Privacy Policy

Last updated: March 1, 2026

1. Who We Are

TowerZ is a business operating system for service professionals — including salons, barbershops, esthetics studios, massage therapists, personal trainers, tattoo artists, coaches, consultants, and more. TowerZ is operated by Automathing Inc., a company incorporated in Quebec, Canada ("we", "us", or "our"). Our platform helps service businesses manage bookings, clients, marketing, and online presence.

2. Information We Collect

We collect information you provide directly: • Account information: name, email address, business name, profile photo. • Business information: services offered, pricing, availability, location. • Payment information: processed via third-party providers (we do not store card numbers). • Communications: messages between you and your clients via the platform. We collect information automatically: • Usage data: pages visited, features used, click patterns. • Device information: browser type, IP address, operating system. • Cookies and similar tracking technologies (see our Cookie section below). We collect information from third-party integrations you authorize: • Google: when you connect your Google account (Calendar or Google Business Profile), we store encrypted OAuth tokens and, for Google Reviews, cached review data fetched via the Google Business Profile API. • Shopify: when you connect a Shopify store, we store your Storefront API access token and display product data on your public link-in-bio page.

3. How We Use Your Information

We use your information to: • Provide, operate, and improve the TowerZ platform. • Send booking confirmations, reminders, and service notifications. • Display your public profile, services, and reviews to potential clients. • Process payments and prevent fraud. • Respond to support requests. • Comply with legal obligations. We do not sell your personal information to third parties.

4. Google Reviews Data

When you connect your Google Business Profile, we fetch your public reviews via the Google Business Profile API and cache them in our database for up to 7 days. This data is used solely to display reviews on your public link-in-bio page. We attribute all reviews to Google as required by Google's Terms of Service. You can disconnect the integration at any time from your Studio settings, which will deactivate the review display.

5. Data Sharing

We share your data only as necessary: • Service providers: Supabase (database hosting), Vercel (hosting), Stripe (payments), Resend (email). These providers process data on our behalf under confidentiality agreements. • Google APIs: data exchanged when you use Google integrations. • Legal requirements: when required by law, court order, or to protect our rights. • Business transfers: in the event of a merger or acquisition, your data may be transferred as a business asset.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where retention is required by law (e.g., financial records). Cached Google review data is refreshed every 7 days and deleted when the integration is disconnected.

7. Security

We protect your data using industry-standard measures including TLS encryption in transit, AES-256-GCM encryption for stored OAuth tokens, and access controls. No system is 100% secure; in the event of a data breach we will notify affected users as required by applicable law.

8. Cookies

We use essential cookies for authentication and session management. We may use analytics cookies to understand how the platform is used. You can control cookie preferences through your browser settings. Disabling essential cookies may affect platform functionality.

9. Your Rights

Depending on your jurisdiction, you may have the right to: • Access the personal data we hold about you. • Correct inaccurate data. • Request deletion of your data ("right to be forgotten"). • Object to or restrict certain processing. • Data portability. To exercise these rights, contact us at privacy@towerz.ca. Residents of Quebec may also contact the Commission d'accès à l'information (CAI).

10. Children's Privacy

TowerZ is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice in the platform. Continued use of TowerZ after changes constitutes acceptance of the updated policy.

12. Contact Us

For privacy questions or requests: Automathing Inc. Email: privacy@towerz.ca Quebec, Canada