Privacy Notice
Working draft, version 2026-09-03 — pending legal
review. This is the exact text the product asks you to accept at signup;
when counsel revises it, the version date changes and every account is
asked again.
What we store, and why:
- Account facts: your name, email, phone, password hash — to run your login.
- Workspace records: jobs, clients, addresses, money rows, worker records —
because putting them there is what the product is for.
- Messages: when you bind a WhatsApp group, messages from that group, including
from participants without accounts — to create and update jobs from them.
- Text messaging: the business phone numbers your workspace uses, the mobile
numbers you add for your workers, the mobile numbers your customers give you
for a job, and the texts sent and received on them — to run the job-dispatch
automation and the customer job updates you configure.
- Connected Google services: if you sign in with Google, the name, email
address and profile picture Google returns — to run your login, and nothing
else. If your workspace connects a Google Ads account, that account's
campaign, ad group and keyword names and its daily cost, impression, click
and conversion figures — to show what the spend produced. The connection is
read-only: HeadHoncho never creates, edits, pauses or deletes anything in a
connected Google account.
- Technical logs: request logs and error reports, kept short-term, to keep the
service working. Error reports carry no workspace content.
What we do not do: sell data, use your records to train models, or read your
workspace except to operate the service or as required by law. Mobile phone
numbers and text-messaging opt-in data are never sold, rented, or shared with
third parties or affiliates for marketing or promotional purposes — not with
anyone, not for any reason.
Google user data: HeadHoncho's use and transfer to any other application of
information received from Google APIs adheres to the Google API Services User
Data Policy, including the Limited Use requirements. Google user data is used
only to provide the features described above; it is never sold, never used for
advertising, and never used to train models, generalized or otherwise. Humans
do not read it, except with your explicit permission for support, where
necessary for security, or as required by law. Disconnecting a Google Ads
account, or unlinking Google sign-in, deletes the stored tokens immediately —
and you can revoke HeadHoncho's access yourself at any time at
myaccount.google.com/permissions.
How sensitive data is protected: every connection to HeadHoncho, and every
exchange between HeadHoncho and Google or another connected provider, travels
encrypted over TLS. Everything we store sits on encrypted infrastructure
(encryption at rest). The most sensitive records — OAuth tokens and provider
credentials — carry a second, application-layer encryption (authenticated
AES, with keys held outside the database) before they are written; they are
decrypted only at the moment a request needs them, and are never written to
logs. Access is isolated per workspace: your records are readable only by
your workspace's signed-in members, and a connected account's data only by
the workspace that connected it.
Where it lives: on infrastructure in the United States (AWS us-east-1),
encrypted at rest. Mail is delivered by SendGrid; text messages by Twilio;
error reports, if enabled, by Sentry. Each processes only what the function
needs.
Your controls: export from every panel's Report button; correct or void any
record; change or delete your account email; ask for organization deletion.
Group participants who want their messages removed can ask the workspace owner
or us.
Retention: workspace records for as long as your account exists; verification
codes minutes; logs weeks, not months.
Contact: privacy@headhoncho.app.