Kafure Receptionist Privacy Policy
What the Kafure Receptionist collects, why, and exactly how we handle data from connected accounts like Google Calendar.
Last updated: June 29, 2026
Who we are
The Kafure Receptionist ("the Service") is operated by Kafure Consulting ("we", "us"), based in Miami, Florida. The Service is an AI-powered phone, chat, and booking assistant we provide to service businesses (salons, barbershops, and similar) so their customers can get answers and book appointments. Questions about this policy go to alex@kafure.com.
Who this policy is for
It covers two groups: the businesses who use the Service (and connect their own accounts, such as Google Calendar), and the customers of those businesses who interact with the assistant by phone or chat to book an appointment.
What we collect
- Business setup data. Business name, address, hours, services, staff, and contact numbers you provide to configure your assistant.
- Connected-account access. When a business connects Google Calendar, we receive an authorization (OAuth) token that lets the Service read availability and create bookings on the calendar that business chooses. See "Google user data" below.
- Booking details. When a customer books, we collect the name, phone number, optional email, requested service, staff, and time needed to make and confirm the appointment.
- Call & message records. For quality and so the business can follow up, we keep records of calls and messages handled by the assistant.
- Server logs. Our host records standard request logs (IP, user-agent, path) for security and uptime.
Google user data
When a business connects Google Calendar, the Service requests these scopes and uses them only as described:
calendar.readonly: to read the connected calendar's free/busy times so the assistant can offer real open appointment slots.calendar.events: to create, update, and cancel the appointment events that the business's customers book through the assistant.
We access this data only to provide the availability-and-booking feature the business asked for. We do not use Google Calendar data for advertising, we do not sell it, and we do not use it to train AI/ML models. We store the OAuth refresh token securely so the assistant can keep booking on the business's behalf; we do not copy or retain the calendar's contents beyond what is needed to check availability and write a requested booking.
Kafure Consulting's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Why we have it
- To run the assistant: answer questions, quote services and prices, and check real availability.
- To create, confirm, and manage appointments the customer requests.
- To keep the Service online and protected from abuse.
Who we share it with
We don't sell your information. We use a small set of vendors ("sub-processors") to run the Service:
- Supabase: database storing business configuration, bookings, and connected-account tokens.
- Vercel: application hosting.
- Vapi and Twilio: voice and SMS for the phone assistant.
- Anthropic: the AI model that powers the assistant's responses.
Google user data is shared with these vendors only as needed to operate the booking feature, never for their own purposes. If a lawful request reaches us, we'll do the legally required minimum and tell you unless prevented from doing so.
How long we keep it, and how to delete it
- Disconnect anytime. A business can disconnect Google Calendar from the admin, or revoke access directly at myaccount.google.com/permissions. On disconnect, we delete the stored token and stop accessing the calendar.
- Booking and call records are kept for the life of the business's account and then deleted on request.
- Deletion requests. Email alex@kafure.com to have your data (including any stored Google tokens and synced booking data) deleted; we'll respond within a reasonable time.
- Server logs are kept for a short rolling window set by our host.
Security
Access tokens and customer data are stored in access-controlled systems and transmitted over encrypted connections. We limit who and what can read connected-account data to the parts of the Service that perform booking.
Your choices
- Access, correction, or deletion. Email us and we'll help.
- EU / UK / California residents. Your GDPR / CCPA rights apply here too.
Children
The Service isn't intended for children under 13, and we don't knowingly collect their data.
Changes
If we make material changes to this policy, we'll update the date above and, where it matters, tell affected businesses directly.
Contact
Kafure Consulting · Miami, FL · alex@kafure.com