Privacy Policy
Last updated: May 15, 2026
Table of Contents
This Privacy Policy explains how Calavai("Calavai," "we," "us," or "our") collects, uses, shares, and protects personal information when you use the Calavai website, applications, and related services (the "Platform"). By using the Platform, you agree to this Policy. If you do not agree, do not use the Platform.
This Policy applies to information we process as a "business" or "controller" for our own purposes (for example, your account). When Professionals ("Pros") process information about their own clients on the Platform, the Pro is the "business" or "controller" of that information and is responsible for its lawful handling; Calavai acts as a "service provider" or "processor" in that context.
1. Information We Collect
Information you provide.
- Account data: name, email address, password (hashed), profile photo, username, time zone, role (Pro or Client), and similar registration information.
- Pro profile data: business name, bio, service descriptions, pricing, scheduling rules, refund policy, branding.
- Booking and content data: appointments, messages, intake responses, notes, files, and any other content you submit.
- Payment data: to use payment features, you provide payment information directly to Stripe. Calavai does not collect, store, or have access to full payment card numbers or bank credentials. We receive limited tokens and metadata from Stripe (for example, last four digits, brand, customer ID, payout status, dispute status).
- Communications: when you email us or contact support, we keep a record of the correspondence.
Information collected automatically.
- Usage and device data: IP address, browser and device type, operating system, language, referring and exit pages, pages viewed, links clicked, timestamps, session identifiers, and approximate location derived from IP.
- Cookies and similar technologies: see Section 8.
Information from third parties.
- Google Calendar / OAuth providers: if you connect a third-party account, we receive the tokens and account metadata you authorize.
- Stripe: transaction, payout, dispute, and identity-verification metadata for your connected account.
- Fraud and security signals from our service providers.
We do not knowingly collect biometric data, precise geolocation, government-issued IDs (Stripe collects these directly for KYC, not Calavai), or sensitive health information. Pros should not share their clients' sensitive personal information through the Platform unless they have a lawful basis to do so.
2. How We Use Information
We use personal information to:
- create and operate your account and provide the Platform;
- enable and process bookings, scheduling, calendar sync, notifications, reminders, and emails;
- facilitate payments through Stripe;
- communicate with you about transactions, security, support, and changes to our services;
- detect, prevent, investigate, and respond to fraud, abuse, security incidents, chargebacks, and violations of our Terms;
- analyze usage and improve, debug, and develop the Platform;
- send marketing communications about Calavai (you can unsubscribe at any time);
- comply with legal obligations, respond to lawful requests, and protect our rights and the rights and safety of others;
- enforce our Terms.
We do not use your personal data to train, fine-tune, or evaluate any third-party artificial intelligence model. We may use de-identified or aggregated data for any business purpose.
3. Legal Bases (EEA / UK)
If you are in the EEA, UK, or Switzerland, we process personal data on the following legal bases under the GDPR / UK GDPR:
- Performance of a contract: to provide the Platform you have requested.
- Legitimate interests: to operate, secure, analyze, and improve the Platform; to prevent fraud; to communicate about service-related matters; and to enforce our Terms. We balance these interests against your rights.
- Consent: for optional cookies, marketing emails where required, and other processing where the law requires consent. You may withdraw consent at any time.
- Legal obligation: to comply with applicable laws.
If you require a Data Processing Addendum reflecting the EU Commission's Standard Contractual Clauses (SCCs), Pros may request one at [email protected].
5. International Transfers
Calavai is operated from the United States. Personal data we collect may be stored and processed in the United States or in any other country where Calavai or our service providers operate. Where required, we rely on appropriate safeguards, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, for transfers from the EEA, UK, or Switzerland.
6. Retention
We retain personal information for as long as your account is active and for a reasonable period thereafter, as needed to: comply with legal, accounting, tax, and audit obligations; resolve disputes; enforce our agreements; prevent fraud and abuse; and maintain backups. Booking and payment records are generally retained for at least seven (7) years to comply with financial and tax recordkeeping laws. We may retain de-identified or aggregated information indefinitely.
7. Your Rights and Choices
United States — CCPA / CPRA and other state laws. If you are a resident of California or another U.S. state with a comprehensive privacy law, you have, subject to verification and legal exceptions, the right to:
- know what personal information we collect, use, disclose, and share;
- access or receive a copy of your personal information;
- correct inaccurate personal information;
- delete personal information we hold about you;
- opt out of the "sale" or "sharing" of personal information — Calavai does not sell PI for money but does share device-level event data with Google and Meta for cross-context behavioral advertising; use the Do Not Sell or Share My Personal Information page to opt out. We also honor recognized Global Privacy Control (GPC) signals as an opt-out request;
- limit the use of sensitive personal information (we do not use it for purposes that trigger this right);
- be free from discrimination for exercising these rights.
Authorized agents may submit requests on your behalf with proof of authorization.
EEA / UK / Switzerland — GDPR.You have the right to: access; rectification; erasure ("right to be forgotten"); restriction; objection (including to direct marketing, which we will honor); data portability; and to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.
How to exercise your rights. Email [email protected] with your request and the account email. We will respond within the timeframes required by applicable law. We may request information to verify your identity.
If you are a client of a Pro, please contact the Pro directly for requests about data they control.
9. Children
The Platform is not directed to, and we do not knowingly collect personal information from, anyone under 18. If we learn that we have collected information from a person under 18, we will delete it. Parents or guardians who believe a minor has provided information may contact [email protected].
10. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, access controls, hashing of credentials, infrastructure provided by reputable cloud vendors, and logging. No system is perfectly secure. We do not warrant or guarantee that personal information will be free from unauthorized access. In the event of a security incident affecting personal information, we will notify affected users and regulators as and to the extent required by applicable law.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the "Last updated" date and, where appropriate, by email or in-app notice. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
12. Contact
For privacy questions or to exercise your rights, contact [email protected]. For general questions, contact [email protected].
Calavai acts as its own privacy contact. We have not appointed a Data Protection Officer because we are not required to do so under Article 37 of the GDPR. If you are in the EEA or UK and require a representative under Article 27 GDPR or UK GDPR for specific processing, please contact us to discuss the arrangement.
13. Legal Entity
Calavai is operated by DGD OPCO LLC, a Texas limited liability company, registered at 5900 Balcones Drive #29311, Austin, TX 78731.
Privacy questions? [email protected]
Back to Calavai →