings and payments
Appointment details (service, time, price, staff assigned), and payment records for deposits or balances paid through Chakusa (amount, status, refunds). Card details are handled entirely by Stripe; we never see or store them. A business's own cancellation, rescheduling, and no-show policies are set by that business, not by Chakusa.
Loyalty, memberships, and referrals
Points balances and history, redemption codes, membership plan details, and, if you refer someone, the referral code and the email address of the person you're referring (collected before they've signed up, so we can credit the referral once they do).
Messages and AI conversations
Content of messages sent through Chakusa (SMS/WhatsApp via Twilio), and, if you use an AI-powered feature, the content of that conversation. See AI Disclosure for the specifics of what happens to that data.
Technical information
Device push-notification tokens, and error/diagnostic data when something breaks. This website itself sets no tracking or advertising cookies, see the Cookie Policy.
How we use it
To run the product: showing your leads, bookings, loyalty balances, and marketplace listings; sending messages you ask us to send or that automation sends on your behalf; generating AI responses where that feature is used; and sending push notifications about activity in your account. We don't sell data, and we don't use it to serve ads.
AI features
Chakusa includes AI-powered features: a business-facing assistant that can draft or send replies to a business's customers (a business must turn this on), and an in-app assistant customers can chat with directly. Both send conversation content to a third-party AI provider (OpenAI or Anthropic, depending on configuration) to generate a response. Full detail, including an important gap in how the customer-facing assistant currently works, its data retention behavior, and who inside Chakusa can view a conversation, is in the dedicated AI Disclosure, which is part of this Privacy Policy by reference.
Text messages
Message delivery runs through Twilio. Standard message and data rates may apply depending on the recipient's carrier. The business is responsible for having consent to message their customer, under whatever law applies where that customer lives (in the US, generally the TCPA; in Canada, CASL; other countries have their own rules). If a customer replies STOP, Chakusa automatically registers that as an opt-out, and our automated messaging checks this before sending anything further. A business sending manually or through a channel outside Chakusa's own automation is still responsible for honoring that opt-out itself.
Who we share it with
We don't sell data to anyone. The services below process data on our behalf, only for the purpose of running Chakusa:
- Twilio, sends SMS/WhatsApp messages
- Stripe, processes booking payments and refunds; also handles payouts to businesses (Stripe Connect)
- OpenAI and/or Anthropic, generate AI responses when an AI feature is used
- Expo, delivers push notifications
- Sentry, receives error/crash reports from our backend, configured to scrub authentication tokens and other sensitive fields before anything is sent
- Google and Apple, handle Sign-In if you use those options, and handle subscription billing for a business's own Chakusa plan (we never see card details there either)
- Our infrastructure and database providers, who host the servers Chakusa runs on
Because these providers operate infrastructure in multiple countries, data may be processed outside the country you're in, including the United States (both AI providers' standard endpoints are US-based unless a data-residency-specific configuration is set up in the future). Each provider is responsible for its own compliance with applicable data-transfer rules.
Automated decisions
When an AI feature is enabled, Chakusa's system automatically decides whether to send an AI-generated reply, hold it for a human to approve, or escalate the conversation to a person, based on confidence and safety rules (see AI Disclosure). A person can always take over. We don't use automated decisions for anything with a legal or similarly significant effect on you (for example, we don't use AI to approve or deny a booking, a refund, or account access).
How long we keep it
Account, booking, loyalty, and message data is kept for as long as the account is active, plus a reasonable period afterward, unless deletion is requested sooner or the law requires longer retention. AI conversation content is currently kept indefinitely rather than on a fixed schedule, see AI Disclosure for the specifics and the retention improvement this points to.
Your rights
Depending on where you are, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain uses of it, for example under the EU/UK GDPR, the California CCPA/CPRA, the UAE PDPL, or South Africa's POPIA. You can exercise these rights by contacting us below; we'll respond within the time required by applicable law. As Chakusa expands to more countries, this section will be updated to name the specific local law that applies.
Reference: European Commission on data protection (GDPR) · California Attorney General on the CCPA
Children's privacy
Chakusa is not directed at children, and we don't knowingly collect personal data from anyone under 16.
Security
Passwords are hashed, never stored in plain text. Sessions are rotated and scoped separately for business accounts, customer accounts, and internal admin access. Any linked sign-in credentials are encrypted at rest. Internal access to production data is limited to what's needed to operate the service, and administrative actions are logged.
Complaints
If you're not satisfied with how we've handled a request, you can contact us below, or, depending on where you live, lodge a complaint with your local data protection authority.
Changes to this policy
If we make a material change to how we handle data, we'll update this page and the date at the top.
Contact
To exercise a data right or ask a question about this policy: privacy@chakusarecovery.com.