Privacy Policy
Last updated: July 10, 2026
Ginivo (“Ginivo”, “we”) provides an AI front-desk assistant for salons, spas, and clinics. This policy explains what data we collect, how we use it, and the choices you have. Questions: privacy@ginivo.ai.
Who this covers
Our customers are businesses (“clinics”) that use Ginivo to run their front desk. Clinics provide information about their business and their own clients. Where a clinic uploads client data, the clinic is the data controller and Ginivo is its processor.
Information we collect
- Account data: name, email, and login credentials of the clinic owner/staff.
- Business data: services, prices, hours, staff, policies, and FAQs (often imported from the clinic's own website).
- Client records: client names, contact details, visit history, and consent status, as provided by the clinic.
- Conversations: messages exchanged with the AI assistant (website, Instagram, or Facebook Messenger).
- Meta data: when a clinic connects Instagram or Facebook, the messages its customers send to the connected account, the sender's platform-scoped id, and the connected Page / Instagram account ids and access token. See the Meta section below.
- Google data: see the dedicated section below.
Google user data - what we access and why
When a clinic connects its Google Calendar, Ginivo requests these scopes:
calendar.readonly- to read busy/free intervals only, so the assistant never offers a time that is already taken. We do not read the titles, attendees, or contents of events we did not create.calendar.events- to create, update, and delete only the appointment events that Ginivo itself books on the clinic's calendar. Ginivo never edits or deletes events it did not create.
We store an encrypted Google refresh token to maintain the connection, and exchange it for short-lived access tokens at request time. A clinic can disconnect at any time from Settings, which stops all access.
Limited Use. Ginivo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except where required for security, to comply with law, or with the user's explicit consent.
Meta Platform Data - Instagram & Facebook Messenger
When a clinic connects its Instagram or Facebook Page, Ginivo receives the messages that the clinic's own customers send to that account, so the assistant can reply on the clinic's behalf. We request only the permissions needed for messaging: pages_messaging, pages_show_list, pages_manage_metadata, instagram_basic, and instagram_manage_messages.
- We use this data only to receive and respond to the customer's messages and to record the conversation for the clinic.
- We store the Page / Instagram access token encrypted at rest and use it solely to send the clinic's replies.
- We do not sell Meta data, use it for advertising, or share it except with the infrastructure providers that run the service.
- A clinic can disconnect at any time from the Channels page, which stops all access. Removing the app from your Meta account triggers our deauthorize callback and we deactivate the connection.
Our use of Meta Platform data complies with the Meta Platform Terms and Developer Policies. To request deletion of your Meta-related data, see Data Deletion.
How we use data
- Answer client questions and book/confirm/cancel appointments.
- Generate win-back outreach to a clinic's lapsed clients who have consented to contact.
- Show the clinic owner their schedule and client history inside the dashboard.
- Operate, secure, and improve the service.
Sharing
We do not sell personal data. We share data only with infrastructure providers that run the service (hosting, database, email/SMS delivery, and the AI model provider), strictly to deliver the product, and with Google as needed to provide the calendar integration you enabled.
SMS / text messaging
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as our messaging carrier, is permitted. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We receive a mobile number either directly from you — with express written consent via the SMS checkbox on a clinic's booking page, or by texting a start keyword to the clinic's number — or from the clinic you do business with, which confirms it has your consent as its customer. We use it solely to send that clinic's appointment confirmations, reminders, waitlist openings, post-visit check-ins, replies to your questions, and occasional re-engagement offers. We do not buy, rent, or sell phone numbers.
Message frequency varies. Message and data rates may apply. Reply STOP to any message to opt out, or HELP for help. Full program terms are in our Terms of Service.
Retention & deletion
We retain data while a clinic's account is active. A clinic can request deletion of its data, and end clients can opt out of outreach at any time — reply STOP to any text, or use the unsubscribe link in any email. Disconnecting Google revokes our access and removes the stored token.
Meta data deletion. You can request deletion of data tied to your Instagram / Facebook connection at any time - see our Data Deletion instructions, or remove the Ginivo app from your Meta account, which automatically notifies us to deactivate the connection. Requests can also be emailed to privacy@ginivo.ai.
Security
Data is encrypted in transit. Sensitive tokens are encrypted at rest. Access is scoped per clinic (multi-tenant isolation) so one clinic can never see another's data.