Effective Date: January 25, 2026 · Last Updated: January 25, 2026
HiLucy ("we," "our," or "us") operates a SaaS platform for hospitality and short-term rental management, including an AI-powered concierge service. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our services.
This policy applies to:
HiLucy
10205 S Komensky Avenue
Oak Lawn, IL 60453, USA
Contact for Privacy Inquiries: privacy@hilucy.com
For EU residents: eu-privacy@hilucy.com
| Category | Examples | When Collected |
|---|---|---|
| Identity Data | Name, nationality, date of birth, ID document details | Guest check-in |
| Contact Data | Phone number, email address, WhatsApp ID | Registration, check-in |
| Location Data | Country/city of residence, shared location | Check-in, chat |
| Communication Data | Messages, requests, preferences | AI chat interactions |
| Payment Data | Card details (via Stripe), billing address | Service purchases |
| Booking Data | Check-in/out dates, room type, guest count | Reservations |
| Category | Examples | Purpose |
|---|---|---|
| Technical Data | IP address, browser type, device info | Security, analytics |
| Usage Data | Pages visited, features used, timestamps | Service improvement |
| Cookie Data | Session cookies, preference cookies | Authentication, UX |
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide AI concierge service | Contract performance |
| Process guest check-ins | Contract performance |
| Process payments | Contract performance |
| Send service notifications | Legitimate interest |
| Improve services | Legitimate interest |
| Comply with legal obligations | Legal obligation |
| Send marketing communications | Consent |
We share your data with the following categories of service providers:
| Provider | Data Shared | Purpose |
|---|---|---|
| OpenAI | Conversation content | AI processing |
| Meta (WhatsApp) | Phone, messages | Messaging |
| Stripe | Payment details | Payment processing |
| Google Cloud | Location, language | Translation, maps |
All subprocessors are bound by Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs) where applicable.
| Data Type | Retention Period |
|---|---|
| AI conversation history | 30 days |
| Guest check-in data | Booking duration + 30 days |
| User account data | Until account deletion |
| Payment records | 7 years (legal requirement) |
| Booking records | 2 years post-checkout |
| Technical logs | 30 days |
To exercise your rights, email privacy@hilucy.com. We will respond within 30 days (GDPR) or 45 days (CCPA).
We protect your data through:
We use essential cookies for authentication and session management. For analytics and marketing cookies, we obtain your consent before setting them. You can manage cookie preferences through your browser settings.
Our AI concierge (Lucy) uses OpenAI GPT-4o-mini to process your messages. AI-assisted routing and recommendations are not legally significant automated decisions. You may request human review of any AI interaction at any time.
Our services are not directed to individuals under 16 years of age. We do not knowingly collect data from children.
We will notify you of material changes via email or in-app notice at least 30 days before they take effect.
Privacy inquiries: privacy@hilucy.com
General support: support@hilucy.com