Privacy Policy
1. Introduction
This Privacy Policy describes how Nostos, LLC ("Nostos," "we," "us," or "our"), a Washington limited liability company doing business as Kai Booking, collects, uses, discloses, and protects personal information in connection with the Kai Booking platform, including the website at kaibooking.com, the customer-facing booking pages we host on behalf of businesses, and any related services (collectively, the "Service").
This Privacy Policy applies to two distinct categories of users:
- Business Users: Owners, managers, and staff members of businesses that subscribe to or use Kai Booking to manage appointments, bookings, and customer relationships.
- Booking Customers: Individuals who book appointments through a business that uses Kai Booking.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Service.
2. Information We Collect
2.1 Information from Business Users
When a business owner or staff member uses the Service, we collect the following information:
- Business legal name and trade name
- Business address and physical location
- Business contact email
- Business phone number and forwarding number
- Business hours and operating schedule
- Business type and category
- Business website content, including marketing copy and photographs
- Service catalog: services offered, service options, descriptions, prices, durations
- Add-on products: descriptions, prices, availability rules
- Staff information: names, profile photos, descriptions, roles, schedules, service assignments, and bookability status
- Booking preferences and settings
- Account credentials, including phone numbers and password hashes for managers and staff PINs for receptionists and staff
- Booking history and operational records associated with the business
2.2 Information from Booking Customers
When a customer books an appointment through a business that uses Kai Booking, we collect on behalf of that business:
- First name and last name
- Phone number
- Booking details: service selected, service options, prices, add-ons, date and time of appointment, assigned staff
- Booking history: previous bookings made through the same business
- Verification codes sent and received via SMS during the booking process
We do not collect payment information from booking customers, as Kai Booking does not process payments. All payments occur directly between the customer and the business.
2.3 Information Collected Automatically
We may collect certain information automatically when you use the Service, including:
- IP address and approximate geographic location
- Browser type and version
- Operating system and device type
- Pages viewed and actions taken on the Service
- Date and time of access
- Referring website addresses
2.4 Cookies and Tracking Technologies
We use cookies and similar tracking technologies to operate the Service, remember user preferences, and analyze usage. The categories of cookies and similar technologies we use include:
- Essential cookies: Required for authentication, session management, and core Service functionality. These cannot be disabled without breaking the Service.
- Preference cookies: Remember language settings, display preferences, and similar non-essential customizations.
- Analytics cookies: We currently use Google Analytics or similar analytics tools to understand how users interact with the Service. We may add additional analytics, error monitoring, or session recording tools in the future. We will update this Privacy Policy when we do.
You may disable cookies in your browser settings, but doing so will likely prevent you from using essential parts of the Service.
We do not use cookies for cross-site advertising or behavioral targeting, and we do not sell your personal information to advertisers.
3. How We Use Information
We use the information we collect to:
- Provide, operate, maintain, and improve the Service
- Authenticate users, manage accounts, and prevent unauthorized access
- Process bookings, send confirmations, reminders, and related transactional communications
- Send SMS messages necessary to operate the Service (see Section 4)
- Communicate with users about the Service, including service announcements, security alerts, and support inquiries
- Detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activity
- Comply with legal obligations and enforce our Terms of Service
- Generate aggregated, de-identified statistics about Service usage
- Develop new features and improve existing functionality
4. SMS Communications
Kai Booking uses Twilio, Inc. as our SMS service provider to deliver text messages on behalf of businesses using the Service.
The Service may send the following categories of SMS messages:
- Verification codes: One-time codes for account creation, login, and password reset
- Booking confirmations: Sent to customers and businesses when an appointment is booked
- Appointment reminders: Sent to customers in advance of their scheduled appointments
- Reschedule and cancellation notifications: Sent when a booking is changed or cancelled
- Service-related notifications: Sent to business users about their account or the Service
- Promotional messages: We may, with consent, send promotional messages on behalf of businesses to their customers in the future
By providing your phone number, you consent to receive transactional SMS messages from Kai Booking and the businesses using our Service. Message and data rates may apply. Message frequency varies based on your booking activity.
You may opt out of non-essential SMS messages at any time by replying STOP to any message. Replying HELP will return contact information for support. Opting out of transactional messages (such as booking confirmations) may prevent you from completing future bookings.
Opt-outs are tracked per business. If you reply STOP to a message from one business using Kai Booking, you will not receive further SMS from that business, but you may still receive transactional SMS from other Kai Booking-powered businesses where you have booked appointments.
We comply with the Telephone Consumer Protection Act (TCPA), the CTIA Messaging Principles and Best Practices, and Twilio's A2P 10DLC requirements.
5. How We Share Information
We share information in the following circumstances:
5.1 With the Business You Booked With
If you book an appointment through a Kai Booking-powered business, your booking information is collected on behalf of that business and is accessible to that business and its authorized staff. The business is responsible for how it uses and retains your information beyond the operational needs of the booking.
5.2 With Service Providers (Subprocessors)
We use the following third-party service providers (subprocessors) to operate the Service:
- Supabase, Inc. — Database, authentication, file storage, and realtime infrastructure
- Vercel Inc. — Application hosting and content delivery
- Twilio Inc. — SMS message delivery
- Google LLC — Translation services via the Google Cloud Translation API; analytics services via Google Analytics
- Functional Software, Inc. (d/b/a Sentry) — Application error monitoring and performance telemetry
These subprocessors process information on our behalf under contractual obligations to maintain its confidentiality and security and to use it only for the purposes for which we engage them. We may add or replace subprocessors. A current list will be maintained in this Privacy Policy.
5.3 For Legal Reasons
We may disclose information if required to do so by law, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to:
- Comply with a legal obligation
- Protect and defend our rights or property
- Investigate or prevent suspected fraud, security violations, or technical issues
- Protect the personal safety of users of the Service or the public
- Enforce our Terms of Service or other agreements
5.4 Business Transfers
If we are involved in a merger, acquisition, asset sale, financing, reorganization, bankruptcy, or similar transaction, your information may be transferred as part of that transaction. We will provide notice before personal information is transferred and becomes subject to a different privacy policy.
5.5 With Your Consent
We may share information for any other purpose with your express consent.
5.6 We Do Not Sell Personal Information
We do not sell personal information to advertisers, data brokers, or any other third party for monetary or other valuable consideration. We do not "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA.
6. Data Retention
We retain personal information only for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy.
- Active business accounts: We retain account and operational data for as long as the account remains active.
- Closed business accounts: When a business closes its account, we provide a 30-day grace period for the business to export its data. After 30 days, we delete account data within an additional 90 days. Data residing in routine system backups is deleted on rolling backup cycles, typically within an additional 90 days.
- Booking customer data: Retained for the operational life of the booking and the business's account, subject to deletion requests as described in Section 7.
- Verification codes and temporary authentication tokens: Deleted within 90 days.
- System logs and operational telemetry: Retained for up to 12 months for security, debugging, and abuse-prevention purposes, then deleted or de-identified.
We may retain certain information beyond these periods if required by law, to enforce our agreements, to resolve disputes, or to prevent fraud and abuse.
7. Your Rights and Choices
7.1 If You Are a Business User
You may request the following at any time by emailing info@kaibooking.com:
- Access: A copy of the personal information we hold about you and your business
- Correction: Correction of inaccurate information
- Deletion: Deletion of your account and associated data, subject to the retention periods described in Section 6 and any legal obligations we have to retain certain records
- Portability: A copy of your data in a portable format
- Withdrawal of consent: Where applicable, withdrawal of consent for specific processing activities
We will respond to verified requests within 45 days. We may extend this period by an additional 45 days if reasonably necessary, with notice to you. We may require you to verify your identity before fulfilling certain requests.
7.2 If You Are a Booking Customer
If you booked an appointment through a business that uses Kai Booking, your booking information is collected on behalf of that business. Requests to access, correct, or delete your booking information should be directed to the business that took your booking.
If you contact us at info@kaibooking.com with such a request, we will direct you to the appropriate business and may, at our discretion, assist that business in fulfilling your request.
7.3 California Residents (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to know what personal information we collect, use, disclose, and (if applicable) sell about you
- Right to delete personal information we have collected from you, subject to certain exceptions
- Right to correct inaccurate personal information
- Right to opt out of sale or sharing of personal information for cross-context behavioral advertising. We do not sell or share personal information for these purposes.
- Right to limit use of sensitive personal information. We do not use sensitive personal information for purposes that would trigger this right.
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, please contact us at info@kaibooking.com. We will verify your identity before responding to a request. You may designate an authorized agent to make a request on your behalf, subject to verification.
We do not knowingly process the personal information of California residents under the age of 16. (See Section 9.)
7.4 Other US State Privacy Laws
We extend equivalent rights to residents of other US states with applicable privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, and other states whose laws come into effect during the period this Privacy Policy is in force). Contact us at info@kaibooking.com to exercise these rights.
8. Data Security
We implement reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit, access controls, audit logging, and routine security reviews of our infrastructure providers.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee its absolute security.
In the event of a data breach involving your personal information, we will notify affected users and applicable regulators in accordance with applicable law.
9. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from anyone under 18.
If you are a parent or guardian and you believe your child has provided personal information to us, please contact info@kaibooking.com and we will delete that information promptly.
Businesses using the Service are required to ensure that all booking customers are 18 years of age or older.
10. International Users
The Service is intended for users located in the United States. If you access the Service from outside the United States, your information may be transferred to, stored in, and processed in the United States, where our servers and subprocessors operate. By using the Service, you consent to such transfer and processing.
11. Third-Party Links and Services
The Service may contain links to third-party websites and services we do not own or control. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing them with personal information.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and post the updated policy at https://www.kaibooking.com/privacy with a new "Last Updated" date.
Your continued use of the Service after the effective date of an updated Privacy Policy constitutes acceptance of the changes.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Nostos, LLC
2265 116th Ave NE
Bellevue, WA 98004
Email: info@kaibooking.com