Privacy Policy
This Privacy Policy explains how Acevestor Software Inc. ("Acevestor," "Askie," "we," "us," or "our") collects, uses, shares, retains, and protects personal information.
Effective Date: July 17, 2026 · Last Updated: July 22, 2026
This policy applies when you visit our website, use Askie, connect a third-party service to Askie, or communicate with a business that uses Askie. It is a notice about our privacy practices and is not a contract or a substitute for consent where consent is required.
1.Who We Are
Acevestor Software Inc. is incorporated in British Columbia, Canada. We operate Askie, a software-as-a-service platform for salons, spas, and other personal-care businesses.
Our Privacy Officer is Mayank Singh. Privacy questions, requests, and complaints may be sent to privacy@getaskie.com.
2.Who This Policy Covers and Our Role
Askie serves three main groups:
- Subscribers: businesses that subscribe to Askie and decide how the platform is used for their operations.
- Staff Users: owners, employees, and contractors authorized to use a Subscriber's Askie account.
- Clients: individuals who book, receive services from, or communicate with a Subscriber.
A Subscriber generally determines why and how its Clients' personal information is collected and used. For that information, the Subscriber is the controller or responsible organization, and Askie processes the information on the Subscriber's behalf as its service provider or processor. Askie is independently responsible for information used to administer Subscriber accounts, billing, security, legal compliance, and our own website and business operations.
Clients should normally direct privacy requests to the business they booked with or communicated with. We assist Subscribers in responding to those requests and will handle requests about information for which Askie is independently responsible.
3.Information We Collect
3.1 Subscriber and Staff Information
We may collect:
- Name, email address, phone number, role, and account identifiers
- Authentication credentials, with passwords stored in hashed form
- Business name, address, category, contact details, hours, and preferences
- Account activity, permissions, settings, and support communications
3.2 Client, Appointment, and Service Information
Subscribers may enter or generate information about their Clients, including:
- Name, email address, and phone number
- Appointments, cancellations, services, staff assignments, and history
- Service preferences and client notes
- Notes about allergies, sensitivities, accessibility needs, or other health-related details that a Client or Subscriber chooses to provide
Subscribers are responsible for collecting only information they need, obtaining any required consent, limiting access to sensitive notes, and complying with laws applicable to their services.
3.3 WhatsApp and SMS Messaging Information
When messaging features are used, we may process:
- Sender and recipient phone numbers
- Outbound and inbound message content and approved template parameters
- Quick-reply selections, including confirm, reschedule, or cancel actions
- Message, conversation, and provider identifiers
- Sent, delivered, read, failed, and fallback status information
- Message timestamps, channel, direction, and staff sender information
- Messaging consent, opt-out, capability, and communication-preference records
Message content and related history may be displayed to authorized users in the Subscriber's Askie inbox so the business can continue the conversation and serve the Client.
3.4 WhatsApp Business Connection Information
When a Subscriber connects WhatsApp through Meta's Embedded Signup, we may process its WhatsApp Business Account ID, business phone number and phone-number ID, display name, template names and approval status, connection status, and authorization credentials needed to operate the integration. Integration tokens and security credentials are restricted to server-side access.
For an Askie-provisioned number, a short-lived voice verification call may be received and transcribed to complete setup. Verification codes, transcriptions, and recording references are temporary and are deleted promptly after the verification process is completed.
3.5 Payment Information
Stripe processes subscription payments. We do not store full payment-card or bank account numbers. We retain billing metadata such as the subscription plan, transaction status, invoices, and Stripe customer identifier.
3.6 Device, Usage, and Security Information
We may collect:
- Features accessed, pages visited, and actions taken
- Device type, browser, operating system, and application version
- IP address, approximate location, session, and security-event information
- Diagnostic information associated with errors or service failures
3.7 Website Forms, reCAPTCHA, and Communications
If you submit a form or contact us, we collect the information you provide and a record of the communication. We use Google reCAPTCHA Enterprise to prevent automated abuse. Google may process information such as IP address and browser behaviour under its Privacy Policy.
4.How We Collect Information
We collect information:
- Directly from you, including through registration, booking, account settings, forms, support requests, and messages
- From Subscribers, when a business or its staff enters or imports Client and appointment information
- From connected services, including Meta/WhatsApp, Twilio, Stripe, Firebase Authentication, and other integrations you authorize
- Automatically, through cookies, logs, diagnostics, and security technologies when you use our website or application
5.How We Use Information
We use personal information to:
- Provide, operate, maintain, and support Askie
- Manage accounts, authentication, permissions, and subscriptions
- Schedule, confirm, remind, reschedule, and cancel appointments
- Send, receive, display, and maintain business communications
- Route a failed or unavailable WhatsApp message to an authorized fallback channel
- Process payments and maintain billing records
- Respond to support, privacy, and security requests
- Diagnose errors, prevent fraud and abuse, and protect accounts and the platform
- Understand use of our platform and improve features, excluding restricted WhatsApp data as described below
- Comply with law, enforce our agreements, and establish or defend legal claims
- Send product or marketing emails to Subscribers where permitted; Subscribers may unsubscribe at any time
6.WhatsApp Business Messaging
Askie enables Subscribers to connect a WhatsApp Business Account and communicate with their Clients using the WhatsApp Business Platform. Askie sends information necessary to deliver a message to Meta and WhatsApp and receives inbound messages, delivery events, template events, and related messaging information from them.
Askie processes WhatsApp information on the relevant Subscriber's instructions to communicate with the same Client, maintain conversation history, manage appointments, track delivery, provide authorized channel fallback, and support and secure the messaging service.
Askie does not use WhatsApp message content or WhatsApp-derived Client data to:
- Advertise or market Askie directly to a Subscriber's Clients
- Build consumer profiles or retarget people on or off WhatsApp
- Sell, rent, or license personal information
- Train general-purpose artificial intelligence models
- Combine it with unrelated third-party data for Askie's own purposes
WhatsApp messages should not include payment-card numbers, government identifiers, detailed medical records, or other information that is not appropriate for a business messaging channel. Clients and Subscribers should use a more suitable channel when sensitive information must be exchanged.
7.Consent and Other Grounds for Processing
Depending on the context and applicable law, we process information with consent, to provide contracted services, for reasonable business purposes such as security and service improvement, or to comply with legal obligations. Where we rely on consent, it may be withdrawn subject to legal or contractual restrictions and reasonable notice.
Subscribers determine the appropriate legal basis for Client information they process using Askie. Before initiating WhatsApp or SMS communications, Subscribers must provide required notices, obtain any required permission, and accurately identify the business and types of messages the Client should expect.
Our privacy practices are designed with reference to laws applicable to our activities, which may include British Columbia's Personal Information Protection Actand Canada's Personal Information Protection and Electronic Documents Act. Additional rights may apply based on where an individual lives.
8.Service Providers and Connected Platforms
We use service providers to operate Askie. They may process information only as needed to provide their services to us or as otherwise permitted by their terms and applicable law.
| Provider | Purpose | Privacy Information |
|---|---|---|
| Google Cloud and Firebase | Authentication, application infrastructure, database storage, customer records, and message history | Google Privacy Policy |
| Meta and WhatsApp | WhatsApp Business onboarding, account management, templates, message delivery, inbound messages, and delivery events | Meta Privacy Policy |
| Twilio | Telephone-number provisioning, voice verification, SMS delivery, and SMS fallback | Twilio Privacy Notice |
| Stripe | Payment processing, subscription billing, and invoicing | Stripe Privacy Policy |
| Mailgun | Transactional and permitted marketing email delivery | Mailgun Privacy Policy |
| Sentry | Application error monitoring, security diagnostics, and troubleshooting | Sentry Privacy Policy |
| Google reCAPTCHA | Bot, fraud, and automated-abuse prevention | Google Privacy Policy |
9.When We Disclose Information
We may disclose personal information:
- To the relevant Subscriber and its authorized Staff Users, so they can operate their business and serve their Clients
- To service providers and connected platforms, as described above
- At your direction or with consent, including when an integration is connected
- For legal and safety reasons, when reasonably necessary to comply with law, lawful process, protect rights or safety, investigate misuse, or enforce agreements
- In a business transaction, such as a financing, merger, reorganization, acquisition, or sale of assets, subject to appropriate safeguards
We do not sell or rent personal information and do not disclose Client information to third parties for their own direct marketing.
Government and Law Enforcement Requests
Where we receive a request from a public authority, court, or law enforcement agency for personal information, we review the request to confirm it has a valid legal basis before responding. Where permitted by law, we disclose only the minimum information necessary to satisfy the specific request. We keep records of such requests and our responses to them.
10.Subscriber Responsibilities for Client Data
Subscribers are responsible for:
- Collecting only Client information reasonably needed for their services
- Providing required privacy and messaging notices
- Obtaining and recording required consent for WhatsApp, SMS, and marketing communications
- Separating service-message permission from marketing permission where required
- Keeping Client information accurate and appropriately secured
- Responding to Client privacy requests, with Askie's assistance where appropriate
- Restricting access to sensitive client notes
- Complying with applicable laws and the policies of connected messaging platforms
Clients may opt out of WhatsApp communications by replying STOP or making another clear request to the business. Subscribers must promptly honour requests made on or off WhatsApp. A WhatsApp opt-out will not authorize Askie or the Subscriber to move the same communication to another channel unless that channel is separately authorized.
11.Retention and Deletion
- Subscriber accounts
- We retain account and business information while the account is active and for up to 12 months after cancellation to support reactivation, export, dispute resolution, security, and orderly deletion.
- Messages and conversation metadata
- WhatsApp and SMS message content, message status, and related conversation metadata are generally retained for up to 12 months from the communication date.
- Consent and opt-out records
- Messaging consent, opt-out, and compliance records may be retained for the Subscriber relationship and for at least 12 months afterward, or longer where required by law or platform rules.
- Integration credentials
- WhatsApp authorization credentials are retained only while needed to operate the connection and are deleted or invalidated when the integration is disconnected, subject to technical and legal requirements.
- Temporary verification information
- Voice verification codes, transcriptions, and recording references are deleted promptly after verification is completed or the short-lived setup session expires.
- Billing, security, and legal records
- We retain these for the period reasonably required for tax, accounting, fraud prevention, security, dispute resolution, or other legal obligations.
- Backups
- Information deleted from active systems may remain temporarily in encrypted backups until those backups are securely overwritten under our normal backup cycle.
We may delete or de-identify information earlier when it is no longer needed. We may retain it longer when required by law, a litigation hold, an active security matter, or a valid instruction from the responsible Subscriber.
12.Your Privacy Rights
Depending on your location and our role, you may have the right to:
- Request access to personal information we hold about you
- Request correction of inaccurate or incomplete information
- Withdraw consent where processing is based on consent
- Request deletion, subject to legal and operational retention requirements
- Request information about how your information has been used or disclosed
- Object to or restrict certain processing where applicable
- Receive portable information where required by law
- Make a complaint about our privacy practices without retaliation
Send requests to privacy@getaskie.com. We may need to verify your identity and authority before acting. If Askie holds the information solely for a Subscriber, we may refer the request to that Subscriber or consult it before responding. We aim to respond within 30 days, subject to permitted extensions.
See our Data Deletion Instructions for request steps and information about disconnecting WhatsApp.
13.Cookies and Similar Technologies
We use cookies and similar technologies to:
- Maintain authenticated sessions
- Remember preferences
- Understand use of our website and application
- Detect fraud, bots, and abuse
Browser controls may allow you to block or delete cookies. Disabling required cookies may prevent parts of Askie from working correctly.
14.Security
We use administrative, technical, and physical safeguards appropriate to the nature of the information, including encryption in transit, encryption at rest where supported, tenant-based access controls, server-side protection for integration credentials, monitoring, and restricted production access.
No system is completely secure. If you believe an account or communication has been compromised, contact privacy@getaskie.com promptly.
15.International Processing
Askie's primary customer records and message history are hosted using Google Cloud and Firebase infrastructure in the United States, currently in the us-central1 region in Iowa. Meta, Twilio, Mailgun, Stripe, Sentry, Google, and their subprocessors may process information in the United States and other jurisdictions where they operate.
Information processed outside your province or country may be subject to the laws of that jurisdiction and lawful access by courts, law enforcement, or national-security authorities. We remain responsible for personal information under our control and use contractual and other measures designed to require appropriate protection by service providers.
16.Children's Privacy
Askie is not intended for use by children under 13, and Subscribers must not knowingly submit personal information about children under 13 to Askie. If we learn that such information was submitted, contact us so we can work with the responsible Subscriber to delete it as appropriate.
17.Changes to This Policy
We may update this policy as our services, providers, or legal obligations change. We will post the revised policy here and update the date above. Where required, we will provide additional notice or obtain consent before a material change takes effect.
18.Contact and Complaints
Questions, privacy requests, and complaints may be directed to:
Mayank Singh, Privacy OfficerAcevestor Software Inc.
British Columbia, Canada
Email: privacy@getaskie.com
Website: https://getaskie.com
Please describe the concern and identify the relevant Subscriber, if applicable. We will investigate and explain the outcome. You may also have the right to contact the privacy regulator responsible for your jurisdiction.