“Chakusa does not sell customer data, and does not use it to serve ads. The customer records a business enters are that business's data, not ours.”
Privacy Policy
How Chakusa collects, stores, and protects data across the CRM, marketplace, booking, loyalty, and AI features, including what we deliberately don't do with it.
This page is grounded in a full backend audit of the actual product (src/modules/*, prisma/schema.prisma) as of 2026-09-01, not written as a legal document. It has not been reviewed by a licensed attorney, and shouldn't be relied on to establish legal compliance. See open engineering follow-ups this page describes honestly rather than papering over.
1. Scope & definitions
This policy covers chakusarecovery.com and the Chakusa app, for both business and customer accounts. A few terms used throughout, in plain language:
| Personal data | Any information that identifies or could reasonably identify you, such as your name, email, phone number, or a booking tied to your account. |
| Processing | Anything done with data: collecting it, storing it, using it to show you a booking, or deleting it. |
| Business account | An account used to run a CRM, marketplace listing, bookings, and loyalty program for a local service business. |
| Customer account | An account used to discover, book, and message businesses through Chakusa. |
| Processor / subprocessor | A company Chakusa uses to help run the product (Section 8); they only act on our instructions, for our stated purposes. |
2. Accounts covered by this policy
Chakusa has two kinds of accounts: business accounts (running a CRM, marketplace listing, bookings, and loyalty program) and customer accounts (people who discover, book, and message businesses through Chakusa). One person can hold both, and this policy covers both equally.
3. Information we collect
| Category | What's collected | Source |
|---|---|---|
| Business accounts | Name, email, business details; Google/Apple profile basics if you sign in that way; the customer records you enter into the CRM (names, phone numbers, notes, messages). That data is yours, not ours; you're responsible for having the right to collect and store it. | Directly from you |
| Customer accounts | Name, email, optional phone, booking history, loyalty points, marketplace searches and favorites, reviews, and messages/AI conversations. | Directly from you |
| Location | Your approximate location, only if you allow it, to show nearby businesses in the marketplace. | From your device, with permission |
| Bookings & payments | Appointment details (service, time, price, staff) and payment records (amount, status, refunds). Card details are handled entirely by Stripe; we never see or store them. | From you and from Stripe |
| Loyalty & referrals | Points balances and history, redemption codes, membership plan details, and referral codes. | Generated by the product |
| Messages & AI | Content of messages sent through Chakusa (SMS/WhatsApp via Twilio), and AI conversation content where an AI feature is used. | Directly from you |
| Technical | Device push-notification tokens and error/diagnostic data. This website sets no tracking or advertising cookies (Section 7). | Automatically, from your device |
4. How we use information
| Purpose | What that means |
|---|---|
| Run the product | Show your leads, bookings, loyalty balances, and marketplace listings. |
| Send messages | Deliver messages you ask us to send, or that automation sends on your behalf, subject to opt-out (Section 6). |
| Generate AI responses | Where an AI feature is used, to draft or send a reply (Section 5). |
| Notify you | Push notifications about activity in your account. |
| Keep the service secure | Detect abuse, enforce opt-outs, and investigate reported problems. |
| Comply with the law | Retain financial and tax records where a law requires it. |
We don't sell data, and we don't use it to serve ads; that applies to every purpose above, not just some of them.
5. AI features
Chakusa includes AI-powered features: a business-facing assistant that can draft or send replies to a business's customers (a business must turn this on), and an in-app assistant customers can chat with directly. Both send conversation content to a third-party AI provider (OpenAI or Anthropic, depending on configuration) to generate a response.
The dedicated AI Disclosure provides full detail about the actions the AI can take, its default human-approval requirement, a current consent gap, its data-retention behavior, and who inside Chakusa can view a conversation. That disclosure is part of this Privacy Policy by reference.
6. Text messages
Message delivery runs through Twilio. Standard message and data rates may apply depending on the recipient's carrier. The business is responsible for having consent to message their customer, under whatever law applies where that customer lives (in the US, generally the TCPA; in Canada, CASL). If a customer replies STOP, Chakusa automatically registers that as an opt-out, and our automated messaging checks this before sending anything further.
9. International data transfers
Because the providers above operate infrastructure in multiple countries, your data may be processed outside the country you're in, including the United States; both AI providers' standard endpoints are US-based unless a data-residency-specific configuration is set up in the future. Each provider is responsible for its own compliance with applicable cross-border data-transfer rules; we haven't independently audited their transfer mechanisms beyond relying on their published terms.
10. Automated decisions
When an AI feature is enabled, Chakusa's system automatically decides whether to send an AI-generated reply, hold it for a human to approve, or escalate the conversation to a person, based on confidence and safety rules (see AI Disclosure). A person can always take over. We don't use automated decisions for anything with a legal or similarly significant effect on you; for example, we don't use AI to approve or deny a booking, a refund, or account access, and payment-related actions always require a human, never the AI, by policy.
11. How long we keep it
| Data | Retention |
|---|---|
| Account profile | While the account is active, plus a reasonable buffer afterward |
| Bookings & payment records | While the account is active; financial records may be kept longer where tax or accounting law requires it |
| Customer records entered by a business | Controlled by that business; it's their data, kept per their own settings, not a fixed Chakusa schedule |
| Messages (SMS/WhatsApp) | While the account is active, plus a reasonable buffer afterward |
| AI conversation content | Currently indefinite, not on a fixed schedule; see the AI Disclosure for the retention improvement this points to |
| Error/diagnostic logs (Sentry) | Governed by Sentry's own retention window for our project, not stored separately by Chakusa |
Deletion can be requested sooner, or the law may require longer retention in specific cases (Section 13).
12. Security measures
- Passwords are hashed with Argon2; never stored in plain text, and not reversible.
- Sessions are rotated and scoped separately for business accounts, customer accounts, and internal admin access.
- Any linked sign-in credentials (Google/Apple) are encrypted at rest.
- Connections to Chakusa use HTTPS in transit.
- Internal access to production data is limited to what's needed to operate the service.
- Administrative actions are logged, including admin views of AI conversation content (see AI Disclosure Section 7).
13. Your rights
Depending on where you are, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain uses of it; for example under the EU/UK GDPR, the California CCPA/CPRA, the UAE PDPL, or South Africa's POPIA. To exercise these rights, email us (Section 17); we'll respond within the time required by applicable law. As Chakusa expands to more countries, this section will be updated to name the specific local law that applies.
Reference: European Commission on data protection (GDPR) · California Attorney General on the CCPA
14. Children's privacy
Chakusa is not directed at children, and we don't knowingly collect personal data from anyone under 16.
15. If something goes wrong
If a security incident affecting your personal data occurs, we will notify affected users and the relevant authorities as required by applicable law. We don't have a public incident-history log today; if that changes, this section will link to it.
16. Changes to this policy
If we make a material change to how we handle data, we'll update this page and the date at the top.
17. Complaints & contact
If you're not satisfied with how we've handled a request, you can contact us below, or, depending on where you live, lodge a complaint with your local data protection authority.