Skip to content
ClientAhead ClientAhead
  • Platform Shopify apps

    Focused software that works with the Shopify operations merchants already run.

    calendar_month Bookimatic Conversational appointment booking In development receipt_long Recoup Supplier-credit tracking Early pilot
    Future platforms

    New categories will appear as the product line grows.

    WooCommerce WordPress Mobile
  • menu_book Bookimatic DocsSetup, product guidance and answers arrow_outward support_agent SupportHelp across the ClientAhead product line arrow_outward
    Changelog Planned API reference Planned
  • How we build
apps Explore products
Home / Privacy Policy

ClientAhead legal

Privacy Policy

A product-specific explanation of the information ClientAhead handles, why we use it, how long we keep it and how to exercise privacy rights.

Last updated
14 August 2026
Applies to
ClientAhead website, Bookimatic and Recoup

On this page

  1. Scope and roles
  2. Information we handle
  3. How we use information
  4. Service providers and sharing
  5. Retention
  6. Security
  7. Your privacy rights
  8. Shopify, AI and Google services
  9. International processing
  10. Changes and contact
Privacy contact Email ClientAhead [email protected]

Plain-language commitment

The policy follows the products we actually operate.

Bookimatic and Recoup have different data flows and are at different release stages. This policy describes those differences rather than applying a generic promise to every ClientAhead product.

1. Scope and roles

This Privacy Policy applies when you visit ClientAhead.com, email ClientAhead, use Bookimatic or participate in the Recoup early pilot. It covers website visitors, merchant users, prospective pilots, people whose booking information is handled through Bookimatic, and supplier contacts whose details a merchant may enter into Recoup.

ClientAhead acts as the controller of its own website, inquiry and business-contact information. When a merchant uses a ClientAhead app to handle information about its customers, suppliers or team, that merchant controls the purpose of that information and ClientAhead processes it to provide, secure and support the relevant app. A merchant remains responsible for its own customer notices, policies and lawful basis for using the app.

2. Information we handle

We handle only the information needed for the website, a product workflow or a legitimate operational purpose. This can include:

  • Website and contact information: the details and message you send by email, plus connection and security information that our hosting or security providers may process to deliver and protect the site.
  • Merchant and account information: store domain, merchant or administrator details, Shopify authentication/session information, app settings and product configuration.
  • Bookimatic information: services, locations, schedules, customer booking records, name, at least an email address or phone number, selected time, booking/payment or refund status, consent timestamp, optional intake answers, conversations, cancellations and waitlist details. Shopify checkout—not Bookimatic—collects payment card details.
  • Recoup information: supplier name and optional email, claim and credit records, RMA, purchase-order and invoice references, notes, dates, selected Shopify product or variant identifiers, titles and SKUs. Recoup does not intentionally request Shopify customer, order, payment or checkout data. Free-text notes can contain anything a merchant enters, so merchants must not enter customer data, card data, credentials or sensitive information there.
  • Operational information: security, rate-limit, audit, delivery and privacy-request records needed to operate, investigate and protect a product.

3. How we use information

We use information to operate and improve the relevant ClientAhead product, authenticate merchant users, create or manage booking and supplier-credit workflows, send requested transactional notices, respond to support or privacy requests, prevent abuse, troubleshoot incidents and meet legal obligations.

Bookimatic uses AI-assisted text interpretation only within the merchant-configured receptionist workflow. Obvious email, phone, payment-card and secret patterns are minimized before AI processing, but names, free text and merchant context can remain. Do not submit payment credentials, secrets, or sensitive medical, legal or children’s information through Bookimatic chat or intake fields.

The current website and product code do not include behavioural advertising or tracking integrations designed to build advertising profiles from merchant or customer information.

4. Service providers and sharing

We share information only where it is needed to operate a product or where law requires it. Depending on the product and the options a merchant enables, this can include:

  • Shopify: the platform used to authenticate merchants and provide the Shopify data required by Bookimatic or Recoup.
  • Bookimatic optional services: Google Calendar for an authorized calendar connection; Resend for transactional booking email; and the merchant-selected AI provider supported by Bookimatic, currently Anthropic or DeepSeek, for AI-assisted text interpretation.
  • Infrastructure and security providers: providers that host, deliver, monitor or protect the application and its supporting services.
  • Legal or safety recipients: regulators, courts, professional advisers or other parties where disclosure is required or reasonably necessary to protect rights, safety or the service.

Recoup’s current pilot scope does not include advertising, email automation, AI, accounting integrations or supplier messaging.

5. Retention

We retain information for no longer than the relevant purpose, product relationship or legal requirement requires. The current product rules are intentionally specific:

  • Website inquiries: retained for as long as needed to respond, maintain a business record or meet a legal obligation.
  • Bookimatic: chat content is redacted after 30 days; final email-delivery records are deleted after 90 days; booking contact and intake information is redacted or deleted on the default 24-month / 730-day schedule, subject to merchant configuration; and privacy exports expire after 30 days. Some booking, financial, audit, compliance or backup records can remain where necessary.
  • Recoup: Recoup is an early pilot and does not yet publish a fixed automated post-uninstall deletion period. Pilot claim records remain for the active pilot or account relationship unless a merchant asks us to delete them or a legal retention need applies. We will publish a consistent retention and redaction process before Recoup is submitted for public App Store distribution.

Uninstalling Bookimatic suspends its tenant and removes the Shopify session; uninstalling Recoup removes its Shopify session. Uninstall alone is not presented as an instant deletion promise for every product record.

6. Security

We use technical and organisational measures designed for the information and product stage involved. These include HTTPS in production, tenant separation, Shopify-managed authentication, restricted session cookies, redacted application logs and security controls that limit access to the intended merchant context.

Bookimatic also encrypts specified sensitive application fields, including contact fields, selected intake and conversation content, Calendar tokens and email-delivery destinations, and uses hashed lookup identifiers. These measures do not mean that every record or backup is encrypted in the same way. We do not claim security certifications or an absolute guarantee against every risk.

7. Your privacy rights

Depending on where you live and the information involved, you may have rights to request access, correction, deletion, restriction, objection or portability. To make a request, use the privacy contact shown on this page and identify the product, merchant/store (if relevant), the information involved and the request you are making.

We verify identity and authority before acting, and may need to involve the merchant that controls customer or supplier information. A merchant administrator can also use the relevant Shopify process where applicable. See our Data Rights & Deletion page for the request process and current product boundaries.

8. Shopify, AI and Google services

Bookimatic registers the Shopify privacy-compliance webhooks used for applicable customer access, customer redaction and shop-redaction requests. Its privacy exports are temporary and available only to an authenticated merchant administrator. Recoup is still an early pilot and is not ready for public App Store distribution; ClientAhead will implement and document Recoup’s equivalent data-request, redaction and shop-deletion workflow before making a public submission.

Bookimatic can use an optional Google Calendar connection when a merchant authorizes it. It accesses the authorized account email, available calendars and availability information to identify the connection and check availability; it creates or manages Bookimatic booking events with service and time information rather than customer contact details. Encrypted OAuth tokens and a hashed account-email identifier are kept while the connection remains active. It does not claim real-time two-way calendar sync. No ClientAhead product currently accesses the Google Ads API or Google Ads data. Before any future Google or Google Ads integration accesses user data, ClientAhead will publish a specific disclosure and obtain the required authorization.

9. International processing

ClientAhead is based in Pakistan and uses service providers that may process information in other countries. Those countries may have data-protection rules that differ from the rules where you live. When a transfer mechanism or additional safeguard is required by applicable law, we will use one appropriate to the processing involved.

If you are a merchant and need information about a particular product’s processing locations or service providers for your own privacy documentation, contact us before enabling that product or integration.

10. Changes and contact

We may update this policy as ClientAhead products, integrations or legal requirements change. Material changes will be posted here with a new last-updated date, and we will provide additional notice or obtain consent where applicable.

For privacy questions or requests, use the email contact shown on this page. Please include enough detail for us to locate the relevant product and verify your authority to make the request.

Related legal pages

Privacy Policy Terms of Service Data Rights & Deletion Cookie Policy

Privacy questions

Need help with your data?

Email ClientAhead with the product, store and type of request so we can route it correctly.

Email ClientAhead↗
ClientAhead ClientAhead

A growing portfolio of focused software for commerce operations.

Solutions
Shopify apps Bookimatic Recoup More platforms as products are ready
Resources
Bookimatic Docs Support Changelog — Planned
ClientAhead
Home How we build Explore all products
Product status
Bookimatic — in development Recoup — early pilot Product support
Global | English
© 2026 ClientAhead
Sitemap Privacy Terms Data rights Cookies Email ClientAhead Pre-launch product site