Legal

Privacy Policy

Effective

This Privacy Policy explains how Opraly, LLC (“Opraly”) collects, uses, shares, and protects personal information when you use our booking and commerce platform, websites, and related services (the “Service”). Opraly is one multi-tenant platform that powers appointments, classes, restaurant orders, on-site service visits, product sales, and rides for businesses across a range of industries, so the information involved depends on which business you interact with and how it has configured the Service. This policy also describes the choices and rights you have over your information.

1. Introduction

Opraly provides software that helps businesses take and manage bookings, payments, records, and communications across appointments, classes, restaurant orders, on-site service visits, product sales, and rides. This policy applies to the personal information we handle in connection with the Service: information about the people who run a business on Opraly (owners, staff, technicians, drivers), information about the end customers a business serves, and information from visitors to our marketing websites.

Because Opraly is the same core platform configured for each supported industry, the categories of data in play differ by business. A salon keeps client preferences and images; a clinic keeps protected health information; a studio keeps minors’ details and waivers; a restaurant keeps food orders; a home-services company keeps customer addresses and site-access notes; a shop keeps purchase history; and a taxi fleet keeps precise location data. The Data by Industry section below describes what is involved in each. If you are a customer of a business that uses Opraly and have questions about how your data is used, please contact that business directly, as it is the controller of that data.

2. Roles: Controller & Processor

Who is responsible for a given piece of data depends on whose data it is and why it is being processed:

  • Business customer data — the business is the controller, Opraly is the processor. The records a business keeps about its own customers — CRM profiles, bookings, clinical charts, class enrollments, food orders, sales, rides, notes, images, consent records — belong to that business. Opraly processes them only to provide the Service and on the business’s documented instructions, subject to applicable contractual terms. Where applicable law requires a data processing agreement, the covered processing may not begin until that agreement is in effect.
  • Account & site data — Opraly is the controller. For a business’s own account and billing details, for staff and driver logins, and for visitors to our marketing websites, Opraly determines the purposes and means of processing and is the controller.
  • Payments. A third-party payment processor acts as an independent controller for the card, identity, and merchant-account data it collects to process payments or verify a business. See Payments & Card Data.

If a request about customer data reaches us directly, we will route it to the business that controls that data, or assist that business in responding, rather than act on it unilaterally.

3. Information We Collect

We collect the following categories of information. Not every category applies to every user or business — what is actually collected depends on the Service features a business turns on and how you interact with it.

  • Account & business information — such as your name, email address, phone number, business name, role, login credentials (and, for clinical businesses, a mandatory second authentication factor), billing details, and the settings and policies you configure.
  • Customer data a business uploads — the information a business adds about its own customers and their activity: contact details, addresses, dates of birth, demographics, emergency contacts, preferences, custom fields, notes and tags, activity history, household and guardian links, service and delivery addresses with any site-access instructions, and intake-form and consent answers. The business is the controller of this data.
  • Booking, order, visit, and trip data — appointments, class enrollments and attendance, restaurant tabs and food orders, on-site service jobs (including the service address, arrival window, job notes, and any recurring service plan), product sales and returns, and rides (including stops, scheduled times, and any flight numbers for airport transfers).
  • Health and clinical data (clinical businesses only) — for health clinics, dentists, physical-therapy practices, and med spas operating clinically, protected health information such as SOAP clinical notes, treatment plans, allergies and medical flags, clinical images, patient documents, insurance details, and coded superbills. See Data by Industry.
  • Precise location data (rides only) — for transportation businesses, continuous driver GPS pings during a trip, pickup and drop-off coordinates, and the geofenced operating zones that determine pricing. See Data by Industry.
  • Payment information — payments are handled by a third-party payment processor. Opraly stores only a payment-method token and safe display fields (card brand, last four digits, expiry); we do not store full card numbers. See Payments & Card Data.
  • Communications — the content and metadata of service email, user-requested verification text messages, push notifications, support threads, and dispatcher–driver chat sent through the Service, together with delivery, consent, suppression, and preference metadata where applicable.
  • Images and files — client and product photos, clinical before/after imaging, patient documents, ID and insurance-card scans, signed forms and waivers, and driver and vehicle compliance documents.
  • Usage & device data — log data about how the Service is used, including IP address, browser and device type, pages viewed, and timestamps.
  • Cookies and similar technologies — used to keep you signed in, remember preferences, and (with consent) understand how the Service is used — see Cookies & Analytics.

4. Data by Industry

Opraly serves businesses across beauty and wellness, health clinics and dentists, classes and studios, restaurants and delivery, home and professional services, and rides and taxi. The data each handles — and the responsibilities that come with it — differ. In every case the business is the controller of its customers’ data and is responsible for using the Service lawfully for its trade; Opraly is the processor.

Beauty & wellness

Salons, barbershops, spas, nail, brow and lash studios, waxing and tattoo studios, and massage and wellness practices. Data typically includes client contact details and preferences, appointment history, service notes and formulas, allergy and medical flags, intake-form answers, before/after and reference images, deposits and tips, and loyalty and membership records. Some of this can be sensitive (for example, health-adjacent notes); the business is responsible for collecting and storing it appropriately.

Health clinics & dentists

Dental practices, physical-therapy and rehab clinics, chiropractic offices, general clinics, and med spas operating clinically. These businesses handle protected health information (PHI): SOAP clinical notes that lock when signed, treatment plans and phased estimates, allergies and medical flags, clinical images and patient documents, provider credentials and scope, and insurance profiles, eligibility results, and coded superbills.

Classes & studios

Yoga and pilates studios, martial-arts dojos, dance and music schools, gyms, and sports academies. Data includes student profiles and attendance, memberships and prepaid class packs, belt/rank progression history, and waivers and intake forms. Because these businesses commonly serve minors, the data often includes a student’s date of birth (used to enforce age restrictions) and links between a minor and a guardian, plus parental-consent and waiver forms. The business is responsible for obtaining the consents required to enroll a minor.

Restaurants & delivery

Full-service restaurants, cafés, bars, quick-service counters, and delivery-first kitchens. Data includes reservations and guest contact details, dine-in tabs and per-seat items, takeout, curbside, and delivery orders, pickup names, phone numbers and vehicle descriptions, and tips. Delivery routes use the same dispatch and live tracking described under Rides.

Home & professional services

Pest control, cleaning and maid services, plumbing, electrical, pressure washing, HVAC and handyman operations, and other trades that do the work at the customer’s address. Data typically includes the service address and any site-access instructions a customer provides (gate codes, key or lockbox details, parking and pet notes), the job history and technician notes held against that property, before/after job photos, the service-area zones that decide which crew can be booked for an address, recurring service agreements and the payment method they bill on a cadence, and the technician, crew, and vehicle records used to schedule the work.

Because the work happens inside a customer’s home or premises, this data is sensitive in practice even where it is not special-category data in law. The business is responsible for vetting the people it sends, for handling access credentials carefully, and for limiting which of its staff can see them.

Products, inventory & stored value

Many businesses also sell products, gift cards and rentals alongside their core service. Where they do, data includes product sales and returns, customer purchase history, sizes and preferences, gift-card and store-credit balances, and rental agreements (including deposits). Inventory data is largely about products rather than people.

Rides & taxi

Taxi fleets, private-hire and chauffeur operators, airport-transfer and shuttle services, and the dispatch desks that coordinate them. This is a heightened-sensitivity vertical because of the data involved:

  • Precise location / GPS. Driver position is pinged continuously during a trip; pickup, drop-off, and any mid-route stops are stored with coordinates. A rider’s tracking link is an unguessable, login-free link that shows only ride status and the car’s latest position — never customer details or the fare breakdown.
  • Driver data. Compliance documents (driver’s licence, insurance), vehicle records and inspections, duty status, and dispatcher–driver chat.
  • Passenger & safety data. Rider contact and trip history, corporate-account billing, and safety events — an SOS / panic alert captures the driver’s location and opens an incident, and routine safety check-ins are recorded as an audit trail.

5. How We Use Information

We use information to:

  • provide, maintain, secure, and improve the Service;
  • run the bookings, classes, orders, on-site service visits, sales, and rides a business operates, including scheduling, dispatch, routing, live tracking, and automated reminders and notifications;
  • process the business’s own subscription billing, and facilitate the payments a business takes from its customers (see Payments & Card Data), and send service-related messages such as receipts and important notices;
  • send user-requested verification codes and service-related email or push notifications, subject to consent and preferences, suppression, quiet-hours controls, and abuse-prevention safeguards;
  • respond to support requests and communicate with you about your account;
  • detect, prevent, and address fraud, abuse, and security issues;
  • fulfil data-subject requests and maintain audit and consent records; and
  • comply with legal obligations and enforce our terms.

We process the customer data a business uploads only to provide the Service to that business, according to its instructions and our agreement with it. We do not sell personal information, and we do not use customer data a business uploads to train general-purpose models or for our own advertising.

Phone verification messages

When you enter a mobile number and explicitly request a verification code, Opraly uses the number, code, delivery status, and related security metadata only to deliver, secure, and troubleshoot that verification. Contracted messaging providers receive only the information necessary to deliver and protect the message. Mobile numbers and verification consent records are not sold or disclosed to third parties for their advertising or promotional purposes. For program terms or help, see Verification Messages, Email & Push or email hello@opraly.com.

6. Payments & Card Data

Opraly does not store full card numbers. Card details are captured directly by a third-party payment processor in the browser, and only a tokenized payment method and safe display fields reach Opraly. Each party remains responsible for its own obligations under applicable payment-security standards and its agreements with the processor. There are three distinct money flows:

  • A business taking payments from its customers. Payments are processed as direct charges on the business’s own connected merchant account. The payment processor underwrites and verifies each business and may decline, restrict, or suspend payment capabilities under its own rules. Opraly is not the underwriter or approver and is not the merchant of record for a business’s sales. Opraly facilitates these payments and earns the platform fee disclosed to the business. The processor collects business, beneficial-owner, identity, and bank details directly and manages the merchant balance and payout schedule. Opraly receives account capability and onboarding status, not the underlying identity documents, bank-account details, merchant balance, or payout schedule.
  • Bring-your-own processor (BYO). A business may instead connect its own payment processor account. In that case Opraly is not the processor, and the business’s relationship is with its own provider under that provider’s terms and privacy practices.
  • Opraly’s own SaaS subscription. Opraly bills its business customers for their Opraly subscription through a third-party billing provider, which handles the card data under its own terms and privacy practices.

Payroll. Opraly is not a payroll processor or an employer of record. The Service may record tips, commissions, and worker payouts for reporting, but Opraly does not initiate payroll or worker payouts. Payroll, tax withholding, and employment compliance are handled by the business and/or a third-party payroll partner, and the business remains responsible for them.

7. Support Access to Your Account

To resolve a support request, an Opraly support agent may sometimes need to view a business’s account the way one of its users sees it (an “impersonation” or “view as user” session). This is a deliberately constrained data-access practice: it happens only within the context of an open support ticket, only after the relevant user explicitly approves it, is read-only, time-limited, and audited — every such session is logged with who accessed what, when, and why. We do not use this mechanism to read the contents of an account without that approval, except where we are required to by law or to address a genuine security or safety emergency. For clinical accounts, any view of a PHI record during such a session is additionally written to the append-only PHI access log.

Where the GDPR or similar laws apply, we rely on the following legal bases to process personal information:contract (to provide the Service you have signed up for), legitimate interests (to secure, improve, and promote the Service in a way that is balanced against your rights), consent (for example, for certain cookies or optional communications, which you may withdraw at any time), and legal obligation (to comply with applicable law). When we process special-category data such as health information on behalf of a clinical business, the business is responsible for establishing the appropriate lawful basis and conditions for that processing, and Opraly processes it under that business’s instructions.

9. How We Share It

We do not sell personal information. We share it only:

  • with the business you interact with — the controller of that data — and the staff and drivers it authorises;
  • with service sub-processors — vendors that host infrastructure, send messages, process payments, provide maps and routing, or provide analytics on our behalf. Each receives only the information it needs to provide its service to us, and where applicable law requires data-protection terms with a vendor, covered data is not shared with it until those terms are in effect (see Sub-processors);
  • with payment providers — to bill the business’s Opraly subscription and to facilitate the payments a business collects from its customers, as described in Payments & Card Data;
  • for legal reasons — when required to comply with law, respond to lawful requests, protect rights and safety, or in connection with a merger, acquisition, or sale of assets.

10. Sub-processors

We use a limited set of vendors to operate the Service, and each vendor receives only the information it needs to provide its service to us. Where applicable law or the sensitivity of the data calls for confidentiality and data-protection terms with a vendor, covered data is not shared with that vendor until those terms are in effect. The categories are:

  • Cloud hosting & storage — the infrastructure, databases, and object storage that run the Service.
  • Payments — payment processors and billing providers, for subscription billing, merchant verification, payment processing, and processor-managed merchant payouts.
  • Communications — the providers that deliver service email, user-requested verification text messages, and push notifications.
  • Maps & routing — the maps provider that geocodes addresses and supplies distance and duration for ride and delivery routing.
  • Payroll partner — the third-party payroll provider a business may use. Opraly may exchange authorized payroll records with that provider but does not initiate payroll or worker payouts (see Payments & Card Data).
  • Insurance eligibility (clinical) — the clearinghouse a clinic configures for real-time insurance eligibility checks.
  • Error monitoring & analytics — privacy-conscious tooling that helps us find faults and understand aggregate usage; sensitive values and card-shaped data are scrubbed before they reach these tools.

We will provide a current list of sub-processors on request. A clinical deployment involving PHI may begin only after all required Business Associate Agreements are effective.

11. Cookies & Analytics

We use cookies and similar technologies that are necessary for the Service to function (such as keeping you signed in) and, where permitted, optional cookies that help us understand usage and improve the Service. Our marketing-site banner lets you accept or reject non-essential cookies, and rejecting is as easy as accepting. We record each choice as durable, server-side evidence, keyed on an anonymous visitor token so logged-out visitors are covered too.

We honour browser privacy signals. A Global Privacy Control (GPC) or Do-Not-Track signal is authoritative: when present, it automatically turns analytics and marketing off and sets the CCPA “Do Not Sell or Share” opt-out on, regardless of any banner default. We use privacy-conscious analytics to measure aggregate usage and performance.

12. Data Retention

We retain personal information for as long as your account is active or as needed to provide the Service, and afterwards only as needed to comply with legal obligations, resolve disputes, and enforce our agreements. The customer data a business uploads is retained according to that business’s settings and our agreement with it; when a business deletes data or closes its account, we delete or anonymise it after a reasonable period unless we are required to keep it.

Some categories carry their own rules. Records needed for tax and financial-audit purposes (such as ledger entries) are anonymised rather than purged where law requires they be kept.Clinical PHI is retained for its statutory medical-record window — clamped up to at least a six-year floor and only ever set longer — and an erasure request cannot delete PHI still inside that window; instead, those records are flagged as retained under a legal obligation and disposed of by a scheduled sweep once the window elapses. Scheduled jobs also prune stale guest records, expired tokens, old notifications, and account deletions that have come due, so personal data does not linger past its purpose.

13. Security

We use technical and organisational measures designed to protect personal information, including encryption in transit (enforced HTTPS with HSTS), application-layer encryption at rest for sensitive categories such as clinical notes, insurance identifiers, and document metadata, server-side encrypted file storage, role-based access controls, append-only audit and PHI-access logs, mandatory two-factor authentication for clinical staff, masking of sensitive and card-shaped values before they reach logs or error reports, and a strict content-security policy at the edge for payment pages.

We are continually maturing our security program.Opraly is not currently certified or attested under any external security or privacy regime (for example, SOC 2 or HIPAA); we describe the controls that exist rather than claim a certification we do not hold. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work continuously to safeguard the data entrusted to us and to notify affected parties of incidents where required by law.

14. Your Rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. Under the GDPR you may also lodge a complaint with a supervisory authority in your country. The categories of information we collect are listed in Information We Collect, the purposes in How We Use Information, and the parties we disclose to in How We Share It.

U.S. state privacy rights

California residents (CCPA/CPRA) and residents of other states with comparable laws have the right to know what personal information is collected and disclosed, to request its deletion or correction, to obtain a portable copy, to opt out of any “sale” or “sharing” and of targeted advertising, and not to be discriminated against or receive a lesser service for exercising those rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not offer financial incentives in exchange for personal information, and we do not use personal information to build advertising profiles. We honour an opt-out preference signal such as Global Privacy Control as described in Cookies & Analytics. An authorised agent may submit a request on your behalf where the law allows; we will ask for proof of their authority and may still need to verify your identity directly.

Sensitive personal information

Some of what the Service handles is treated as sensitive under privacy law — health and clinical information, precise geolocation, government identifiers and identity documents, information about a known minor, and account credentials. We use it only to deliver the Service the relevant business has configured, to keep accounts and payments secure, and to meet legal obligations. We do not use or disclose it to infer characteristics about you, and we do not use it for advertising, so the CPRA right to limit its use has no additional effect here. Where a business is the controller of that data — a clinic and its patient records, for example — requests about it are directed to that business.

Self-service tools

The Service includes self-service privacy tooling. As a customer of a business on Opraly, you can export the complete personal-data bundle a business holds for you (bookings, CRM record, notes, activity, forms, notifications, messages, payment methods, reviews, support threads, consent records, and, for clinical businesses, charts, documents, and insurance), and you can request erasure of your account within that business, with a grace window to cancel before it runs. Erasure anonymises records that must be kept for tax/audit, purges pure personal data, and retains clinical PHI under its legal floor as described above.

Making a request — and appealing a decision

To exercise your rights, use the in-product tools where they are available, or contact us at privacy@opraly.com. So that we do not hand someone’s records to the wrong person, we ask you to verify your identity, usually by proving control of the email address or phone number on the record; we use what you send to verify the request and nothing else. We respond within the period the applicable law allows, and will tell you if we need the extension that law permits. Exercising these rights is free unless a request is excessive or repetitive.

If your request relates to data a business uploaded about you, we will direct it to that business as the controller, or assist the business in responding. If we decline your request, you may appeal by replying to our decision or writing to privacy@opraly.com with “Appeal” in the subject line; we will review it and give you a written answer explaining the outcome. If you disagree with the result, you may contact your state Attorney General or, in the EU/UK, your supervisory authority.

15. International Transfers

We may process and store information in countries other than the one in which you are located. A covered international transfer may occur only when permitted under applicable law and, where required, after an appropriate transfer mechanism — such as standard contractual clauses or an equivalent safeguard — is in effect.

16. Children’s & Minors’ Privacy

Our websites and the business-facing Service are intended for businesses and adults, and we do not knowingly collect personal information directly from children through them. Some businesses on Opraly — particularly classes and studios — enroll minors, and may record a student’s date of birth, link a minor to a guardian, and capture parental-consent and waiver forms. Where a business enrolls a minor, that business is the controller of the minor’s data and is responsible for obtaining any consent required by law from a parent or guardian. If you believe a child has provided us personal information directly, please contact us so we can take appropriate action.

17. Changes

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Service or by email before they take effect. The effective date above shows when this policy takes effect.

18. Contact

The Service is provided by Opraly, LLC. If you have questions about this Privacy Policy, or want to exercise a privacy right, please contact us at privacy@opraly.com or through our contact page. We will provide a postal address for written correspondence on request.

If you are a customer of a business that uses Opraly and your question is about how that business uses your data, please contact the business directly, as it is the controller of that data. Your use of the Service is also governed by our Terms of Service.