Effective Date: January 25, 2026 · Last Updated: September 6, 2026
HiLucy ("we," "our," or "us") operates a SaaS platform for hospitality and short-term rental management, including an AI-powered concierge service. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our services.
This policy applies to:
HiLucy
10205 S Komensky Avenue
Oak Lawn, IL 60453, USA
Contact for Privacy Inquiries: [email protected]
For EU residents: [email protected]
| Category | Examples | When Collected |
|---|---|---|
| Identity Data | Name, nationality, date of birth, ID document details | Guest check-in |
| Contact Data | Phone number, email address, WhatsApp ID | Registration, check-in |
| Location Data | Country/city of residence, shared location | Check-in, chat |
| Communication Data | Messages, requests, preferences | AI chat interactions |
| Payment Data | Card details (via Stripe), billing address | Service purchases |
| Booking Data | Check-in/out dates, room type, guest count | Reservations |
| Category | Examples | Purpose |
|---|---|---|
| Technical Data | IP address, browser type, device info | Security, analytics |
| Usage Data | Pages visited, features used, timestamps | Service improvement |
| Cookie Data | Session cookies, preference cookies | Authentication, UX |
| Prospect Activity | Pages viewed and sign-ins by business prospects, via the hl_pid cookie (see 9.1) | Sales follow-up |
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide AI concierge service | Contract performance |
| Process guest check-ins | Contract performance |
| Process payments | Contract performance |
| Send service notifications | Legitimate interest |
| Improve services | Legitimate interest |
| Comply with legal obligations | Legal obligation |
| Send marketing communications | Consent |
We share your data with the following categories of service providers:
| Provider | Data Shared | Purpose |
|---|---|---|
| OpenAI | Conversation content | AI processing |
| Meta (WhatsApp) | Phone, messages | Messaging |
| Stripe | Payment details | Payment processing |
| Google Cloud | Location, language | Translation, maps |
| Twilio | Phone number, message content | SMS delivery |
All subprocessors are bound by Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs) where applicable.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We use your mobile number solely to deliver the messages described in our Terms of Service — one-time verification codes and notifications about your own stay or account. We do not sell mobile numbers, and we do not use them for marketing.
| Data Type | Retention Period |
|---|---|
| AI conversation history | 30 days |
| Guest check-in data | Booking duration + 30 days |
| User account data | Until account deletion |
| Payment records | 7 years (legal requirement) |
| Booking records | 2 years post-checkout |
| Technical logs | 30 days |
To exercise your rights, email [email protected]. We will respond within 30 days (GDPR) or 45 days (CCPA).
We protect your data through:
We use essential cookies for authentication and session management. For analytics and marketing cookies, we obtain your consent before setting them. You can manage cookie preferences through your browser settings.
hl_pid cookie (business prospects)If you run a property and you click a link in a message we sent you, we set a first-party cookie called hl_pid in your browser. It holds a reference to the property listing the link was about and to the message itself. It is signed so it cannot be edited, and it cannot be read by scripts on the page.
Its only purpose is sales follow-up: it lets our team see that you came back to look at the pricing or demo page, so that when we contact you the conversation is about something you were actually interested in. It records the page you were on, not what you typed, and it never records your IP address or any payment details.
This applies to business prospects only. It is never set for hotel guests using the service, and it plays no part in guest bookings, check-in or messaging.
The cookie lasts 90 days from your most recent click. To stop it: use the unsubscribe link in any message we sent you, reply STOP, or email [email protected]. Any of these stops the collection itself, not just what we display. You can also delete the cookie in your browser at any time.
We rely on legitimate interest for this (Article 6(1)(f) GDPR): you are a business contact who has already engaged with us, the data is limited to business context, and you can stop it at any time.
Our AI concierge (Lucy) uses OpenAI GPT-4o-mini to process your messages. AI-assisted routing and recommendations are not legally significant automated decisions. You may request human review of any AI interaction at any time.
This section applies only if you choose to connect a Google account to HiLucy. Connecting is optional. If you never connect one, HiLucy never receives any data from your Google account and nothing in this section applies to you.
Two features can use a connected Google account: scheduling video meetings from the HiLucy CRM, and keeping rental bookings in step with a calendar. Each connection is made by one person, for one account, and can be undone at any time (see 11.8).
When you connect a Google account, HiLucy requests two permissions:
https://www.googleapis.com/auth/calendar.readonly
Google grants this permission read access to your calendars. HiLucy's use of it is limited to three things: the list of calendars on your account (their names and identifiers) so you can choose which one to use; the email address of the account you connected, so we can show you which account is in use; and free/busy information — the start and end times of periods when you are busy, within a window we ask about. Free/busy responses contain times only. They do not contain event titles, descriptions, locations, attachments or attendees, and HiLucy does not request the contents of your calendar events.
https://www.googleapis.com/auth/calendar.events
This permission lets HiLucy create, update and delete calendar events. HiLucy uses it only for events it creates itself: meetings you schedule through the HiLucy CRM, and events representing rental bookings made through HiLucy. We record the identifier Google returns for each event we create, and we act only on those identifiers. HiLucy does not modify or delete events it did not create.
We do not use Google user data for advertising, for building profiles, to train machine-learning or AI models, or for any purpose other than providing these features to you.
We do not copy your calendar into our systems. We do not store your events, their contents, or your free/busy history. Free/busy data is requested when a scheduling screen needs it and is used to render that screen.
We do not sell Google user data, and we do not transfer it to third parties for advertising or any independent purpose. It is disclosed only:
Events HiLucy creates on your calendar may be visible to people you invite to them, and to anyone you have separately shared that calendar with. That sharing is controlled by you in Google Calendar, not by HiLucy.
HiLucy's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data passes between HiLucy and Google over encrypted connections. Tokens are held in our production database, access to which is restricted to the systems and staff that require it. Each connection is scoped to the person or property that created it, so one customer's connection cannot be used to reach another's calendar.
You can end the connection in either of two ways, and either is sufficient:
Disconnecting does not delete calendar events HiLucy already created; those remain yours, on your calendar, and you can delete them in Google Calendar. To ask us to delete the identifiers we retained for those events, or any other data described in this section, contact us using the details below and we will do so.
Questions about this section, or requests to delete data covered by it, can be sent to [email protected]. We respond within 30 days.
Our services are not directed to individuals under 16 years of age. We do not knowingly collect data from children.
We will notify you of material changes via email or in-app notice at least 30 days before they take effect.
Privacy inquiries: [email protected]
General support: [email protected]