Privacy Policy
Effective July 16, 2026 · HostBuddy Inc, San Jose, California
HostBuddy provides AI agents that answer phone calls, take orders, and run
memberships and marketing for restaurants and other merchants ("merchants").
This policy explains what we collect, how we use it, and the choices you have —
whether you are a merchant using our console or a guest interacting with a
merchant's HostBuddy agent.
Information we collect
- Merchant account data — name, email, business name, and the menu,
pricing, and settings you configure. If you connect a platform (Stripe, Square,
Clover, Olo, Toast, Shopify, Slack), we receive the business profile and catalog
data those platforms authorize, using scoped tokens you can revoke at any time.
- Guest interaction data — when a guest talks or types to a merchant's
agent, we process the conversation, order contents, and the phone number or
session used, on the merchant's behalf, to fulfill the order, apply loyalty or
membership benefits, and let the merchant serve that guest.
- Payment data — payments are processed by Stripe or PayPal. Card
numbers go directly to those processors; we never see or store card
numbers. We keep only references (e.g., a subscription or payment id) needed
to verify status.
- Usage data — standard logs and analytics (Google Analytics) on our
websites and console.
How we use it
- To operate the service: answering calls and chats, processing orders,
memberships, value packs, reservations, and marketing campaigns a merchant runs.
- To improve reliability and agent quality. Conversations may be processed by
AI providers (such as OpenAI and Anthropic) and telephony/messaging providers
(such as Plivo) strictly to deliver the service.
- To bill merchants for subscriptions and usage credits.
We do not sell personal information, and we do not use guest data to
advertise to guests.
Sharing
We share data only with the service providers above, with the merchant a guest
interacted with, and where required by law. Connected-platform data stays within
the scopes the merchant granted.
Retention & deletion
Merchant data is retained while an account is active. Merchants can disconnect
integrations at any time (revoking our access tokens) and can request full
deletion of their account and guest records by emailing us. Guests may request
deletion of their data via the merchant or directly at the address below.
Security
Data is encrypted in transit (TLS) and access to production systems is
restricted. Payment credentials are held by Stripe and PayPal, not by us.
Your rights
Depending on where you live (including California), you may have rights to
access, correct, or delete personal information. Contact us and we will respond
within 30 days.
Contact
HostBuddy Inc · 1900 Camden Avenue, San Jose, CA 95124 ·
sagar@hostbuddy.io
We will post any changes to this policy on this page.