JuanService ← Back to home

Privacy Policy

Last updated: 3 August 2026

How JuanService handles personal data — for the businesses that use it and the customers who message their assistants.

The short version

To run an AI booking assistant we store the details a booking needs — a name, contact, the messages exchanged, and the appointment. To answer, your messages are sent to our AI provider. We don’t sell your data. Each business controls its own customers’ data; we process it on their behalf.

1.What this page is for

This policy explains what personal data JuanService collects, why, who we share it with, and the choices you have. It covers both the businesses that use JuanService and the end-customers who message a business’s assistant.

2.Our role: controller vs processor

Our role depends on whose data it is:

  • For a business’s own account data (the details of the business and its staff), JuanService is the controller.
  • For end-customer data that flows through a business’s assistant (the people who message it), the business is the controller and JuanService is the processor — we handle that data on the business’s instructions to provide the service. If you’re an end-customer, the business you contacted is responsible for your data, and requests about it are usually best directed to them.

3.What we collect

From businesses

  • Account and contact details (name, email, organisation) and staff logins.
  • Configuration you provide (services, hours, knowledge-base content, branding).
  • Billing information needed to run your subscription.

From / about end-customers

  • Identity & contact: name, phone number and email address where provided.
  • Channel identifiers: the ID the messaging platform gives us — for example a Facebook Messenger page-scoped ID (PSID) or a Telegram user ID.
  • Message content: the messages exchanged with the assistant (the conversation transcript).
  • Booking details: appointment or stay times, notes you provide, and payment status.

4.What leaves to third parties

To deliver the service, some data is shared with the providers below:

  • To generate replies, the content of messages and relevant knowledge-base text is sent to our AI provider (OpenAI). This is how the assistant understands and answers.
  • To deliver messages, content passes through the messaging platform you’re using (Meta/Messenger or Telegram).
  • To sync bookings, appointment details may be written to the business’s Google Calendar.
  • To take payments, booking payment details are handled by the payment gateway your business connects, under its own account; card details are entered on that gateway’s hosted checkout and don’t reach us. Your JuanService subscription is billed separately by Paddle.

5.Who processes data for us

We rely on these sub-processors:

  • OpenAI — generates assistant replies and knowledge-base search embeddings; receives message and knowledge-base content.
  • Paddle — merchant of record for JuanService subscription billing (payment, invoicing, tax); subscription card details go to Paddle, not us.
  • Meta (Facebook Messenger) — messaging channel.
  • Telegram — messaging channel.
  • Google — Calendar sync.
  • Supabase — our database and file storage, hosted in Singapore (AWS ap-southeast-1).
  • Render — application hosting.

If your business connects its own payment gateway to collect booking payments, that gateway processes those payments under your business’s own account — it’s your provider, not a JuanService sub-processor.

6.What we do not do

We don’t sell personal data, and we don’t use customer conversations for anything beyond providing and improving the service you asked for. We don’t share one business’s data with another.

7.Legal basis

We process personal data to perform our contract with a business, to pursue legitimate interests in running and securing the service, to meet legal obligations, and on the basis of consent where that applies (for example, marketing messages a business chooses to send its customers, which the business is responsible for obtaining consent for).

8.How long we keep it

We keep personal data for as long as an account is active and as needed to provide the service, and we act on a business’s instructions about its customers’ data. When a business closes its account, its associated data is removed. As a guide: conversation transcripts and messages are kept for up to 12 months after the last activity; booking and appointment records for as long as the business’s account is active and then up to 24 months (or longer where tax or other law requires); and operational logs for about 90 days. A business may request earlier deletion of its data.

9.Security

We take reasonable measures to protect data: connections use HTTPS; stored secrets such as third-party OAuth tokens and payment-gateway keys are encrypted at rest (AES-256-GCM); passwords are hashed (bcrypt); and access to data is scoped per business at the application layer so one business can’t see another’s. No system is perfectly secure, but we work to keep your data safe.

10.Your rights

Depending on where you live, you may have rights to access, correct, delete, export or restrict the processing of your personal data. Businesses can manage much of this directly from their account. End-customers should contact the business they messaged, since that business controls the data; we’ll support the business in responding. You can also stop assistant messages at any time using the opt-out/STOP option on your messaging channel.

11.Children

JuanService isn’t directed at children, and businesses shouldn’t use it to knowingly collect data from children. If you believe a child’s data has been provided, contact us and we’ll help the responsible business address it.

12.Where your data is held

Our infrastructure is provided by Supabase and Render, and processing may occur outside your country. Our database, file storage and application servers are located in Singapore; if you are outside Singapore, your data is transferred there to provide the service. Where data-protection law restricts transfers abroad, we rely on appropriate safeguards.

13.Changes

We may update this policy and will change the “last updated” date above; for material changes we’ll give reasonable notice.

14.Contact

Questions or requests about your data? Email support@juanservice.com. In the Philippines you may also contact the National Privacy Commission; if you’re in the EU or UK, you may contact your local data-protection authority.