Legal
Privacy Policy
Effective date: 8 September 2026 · Last updated: 8 September 2026
Appy Hub is operated by My Pet Walker Ltd, a company registered in England and Wales (company number 11215766) with its registered office at 247 Bury Old Road, Prestwich, Manchester, M25 1JE (“we”, “us”, “our”). We are the data controller for the personal data described in this policy unless stated otherwise.
If you have any questions about this policy or how we handle your data, contact us at privacy@appyhub.io.
1. Who this policy covers
This policy applies to:
- Visitors to appyhub.io and app.appyhub.io.
- Account holders: businesses that subscribe to Appy Hub and the staff members they invite.
- End customers: people who communicate with an Appy Hub account holder through a messaging channel connected to Appy Hub, or who book, pay, or submit a form through an Appy Hub powered widget.
Where an account holder uses Appy Hub to store or process information about their own customers, that account holder is the data controller for that information and we act as their data processor. Our processing of that data is governed by our Terms of Service and Data Processing Addendum, and by the account holder’s own privacy notice. If you are an end customer and want to exercise your rights over data held in an account holder’s Appy Hub workspace, contact that business directly. We will assist them in responding.
2. What we collect
From visitors
- Pages visited, referring site, approximate location derived from IP address, browser and device type.
- Anything you submit through a contact or registration form.
From account holders and their staff
- Name, email address, phone number, job title and profile photo.
- Business name, address, VAT or registration number, and billing details. Card details are collected and stored by our payment provider, Stripe, and never touch our servers.
- Login credentials (passwords are stored hashed), authentication tokens and session information.
- Everything you enter into your workspace: contacts, bookings, notes, tasks, documents, finance records, HR records, messages and files.
- Usage data: features used, actions taken, timestamps and error logs.
- Support conversations with us.
From connected messaging channels
When an account holder connects a messaging channel (for example a Facebook Page, an Instagram professional account, a business WhatsApp number, Telegram, email or SMS), we receive and store on their behalf:
- Messages, attachments, reactions and delivery or read status.
- The sender's name, profile picture, and the platform specific identifier (for example a Page Scoped ID or Instagram Scoped ID).
- Comments on the account holder's posts where the channel supports it.
- Access tokens issued by the platform so we can send and receive on the account holder's behalf. Tokens are encrypted at rest and used only for the purposes the account holder authorised.
We never receive the account holder’s or the end customer’s platform password.
From end customers using widgets
- Name, contact details and message content submitted through a chat or booking widget.
- Booking and payment details where the account holder has enabled payments.
3. Information from Meta platforms
Appy Hub integrates with Facebook Pages, Messenger and Instagram through Meta’s Graph API, under Meta’s Platform Terms and Developer Policies.
- We access Meta data only after an authorised admin of the account holder's business grants permission through Facebook Login for Business.
- We use that data solely to provide the features the account holder chose: displaying and replying to messages and comments, publishing content to their Page or Instagram account, and reporting engagement to them.
- We do not sell Meta platform data, use it to build advertising profiles, or transfer it to any third party except the subprocessors listed in section 7 as needed to run the service.
- Data received from Meta is retained only for as long as the account holder keeps the channel connected and their account active, or as required by law. When a channel is disconnected, we delete the associated access tokens immediately and the message history within 30 days unless the account holder exports or retains it under section 8.
- You can request deletion of your Meta related data using the process in our Data Deletion Instructions at appyhub.io/data-deletion.
4. Why we process your data and our legal basis
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Providing the Appy Hub service, including messaging, bookings, CRM, finance and HR modules | Performance of a contract |
| Billing and account administration | Performance of a contract; legal obligation |
| Securing the service, preventing abuse and fraud | Legitimate interests |
| Improving the product, fixing bugs, analytics | Legitimate interests |
| Sending service messages (outages, security, changes to terms) | Legitimate interests; legal obligation |
| Marketing emails to account holders | Consent, or legitimate interests for existing customers with an opt out on every email |
| Responding to support requests | Performance of a contract; legitimate interests |
| Complying with law, court orders and regulator requests | Legal obligation |
We do not use your data for automated decisions that have legal or similarly significant effects on you.
5. AI features
Some Appy Hub features use artificial intelligence, for example suggested replies, message summaries, receipt scanning and content drafting. Where these features run, the relevant text or image is sent to an AI provider listed in section 7 to generate the output. We use providers that do not train their models on our customers’ data. Account holders can turn AI features off in their workspace settings.
6. Cookies and similar technologies
This website uses strictly necessary cookies only. One first-party cookie remembers your cookie choice, and the app uses strictly necessary cookies to keep you signed in and to protect against cross site request forgery. We do not use analytics cookies, advertising cookies or third-party tracking scripts at present. Our consent tool already includes an analytics category that is switched off and empty: if we ever introduce a measurement tool it will be listed in our cookie notice first and will only load for visitors who consent to that category. You can review or withdraw your choice at any time from the cookie settings link in the site footer.
7. Who we share data with
We share personal data only with the subprocessors we need to run the service, and only for that purpose:
- Supabase (database, authentication and file storage), hosted in the EU.
- Lovable (application hosting).
- Stripe (payments and billing).
- Meta Platforms (Facebook, Messenger and Instagram messaging and publishing, when connected).
- Messaging providers for email, SMS and other channels the account holder connects.
- DigitalOcean (infrastructure for messaging connectors).
- AI providers used for the features described in section 5.
- Cloudflare (DNS and network security).
- The Appy Hub mail server at mail.appyhub.io (transactional and enquiry email).
We may also disclose data where required by law, to protect our rights or safety, or as part of a business sale or merger, in which case the acquirer will be bound by this policy.
We do not sell personal data.
8. How long we keep data
- Account data: for the life of the account and 30 days after closure, then deleted, except where the account holder has requested an export within that window.
- Messaging data from connected channels: as set out in section 3.
- Billing records: seven years, to meet UK tax and accounting law.
- Security and access logs: 12 months.
- Backups: rolling 30 days, after which deleted data is purged from backups.
9. International transfers
Our primary data storage is in the United Kingdom and the European Union. Some subprocessors process data in the United States. Where that happens, we rely on the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision.
10. Security
We use encryption in transit (TLS) and at rest, row level access controls so that each account holder can only see their own workspace, role based permissions inside each workspace, hashed passwords, encrypted storage of third party access tokens, rate limiting and audit logging. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you and the Information Commissioner’s Office where the law requires it.
11. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to our processing of your personal data, and to receive a copy of it in a portable format. You can also withdraw consent at any time where consent is the legal basis.
To exercise any right, email privacy@appyhub.io. We will respond within one month. We may need to verify your identity first.
If you are unhappy with how we handle your data you can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to resolve it with you first.
12. Children
Appy Hub is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with data, contact us and we will delete it.
13. Changes to this policy
We will post any changes here and update the date at the top. For material changes we will notify account holders by email or in app at least 14 days before they take effect.
14. Contact
My Pet Walker Ltd, trading as Appy Hub
247 Bury Old Road, Prestwich, Manchester, M25 1JE
privacy@appyhub.io