Privacy Policy

Effective Date: January 25, 2026 · Last Updated: September 6, 2026

1. Introduction

HiLucy ("we," "our," or "us") operates a SaaS platform for hospitality and short-term rental management, including an AI-powered concierge service. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our services.

This policy applies to:

  • Hotel and property guests using our AI concierge
  • Property managers and staff using our platform
  • Visitors to our website

2. Data Controller

HiLucy
10205 S Komensky Avenue
Oak Lawn, IL 60453, USA

Contact for Privacy Inquiries: [email protected]

For EU residents: [email protected]

3. Personal Data We Collect

3.1 Information You Provide

CategoryExamplesWhen Collected
Identity DataName, nationality, date of birth, ID document detailsGuest check-in
Contact DataPhone number, email address, WhatsApp IDRegistration, check-in
Location DataCountry/city of residence, shared locationCheck-in, chat
Communication DataMessages, requests, preferencesAI chat interactions
Payment DataCard details (via Stripe), billing addressService purchases
Booking DataCheck-in/out dates, room type, guest countReservations

3.2 Information Collected Automatically

CategoryExamplesPurpose
Technical DataIP address, browser type, device infoSecurity, analytics
Usage DataPages visited, features used, timestampsService improvement
Cookie DataSession cookies, preference cookiesAuthentication, UX
Prospect ActivityPages viewed and sign-ins by business prospects, via the hl_pid cookie (see 9.1)Sales follow-up

4. How We Use Your Data

PurposeLegal Basis (GDPR)
Provide AI concierge serviceContract performance
Process guest check-insContract performance
Process paymentsContract performance
Send service notificationsLegitimate interest
Improve servicesLegitimate interest
Comply with legal obligationsLegal obligation
Send marketing communicationsConsent

5. Data Sharing

We share your data with the following categories of service providers:

ProviderData SharedPurpose
OpenAIConversation contentAI processing
Meta (WhatsApp)Phone, messagesMessaging
StripePayment detailsPayment processing
Google CloudLocation, languageTranslation, maps
TwilioPhone number, message contentSMS delivery

All subprocessors are bound by Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs) where applicable.

5.1 Mobile Information and SMS

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

We use your mobile number solely to deliver the messages described in our Terms of Service — one-time verification codes and notifications about your own stay or account. We do not sell mobile numbers, and we do not use them for marketing.

6. Data Retention

Data TypeRetention Period
AI conversation history30 days
Guest check-in dataBooking duration + 30 days
User account dataUntil account deletion
Payment records7 years (legal requirement)
Booking records2 years post-checkout
Technical logs30 days

7. Your Rights

GDPR Rights (EU/EEA Residents)

  • Access: request a copy of your personal data
  • Rectification: correct inaccurate or incomplete data
  • Erasure: request deletion of your data
  • Restriction: limit how we process your data
  • Portability: receive your data in a structured format
  • Object: object to processing based on legitimate interest
  • Automated Decision-Making: request human review

CCPA Rights (California Residents)

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of the sale of personal information
  • Right to non-discrimination for exercising privacy rights

To exercise your rights, email [email protected]. We will respond within 30 days (GDPR) or 45 days (CCPA).

8. Security

We protect your data through:

  • TLS 1.2+ encryption for all data in transit
  • Encryption at rest for stored consumer data
  • Multi-factor authentication for all admin access
  • Role-based access controls
  • Regular security monitoring and logging
  • PCI-DSS compliance for payment processing (via Stripe)

9. Cookies

We use essential cookies for authentication and session management. For analytics and marketing cookies, we obtain your consent before setting them. You can manage cookie preferences through your browser settings.

9.1 The hl_pid cookie (business prospects)

If you run a property and you click a link in a message we sent you, we set a first-party cookie called hl_pid in your browser. It holds a reference to the property listing the link was about and to the message itself. It is signed so it cannot be edited, and it cannot be read by scripts on the page.

Its only purpose is sales follow-up: it lets our team see that you came back to look at the pricing or demo page, so that when we contact you the conversation is about something you were actually interested in. It records the page you were on, not what you typed, and it never records your IP address or any payment details.

This applies to business prospects only. It is never set for hotel guests using the service, and it plays no part in guest bookings, check-in or messaging.

The cookie lasts 90 days from your most recent click. To stop it: use the unsubscribe link in any message we sent you, reply STOP, or email [email protected]. Any of these stops the collection itself, not just what we display. You can also delete the cookie in your browser at any time.

We rely on legitimate interest for this (Article 6(1)(f) GDPR): you are a business contact who has already engaged with us, the data is limited to business context, and you can stop it at any time.

10. AI and Automated Processing

Our AI concierge (Lucy) uses OpenAI GPT-4o-mini to process your messages. AI-assisted routing and recommendations are not legally significant automated decisions. You may request human review of any AI interaction at any time.

11. Google User Data

11.1 When this section applies

This section applies only if you choose to connect a Google account to HiLucy. Connecting is optional. If you never connect one, HiLucy never receives any data from your Google account and nothing in this section applies to you.

Two features can use a connected Google account: scheduling video meetings from the HiLucy CRM, and keeping rental bookings in step with a calendar. Each connection is made by one person, for one account, and can be undone at any time (see 11.8).

11.2 What we access

When you connect a Google account, HiLucy requests two permissions:

https://www.googleapis.com/auth/calendar.readonly

Google grants this permission read access to your calendars. HiLucy's use of it is limited to three things: the list of calendars on your account (their names and identifiers) so you can choose which one to use; the email address of the account you connected, so we can show you which account is in use; and free/busy information — the start and end times of periods when you are busy, within a window we ask about. Free/busy responses contain times only. They do not contain event titles, descriptions, locations, attachments or attendees, and HiLucy does not request the contents of your calendar events.

https://www.googleapis.com/auth/calendar.events

This permission lets HiLucy create, update and delete calendar events. HiLucy uses it only for events it creates itself: meetings you schedule through the HiLucy CRM, and events representing rental bookings made through HiLucy. We record the identifier Google returns for each event we create, and we act only on those identifiers. HiLucy does not modify or delete events it did not create.

11.3 How we use it

  • Confirming the connection. We display the connected account's address so you can see which Google account HiLucy is using.
  • Choosing a calendar. We show your calendar list so you can pick which calendar HiLucy writes to.
  • Offering meeting times. We read free/busy for the selected calendar so the scheduling screen does not offer a time you are already booked.
  • Creating meetings. When you schedule a meeting, we create a calendar event with a Google Meet link and, if you ask us to, send invitations to the people you invited.
  • Keeping bookings in step. For rental bookings, we create events for the agreed times and update or remove them when the booking changes or is cancelled.

We do not use Google user data for advertising, for building profiles, to train machine-learning or AI models, or for any purpose other than providing these features to you.

11.4 What we store, and for how long

  • A refresh token issued by Google, to keep the connection working without asking you to sign in again — until you disconnect or revoke access.
  • A short-lived access token, to make the individual API calls — cached under one hour, then discarded.
  • The identifier of the calendar you selected, so we write to the calendar you chose — until you disconnect or change it.
  • Identifiers of events HiLucy created, so we can update or cancel the right event later — kept with the related meeting or booking record.
  • Timestamps of the last successful and last failed connection, so we can tell you when a connection has stopped working — until you disconnect.

We do not copy your calendar into our systems. We do not store your events, their contents, or your free/busy history. Free/busy data is requested when a scheduling screen needs it and is used to render that screen.

11.5 How we share it

We do not sell Google user data, and we do not transfer it to third parties for advertising or any independent purpose. It is disclosed only:

  • to Google, in the course of making the API requests described above;
  • to the infrastructure providers that host HiLucy and act on our instructions as service providers;
  • where we are required to by law, or to establish or defend a legal claim.

Events HiLucy creates on your calendar may be visible to people you invite to them, and to anyone you have separately shared that calendar with. That sharing is controlled by you in Google Calendar, not by HiLucy.

11.6 Limited Use

HiLucy's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

11.7 How we protect it

Data passes between HiLucy and Google over encrypted connections. Tokens are held in our production database, access to which is restricted to the systems and staff that require it. Each connection is scoped to the person or property that created it, so one customer's connection cannot be used to reach another's calendar.

11.8 How to withdraw access and delete the data

You can end the connection in either of two ways, and either is sufficient:

  • In HiLucy — open the calendar settings for the connection and choose Disconnect. We delete the stored refresh token and discard any cached access token immediately.
  • In your Google account — visit myaccount.google.com/permissions, select HiLucy and choose Remove access. This revokes our tokens at Google.

Disconnecting does not delete calendar events HiLucy already created; those remain yours, on your calendar, and you can delete them in Google Calendar. To ask us to delete the identifiers we retained for those events, or any other data described in this section, contact us using the details below and we will do so.

11.9 Contact

Questions about this section, or requests to delete data covered by it, can be sent to [email protected]. We respond within 30 days.

12. Children's Privacy

Our services are not directed to individuals under 16 years of age. We do not knowingly collect data from children.

13. Changes to This Policy

We will notify you of material changes via email or in-app notice at least 30 days before they take effect.

14. Contact Us

Privacy inquiries: [email protected]
General support: [email protected]

© 2026 HiLucy. All rights reserved.Terms of Service