Privacy Policy
Last updated:
How Tornaly collects, uses and protects personal information: for the businesses that use it, for their clients who message or book them, and for visitors to our website.
The short version
- We run websites, online booking and an AI front desk for appointment businesses.
- If you message or book a business that uses Tornaly, that business is in charge of your information. We handle it for them, only to run the service.
- We don’t sell personal information or use it for advertising. Our AI providers don’t train their models on it.
- Data is stored in the United States, with the providers listed below.
- You can ask to see, correct or delete your information at hello@tornaly.com. We answer within 30 days.
This summary helps you find your way. The full text below is what applies.
1. Who we are
Tornaly is a Canadian business operated by Tornaly, registered in Ontario, Canada.
Our privacy officer, Privacy Officer, Tornaly, is accountable for how we handle personal information. You can reach them at hello@tornaly.com.
This policy covers:
- businesses that use Tornaly and the people on their teams (“customers”);
- the clients of those businesses who message them, book with them or visit their websites (“end clients”);
- visitors to our own website, including people who join our waitlist.
2. Our two roles
For end clients’ information, the business decides why and how it is used. The business is responsible for it, and we are its service provider: we process that information only on the business’s instructions and only to provide the service, under our Data Processing Agreement. The business’s own privacy policy also applies, and the business is your first point of contact.
For our customers’ account information, our website visitors and our waitlist, we are responsible for the information ourselves.
3. What we collect
- Account information: name, email address, phone number, language, and business details such as the business name, address, type, services, prices, hours, team members and their roles. We also keep sign-in times and a description of the browser used for each active session.
- Client records: what a business imports from another booking tool or creates in Tornaly, such as names, phone numbers, email addresses, booking history, notes, preferences and consent choices.
- Messages: conversations between a business and its clients on WhatsApp, Instagram, text message (SMS), web chat and email, including the replies the AI front desk writes. Voice notes are transcribed to text so they can be answered.
- Missed calls: when a call to a business’s number is missed, the caller’s number and the time, so a text can be sent back. Tornaly does not answer or record phone calls.
- Bookings and payments: appointment details, deposits, no-show fees and payment status. Payments are processed by Stripe, through the business’s own Stripe account. We never see or store full card numbers.
- Website content: the text, services, prices and images a business adds to its website on tornaly.site or on its own domain.
- Waitlist: your name, email, phone number, business details, the products you are interested in and any message you send. We also keep a record of your consent (which boxes you ticked, when, in which language, and the version of the wording) and how you found us (first page visited, referring site, campaign tags and ad click IDs in the link).
- Web chat visits: where a visitor to a business’s chat page came from (referring site and campaign tags), so the business can see which links bring it clients.
- Technical information: IP address, browser and device type, pages requested, and logs of errors and service health. Error reports have tokens and secrets removed.
4. How we use it
- To provide the service: host websites, take bookings, send the reminders and messages a business has set up, answer messages with the AI front desk, and show the business its results.
- To keep the service safe: prevent spam and abuse, tell people from bots, and find and fix errors.
- To bill businesses for their plan and to give support.
- To contact people on our waitlist about joining Tornaly, and to send product news only to those who ticked that separate box.
- To meet our legal obligations.
We do not sell personal information. We do not use end clients’ information for advertising, and we never use one business’s client data for another business.
5. The AI front desk
When a business turns on the AI front desk, incoming messages, voice-note transcripts and the business’s own information (services, prices, hours and policies) are sent to an AI provider so it can write a reply. We use OpenAI, and may use Anthropic instead.
Under their business terms, these providers do not use this data to train their models. Where a provider lets us ask for data not to be stored, we ask.
The AI front desk follows the business’s settings and uses only the information the business entered. It hands unclear or sensitive conversations to a person. It can still make mistakes, so the business can review any conversation and take over at any time.
7. Our service providers (subprocessors)
These companies process personal information for us, each only for the purpose shown:
| Provider | What they do | Where |
|---|---|---|
| Render | Hosting for the app and customer websites | United States |
| Neon | Database | United States |
| Resend | Email delivery (sign-in codes, notices, reminders) | United States |
| OpenAI | AI replies and voice-note transcription | United States |
| Anthropic | AI replies, when used instead of OpenAI | United States |
| Twilio | Text messages and business phone numbers (missed-call text-back) | United States |
| Telnyx | Text messages and business phone numbers, for numbers hosted with them | United States |
| Meta Platforms | WhatsApp and Instagram messages | United States and other countries |
| Stripe | Payments into each business’s own Stripe account, and our subscription billing | United States and other countries |
| Cloudflare | Bot protection (Turnstile), DNS and content delivery | Global network |
| Sentry | Error reports, with tokens and secrets removed | United States |
8. Changes to our providers
This list may change. We update it here, and we tell businesses at least 30 days before a new provider starts handling their clients’ information, as set out in our Data Processing Agreement.
9. Where your information is stored
Our providers store and process information in the United States, and some operate in other countries too. While it is there, the law of that country applies, and its courts and authorities may be able to access it.
We stay responsible for your information under Canadian law wherever it is processed. Before information about people in Quebec leaves the province, we assess whether it will be adequately protected, taking into account how sensitive it is, why it is used, the safeguards in place and the laws that apply where it goes. Each provider is bound by a written agreement that protects the information.
11. Text messages, WhatsApp and consent
Businesses must have permission to message their clients, as required by Canada’s Anti-Spam Legislation (CASL), the US Telephone Consumer Protection Act (TCPA), carrier rules and Meta’s policies. Booking confirmations and reminders are service messages about an appointment the client made.
Tornaly only texts a number that asked for texts or agreed to them. A number typed into a chat must first confirm by replying YES.
Reply STOP to any text to stop them, or HELP for help. Opt-outs are recorded and applied automatically. Asking in your own words (“please stop texting me”) also works: a person at the business follows up.
From Tornaly itself, you receive emails about your account and the service. We send marketing emails only with your express consent, for example the product news box on our waitlist, and every one has a way to unsubscribe.
12. How long we keep it
- Sign-in codes: deleted after 30 days.
- Sign-in sessions: deleted when they expire or after 30 days without use.
- Team invitations nobody accepted: deleted 30 days after they expire.
- Records of which tools the AI front desk used for each reply: details removed after 90 days (counts are kept).
- Messages and client records: for as long as the business keeps its account, or until the business erases the client. Erasing a client removes their chats, contact details, notes and feedback. Anonymous booking counts stay, along with a scrambled (hashed) record of any opt-out, so the opt-out is never forgotten.
- Consent and opt-out records: kept as long as needed to prove consent.
- Closed accounts: the business has 30 days to export its data. We then delete it from our live systems. Copies in backups are deleted as the backups expire, within 30 days after that.
- Billing records: as long as tax law requires (in Canada, generally six years).
- Waitlist: until you ask us to remove you, or 24 months after our last contact with you, whichever comes first.
- Technical logs and error reports: up to 90 days.
13. Your rights
You can ask us to:
- tell you what personal information we hold about you and give you a copy;
- correct information that is wrong or incomplete;
- delete your information, unless we must keep it by law or to finish something you asked for;
- stop using it for something you consented to (you can withdraw consent at any time, subject to legal or contract limits);
- if you live in Quebec, give you your information in a structured, commonly used technological format.
Write to hello@tornaly.com. We may ask you to confirm your identity. We answer within 30 days, and if we need more time as the law allows, we tell you why. These requests are free.
If you are a client of a business that uses Tornaly, please contact that business first: it controls your information and can usually help right away. If you write to us, we pass your request to the business and help it respond.
14. Complaints
If you are unhappy with how we handled your information, please tell us first at hello@tornaly.com so we can fix it.
You can also complain to the Office of the Privacy Commissioner of Canada. If you live in Quebec, you can contact the Commission d’accès à l’information du Québec. In Alberta and British Columbia, the provincial privacy commissioner can also help.
15. Security
- All connections to Tornaly are encrypted in transit (HTTPS).
- Our database provider encrypts stored data. Access tokens for connected WhatsApp, Instagram and other accounts are additionally encrypted (AES-256).
- Sign-in codes and session keys are stored only in scrambled (hashed) form.
- Each business’s data is kept separate, and access is checked by role on every request.
- Our staff with platform access must use two-step verification.
- Messages from Meta, phone carriers and Stripe are checked for a valid signature before we accept them.
No system is perfectly secure. If a breach of security creates a real risk of significant harm to you, we will tell you and the Office of the Privacy Commissioner of Canada as soon as possible (and Quebec’s Commission d’accès à l’information where it applies). We keep a record of every breach, as the law requires. If a breach affects a business’s client data, we tell the business promptly so it can meet its own duties.
16. Children
Tornaly is a service for businesses. It is not directed at children, and we do not knowingly collect information from anyone under 16 for our own purposes. A business may have younger clients; it is responsible for getting a parent’s or guardian’s consent where the law requires it.
17. Changes to this policy
When we change this policy, we post the new version here with a new date. If a change is significant, we tell account owners by email or in the app at least 30 days before it takes effect.
18. Contact us
Privacy officer: Privacy Officer, Tornaly
Email: hello@tornaly.com
Questions about this page: hello@tornaly.com