WinnyNo-nonsense AI Front Desk

Privacy

Privacy Policy

This policy explains how Winny handles personal data for the website, admin console, AI front desk, Google sign-in, and calendar integrations.

Last updated: June 15, 2026

Who we are

Winny provides AI front desk software for booking-driven service businesses. This policy applies to heywinny.com, the Winny admin console, public widgets, and connected front-desk workflows.

Questions about this policy can be sent to privacy@heywinny.com.

Data we collect

Account and workspace data: name, email address, business details, role, authentication events, billing state, and support context.

Front-desk data: caller or contact details, call recordings and transcripts when enabled, booking requests, messages, appointments, unresolved work, and handoff notes supplied by a workspace or its customers.

Technical data: device, browser, IP address, log events, security events, and usage metrics needed to run, secure, and improve the service.

Google sign-in and calendar data

If you use Google sign-in, Winny uses Google profile information such as your email address and name to authenticate you and attach you to the correct workspace.

If a workspace connects Google Calendar, Winny accesses calendar events and free/busy information needed to check availability and create, update, or cancel bookings requested through the front-desk workflow.

Winny does not sell Google user data, use Google Workspace API data for advertising, or use Google user data to train generalized AI models. Google data is used only to provide and secure the requested sign-in, calendar, booking, and support functionality.

How we use data

We use data to provide the Winny service, authenticate admins, answer and route customer conversations, coordinate bookings, send notifications, prevent abuse, maintain audit logs, support customers, and comply with legal obligations.

Workspace owners control the business rules, connected systems, retention settings, and customer-facing workflows they configure inside Winny.

Sharing and subprocessors

Winny shares data with service providers only when needed to operate the product, such as hosting, telephony, email, payment, analytics, security, and connected calendar providers.

A workspace may choose to connect third-party systems such as Google Calendar, Microsoft Calendar, email, telephony, or payment tools. Data sent to those systems is governed by the workspace configuration and the third party's own terms.

We may disclose information when required by law, to protect the service, or to prevent fraud or security abuse.

Retention, deletion, and rights

We retain personal data for as long as needed to provide the service, meet security and audit requirements, support configured retention workflows, and comply with legal obligations.

Users and workspace owners may request access, correction, export, or deletion of personal data. Where a business uses Winny for its own customers, that business may be the controller for its customer data and Winny processes it according to the workspace's instructions and applicable agreements.

Security

Winny uses tenant-scoped access controls, authenticated admin sessions, encrypted vendor secrets, audit trails, retention controls, and operational monitoring to protect workspace data.

No internet service is perfectly secure, but we design the product so front-desk data stays bounded to the workspace and the connected systems the workspace authorizes.