Legal

Privacy Policy

Effective 3 August 2026 · Last updated 11 September 2026

How the Ihjiz booking and business-management platform collects, uses, shares and protects personal data — for the businesses that run on it, and for the people they serve.

1.Who we are

Ihjiz ("Ihjiz", "we", "us") provides a booking and business-management platform that businesses — clinics, salons, studios, service providers and similar — use to schedule appointments, manage customers, take payments, and communicate with the people they serve.

Two different relationships are covered by this policy, and it matters which one applies to you:

  • If you use Ihjiz to run your business (an owner, manager or staff member with an Ihjiz account), we are the controller of your account data and act as described below.
  • If you are a customer of a business that uses Ihjiz (you booked an appointment, received a reminder, or messaged that business), the business is the controller of your data and decides what is collected and how long it is kept. Ihjiz is that business's processor and handles your data on its written instructions. Requests about your data are best directed to the business first; we will assist them, and you can also contact us directly using the details in section 11.

2.Data we collect

Account and staff data

  • Name, email address, phone number, job title, department and role assignments.
  • Authentication credentials: a hashed password, and — if you enable them — passkey (WebAuthn) public keys and one-time codes sent by email or SMS.
  • Profile photo, language preference, and interface settings.

Customer records created by businesses

  • Name, email address, phone number, city and province.
  • Date of birth, gender, profile photo, and free-text notes.
  • A business-assigned reference number (for example a patient or file number).
  • Appointment, visit and waiting-list history, including services booked, assigned staff, timings, cancellations and no-shows.
  • Invoices, payments, deposits, store credit, gift cards and refunds.
  • Custom fields the business defines. In clinical and veterinary settings these can include health information such as allergies, current medications and consent records. This is sensitive data, and the business is responsible for collecting it lawfully and for obtaining any consent its jurisdiction requires.
  • Files a business or customer uploads, such as documents and images attached to a record.
  • Records of which policies (terms, privacy, cancellation, consent forms) were shown and acknowledged, with the time, IP address and user agent of the acknowledgement.

Messages and notifications

  • The content of messages sent through the platform — email, SMS, WhatsApp, Facebook Messenger, Instagram, web push and in-app messages — along with delivery status.
  • Engagement events for email: whether a message was opened and whether links in it were clicked.
  • Push notification tokens for browsers and mobile devices.

Technical and security data

  • IP address, browser user agent, device description and approximate location derived from IP.
  • Sign-in events, active sessions and devices, refresh tokens, and security-relevant audit logs of actions taken in the platform.
  • Diagnostic logs and error reports.

We do not collect precise device GPS location, and we do not use advertising cookies or third-party tracking pixels. Session and preference data is stored on your device using browser storage that is strictly necessary to keep you signed in and to remember your settings.

3.Meta platforms: Facebook, Instagram and WhatsApp

This section describes data obtained through Meta's APIs and exists so that both businesses and the people who message them understand exactly what happens to that data.

A business using Ihjiz may connect its Facebook Page, Instagram professional account, or WhatsApp Business account so that conversations with its customers appear in one inbox inside Ihjiz. The connection is made by the business through Facebook Login, and only with the permissions it grants. When connected, we receive and store:

  • The Page, Instagram account or WhatsApp Business account identifier, its name, and its profile image.
  • Access tokens issued by Meta, which are encrypted at rest and used only to send and receive messages on the business's behalf.
  • Inbound and outbound message content, attachments, timestamps, and the sender's platform-scoped identifier, display name and — for WhatsApp — phone number.

We use this data only to:

  • Display conversations to authorised staff of the connected business and let them reply.
  • Send appointment confirmations, reminders and other transactional messages the business has configured, within Meta's messaging policies.
  • Match a conversation to an existing customer record so staff have context.
  • Generate suggested replies, where the business has enabled AI assistance (see section 5).

We do not sell this data, use it for advertising or audience building, share it with other businesses on the platform, or use it for any purpose beyond operating the connected inbox. A business can disconnect its Meta accounts at any time from the Integrations area of the platform; disconnecting deletes the stored access token from our systems and stops all message sending and receiving immediately. You can also remove Ihjiz from your own Facebook account settings at any time, which withdraws the permissions you granted. See our Data Deletion Instructions for how to have the associated data erased.

4.Why we use your data

  • To deliver the service — creating and managing bookings, records, invoices and payments.
  • To communicate — appointment confirmations, reminders, follow-ups, receipts and service notices, plus marketing campaigns where the business has a lawful basis and you have not opted out.
  • To keep accounts secure — authentication, session management, fraud and abuse prevention, and audit logging.
  • To support and improve the platform — diagnosing faults, monitoring reliability, and understanding which features are used in aggregate.
  • To meet legal obligations — tax, accounting and record-keeping requirements applicable to the business.

Where the law requires a legal basis, we rely on performance of a contract, our legitimate interests in operating and securing the platform, compliance with legal obligations, and consent where consent is the appropriate basis — for example marketing messages and sensitive health information.

5.Artificial intelligence features

Businesses can enable optional AI features such as the in-app assistant and suggested replies. When an AI feature is used, the relevant content — the question asked and the records needed to answer it — is sent to the configured model provider (Google Gemini, Anthropic Claude, OpenAI or DeepSeek) over an encrypted connection. We use these providers' business API tiers. Google, Anthropic and OpenAI state that content submitted through those APIs is not used to train their models; DeepSeek's standard terms do not offer the same commitment, so a business selecting DeepSeek should review them. AI features are off unless a business turns them on, and a business may use its own provider key instead of ours.

6.Who we share data with

We do not sell personal data. We share it with service providers who process it on our behalf under contract, and only as needed to run the platform:

ProviderPurpose
Meta PlatformsWhatsApp Cloud API, Messenger and Instagram messaging
Telegram FZ-LLCTelegram Bot API messaging, where a business connects a Telegram bot
StripeCard payments and payouts to businesses. Card details are entered directly with Stripe and never reach our servers.
GoogleCalendar synchronisation, Firebase Cloud Messaging for mobile push, and Gemini where AI is enabled
Anthropic, OpenAI, DeepSeekAI assistant features, where enabled
Resend, SendGrid, MailgunTransactional and campaign email delivery
Twilio, Vonage, MessageBirdSMS delivery and one-time codes
RenderApplication hosting
NeonManaged database hosting
S3-compatible object storageUploaded files, generated documents and exports

Which of these are active depends on what the business has configured. We also disclose data where required by law, to enforce our terms, or in connection with a merger or acquisition — in which case we will give notice before your data becomes subject to a different policy.

Each business's data is logically isolated from every other business on the platform. Staff of one business cannot access another business's records.

7.International transfers

Our infrastructure and service providers operate data centres in several countries, so your data may be processed outside the country where you live. Where transfers are subject to data-protection law, we rely on the safeguards offered by those providers, including standard contractual clauses.

8.How long we keep data

  • Account and customer records are kept while the business's account is active.
  • When an account is closed, or when we receive a deletion request, we delete the data within 30 days, except where a longer period is required by law. Account closure is carried out by our team on request — see the Data Deletion Instructions.
  • Invoices, payments and other financial records are retained for the period tax and accounting law requires, typically up to seven years.
  • Security and audit logs are retained for up to 12 months.
  • The stored access token for a Meta integration is deleted the moment the integration is disconnected. Message content already synced into a business's inbox forms part of that business's records and is deleted on request.
  • Deleted records are removed from the application and then purged from active systems. Encrypted backups held by our infrastructure providers are overwritten on their own rolling cycle.

9.Your rights

Depending on where you live, you may have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Delete your data — see the Data Deletion Instructions.
  • Object to or restrict certain processing, and withdraw consent you previously gave.
  • Receive your data in a portable, machine-readable format.
  • Opt out of marketing messages at any time, using the unsubscribe link in an email or by asking the business to stop contacting you. You cannot opt out of transactional messages such as appointment confirmations while you have an active booking.
  • Lodge a complaint with your local data-protection authority.

To exercise a right, contact the business you dealt with, or write to us at privacy@ihjiz.co. We respond within 30 days and may need to verify your identity first. Where we act as a processor for a business, we will refer your request to that business and support them in answering it.

10.Security and children

All traffic is encrypted in transit with TLS. Stored secrets — integration tokens, provider keys and credentials — are encrypted at rest with AES-256-GCM. Access inside a business is governed by role-based permissions, and sessions can be reviewed and revoked from your account settings. No system is perfectly secure, but we work to protect your data and will notify affected users and regulators of a breach where the law requires it.

The platform is not directed at children. A business may hold records for a minor where its service involves treating or serving them, in which case a parent or guardian provides the information and any required consent, and the business is responsible for that consent.

11.Changes and contact

If we make a material change to this policy we will update the date at the top and notify account holders in the platform or by email before the change takes effect.

Questions, requests or complaints about privacy: privacy@ihjiz.co