Legal
Privacy Policy
Effective date: July 16, 2026
This Privacy Policy explains how Beily Inc. ("Beily", "we", "us") collects, uses, shares, and protects personal information when you visit beily.io, use our client portal at app.beily.io, or use our services. It also explains your rights, including under the EU General Data Protection Regulation (GDPR). If you have any questions, contact us at hello@beily.io.
The two roles we play
It helps to know which "hat" we are wearing:
- As a controller, for our own website visitors, people who contact us, and our subscribing business customers (their account, billing, and the business details they share with us), we decide how and why that data is used. This policy governs that processing.
- As a processor, when we run a service for a business customer we also handle that business's own end-customer data on their instructions, for example the names, emails, and phone numbers in their bookings, or the reviews we help them reply to. For that data the business is the controller and its own privacy notice applies. We only use it to deliver the service and never for our own purposes.
Information we collect
Information you provide. When you contact us, we collect your name, business name, email, phone number, and message. When you subscribe, our payment processor collects your billing details; we never see or store your full card number. To deliver our services, we collect the business information and account access you choose to share, for example your Google or Yelp profile or your social accounts.
Information collected automatically. Our hosting and network providers keep basic server logs, such as IP address and request time, for security and reliability. We use privacy-friendly, cookieless website analytics (see "Cookies and analytics" below). We do not use advertising trackers.
Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract, to provide the services you subscribe to, manage your account, and process payments.
- Legitimate interests, to respond to your inquiries, keep our site and services secure, understand aggregate usage through cookieless analytics, and run our business, balanced against your rights.
- Consent, where we ask for it, for example optional marketing emails. You can withdraw consent at any time.
- Legal obligation, where we must keep records or respond to lawful requests.
How we use information
We use your information to respond to inquiries, provide and operate the services you subscribe to, process payments, keep your account and content up to date, secure our systems, and communicate with you about your service.
Who we share it with (our sub-processors)
We do not sell your personal information. We share it only with the service providers who help us run Beily, each under a data-processing agreement:
- Stripe, payments and subscription billing (United States).
- Supabase, our database and file storage, hosted in the EU (Frankfurt, Germany).
- Resend, sending transactional email such as notifications and login links (United States).
- Vercel, website and application hosting (United States and EU regions).
- Cloudflare, DNS and network delivery (United States).
We may also disclose information if required by law or to protect our rights.
International data transfers
Beily is based in the United States, and some of the providers above process data in the US. When personal data of people in the EU or EEA is transferred outside the EEA, we rely on an approved safeguard: either the EU-US Data Privacy Framework (for certified providers) or the European Commission's Standard Contractual Clauses, together with additional protections where appropriate. Our primary database is hosted in the EU (Frankfurt) to keep core customer data in the region.
Data retention
We keep your information for as long as needed to provide the services and for legitimate business or legal purposes, then delete or anonymize it. You can ask us to delete your information at any time, subject to any records we are legally required to keep.
Your rights
Depending on where you live, and in particular under the GDPR, you have the right to access your personal data, correct it, delete it, restrict or object to its use, receive a copy in a portable format, and withdraw consent where we relied on it. To exercise any of these, email hello@beily.io. If we process data on behalf of a business customer (as a processor), we will pass your request to that business and support them in answering it.
You also have the right to lodge a complaint with a data protection authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), at uoou.gov.cz, or you may contact your own local authority.
Cookies and analytics
We do not use tracking or advertising cookies. Our sites set only strictly necessary items, such as the secure session that keeps you logged in to the portal. For usage insight we use privacy-friendly, cookieless analytics that do not store identifiers on your device or track you across sites, so no consent banner is required. If we ever add technology that needs your consent, we will ask for it first and update this policy.
Security
We use reasonable technical and organizational measures to protect your information, including encryption in transit, access controls, and multi-factor authentication on administrative accounts. No method of storage or transmission is completely secure, but we work to keep your data safe and will notify you and the relevant authority of a personal data breach where the law requires.
Children's privacy
Beily is intended for businesses and is not directed to children. We do not knowingly collect information from children.
Changes to this policy
We may update this policy from time to time. The effective date above shows when it was last changed.
Contact us
Beily Inc.2261 Market Street, STE 65437
San Francisco, CA 94114
hello@beily.io