Yooty Return to yooty.app
Legal & privacy

Privacy Policy

How Yooty collects, uses, discloses, retains, and protects information in its business-management app and related services.

Effective: August 10, 2026 Last updated: August 21, 2026

Scope and operator

Yooty is operated by Yooty Inc. ("Yooty," "we," "us," or "our"). This Privacy Policy applies to the Yooty business-management mobile application, web portal, login and registration pages, and related business services (collectively, the "Services").

The Services are offered in the United States to businesses, their authorized workforce users, and customers who use a business's Yooty-enabled portal or branded application. The Services are not intended for anyone under 18.

1. Yooty's role and the business's role

Yooty provides tools that businesses use to manage their operations, workforce, customers, jobs, communications, payments, and related records.

  • Business-account information. Yooty is responsible for personal information used to create, administer, secure, support, and market the Yooty service, such as an account holder's name, business contact details, login information, and service-usage records.
  • Business-controlled data. Each business using Yooty controls the customer, employee, contractor, job, communication, and other operational data it places in the Services. For that information, Yooty acts as a service provider or processor on the business's instructions. The business is responsible for its own privacy notices, permissions, legal bases, and responses to the people whose information it controls.
If your information was entered into Yooty by a business—for example, because you are that business's customer, employee, or contractor—please direct privacy requests to that business first. We will assist the business with verified requests as required by applicable law and our agreement with the business.

2. Information we collect

Depending on how a business configures and uses the Services, we may collect the following categories of information.

Business and user-account information

  • Name, business name, email address, telephone number, and business address.
  • User ID, business ID, role, permissions, team membership, profile image, ratings, language, time zone, and app preferences.
  • Login credentials, authentication cookies, OAuth identifiers, passkey credential identifiers, session tokens, and account-recovery information.
  • Subscription, billing, support, and account-administration records.

Passwords are processed for authentication but are not saved in the mobile app. Face ID and Touch ID are handled by Apple on the device; Yooty receives only whether device authentication succeeded and does not receive or store biometric templates.

Business customer and operational information

A business or its authorized users may enter or access:

  • Customer names, telephone numbers, email addresses, physical addresses, company details, profile images, language, notes, contact labels, and communication preferences.
  • Jobs, appointments, requested services, assigned team members, schedules, status updates, addresses, invoices, tips, coupons, reviews, wallet balances, and transaction history.
  • Records showing whether a customer accepted a business's privacy, terms, cancellation, email, or SMS choices.
  • Other information that a business chooses to store in free-text fields or uploaded files.

Communications and user content

  • SMS, MMS, web-chat, team-chat, and email content.
  • Photographs, videos, documents, and other attachments.
  • Call telephone numbers, participants, direction, date, time, duration, status, notes, and outcomes.
  • Call audio, recordings, and transcripts when call recording or transcription is enabled.
  • Support requests, feedback, and communications with Yooty.
Call-recording notice. Laws governing call recording and transcription vary by state and by the location of the call participants. A business using Yooty must provide all required notices and obtain all required consents before recording or transcribing a call. A business must disable recording where it cannot lawfully use it. Yooty does not authorize any business or user to record a call unlawfully.

Mobile messaging privacy and SMS verification codes

Yooty does not share mobile information or SMS consent with third parties or affiliates for their own marketing or promotional purposes.

When a person creates a Yooty customer account or provides a mobile number while making a booking, Yooty may use its centralized platform number to send requested one-time security codes for account access, phone verification, or booking security. Message frequency varies with requested verification attempts. Message and data rates may apply.

Recipients can reply STOP to stop text messages or HELP for help, or contact us at [email protected]. Carriers are not liable for delayed or undelivered messages. Mobile numbers and SMS consent are not shared with third parties or affiliates for their marketing or promotional purposes.

Location information

For authorized workforce users, the mobile app may collect a precise location snapshot—including latitude, longitude, accuracy, altitude when available, and capture time—when the user performs a job-status action such as In Transit, Start, Pause, Resume, or Complete. Yooty uses the location to calculate travel time, support the requested job update, and maintain an event record.

The current business app requests location only while the app is in use and does not continuously track a user's background location.

Payment and financial information

Yooty may process invoices, amounts, tips, payment status, transaction identifiers, processor customer IDs, payment tokens, card brand, card type, expiration information, and the last four digits of a payment card.

Full payment-card and bank-account details are entered into and stored by the applicable payment processor. Yooty does not receive or store full card numbers, card security codes, or full bank-account numbers.

Device, technical, and usage information

  • IP address, browser or device type, operating system, app version, language, time zone, and request timestamps.
  • User, session, APNs push, and VoIP device identifiers.
  • Authentication, security, feature-interaction, and error logs.
  • Notification preferences and delivery status.
  • Cookie, referral, and campaign-attribution information from Yooty websites.

The mobile app does not use third-party advertising SDKs to track users across unrelated apps or websites.

3. How we collect information

We collect information:

  • Directly from business account holders and authorized users.
  • From customers and other people who communicate with a business through a Yooty-enabled channel.
  • From the user's device when the user grants permission or uses a related feature.
  • From a business's connected services and integrations.
  • Automatically through server logs, cookies, and similar technologies.
  • From authentication, communications, payment, mapping, storage, and infrastructure providers.

4. How we use information

We use personal information to:

  • Create, authenticate, administer, and secure accounts.
  • Provide customer management, scheduling, job, calling, messaging, email, payment, notification, and file-storage features.
  • Route communications and show them to the correct business and authorized users.
  • Record and transcribe calls when enabled and lawfully authorized.
  • Calculate travel time and validate or document job-status events.
  • Process payment records through connected payment processors.
  • Provide support, troubleshoot problems, prevent fraud and abuse, and protect the Services.
  • Personalize settings, permissions, language, and the user experience.
  • Analyze and improve reliability, performance, and features.
  • Send service notices and, where permitted, marketing communications to business account holders and business users.
  • Enforce agreements, comply with legal obligations, and establish, exercise, or defend legal claims.

Yooty does not use contact information from a business's customer records to market Yooty directly to those customers. We may market Yooty to business account holders and business users, subject to applicable law and their communication choices.

Google API Services and Google user data

Google connections are optional. Yooty accesses Google user data only after an authorized user chooses a Google feature and grants the permissions requested for that feature. The information accessed depends on the connection the user selects.

Google Sign-In

When a user chooses Google Sign-In, Yooty receives the user's Google Account identifier, name, email address, and basic profile information. Yooty uses this information to authenticate the user, identify the appropriate Yooty account and business, prevent unauthorized access, and connect the Google identity to that account. Yooty stores the Google Account identifier needed to maintain that connection.

Gmail

When an authorized business user connects Gmail, Yooty may access message and thread identifiers, sender and recipient addresses, timestamps, subject lines, message content, labels, and attachments as needed to display and manage the connected business mailbox and perform an email action requested by the user. Yooty stores Gmail message or thread identifiers needed to associate and synchronize email records. Gmail data is not used for advertising, sold, or used to determine creditworthiness.

Google Calendar

When an authorized business user connects Google Calendar, Yooty may access calendar lists and event information such as titles, times, attendees, locations, descriptions, and identifiers. Yooty uses this information to display availability and synchronize Yooty appointments and jobs with the calendar selected by the user. When synchronization is enabled, Yooty may create, update, or delete the corresponding Google Calendar events.

Google Business Profile

When an authorized business user connects Google Business Profile, Yooty may access the Google accounts, locations, business-profile information, reviews, and replies that the user is authorized to manage. Yooty uses this information to display and manage those locations and to let the user review and respond to customer reviews or perform another clearly selected Business Profile action. Yooty stores the Google Business Profile location identifiers and review identifiers needed to associate these records and actions with the correct business and location.

Storage, security, sharing, and retention

Yooty's persistent Google-specific records are limited to the identifiers needed to maintain and synchronize the selected features—including the Google Account identifier, Business Profile location and review identifiers, and Gmail message or thread identifiers—and the OAuth credentials needed to maintain an authorized connection. Google OAuth access and refresh tokens are encrypted at rest and protected by access controls. Other Google data may be processed transiently to provide the user-requested feature or retained as a Yooty business record when an authorized user deliberately saves or submits it to Yooty.

Google user data is disclosed only to service providers that process it for Yooty as necessary to operate a visible, user-facing feature; for security or abuse prevention; when required by law; or as otherwise permitted by Google's policies with any required user consent. Yooty does not permit employees or contractors to read Google user data except with the user's affirmative agreement for support, when needed for security or abuse investigation, when required by law, or when the data has been aggregated for lawful internal operations.

When an authorized business enables or uses an AI-assisted feature for text obtained from a connected Gmail message, the portions of text needed for that feature may be sent to OpenAI solely to provide the visible, user-facing analysis or output selected by the business. This transfer does not occur merely because a user uses Google Sign-In. Yooty does not use Google user data to train generalized artificial-intelligence models.

Google Limited Use. Yooty's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Disconnection, revocation, and deletion

A user can disconnect an available Google integration through Yooty and can revoke Yooty's access from the user's Google Account permissions. Revocation stops future Google API access. After disconnection or revocation, Yooty deletes the associated OAuth tokens. Identifiers or Google-derived information already saved as part of a Yooty business record follow the retention and deletion rules described below. Users may also request account or data deletion as described in the Account and data deletion section.

5. Artificial intelligence features

Yooty may use artificial intelligence to analyze message or other text content, extract suggested customer or job details, translate or summarize information, or generate suggested content.

When the current message-analysis feature is used, Yooty sends the portions of message text needed for that feature to OpenAI for processing. Separately stored contact fields—such as the telephone number associated with a conversation—are not added to the AI prompt merely as context. However, Yooty does not guarantee that personal information has been removed from the message text itself. Messages may contain names, telephone numbers, email addresses, postal addresses, or other personal information, and the feature may identify or extract some of those details. Businesses and users should not include unnecessary sensitive information in content submitted for AI processing.

The current call-recording and call-transcription workflow uses Twilio and does not send call audio to OpenAI.

AI output can be incomplete or inaccurate and should be reviewed by an authorized person. Yooty does not use AI output to make solely automated decisions about employment, credit, insurance, housing, legal rights, or similarly significant matters.

We will update this Policy before materially expanding the personal information processed by future AI features.

6. When we disclose information

The business and its authorized users

We make business-controlled data available to the business account that supplied or received it and to users authorized by that business, according to their roles and permissions.

Service providers and integrations

We use providers to perform services on our behalf or at a business's direction. Depending on enabled features, these providers include:

Provider Purpose and information involved
Hostinger U.S.-based website, application, database, and server hosting; account, content, request, and log data.
Twilio Calling, SMS/MMS, telephone numbers, voice connectivity, call media, recordings, transcripts, and delivery information.
Stripe and Square Payment processing, processor tokens, limited card details, customer identifiers, transaction and payment status.
Google Google Sign-In, Google Maps/geocoding, Gmail, Google Calendar, and Google Business Profile; account and profile information, addresses and map data, email information, calendar and event information, business locations, reviews, replies, identifiers, and encrypted OAuth tokens.
Meta/Facebook Facebook and Instagram sign-in; where a business chooses to connect Meta channels, the account, channel, message, delivery, reaction, and read-status information needed to provide that connection; and, where enabled on Yooty websites, campaign measurement.
OpenAI AI analysis, translation, summarization, extraction, or content assistance using submitted message or other text content.
Amazon Web Services (AWS/S3) Storage and delivery of files, media, recordings, or other service content.
Cloudflare Website and API delivery, security, availability, and performance; IP address, request, device, and security data.
Apple App Store distribution, system permissions, Sign in with Apple where enabled, push notifications, and device services.

These providers may receive only the information reasonably needed for the services they perform. We require providers, through contracts or other appropriate safeguards, to protect personal information consistently with this Policy and applicable law and not to use it for unrelated independent purposes.

Third-party integrations chosen by a business are also governed by the business's relationship with that provider and the provider's own privacy terms.

Legal, safety, and compliance disclosures

We may disclose information when reasonably necessary to comply with law, legal process, or a valid government request; enforce our agreements; detect or prevent fraud, abuse, or security incidents; or protect the rights, safety, and property of Yooty, a business, users, or others.

Business transfers

If the Yooty business is reorganized, financed, sold, merged, or transferred, information may be disclosed as part of that transaction, subject to appropriate confidentiality and continued protection.

7. Sale, targeted advertising, and website cookies

Yooty does not sell personal information for money. The mobile app does not use personal information for cross-context behavioral advertising and does not track users across unrelated apps or websites.

Yooty's websites may use cookies, pixels, referral parameters, or similar technologies for security, functionality, analytics, and measuring the performance of online campaigns. Some U.S. privacy laws define certain disclosures through advertising technologies as a "sale," "sharing," or "targeted advertising" even when no money changes hands. Where those laws apply, you may opt out using an available cookie or privacy control, by enabling a legally recognized browser signal such as Global Privacy Control, or by contacting us at [email protected].

You can also limit cookies through browser settings, although doing so may affect website functionality.

8. Data retention

Our current retention schedule is:

Information Default retention period
Business and user account records While the account is active and, if deletion is requested, during the review period. Verified user-account deletion requests are generally completed within 45 days. Limited residual copies may remain in backups for the period described below or longer where retention is legally required.
Customer, job, schedule, message, attachment, call-metadata, and other business-controlled content While the business account is active or until the business deletes it; remaining active-system copies are removed within 90 days after verified workspace deletion.
Call recordings and transcripts Up to 12 months by default, unless the business selects a shorter or another documented, legally permitted period; no longer than 90 days after workspace termination unless retention is legally required.
Precise job-location event records Up to 24 months after the event.
Invoice, transaction, tax, and accounting records Up to 7 years, or longer if required by law.
Push tokens, VoIP tokens, OAuth connections, and device sessions Until logout, disconnection, revocation, expiration, or account deletion; trusted-device sessions normally expire after 30 days.
Google connection identifiers and encrypted OAuth tokens OAuth tokens are retained only while the Google connection remains authorized and are deleted after disconnection or revocation. Google Account, Gmail message or thread, Business Profile location, and review identifiers retained in Yooty business records follow the applicable business record retention period above.
Security, access, server, and diagnostic logs Up to 12 months.
Backups Up to 90 additional days after deletion from active systems.
Marketing preferences and opt-out records Until the preference changes, plus a minimal suppression record for as long as needed to honor the opt-out.

We may retain information longer when required by law, court order, tax or accounting rules, fraud prevention, security investigation, dispute resolution, or the establishment or defense of legal claims. When deletion is not possible, we restrict the information from ordinary use and delete or de-identify it when the applicable obligation ends.

De-identified information that cannot reasonably be linked to a person may be retained for analytics, security, and service improvement.

9. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These include encrypted network transmission, encryption at rest for stored Google OAuth access and refresh tokens, authentication and authorization controls, role-based permissions, restricted administrative access, server-side credential storage, and device-level protections where supported.

No system is completely secure. Businesses and users are responsible for protecting their credentials, using appropriate device security, limiting team permissions, and promptly reporting suspected unauthorized access to [email protected].

10. Your choices and privacy rights

Depending on your relationship with Yooty and applicable law, you may have the right to:

  • Request access to or a copy of personal information.
  • Request correction of inaccurate information.
  • Request deletion of personal information or an account.
  • Obtain certain information in a portable format.
  • Opt out of certain targeted advertising, sale, or sharing as those terms are defined by applicable law.
  • Withdraw consent where processing depends on consent.
  • Limit certain uses of sensitive personal information.
  • Appeal a denied privacy request.
  • Receive equal service and pricing without unlawful discrimination for exercising a privacy right.

We may verify a request using the account email, an authenticated session, or other information reasonably necessary to prevent unauthorized access or deletion. An authorized agent may submit a request where permitted by law, but we may request proof of authority and direct verification from the individual.

Permission and communication choices

  • Location, camera, photo-library, microphone, biometric-lock, and notification permissions can be changed in iPhone Settings. Disabling a permission may make the related feature unavailable.
  • Connected Google, Facebook, or Apple login methods can be disconnected through available account controls or the provider's settings, subject to maintaining another login method.
  • Google integrations can be disconnected through available Yooty controls or revoked through Google Account permissions. Revocation stops future Google API access and the associated OAuth tokens are deleted.
  • Promotional email may be stopped through an unsubscribe link or by emailing [email protected]. Service and security messages may still be sent while an account remains active.
  • Website cookies can be limited using browser and available website privacy controls.

11. Account and data deletion

Deleting the mobile app from a device does not delete the Yooty account or server records.

How to initiate deletion. A signed-in business user may select Request Account Deletion in the Yooty account menu or, in the iPhone app, open Settings > Request Account Deletion. The request is recorded immediately and made available to an authorized manager of the user's business for review. If the user cannot access the account, the user may instead email [email protected] with the subject "Delete Yooty Account." Include the account email address and business name, but never send a password or full payment-card information.
  • An invited business user may initiate deletion of the user's Yooty login and associated personal profile. Submitting the request does not immediately disable the account; the account remains active while the request is reviewed.
  • An authorized manager may confirm an individual user's request after reviewing outstanding pay, charges, refunds, disputes, assignments, and other obligations. This review is intended to verify and safely complete deletion, not to permit an indefinite or discretionary denial of a verified request.
  • Only an authorized business owner may request deletion of the entire business workspace and its business-controlled data. A business deletion request is recorded for Yooty review and does not cause immediate deletion. Outstanding billing, payment, refund, dispute, subscription, record-retention, and other obligations must be reviewed before workspace deletion is completed.
  • A customer, employee, or contractor whose information is controlled by a Yooty business should contact that business first. If the business is unavailable, the person may contact Yooty and identify the relevant business so we can route or support the request.

An in-app request is acknowledged immediately. We acknowledge email requests within 10 business days and generally complete verified user-account deletion requests within 45 days. We may ask for reauthentication or other confirmation reasonably necessary to prevent unauthorized deletion. If additional time or limited retention is required by law, for fraud or security review, or to resolve a dispute, we will provide the requester with available status information. We will notify the requester when deletion is complete or explain any lawful exception.

Timing for deletion of an entire business workspace may depend on the amount of business-controlled data and the resolution of outstanding billing, payment, tax, accounting, security, dispute, subscription, and legal obligations. Yooty will provide the requesting owner with available status and timing information during that review.

Deletion removes or de-identifies information associated with the account from active systems, subject to the retention schedule above. Records that a business or Yooty must retain for legal, tax, security, fraud-prevention, or dispute purposes may be retained in a restricted form. Where business communications must remain as a legitimate business record, we may remove or de-identify the deleted user's account attribution where reasonably possible.

12. Children and minors

The Services are designed for businesses and authorized workforce users who are at least 18 years old. Yooty does not knowingly create accounts for or market the Services to anyone under 18. Businesses must not invite a user under 18 to the Yooty business app.

If a business stores information about a minor as part of its own customer records, that business is responsible for having all authority, consent, and notices required by law. If you believe an under-18 user has created an account, contact [email protected].

13. United States service and data location

The Services are offered for use in the United States. Yooty's primary hosting is located in the United States. Some providers may process information from other locations as permitted by their agreements and applicable law. By using the Services in the United States, you understand that information will be processed in the United States.

14. Changes to this Policy

We may update this Policy to reflect changes in the Services, providers, data practices, or law. We will post the updated version at https://yooty.app/policy/ and update the "Last updated" date. If a change materially affects how we use personal information, we will provide additional notice when required.

We will update this Policy before launching another feature that materially changes the practices described here.

15. Contact us

Yooty Inc.
495 9th Ave Apt 1C
New York, NY 10018
United States
Email: [email protected]
Privacy Policy: https://yooty.app/policy/