Privacy Policy
Effective August 19, 2026
1. Who we are
EveryHello is operated by DueIQ Corp, a Florida corporation (“DueIQ”, “we”, “us”, “our”). This policy explains what information we collect in connection with the EveryHello website and service, how we use it, who we share it with, and the choices you have. Questions go to contact@everyhello.ai.
2. Who this policy covers
This policy covers three groups of people:
- Visitors to www.everyhello.ai.
- Clients — salons and other businesses that subscribe to EveryHello, and the individuals who administer those accounts.
- Customers — people who call or message a Client’s business and are answered by EveryHello.
For Customer conversations, the Client is the party that decides why and how the information is used, and we act as its service provider, processing that information on the Client’s instructions. If you are a Customer, please also review the privacy notice of the salon you contacted.
3. Information we collect
- Contact and account information — name, business name, email address, phone number, business address and role.
- Call recordings and transcripts — the audio and text of calls handled by our voice agent, together with call metadata such as time, duration, the phone number involved and the outcome of the call.
- Message content — the content of WhatsApp and comparable messaging conversations we handle on a Client’s behalf, together with message metadata.
- Booking details — the service requested, the staff member, the date and time, cancellation and rescheduling history, and the customer contact details needed to hold the appointment.
- Business configuration — the services, prices, durations, opening hours, staff, policies and frequently asked questions a Client gives us so the agent can answer accurately.
- Billing information — plan, invoices and payment status. Card details are entered directly with Stripe; we never receive or store full payment card numbers.
- Website and technical data — IP address, browser and device type, pages viewed, and similar server log information.
We do not intentionally collect sensitive categories of personal information, such as health, biometric or financial account data, and we ask that you do not share them with the agent.
4. How we use information
- To answer calls and messages, quote services and prices, and create, change or cancel bookings on a Client’s behalf.
- To operate, secure, monitor, troubleshoot and improve the service.
- To bill Clients and administer subscriptions.
- To send transactional and service communications, such as setup steps, incident notices and billing messages.
- To comply with legal obligations and to establish, exercise or defend legal claims.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We configure our AI vendors so that Client and Customer content is not used to train their general-purpose models.
5. Calls, recordings and AI disclosure
Our voice agent identifies itself as an automated AI assistant and gives a recording notice at the start of every call. Florida is an all-party consent state for the recording of communications; by continuing the call after that notice, a caller consents to the call being recorded and transcribed. A caller who does not wish to be recorded can end the call, or ask to be transferred or called back by a person where the Client offers that option. Clients are responsible for ensuring the disclosure is enabled and accurate on every phone number they use with the service.
6. Messaging and opt-outs
Messages we send on a Client’s behalf are transactional or utility in nature — replies to inbound questions, booking confirmations, reminders and changes. We do not send marketing broadcasts. Replying STOP, or an equivalent opt-out, at any time stops further messages from that business; opt-outs are honored immediately and recorded. Messaging through WhatsApp is also governed by Meta’s WhatsApp Business Messaging Policy.
7. Service providers and subprocessors
We share information with the providers below so they can perform services for us, under contracts that limit their use of it. We keep this list current and update it when a provider changes.
| Provider | What it does for us | Information it may process |
|---|---|---|
| Vapi | Voice agent orchestration and telephony | Call audio, transcripts, call metadata |
| Meta Platforms (WhatsApp Business Cloud API) | Delivering and receiving WhatsApp messages | Message content, phone numbers, delivery status |
| Square | Bookings, service catalog and customer records for salons on Square | Appointments, services and prices, customer contact details |
| Stripe | Subscription billing and payment processing | Client billing contact, plan and payment status |
| Supabase | Application database and authentication | Stored account, configuration, conversation and booking records |
| Railway | Application and worker hosting | Data in transit through the service, server logs |
| Business email and productivity | Correspondence with us |
8. When we disclose information
- To the service providers listed above, so they can perform the service.
- To a Client, for the conversations, calls and bookings belonging to that Client.
- To our professional advisers, such as lawyers and accountants, under confidentiality.
- In connection with a merger, financing, acquisition or sale of assets, with notice where the law requires it.
- Where required by law or valid legal process, or where we reasonably believe disclosure is necessary to protect rights, safety or the integrity of the service.
9. How long we keep information
We keep account and billing records for the life of the account and afterwards for as long as tax, accounting and legal obligations require. We keep call recordings, transcripts, message logs and booking records for as long as the Client’s account is active, unless the Client asks us for a shorter retention period. When an account ends, we delete or de-identify that content within 90 days, except for backups, which expire on their own cycle. Clients may request deletion of specific records at any time.
10. Security
We protect information in transit with TLS and at rest with encryption. Third-party access credentials are encrypted at the application layer. Row-level access controls scope every record to a single Client, so one salon’s data is not reachable by another. Access by our personnel is limited to what their role requires. No system is perfectly secure, and we cannot guarantee absolute security.
11. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to opt out of certain processing, and to withdraw consent. Email contact@everyhello.ai and we will respond within the period the applicable law requires. If you are a Customer of a salon that uses EveryHello, we will normally refer your request to that salon, which decides how the information is used, and we will help it respond. We will not discriminate against you for exercising these rights.
12. Children
EveryHello is a tool for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with information, email us and we will delete it.
13. Where we operate
We operate in the United States and store information there. If you contact us or use the service from another country, you are sending your information to the United States, where privacy laws may differ from those where you live.
14. Other sites and services
Our site and the service may link to services we do not control, such as Square, Meta or Stripe. Their privacy practices are their own, and this policy does not cover them.
15. Changes to this policy
We may update this policy. When we do, we will post the revised version here with a new effective date, and we will notify Clients by email of changes that materially affect them.
16. Contact
DueIQ Corp, Florida, United States — contact@everyhello.ai.