This Privacy Policy explains how Genaya LLC ("Genaya", "we", "us", or "our") collects, uses, and shares information when you visit our websites (including genaya.com, help.genaya.com, and engage.genaya.com), use the Genaya platform at app.genaya.com, our mobile apps, the client portal at client.genaya.com, or the affiliate portal at affiliate.genaya.com (collectively, the "Services"). It covers two roles: information we collect and control about you directly (for example when you create an account, visit our sites, or contact us), and "Customer Data" that an organization using Genaya stores in its workspace, which we process on that organization's behalf and under its instructions. If you are a customer, client, or patient of a business that uses Genaya, that business is responsible for its use of your information; see the "Customer Data and your organization" section below.
1Information you provide to us
Account and profile information: name, email address, password, phone number, profile photo, organization name, industry, approximate revenue range, team size, and how you heard about us, collected at signup and during onboarding.
Team member information: organizations may add member profiles including name, email, phone, home address, bio, photo, role, permissions, assigned companies and service areas, compensation settings (such as hourly rates, commissions, and deductions), and timesheet entries.
Business and compliance information: to register business texting (A2P 10DLC) and caller-ID trust services, we collect your business legal name, tax ID (EIN), business address, and an authorized representative's name, email, and phone, and share them with our carrier and registration providers. For tax reporting features, payee tax identification numbers are collected and stored encrypted.
Payment and identity verification information: when you subscribe, our payment processor (Stripe) collects your payment card details; we store payment-method metadata such as card brand and last four digits. When you enable GenayaPay, we and Stripe process identity and banking information required to provide payment services and meet financial requirements, including legal name, date of birth, government ID numbers, verification documents, bank account holder details, routing and account numbers, and payment-method identifiers. Bank information may be provided by you, through a bank connection, or by an authorized representative to process an authorized debit. Genaya does not store full card numbers.
Bank-debit and recovery records: we process bank information to verify accounts, carry out authorized ACH debits, and reconcile obligations arising from refunds, disputes, chargebacks, payment reversals, ACH returns, actual losses from fraudulent or unauthorized transactions for which an Organization is responsible, and disclosed fees. For bank-login connections, Stripe supplies payment references, routing information, and masked bank details; its standard linking integration does not provide Genaya with the readable full account number. We retain the available bank-link data in a separate encrypted bank record, along with limited masked display information and authorization and transaction records. Full account numbers entered for a manual ACH fee are transmitted to Stripe and are not retained by that manual-fee feature. This Privacy Policy explains data handling and does not itself authorize a debit or expand an existing mandate.
Payment review and payout records: we process transaction and payment-method information, balances, payout-bank references, verification evidence, dispute and return records, account restriction status, processor notices, support correspondence, and records of decisions about holds or releases. These records may relate to card, ACH, financing, and other supported payment methods, including after a payment account is restricted, rejected, or closed.
Communications with us: demo requests, contact and support forms (name, email, company, message), help tickets, and in-app feedback, which may include screenshots you attach.
Affiliate program information: affiliate applicants provide name, email, website and social handles, audience details, and payout details (such as PayPal, bank, or other payout identifiers), which are processed with our affiliate platform provider.
2Information collected automatically
Usage and device information: pages viewed, features used, actions taken, browser and device type, operating system, app version, language, and timestamps.
Log and network information: IP address and approximate location derived from it. For signed-in team members, we resolve IP-based approximate location (city-level) to power security alerts about new sign-ins and, where your organization uses it, the live team presence map. On public contact forms we store only a one-way hash of the IP address for rate limiting, not the raw address.
Cookies and similar technologies: we and our analytics and advertising providers use cookies, local storage, and similar technologies to keep you signed in, remember preferences, measure site usage (Google Analytics), measure advertising campaigns on our public pages (Meta Pixel - unless you opt out, see the Cookies section below and genaya.com/privacy-choices), protect forms (Google reCAPTCHA), and attribute signups to marketing campaigns and affiliate referrals (including UTM parameters, referrer, ad click identifiers, and referral identifiers). See the Cookies section below.
3Customer Data processed for organizations
Organizations use Genaya to run their operations, and the records they store are Customer Data. We process it on the organization's behalf to provide the Services. Depending on how the organization uses Genaya, Customer Data can include:
- Client, patient, and contact records: names, phone numbers, email addresses, physical addresses (which we geocode to map coordinates), notes, tags, lead sources, and custom fields.
- Work records: appointments, projects, estimates, invoices, expenses, payments, and files attached to them.
- Communications content: SMS/MMS messages and media, emails, live chat conversations with website visitors, Facebook Messenger and Instagram messages routed into the shared inbox, and voicemails.
- Call data: call logs (numbers, duration, status), call recordings, live transcriptions, and caller-ID name lookups.
- Video meetings: room participants, and where the organization enables it, meeting recordings and transcripts, including AI-generated meeting summaries and action items.
- Public engagement data: reviews, booking requests, form and survey submissions collected through the organization's public pages on engage.genaya.com, and client portal activity.
- Payment records: transactions the organization's customers make through GenayaPay (processed by Stripe; we store transaction metadata, not card numbers).
4Call recording, transcription, and messaging content
Organizations can enable call recording, voicemail, and live transcription. Recordings and transcripts are stored as part of the organization's Customer Data and are accessible only to workspace members with the right permissions. The organization is responsible for obtaining any legally required consent from call and meeting participants; where configured, an audible recording notice is played to callers. Transcription is performed by our communications carrier using a speech-to-text engine (currently Deepgram, engaged through Telnyx). Message content sent or received through the platform (SMS/MMS, chat, social messaging) is processed and stored to deliver the conversation features.
5How we use information
We use information to:
- Provide and operate the Services: scheduling, calling and messaging, payments, video, analytics, search, file storage, and AI features.
- Secure the platform: authenticate users, send sign-in verification codes, detect and prevent fraud and abuse, enforce role-based access within each organization, and alert you to new sign-ins.
- Bill and manage accounts: subscriptions, plan limits, metered usage, bank verification, encrypted bank-record storage, authorized bank debits, and recovery and reconciliation of amounts owed for payment disputes, chargebacks, refunds, reversals, ACH returns, and applicable transaction losses and disclosed fees. We use payment, bank-link, and authorization records to validate debits, assess documented payment risk, administer permitted payout holds and reserves, account for prior recoveries, and investigate errors or disputed debits.
- Administer payment reviews and refunds: determine eligibility for the GenayaPay card-refund feature, assess and reassess holds and reserves, respond to processor or bank review requests, reconcile amounts applied to a balance, and arrange an approved payout of the remaining eligible funds to the bank on file. Refund eligibility and payout-hold rules are described in Section 8 of the Terms of Service at genaya.com/terms. A displayed available balance or a review period does not guarantee a payout. This Privacy Policy explains information use; it does not independently authorize a hold, refund, or bank debit.
- Support you: respond to requests, troubleshoot, and improve documentation.
- Improve and develop the Services: understand aggregate usage, diagnose errors, and build new features. We may create aggregated or de-identified data from any information we hold and use or disclose it without restriction; we do not attempt to re-identify it.
- Market our own services: send product news and offers where permitted, measure campaigns, and run our affiliate and referral program. You can opt out of marketing at any time.
- Comply with law: meet legal, tax, accounting, and regulatory obligations, and enforce our agreements.
6AI features and model providers
Genaya's AI features (the Genaya AI assistant, AI Receptionist, smart parsing, content generation, and call and meeting intelligence) send the relevant context - such as the question you ask, the record you are viewing, pasted text, or a conversation transcript - to our AI model providers, currently OpenAI and Anthropic, to generate the response. We send the minimum context needed for the feature, we do not send credential collections or masked phone-number records to AI features, and our providers process API data under terms that do not permit them to use it to train their generally available models. AI usage is metered and governed by your plan.
8Integrations you connect
If your organization connects a third-party integration or runs a data import (for example QuickBooks, Xero, Salesforce, HubSpot, Jobber, Housecall Pro, ServiceTitan, Square, Calendly, Google Contacts, Microsoft 365, and similar providers), we access and transfer the data you direct us to, and we store the connection credentials securely. Those providers process your data under their own privacy policies, and connecting them is your choice. Disconnecting an integration stops future syncs.
9Other disclosures
We may disclose information: to comply with law, subpoena, or legal process; to enforce our agreements and protect the rights, property, safety, and security of Genaya, our users, and the public; to our professional advisors (lawyers, accountants, auditors, insurers) under confidentiality obligations; to debt collection providers for amounts owed to us; and in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, in which case personal information may be transferred to the successor entity subject to this policy or one that is at least as protective, and we will notify you of material changes.
10SMS program terms
When you provide your phone number to Genaya (for example by creating an account or submitting a form that references this policy), you agree to receive communications from Genaya by phone, SMS, and email, including account and security notifications (such as sign-in verification codes) and, where you have consented, marketing messages. Message frequency varies. Message and data rates may apply; check with your mobile carrier. Carriers are not liable for delayed or undelivered messages.
Your mobile information - including a phone number you give us for SMS and the fact that you opted in - is never sold, rented, or shared with third parties or affiliates for their own promotional or marketing purposes. We share it only with the service providers who deliver the messages on our behalf (our telecommunications carriers and messaging providers), and only so they can send them, or where the law requires it.
Opt out of SMS at any time by replying STOP to any message; you may receive a final message confirming your opt-out. Reply HELP for help, or contact us at help@genaya.com. Opting out of marketing does not stop transactional messages necessary to operate your account, such as verification codes you request. Consent to marketing messages is not a condition of purchasing any goods or services.
Separately, organizations use Genaya to send their own messages to their own customers. The organization is the sender of those messages, is responsible for obtaining recipient consent and honoring opt-outs, and must comply with applicable law and carrier rules, as described in our Terms of Service.
12Customer Data and your organization
The organization that operates a Genaya workspace is the controller of, and responsible for, the Customer Data it stores - including deciding what to collect from its customers, enabling recording or messaging, and honoring privacy requests. If you are a customer, client, patient, or contact of an organization that uses Genaya and you want to access, correct, or delete information about you, contact that organization directly; we support organizations in honoring those requests. If you contact us about Customer Data, we may refer your request to the organization.
Note for workspace members: your organization's owner and administrators control the workspace and can see activity and records within it consistent with the permissions they configure, including presence, timesheets, and communications handled through the workspace.
13Data retention
We keep information for as long as your account is active or as needed to provide the Services, comply with legal, tax, and accounting obligations, resolve disputes, prevent fraud and abuse, and enforce agreements. Telephone numbers assigned to your account are held for 14 days after cancellation and are then released back to the underlying carrier, as described in our Terms of Service. Numbers are also released if a subscription payment goes unpaid: your workspace is locked 14 days after a failed charge and your numbers are released 16 days after it, unless the amount is paid before then. A released number cannot be recovered and may be reassigned to someone else. After cancellation, we retain your workspace data for a 30-day export window (except where an account is terminated for cause, as described in our Terms of Service); during that window you can reactivate your subscription to access and export your data, or contact help@genaya.com to request an export, and we then delete or de-identify Customer Data on a scheduled basis. Backups are purged on a rolling schedule (see the deletion section below). Some records are retained longer where the law requires it - for example billing and tax records - or where retention is needed for suppression lists that record who opted out of communications.
Bank information and authorization records may be retained while the bank connection is active and for as long as reasonably necessary to settle outstanding transactions, address disputes or returns, maintain required accounting and authorization evidence, prevent fraud, or comply with legal obligations. Linked banks cannot be removed through payout settings. Contact help@genaya.com to request disconnection, authorization revocation, account closure, or exercise data rights. When disconnection or revocation takes effect, new use is restricted accordingly; records that must be retained for the purposes above are not immediately erased. Retained records remain protected and are deleted or de-identified when those purposes and applicable retention requirements end.
Restriction and review records may be retained after account suspension, rejection, closure, or a payout for as long as reasonably necessary to complete pending reviews or transactions, address potential or actual disputes and returns, document a release or recovery, or meet legal and accounting duties. A payout hold or a processor review period is not an automatic data-deletion deadline and does not authorize indefinite retention unrelated to these purposes. We limit retention to the relevant information and applicable requirements, subject to your nonwaivable privacy rights.
14Security
We protect information with administrative, technical, and physical safeguards appropriate to its sensitivity, including encryption in transit, tenant isolation, role-based access control, hashed portal and API access tokens, and field-level encryption for tax identifiers and stored sensitive bank-link data. Bank records use authenticated encryption with a dedicated server-side key, and are separated from ordinary application records and search/AI data access. Only authorized server processes can decrypt those records for the stated purposes; customer-facing screens use masked details. Encryption does not grant authority to debit an account or guarantee that a payment will succeed. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. Use a strong, unique password, keep sign-in verification enabled, and configure workspace permissions carefully.
15International data transfers
We are based in the United States and process information on servers located in the United States. If you use the Services from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate, which may have data-protection laws different from those of your jurisdiction. Where required by applicable law, we rely on appropriate safeguards for such transfers, such as standard contractual clauses with our service providers.
16Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. To exercise these rights for information Genaya controls, email help@genaya.com from the email address associated with your account; we may need to verify your identity before acting and will respond within the time required by law. You may authorize an agent to act for you, subject to verification. We will not discriminate against you for exercising your rights. For Customer Data, contact the organization that holds your records. If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your local supervisory authority.
17United States state privacy rights
If you are a California resident, please see our California Privacy Notice at genaya.com/california-privacy for disclosures required by the California Consumer Privacy Act (as amended by the CPRA), including the categories of personal information we collect and your California rights. We do not sell personal information for money. Our use of the Meta advertising pixel on public pages may be considered "sharing" for cross-context behavioral advertising under the CCPA; you can opt out at genaya.com/privacy-choices or with a Global Privacy Control browser signal.
Residents of other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others) may have similar rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, or certain profiling. We do not sell personal data. Where our advertising measurement qualifies as "targeted advertising" under those laws, you may opt out at genaya.com/privacy-choices, and we honor Global Privacy Control. To exercise your rights, or to appeal a decision we make about your request, email help@genaya.com.
18Children
The Services are for businesses. Account holders must be at least 18 years old, and the Services are not directed to children under 16. We do not knowingly collect personal information from children under 16 for our own purposes; if we learn that we have, we will delete it. Organizations that store information about minors in Customer Data (for example a family member on a client record) are responsible for having the right to do so.
19Account and data deletion
You can delete your Genaya account and the personal information we control at any time.
To request deletion: email help@genaya.com from the email address on your account with the subject "Delete my account". We will verify the request and confirm by email.
What happens next: we deactivate the account after verification and delete or de-identify the personal information we control from our active systems within 30 days. Residual copies in encrypted backups and derived data stores (such as analytics mirrors and search indexes) are purged or overwritten on a rolling schedule, typically within 90 days. We may keep limited records where the law requires it, for example billing and tax records, suppression-list entries recording your opt-outs, and information needed to resolve disputes or enforce our agreements.
Organization workspaces: if you are an organization owner, deleting your workspace removes the organization's Customer Data on the same schedule, after the export window described in the Data retention section. If your information is stored in a workspace owned by another organization (for example you are their client or contact), contact that organization directly; we support them in honoring deletion requests.
If you signed in with Facebook, Google, or Apple: you can disconnect Genaya from your provider at any time (for Facebook: Settings and Privacy -> Settings -> Apps and Websites). Disconnecting stops future data sharing; to delete the information Genaya already holds, follow the steps above.
20Third-party sites
The Services may contain links to third-party websites and services we do not operate, and organizations may embed Genaya features (such as chat widgets or booking pages) on their own sites. We are not responsible for the content or privacy practices of third parties; review their policies before providing information to them.
21Changes to this policy
We may update this policy at any time and at our sole discretion, including to reflect changes to the Services, to our vendors and subprocessors, or to applicable law. If a change is material we will give reasonable notice, for example by email or an in-product message, before it takes effect. The date above identifies this version, and prior versions are available on request. For existing users, material changes apply only after the required advance notice and the effective date stated in that notice. Updating this policy does not itself create or expand a bank-debit authorization. Each time this policy is updated, your continued use of the Services after that version takes effect for you means this policy, as updated, forms part of your continuing agreement with Genaya under our Terms, subject to the notice and effective-date requirements above and applicable law. No new signature is required unless applicable law requires separate affirmative consent. Where applicable law requires consent for a new or changed use of personal information, including a materially different use of previously collected information, we will obtain that consent before that use; continued use alone does not supply it. An update does not override your privacy choices or waive nonwaivable rights. If you do not agree to an update, stop using the Services and close your account before it applies to you.
22Contact us
Privacy questions or requests? Email us at help@genaya.com. We are Genaya LLC, and we act as the business (controller) for the information described in this policy other than Customer Data, which we process on behalf of the organization that stores it.