Legal
Privacy Policy
Effective Date: May 26, 2026
Sentio("Sentio," "we," "our," or "us") operates a WhatsApp-based business communication and automation platform. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you or your customers interact with our services, including our WhatsApp messaging automation, AI-powered chatbot, and associated web interfaces.
By using Sentio, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the service.
1. Information We Collect
1.1 Information Provided by Business Customers
When a business signs up for and configures Sentio, we collect:
- Business name, contact name, and email address
- WhatsApp Business phone number(s)
- Vagaro account credentials (via OAuth 2.0 — we do not store raw passwords)
- Billing and payment information (processed by our payment provider)
- Custom message templates and automation configuration settings
1.2 End-Customer Data (Appointment Holders)
Through our integration with Vagaro and the Meta WhatsApp Cloud API, we process data about the business's customers, including:
- Name and WhatsApp-registered phone number
- Appointment date, time, service type, and status
- Inbound and outbound WhatsApp message content
- Conversation history (retained to enable contextual AI responses — see Section 5)
- Opt-out status (STOP / UNSUBSCRIBE requests)
- Message delivery metadata (sent, delivered, read timestamps from Meta)
1.3 Automatically Collected Data
When our services are accessed, we may automatically collect:
- Server logs (IP addresses, request timestamps, response codes)
- Webhook payloads from Meta and Vagaro
- Performance and error telemetry for service reliability
2. How We Use Information
We use the collected information to:
- Deliver appointment reminder and review-request messages via WhatsApp on behalf of the business customer
- Send Canadian Choice Award vote requests on behalf of the business customer
- Operate the AI chatbot to respond to inbound customer questions about pricing, availability, and bookings
- Execute re-engagement and win-back campaigns as configured by the business
- Authenticate and maintain the Vagaro OAuth connection to retrieve appointment and customer data
- Detect and honor STOP / UNSUBSCRIBE opt-out requests in compliance with CTIA guidelines
- Prevent duplicate or fraudulent message delivery using idempotency mechanisms
- Provide business customers with message analytics and performance data
- Improve, debug, and maintain the reliability of our platform
- Comply with applicable legal obligations
We do not sell end-customer personal data to third parties. We do not use end-customer data for advertising or marketing unrelated to the business that collected it.
3. WhatsApp and Meta Platform Data
Sentio integrates with the Meta WhatsApp Business Cloud API. By using Sentio, business customers and their end-users acknowledge that:
- All WhatsApp messages are transmitted through Meta's infrastructure and are subject to WhatsApp's Privacy Policy and WhatsApp Business Policy
- Sentio processes WhatsApp message data solely to provide the automation services described in this policy and does not use it for any purpose prohibited by Meta's platform policies
- Message content accessed through the WhatsApp Business API is used only to deliver requested services and is not shared with third parties except as necessary to operate the service (e.g., sending to OpenAI for AI response generation — see Section 4)
- End-customers may opt out of marketing and promotional messages at any time by replying STOP to any message. Sentio processes opt-outs immediately and suppresses all future promotional messages to that number — including review requests, rebooking nudges, win-back messages, Canadian Choice Award vote requests, and — for businesses where enabled — seasonal or birthday campaigns
- Transactional messages tied to an appointment the customer has already booked — such as a reminder ahead of that appointment — continue to be sent after a STOP request. These relate to a booking the customer made themselves rather than to marketing, and stop when the underlying appointment is cancelled or completed
4. Third-Party Services and Data Sharing
Sentio relies on the following third-party services to deliver its functionality. Each provider's data handling is governed by their own privacy policies:
| Service | Purpose |
|---|---|
| Meta (WhatsApp) | Sending and receiving WhatsApp messages via the Cloud API |
| Vagaro | Retrieving appointment, customer, and availability data |
| OpenAI | Generating AI chatbot responses to inbound customer messages |
| Supabase | Secure, multi-tenant database storage for all platform data |
When customer message content is sent to OpenAI for AI response generation, it is processed solely to generate a reply and is subject to OpenAI's Privacy Policy. We do not instruct OpenAI to train models on customer data.
We may also disclose information if required by law, court order, or government authority, or to protect the rights, safety, or property of Sentio, its customers, or the public.
5. Data Retention
Sentio is built around continuity. The AI assistant answers each customer using the history of that conversation, and business customers rely on accumulated message history to understand how the service performs over time. We therefore retain the records below for as long as the business customer's account is active, rather than deleting them on a fixed schedule.
- Conversation history: Retained for the duration of the account so the AI assistant can respond with full context when a customer returns. Deleted immediately if that end-customer replies STOP. If a transactional message is sent to that customer afterwards — such as a reminder for an appointment they have already booked — a new conversation record begins from that point.
- Message logs and analytics: Retained for the duration of the account so business customers have ongoing visibility into message volume and performance. These aggregate records are not removed by a STOP request.
- Appointment and customer records synced from Vagaro: Retained for the duration of the account to schedule reminders and review requests and to identify lapsed customers.
- Idempotency records: General webhook-processing records are automatically deleted 30 days after they are written. Delivery-claim records for automated sends — appointment reminders, review requests, award-vote requests, re-engagement, win-back, and handoff-reset — are retained permanently by design, as a safeguard against duplicate or repeated messaging. None of these records hold message content.
- Opt-out records: Retained indefinitely so an opted-out number is not sent further marketing or promotional messages. An opt-out is cleared only if that customer later replies START to opt back in.
- Business account data: Retained for the duration of the account and for up to 90 days after account deletion, then permanently removed.
Business customers may request deletion of specific end-customer records at any time by contacting us — see Section 7.
6. Data Security
We implement industry-standard security measures including:
- HMAC-SHA256 signature verification on all incoming webhooks from Meta and Vagaro
- Encryption in transit (TLS 1.2+) for all data exchanges
- Encryption at rest for database storage via Supabase's infrastructure
- Per-tenant data isolation — no business customer can access another's data
- Named staff and owner accounts at a business customer can log in to the Sentio dashboard to view that business's own customer conversation transcripts and message analytics — this access is limited to their own tenant and controlled by the business
- OAuth 2.0 for third-party authentication (no raw credentials stored)
- Access controls limiting staff access to production data
No method of transmission or storage is 100% secure. In the event of a data breach that affects your rights, we will notify affected parties as required by applicable law.
7. Your Rights and Choices
End-Customers (Appointment Holders)
- Opt out of marketing messages: Reply STOP or UNSUBSCRIBE to any message at any time. We will immediately cease sending marketing and promotional messages to your number, including review requests, rebooking nudges, and win-back campaigns. Reply START to opt back in.
- Appointment reminders: Messages tied to an appointment you have already booked, such as a reminder before that appointment, are transactional rather than marketing and continue after a STOP request. To stop these, cancel the appointment with the business directly, or contact us at contact@performicy.com.
- Request deletion: Contact the business that sent you messages. As the data controller, they can request deletion of your data from Sentio on your behalf.
- Access your data: Contact us at contact@performicy.com and we will assist you in coordination with the relevant business customer.
Business Customers
- Account data: You may update or delete your account information at any time through the platform settings or by contacting us.
- Data export: Request a copy of your data by emailing contact@performicy.com.
- Account deletion: Request full account and data deletion by contacting us. Deletion will be completed within 30 days, subject to legal retention obligations.
8. Children's Privacy
Sentio is not directed to individuals under the age of 13 (or 16 in applicable jurisdictions). We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will delete it promptly.
9. International Data Transfers
Sentio operates globally and your data may be processed in countries other than your country of residence, including the United States and Canada. By using our services, you consent to the transfer and processing of your information in these countries, which may have different data protection laws than your jurisdiction. We take appropriate safeguards to ensure your data is protected in accordance with this policy wherever it is processed.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify business customers of material changes via email or through the platform. The updated policy will be posted on this page with a revised effective date. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, contact us at:
Sentio
Email: contact@performicy.com