Aly Suite Privacy Policy
Last updated:
1. Scope
Aly Suite is an Aly AI product. This policy explains how Aly AI ("Aly", "we", "us") collects, uses, shares and protects information in connection with Aly Suite, the business management and automation service described on the Aly Suite homepage, including its website, customer workspaces and the integrations customers choose to connect.
Aly Suite is provided to businesses. When a customer uses Aly Suite to manage its own operations, the customer decides what information about its staff, clients and contacts is entered into or connected to its workspace, and we process that information on the customer's behalf and according to our agreement with the customer. The use of Aly Suite is also governed by our Terms and Conditions.
2. Information we collect
- Contact and account information, such as names, business names, email addresses, phone numbers and sign-in details for users of a customer workspace.
- Information you send us through website forms, demo requests, email or support conversations.
- Customer workspace data that a customer enters into or connects to Aly Suite in order to run its operations, such as contacts, bookings, appointments, documents and billing records.
- Data from connected services that a customer explicitly authorizes, such as Google Calendar, as described in section 4.
- Technical information, such as IP address, browser type, pages visited, timestamps and cookies needed to keep sessions working and to protect the service from abuse.
3. How we use information
We use information to:
- provide, operate and support Aly Suite for our customers;
- perform the features a customer enables, such as scheduling and booking operations;
- respond to inquiries, demo requests and support requests;
- send service, billing and security communications;
- maintain, secure and troubleshoot the service and prevent abuse; and
- comply with legal obligations.
We do not sell personal information, and we do not use customer workspace data or data from connected services for advertising.
4. Google API and Google Calendar data
Some Aly Suite features, such as booking and appointment scheduling, can connect to a customer's Google Calendar. This connection is only made when an authorized user of the customer signs in with Google and grants access on Google's consent screen.
Data accessed
Depending on the permissions the user approves, Aly Suite may access:
- calendar metadata for the calendars the user connects, such as calendar identifiers, names and time zones;
- calendar events and their details, such as start and end times, free/busy status, titles, descriptions, locations and attendees, when needed to display or coordinate schedules or when Aly Suite creates or updates confirmed appointments; and
- the OAuth authorization tokens that Google issues so that Aly Suite can keep the connection working without asking the user to sign in each time.
How the data is used
Google Calendar data is used only to:
- display and coordinate scheduling information from the connected calendar within the customer's workspace;
- create, update or cancel calendar events for service appointments that have been confirmed, rescheduled or cancelled in the customer's Aly Suite workspace; and
- keep the customer's Aly Suite schedule and the connected Google Calendar synchronized, and troubleshoot that synchronization when the customer asks for support.
Aly Suite's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not:
- sell Google user data;
- use Google user data for advertising, including personalized or retargeted advertising;
- use Google user data to determine creditworthiness or for lending purposes;
- use Google user data to develop, improve or train generalized artificial intelligence or machine learning models; or
- allow people to read Google user data, except with the user's affirmative agreement for specific messages or events, when necessary for security purposes such as investigating abuse, to comply with applicable law, or when the data has been aggregated and anonymized for internal operations.
OAuth token handling
OAuth tokens are stored on the server side of the customer's Aly Suite workspace, are used only to call the Google Calendar API for the purposes above, and are not shown in the public website or shared with other customers. Users can make tokens stop working by revoking access from their Google Account and can request deletion of connection data by contacting us.
Sharing of Google data
Google Calendar data is shared only as needed to provide the feature the customer enabled: with the customer's own authorized users, with infrastructure providers that host Aly Suite on our behalf, or when required by law, as described in section 5.
Retention, deletion and revocation
Calendar data is kept only while the connection is active and as long as it is needed for the customer's scheduling records. A user can revoke Aly Suite's access at any time from Google Account permissions or ask the customer's workspace administrator to disconnect the calendar. To request deletion of Google Calendar data held by Aly Suite, contact [email protected].
6. Retention and deletion
We keep information for as long as needed to provide Aly Suite, to meet our agreement with the customer, and to comply with legal, accounting and tax obligations. When a customer ends its service or asks us to delete data, we delete or anonymize it within a reasonable period, except where we must keep it by law. Deleted data may remain in backups for a limited period until those backups expire.
7. Security
We use administrative, technical and organizational measures designed to protect information, including encrypted connections (HTTPS), access restricted to authorized personnel, separation of customer workspaces and regular backups. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your choices and controls
- You can ask us to access, correct or delete personal information we hold about you. If your information is held in a customer's workspace, we may refer your request to that customer.
- You can disconnect a connected service, such as Google Calendar, from Aly Suite or revoke its access from the provider's account settings at any time.
- You can opt out of non-essential emails by using the unsubscribe link or by contacting us.
9. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date above and, where the change is material, notify customers through the service or by email.
10. Contact
For privacy questions or requests, email [email protected] or use our contact page.