Privacy Policy
Last reviewed: 2026-08-28.
This policy describes how RunYourHub ("RunYourHub", "we", "us") handles personal data through the RunYourHub application (app.runyourhub.com) and this website.
1. Who operates RunYourHub
RunYourHub is currently operated by Paulo Carreira, an individual established in Portugal. RunYourHub is the commercial name of the software service.
RunYourHub is a B2B platform used by service businesses ("account owners" and their staff) to manage bookings, calendar, customers, messaging and payments. Those businesses' own clients ("end customers") also have data processed through the platform, as described below. For data relating to your own RunYourHub account, RunYourHub acts as controller where applicable. For data about a business's end customers that is entered into or processed through the platform, the business is normally the controller of that data and RunYourHub acts as processor on the business's behalf, to the extent applicable under data-protection law.
2. Information we collect
2.1 Account data
When you create a RunYourHub account, we collect your email address, a display name, and — if you sign in with Google — basic profile information provided by Google OAuth. Authentication is handled by our infrastructure provider, Supabase (see §4).
2.2 Business and tenant data
Account owners configure business information for their own space (business name, working hours, products/services offered, team members and their roles).
2.3 End-customer data (bookings, calendar, CRM)
When a business uses RunYourHub, it stores information about its own clients: name, email, phone number, booking/appointment details, and notes the business adds.
2.4 Messaging (Instagram / WhatsApp)
If a business connects its own Instagram or WhatsApp account, RunYourHub stores the messages exchanged with that business's clients (text, media, timestamps, delivery status) so the conversation can be shown inside the app. Profile pictures of contacts may be cached from Instagram/Meta to display avatars reliably.
2.5 Payments
Card and other online payment details are collected and processed directly by Stripe, our payment processor — RunYourHub's servers do not receive or store full card numbers. We store payment records relevant to a booking (amount, status, timestamps, a reference to the Stripe payment) and, when a customer pays, the name/email/phone they provide at checkout.
2.6 Technical/operational logs
Our servers keep standard operational logs (errors, request metadata) for maintaining and debugging the service. These are technical logs, not an analytics or tracking system. They are kept only for as long as needed for the operation, security, troubleshooting and legal-compliance purposes described in §8; different categories of logs may be kept for different periods.
3. How we use this information
- To provide the core functionality of the platform: authentication, bookings, calendar, customer records, messaging and payments.
- To let a business's team reply to Instagram/WhatsApp conversations, optionally with AI-generated draft responses or conversation summaries (see §4 — AI providers).
- To process payments and booking deposits through Stripe.
- To keep the service secure and to diagnose technical issues.
- To record acceptance of our Terms of Service and this Privacy Policy when you accept them in the app.
We do not sell personal data, and we do not currently use advertising or third-party behavioural tracking pixels on the RunYourHub website or application.
4. Third parties we work with (subprocessors)
The following third parties process data on our behalf, strictly to provide the corresponding feature. We only send them what each feature requires.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, real-time messaging infrastructure | All application data described in §2 |
| Stripe | Payment processing (bookings, deposits, platform billing) | Payment details, payer name/email/phone, transaction records |
| Google (Google Calendar) | Calendar sync, when a user connects their Google account | Calendar events the user chooses to sync — see §5 |
| Meta (Instagram & WhatsApp) | Messaging with a business's own clients | Messages, media, contact profile info made available by Meta's APIs |
| ManyChat | Delivery of certain outgoing messages to a business's clients | Message content for the flows routed through it |
| OpenRouter (primary) / OpenAI (fallback) | AI-generated reply suggestions and conversation summaries, when a business enables this feature | The relevant conversation text sent for that specific request |
RunYourHub uses third-party providers which may process data in different jurisdictions. Appropriate contractual and data-protection arrangements are used with these providers where required by applicable law.
5. Google Calendar integration
Connecting a Google Calendar account is entirely optional and only happens if a user explicitly authorizes it through Google's own OAuth consent screen. Google data obtained through this integration is used solely to provide calendar synchronization inside RunYourHub — reading and writing the calendar events needed for that feature. We do not sell Google user data, and we do not use it for advertising. Disconnecting the Google Calendar integration revokes RunYourHub's access token with Google and prevents any further access or synchronization; it does not retroactively delete calendar data already legitimately stored in RunYourHub before the disconnection, which remains subject to this Privacy Policy. RunYourHub's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Legal bases (GDPR)
Where the GDPR applies, we rely on the following legal bases, depending on the specific processing activity:
- Performance of a contract — account creation, authentication, and providing the core service you or your business have signed up for.
- Legitimate interests — security, fraud prevention, operational reliability, debugging and service improvement, where these interests are not overridden by your data-protection rights.
- Legal obligations — records or information that must be retained or processed to comply with applicable law.
- Consent — only where consent is the appropriate legal basis for a specific optional processing activity. AI-assisted reply suggestions are provided as a feature of the service to the business using RunYourHub, under performance of contract/legitimate interest; where a distinct consent flow is introduced for a specific optional processing activity in the future, it will be described here.
7. Cookies and local storage
RunYourHub itself does not set advertising or analytics cookies. The application keeps your sign-in session as a token in your browser's local storage, not in a cookie. Payment pages load Stripe's own checkout scripts (Stripe.js/Elements) directly from Stripe, which may set cookies on Stripe's own domain for fraud prevention and payment processing purposes, under Stripe's own privacy practices — these are not set by RunYourHub. This website (runyourhub.com) does not set any cookies.
8. Data retention and deletion
We keep personal data for as long as an account is active and the data is needed to provide the service, and for as long as afterwards may be necessary to comply with legal obligations, resolve disputes, maintain security, and support other legitimate operational needs described in this policy. Data may be deleted or anonymized once it is no longer needed for these purposes, subject to any applicable legal retention requirements.
When an account owner removes a team member permanently, both the team member's profile and their authentication account are deleted — as opposed to deactivation, which is reversible and keeps history intact.
You can request deletion or export of your data at any time by contacting info@runyourhub.com.
9. Your rights
Depending on where you are located, you may have the right to access, rectify, erase, restrict or object to the processing of your personal data, to receive a copy of it in a portable format, and — where processing relies on consent — to withdraw that consent at any time. For data related to a specific business's customers, these requests are generally directed to that business first, since it controls its own customer data; for your own RunYourHub account data, contact us directly at info@runyourhub.com.
You also have the right to lodge a complaint with a data protection supervisory authority. In Portugal, this is the Comissão Nacional de Proteção de Dados (CNPD).
10. International data transfers
When personal data is transferred outside the European Economic Area, RunYourHub relies on transfer mechanisms or safeguards required by applicable data-protection law, where applicable.
11. Contact
Questions about this policy or your data: info@runyourhub.com.
12. Changes to this policy
We may update this policy as the product changes. Material changes will be reflected here with an updated review date.