BusyDays ("we", "us") provides booking and client-communication automation to independent appointment-based professionals and studios ("artists"). This policy explains what we collect, why, and your choices. Each artist's data is isolated in its own workspace and never shared with other workspaces.
1. Information we process
Account & profile: your name, email, and profile photo from Google Sign-In.
Google Workspace data: with your consent, we access Google Sheets (to store your leads, bookings and settings in a spreadsheet you own), Google Calendar (to create and read booking events), and Drive file access limited to files the app creates.
Meta platform data: if you connect WhatsApp Business or Instagram, we process the messages your clients send you and the tokens needed to reply on your behalf.
Client & booking records: client names, contact handles, event details, quotes, invoices and payment status that you or your clients enter.
Payments: credit-pack purchases are processed by Razorpay; we store only the resulting payment reference, never card details.
2. How we use it
To run your booking pipeline: capturing leads, scheduling, generating quotes/invoices/contracts, and sending messages you authorise.
To provide AI assistance (drafting replies, enriching leads, drafting review responses) using the xAI Grok API.
To meter usage and process credit-pack purchases.
We do not sell your data or your clients' data, and we do not use it for advertising.
2a. Google API Limited Use disclosure
BusyDays' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
We use Google Sheets access only to read and write the booking/lead spreadsheet we create in your own Drive. We do not read any other spreadsheets.
We use Google Calendar access only to create, update and delete booking events we create on your behalf. We do not read events we did not create, except to check free/busy availability at your explicit request.
We use Drive file access (drive.file scope) only to upload files our app generates — payment screenshots, portfolio photos, and your business logo. We cannot see or access other files in your Drive.
We do not use data obtained via Google APIs to serve advertisements, and we do not transfer it to any third party except as necessary to provide the features you explicitly activate.
No AI/ML model training: we do not use any data obtained through Google Workspace APIs (Sheets, Calendar, Drive) to develop, improve, or train generalized artificial-intelligence or machine-learning models — neither our own nor any third party's. Where you invoke an AI feature, the minimum data needed is sent to our AI processor (xAI) solely to generate that one response for you; it is not retained by us for training and we contractually prohibit its use for model training.
No human access: our staff do not read data obtained via Google APIs except with your explicit permission (e.g. a support request), where required for security or legal compliance, or in aggregated, anonymised form.
3. Third parties we share with
We share data only with the processors needed to deliver the service: Google (Sheets, Calendar, Drive), Meta (WhatsApp/Instagram messaging), xAI (AI generation), Razorpay (payments), and Leegality (e-signature, when you send a contract). Each receives only what is necessary for its function.
4. Storage & security
Operational records are stored in your own Google Sheet plus our database. OAuth tokens are encrypted at rest using AES-256-GCM. Sessions are stored server-side and transmitted over HTTPS. Access is restricted to the authenticated workspace owner.
5. Retention
We retain workspace data for as long as your account is active. When you disconnect an integration, the related access tokens are revoked and marked disconnected. When you delete your workspace, associated records are removed from our database; data you stored in your own Google Sheet remains under your control in your Google account.
6. Your rights & choices
Disconnect Google or Meta at any time from Settings; this revokes our access.
Request deletion of your data — see our Data Deletion page.
Export your personal data at any time from Settings → Account → Export my data.
Delete your workspace instantly via Settings → Account → Delete workspace, or by emailing us.
Access or export your records directly from the Google Sheet you own.
7. WhatsApp messaging opt-out
Clients who receive WhatsApp messages through BusyDays may reply STOP (or UNSUBSCRIBE / OPT OUT) at any time. We record the opt-out immediately and exclude that contact from all future campaign messages sent by that artist. Artists can view opted-out contacts in Settings → Campaigns → Opt-outs.