Legal
Privacy Policy
Last updated: October 8, 2026
Guwy Software LLC ("Guwy," "we," "us," or "our") operates the website guwy.com and the Guwy platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our Service.
1. Information We Collect
1.1 Personal Information You Provide
When you register for an account, use our Service, or contact us, we may collect:
- Account information: Name, email address, phone number, business name, and login credentials.
- Client data: Names, phone numbers, email addresses, appointment history, and service preferences of your business's clients, as entered by you into the platform.
- Consent form data: Information provided in digital consent forms, including signatures, photo IDs, medical history, and other form fields as configured by the business.
- Payment information: Billing details processed through our third-party payment processors (we do not store full credit card numbers).
- Communications: Messages you send us via email or support channels.
1.2 Information Collected Automatically
- Usage data: Pages visited, features used, timestamps, and interaction patterns. On our public booking pages this is measured with Google Analytics; our website, guwy.com, does not use analytics. See Section 8.
- Device information: IP address, browser type, operating system, and device identifiers.
- Cookies and similar technologies: Session cookies for authentication and preferences, and analytics cookies on our public booking pages. See Section 8.
1.3 Information from Third-Party Integrations
We may receive information from integrated services such as Twilio (SMS delivery status), Stripe (payment processing and transaction status), PayPal (payment processing and transaction status), and other payment processors (transaction confirmations).
If you choose to connect third-party services through our integrations, we may also collect:
- Sign in with Apple or Google: If you choose to create your account or sign in with Apple or Google, we receive an account identifier, your name, and your email address from that provider (or, if you use Apple's "Hide My Email", a private relay address). We use this information solely to create and authenticate your business account. You can unlink these services at any time from Settings → Security.
- Google Calendar: Calendar event data (event titles, times, descriptions, and attendees) from your Google Calendar when you enable the Google Calendar sync feature. We access this data using Google OAuth 2.0 with your explicit consent.
- Google Business Profile: Your Google Place ID and business listing information when you enable the Google Reviews feature.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Service.
- Process appointments, consent forms, and business operations.
- Send transactional communications: appointment reminders, consent form links, password resets, and account notifications.
- Send promotional communications only with your explicit opt-in consent.
- Send SMS messages on behalf of businesses to their clients for appointment reminders, consent forms, and service-related notifications.
- Generate reports and analytics for business owners.
- Synchronize appointment data with your Google Calendar when you enable the integration.
- Send review request emails to your clients after completed appointments when you enable Google Reviews.
- Detect, prevent, and address technical issues, fraud, or abuse.
- Comply with legal obligations.
3. SMS and Messaging Communications
No mobile data sharing. Guwy does not sell, share, or transfer mobile phone numbers or SMS opt-in data to third parties for marketing purposes. SMS consent and mobile opt-in information are not shared with affiliates or external marketing partners. Phone numbers collected for SMS are used solely to deliver the messages the recipient consented to receive (appointment reminders, booking confirmations, account notifications, or — with a separate, granular opt-in — promotional messages from the business the recipient booked with).
Guwy facilitates SMS messaging on behalf of businesses using our platform. By using our messaging features:
- Granular opt-in. SMS opt-in is collected with separate, independent checkboxes for each use case. Service-related SMS (appointment reminders, booking confirmations, account notifications) is one opt-in. Promotional SMS is a separate, independent opt-in. Checking one does not opt the recipient into the other.
- Business users are responsible for obtaining proper consent from their clients before sending messages through our platform.
- End-user clients receive messages only when the business has a legitimate reason (appointment confirmation, consent form delivery, reminders) and the client has provided their phone number and explicit, granular consent.
- Message frequency varies based on appointments and services booked.
- Message and data rates may apply depending on the recipient's carrier.
- Recipients can opt out at any time by replying STOP to any message. Reply HELP for support, or contact us at privacy@guwy.com.
- No third-party sharing of SMS data. Mobile phone numbers, SMS opt-in records, and message content are not sold, rented, leased, or shared with third parties for marketing purposes. Twilio, our messaging provider, is the only third party we share SMS data with for message delivery, and it acts solely as a processor under our instructions. Our infrastructure providers listed in Section 5 store our systems' data (including message logs) as part of hosting and backups.
- We use Twilio as our messaging service provider. Twilio's privacy policy is available at twilio.com/legal/privacy.
4. Third-Party Integrations and Google API Services
4.1 Google Calendar Integration
When you connect your Google Calendar to Guwy:
- We request access to your Google Calendar data through Google's OAuth 2.0 authorization flow.
- We use the
calendar.eventsscope to read, create, update, and delete calendar events on your behalf. - Appointment data from Guwy is synced to your Google Calendar, and events from your Google Calendar are used to determine availability in Guwy.
- We store your Google OAuth tokens to maintain the connection, with access restricted to the calendar sync feature. You can revoke access at any time from Guwy's Integrations page or from your Google Account permissions.
- We do not use your Google Calendar data for advertising, profiling, or any purpose other than providing the calendar sync feature.
- Guwy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4.2 Google Reviews Integration
When you enable the Google Reviews feature:
- We store your Google Place ID to generate review request links.
- We send automated emails to your clients after completed appointments containing a direct link to leave a review on Google.
- We do not access or store your Google Reviews data; we only generate links to the Google review page.
4.3 Mobile Application
When you use the Guwy mobile application, we may request access to certain device features. Each permission is only used for its stated purpose and is never accessed without your action:
- Camera: Used to capture photos for client profiles, consent forms, and service documentation. Photos are uploaded to your business account and stored on our servers, with access restricted to your business. The camera is only activated when you explicitly choose to take a photo within the app.
- Bluetooth: Used exclusively to connect to Stripe card readers (such as the Stripe M2) for in-person payment processing. Bluetooth is only activated when you initiate the card reader connection from the POS screen.
- Location (approximate): Used solely in conjunction with Bluetooth to discover nearby Stripe card readers, as required by Android system permissions. We do not track, store, or transmit your location data.
- Internet access: Required for the app to communicate with Guwy servers, process payments, send notifications, and sync data.
- Push notifications: Used to deliver appointment reminders, incoming call alerts, and system notifications. You can disable push notifications at any time through your device settings.
You can revoke any of these permissions at any time through your device settings. Revoking a permission may limit certain features of the app (for example, revoking Bluetooth access will prevent card reader connectivity).
5. How We Share Your Information
We do not sell your personal information. We may share information with:
- Service providers: Twilio (SMS), Cloudflare (CDN/security, backup storage), Amazon Web Services (encrypted backup storage), Google APIs (Calendar sync, Maps, Reviews), Google Analytics (usage analytics on our public booking pages), Stripe (payment processing), PayPal (payment processing), email providers, other payment processors, the services that deliver notifications to the phones of a business's staff, our artificial-intelligence provider for the optional in-dashboard assistant, app-store and mobile update services, and any optional service a business chooses to connect (such as a calendar, a marketing tool, or a destination for appointment events) — only as necessary to operate the Service. A business using Guwy can request the current list of our service providers under its agreement with us.
- Business-client relationship: Client data is accessible to the business that created the client record. Businesses are data controllers for their client data.
- Legal requirements: When required by law, court order, or to protect our rights, safety, or property.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users.
6. Data Retention
While your business account is active, we retain all of your business data indefinitely — clients, appointments, documents, consent forms, photos and history. Long-term storage of your records is part of the service you pay for; we never delete an active business's data through age-based expiration.
- Account deletion: If you delete your account, all of your business data is retained for 90 days so you can export it or restore the account, either by signing in again with the same sign-in account (email, Apple or Google) or by contacting us (we email you the exact deadline). After that period, it is permanently and irreversibly erased from our systems.
- Suspended accounts: Data is kept frozen while an account is suspended. If a suspended account is not reactivated within 6 months, we send a notice and the same 90-day export window applies before permanent erasure.
- Data export: Business owners can download a complete copy of their data (spreadsheets plus all stored files) at any time from the panel, or request it at privacy@guwy.com.
- Client data: Businesses can delete individual client records at any time.
- Consent forms: Retained while the business account is active. A business can erase an individual client’s records at any time from within its own account. Businesses subject to record-keeping laws remain responsible for meeting those obligations and for retaining their own copies, both before and after account deletion.
- Messaging and audit logs: SMS delivery logs are retained for at least 12 months and audit logs for at least 3 years; while the account is active they are retained like the rest of the account's data.
7. Data Security
We implement security measures including:
- TLS 1.2/1.3 encryption for all data in transit.
- Encryption at rest (LUKS2, AES-256-XTS) on the volume holding our database and uploaded consent documents, including signatures and ID photos. This protects your data on the physical storage medium if a disk is retired, replaced, or removed from our infrastructure.
- Encrypted off-site backups: our primary backup pipeline encrypts data on our servers before upload, and every backup storage provider applies its own encryption at rest.
- Role-based access controls and data isolation between businesses.
- Access logging on consent documents: we record who viewed or downloaded each record, and when.
- Security monitoring, with a security review before significant changes to the Service.
- Secure password hashing (bcrypt).
- We do not use identity-document images or signatures to create biometric templates or perform facial recognition.
No method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
8. Cookies
We use essential cookies for:
- Authentication: JWT tokens stored in localStorage to maintain your session.
- Preferences: Language selection and UI preferences.
Our public booking pages use Google Analytics, which sets analytics cookies to help us understand site usage. Our website, guwy.com, does not use analytics and does not set analytics cookies. Our client panel and consent form pages do not load any analytics. We do not use advertising cookies.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data (subject to legal retention requirements).
- Object to or restrict processing of your data.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time for consent-based processing.
- Opt out of SMS communications by replying STOP.
To exercise any of these rights, contact us at privacy@guwy.com.
10. California Privacy Rights (CCPA)
California residents have additional rights under the CCPA:
- Right to know what personal information is collected, used, and shared.
- Right to delete personal information.
- Right to opt out of the sale of personal information (we do not sell personal information).
- Right to non-discrimination for exercising privacy rights.
11. Children's Privacy
Our Service is not directed to children under 16. We do not knowingly collect personal information from children under 16. If we discover that a child under 16 has provided us with personal information, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at privacy@guwy.com.
12. International Data Transfers
Our servers are located in the United States and Canada. If you are accessing our Service from outside these countries, please be aware that your data will be transferred to and processed in these jurisdictions.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
14. HIPAA
Guwy is not a HIPAA covered entity. We do not enter into Business Associate Agreements, and the Service is not offered or configured for creating, receiving, maintaining, or transmitting Protected Health Information on behalf of a covered entity.
You may not use the Service to process Protected Health Information. Guwy does not determine whether your practice is a covered entity; that determination, and the choice of tools suited to your obligations, are yours. If we learn the Service is being used inconsistently with this section, we may suspend or terminate the account.
This section does not limit our other commitments. Health-related information entered into the Service remains protected by this Policy and subject to applicable consumer-protection and state privacy laws, including state consumer health data laws.
15. Contact Us
If you have questions about this Privacy Policy, contact us at:
Guwy Software LLC
Email: privacy@guwy.com
Address: 1276 Industrial Blvd, Suite 2, Gainesville, GA 30501
Website: guwy.com
