Legal
Who we are
Intilly is a software-as-a-service platform operated by [FOUNDER: legal entity name, e.g. “Intilly LLC”] (“Intilly”, “we”, “us”). Our registered address is [FOUNDER: business address]. You can reach us at privacy@intilly.com for any data-related question.
What this policy covers
This policy explains what personal data we collect when you use intilly.com or my.intilly.com, why we collect it, how long we keep it, and the rights you have over it. It applies to business owners who sign up for an Intilly account, the staff they invite, and the end clients those businesses book through Intilly.
What we collect
- Account data. Name, email, phone, business name, country, currency, hashed password.
- Operational data you enter. Clients, appointments, services, sale records, staff schedules, inventory. This is your business data; we store it on your behalf.
- Billing data. Stripe stores card details directly. We never see or store full card numbers; we receive only a Stripe customer ID, last4, and subscription status.
- Usage data. IP address, browser type, page views, request logs. Retained 90 days for security and debugging.
- Email logs. Subject lines, recipient, send status (delivered/bounced) for transactional mail. No body content is logged.
Why we collect it
To run your account, send transactional email (booking confirmations, password resets, receipts), bill your subscription, prevent abuse, and improve the product. We do not sell personal data and we do not use it for cross-context behavioural advertising.
Sub-processors
We share data only with vendors required to deliver the service:
- Stripe (billing) — US, stripe.com/privacy
- AWS SES (transactional email) — US, region us-east-1
- Hetzner Online GmbH (hosting) — data stored in Ashburn, VA, US
- Telegram (optional client notifications, opt-in per company) — Telegram FZ-LLC
- DeepSeek (AI concierge feature, optional) — provider of the LLM that powers automated client replies. Conversations sent to DeepSeek are not used by them for model training per their API policy.
We do not transfer data outside these processors.
Your rights
- Access / export. Request a copy of your data via your dashboard (Account → Export data) or by emailing privacy@intilly.com.
- Deletion. Delete your account at Account → Delete account. Backups are purged within 30 days.
- Correction. Edit your account information at any time in the dashboard.
- GDPR (EEA / UK). You have the rights of access, rectification, erasure, restriction, portability, and objection. Lawful basis: contract performance and legitimate interest.
- CCPA (California). California residents may request what categories we hold and ask for deletion. We do not “sell” personal information as defined by CCPA.
To exercise any right, email privacy@intilly.com from the address on your account. We respond within 30 days.
Cookies
intilly.com is a static marketing site and sets no cookies of its own. my.intilly.com sets a session cookie (required for authentication) and a CSRF cookie. These are strictly necessary; no consent banner is required for them.
Data retention
Active account data is retained for as long as your subscription is active. After cancellation we keep records for 12 months for invoice/tax compliance, then delete. You can request earlier deletion under “Your rights”.
Security
TLS 1.2+ in transit. Passwords hashed with PBKDF2. Database backups encrypted at rest. Production access is SSH-key-only with two-factor on the account that holds the key.
Changes
We will email account holders at least 14 days before any material change to this policy. Last updated 2026-04-30.
Contact
privacy@intilly.com — [FOUNDER: business address]