Privacy Policy
Last updated: August 2026
Overview
Clinqly helps service businesses capture and manage enquiries across their website widget, WhatsApp, Instagram and Facebook Messenger, and, where a business adds the optional Voice add-on, phone calls diverted to a dedicated number. This policy describes how we handle personal data for the businesses that use Clinqly, their team members, and the customers who contact those businesses through it.
For enquiry and customer data handled inside a business's account, that business decides what is collected and why, and Clinqlyprocesses it on the business's behalf. For our own website, accounts and billing, Clinqly decides how data is used. If you are a customer of a business that uses Clinqly, that business is your first point of contact for questions about your data; we support them in answering.
Data we collect
- Account details for the business and its team (names, email addresses, organisation and location names, roles)
- Enquiry data from the website widget, WhatsApp, Instagram and Facebook Messenger: name, email, phone, the service asked about, qualification answers, conversation transcripts, and the enquiry priority Clinqly assigns
- Appointment data when built-in booking is used: the service, time, practitioner, booking status, and changes made by the customer through their secure manage link
- Approved business information the business provides to configure its AI receptionist (its services, prices, policies and similar content). Clinqly uses this to ground answers at the moment of answering; Clinqly does not use it to train its own models
- Voice add-on call data, for businesses that switch it on: the caller's phone number, call recordings and transcripts (recording is a per-location setting, on by default and switchable off), and the call outcome
- Connected calendar data: free/busy times and the events Clinqly itself creates, when a practitioner connects their Google Calendar (Microsoft Outlook will be offered when it becomes available)
- Billing data needed to run subscriptions. Card details are collected and held by Stripe, our payment provider; Clinqly does not store card numbers
- Technical data such as source URL and UTM parameters when provided
How we use data
We process data to provide the service: answering and qualifying enquiries from the business's approved information, notifying the business's team, booking and managing appointments, sending the confirmation, reminder and follow-up emails the business configures, answering calls for businesses with the Voice add-on, and billing for the subscription. We do not sell personal data and we do not use enquiry content for advertising.
AI processing
Clinqlygenerates replies with large language models run by the AI providers listed under sub-processors. To produce each reply, relevant conversation content is sent to those providers together with the business's approved information, so answers stay grounded in what the business has said. Clinqly itself does not use business or customer content to fine-tune or train its own models: approved information is retrieved at the moment of answering, not used for model training. The providers we route to process conversation content in order to generate replies, under their own terms; questions about a specific provider are welcome at the contact address below.
Voice calls
When a business adds the Voice add-on, calls it diverts are answered by the business's AI receptionist. Callers are told at the start of every call that they are speaking with the business's AI receptionist, and, when recording is on, that the call may be recorded. Recordings and transcripts appear in the business's inbox alongside its other conversations and are accessible to that business's team only. Recording is controlled per location and can be switched off, in which case calls are not recorded and transcripts are not retained. Call audio is processed by our voice provider, Retell, and calls are carried over dedicated phone numbers provided through telephony carriers.
Connected calendars
A practitioner may connect their Google Calendar so Clinqlycan schedule around their existing commitments. Microsoft Outlook is built on the same foundation and will be offered when available. With the practitioner's explicit authorisation, we access only what is needed for this:
- Free/busy times: to read when the practitioner is busy, so the AI receptionist does not offer a time they are already booked.
- Calendar events: to create, update and delete events for Clinqlybookings only, keeping the practitioner's calendar in step with appointments made through Clinqly.
We use this calendar data solely to provide these scheduling features. We do not use it for advertising, we do not sell it, and we do not share it with third parties except the sub-processors below strictly to operate the service. Access tokens are encrypted at rest, and a practitioner can disconnect at any time from Settings, which revokes Clinqly's access.
Clinqly's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Sub-processors
We use a named list of providers to run the service, each only for the purpose described:
- Supabase: database, authentication and file storage
- Vercel: application hosting and Vercel Web Analytics (cookieless aggregate site traffic on our marketing pages, as described above)
- Railway: hosting for the Voice call relay service
- Stripe: payments, subscriptions and billing
- Resend: transactional and follow-up email
- Meta: WhatsApp, Instagram and Facebook Messenger, when the business connects those channels
- Google: Google Calendar API, for practitioners who connect a Google calendar
- Microsoft: Outlook / Microsoft Graph, once Outlook calendar connections become available
- Retell: call handling, recording and transcription for the Voice add-on, with phone numbers provided through telephony carriers
- AI providers that generate replies: OpenRouter as the routing gateway, through which conversation content may reach the model providers we configure (currently DeepSeek, Anthropic, OpenAI and Moonshot), with OpenAI also used directly as a fallback
- Jina AI: text embeddings for knowledge retrieval
- PostHog and Google Analytics: optional website analytics, only after you accept them (see below)
Businesses are responsible for their own channel and calendar connections and their own customer communications. Some of these providers process data outside the UK and EEA; questions about a specific provider are welcome at the contact address below.
Retention
Clinqly stores conversation, appointment and call data to give the business its account history and to operate the service. Retention periods vary by data type and are being formalised; the one fixed period today is for raw first-party analytics events, which are reduced to aggregate counts after about 48 hours as described below. A business can contact us at the address below about deletion requests.
Your rights and requests
If you are a customer of a business that uses Clinqly and want your data corrected or deleted, contact that business: it controls its customer records, and we support it in answering requests. For data Clinqly controls, such as our own website and account data, contact us at the address below and we will respond to access, correction and deletion requests.
Analytics and cookies
We measure how our own website is used in separate layers, each with its own purpose and controls. We describe here what each one does, which is not a legal conclusion.
Aggregate site traffic (Vercel Web Analytics)
Vercel Web Analytics helps us understand aggregate visits to the Clinqly website, such as page views, referrers, broad location and device or browser information. Vercel describes Web Analytics as cookieless: it identifies visits with an anonymised hash that resets daily rather than a persistent visitor identifier, and it does not track visitors across sites. It runs on a fixed list of our public marketing pages only, never inside the product, on booking pages or in the widget, and we send it only the page address with the query string removed, so it receives no names, email addresses, message content or account identifiers. It is separate from the first-party statistics and optional analytics described below.
Privacy-preserving usage statistics (first-party)
To understand how our website is used and improve it, we collect first-party, aggregate statistics on our own site. These use no cookies; a short-lived random key kept only in your browser tab (and cleared when you close it) is used to join the steps of a single visit. They are not used for advertising or to build a persistent profile of you. Where the applicable regional policy permits, these statistics may run before you accept optional detailed analytics; you can turn them off at any time via the “Privacy-preserving usage statistics” toggle in “Cookie preferences” (footer). In regions with a more conservative default (for example the EEA), they run only if you accept optional analytics.
What we keep is limited to coarse statistical dimensions: the event (e.g. a page view or a widget open), a server-set timestamp, a short-lived random session key that lives only for your browser tab, the page path, a referrer category, campaign tags (utm), a coarse country, a device class (mobile/tablet/desktop) and a broad browser/OS family, and any experiment variant. We do not store your name, email, phone, address, IP address, precise location, full browser fingerprint, conversation or scraped-website content, advertising identifiers, or the full page URL/query string. Raw events are kept only briefly (about 48 hours) to compute funnels, then deleted; only aggregate, per-day counts are retained.
Detailed analytics (optional)
With your consent we also use PostHog and Google Analytics for more detailed product and marketing analytics. These are off until you accept analytics in the cookie banner: neither script is loaded and nothing is sent before you accept. They stop immediately if you withdraw consent, and can be changed any time via “Cookie preferences”. PostHog runs cookie-free with no autocapture and no session recording; Google Analytics loads only after you accept and then runs in Consent Mode. Neither receives your messages or direct identifiers such as names, email addresses or phone numbers.
We also use essential cookies for sign-in and security, which are always required for the site to work.
Contact
Questions about this policy: hello@clinqly.io