R2PR2PBack to site

Privacy Policy

Effective August 30, 2026

R2P runs a WhatsApp assistant that takes gym and physiotherapy booking requests, plus a staff dashboard where our team reviews and acts on them. This page explains what we collect when you message us, what we do with it, and how you can control it — and, in section 4, what a staff member's optional Google Calendar connection gives us access to.

1. What we collect

When you message the business on WhatsApp, we receive and store:

  • Your name and WhatsApp phone number, as provided by WhatsApp itself
  • The content of your messages — typed text and/or voice notes
  • For physiotherapy inquiries: the condition or injury you describe, kept in your own words rather than paraphrased, since for physio it doubles as the first clinical note
  • The service, branch, and day/time you ask for or are offered
  • The language(s) you write or speak in
  • Message timestamps

2. How we use it

A purpose-built assistant reads each message — including voice notes directly, without a manual transcription step — and turns it into a structured booking request: service, branch, day, time, and (for physio) the condition described. We use that to:

  • Understand and act on your booking request
  • Reply to you on WhatsApp, propose appointment times, and confirm bookings
  • Send appointment reminders ahead of a confirmed booking
  • Hand off to a staff member when something falls outside booking intake
  • Give our staff a record to review before they contact you

3. Voice notes specifically

If you send a voice note, the audio itself is stored for a limited time — it can contain your voice and, for physio, a spoken injury description tied to your phone number, so we treat it as sensitive. By default it is kept for 90 days and then permanently deleted by an automated job; a branch can configure this window shorter, or to never store audio at all. While retained, audio is reachable only through an authenticated, staff-only link scoped to the branch you messaged — it is never public.

4. Google Calendar (staff connections)

A staff member of the business can optionally connect their own Google Calendar to R2P, so that confirmed bookings appear on the calendar they already work from and so the assistant can avoid offering a time they are already busy. This is opt-in, per staff member, and initiated from the staff dashboard — customers messaging on WhatsApp are never asked to connect anything, and no customer's Google account is ever involved.

When a staff member connects, we request exactly two Google permissions and no others:

  • See and edit events on your calendars (calendar.events) — used only to create and update the calendar entry for a booking made through this platform. Each entry carries the service, the customer's name, the branch, the booking status and, where the customer gave one, their note. We do not read, copy, store or analyse the staff member's other calendar events.
  • See your availability (calendar.freebusy) — used only to check which blocks of time are already busy before the assistant offers a slot to a customer. This returns busy/free periods only; it does not expose event titles, guests, locations or any other event content, and we do not retain the result beyond the moment of offering times.

What we store from this connection is the Google OAuth access and refresh tokens, encrypted at rest (AES-256-GCM), together with the connection date, the granted permissions and which calendar to write to. We do not store the contents of the staff member's calendar.

Limited Use. R2P's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: we use Google user data only to provide and improve the booking features described above; we do not transfer it to others except as needed for those features, for security, or to comply with the law; we do not use it for advertising; we do not sell it; and we do not allow humans to read it, except with the staff member's explicit consent, for security purposes, to comply with the law, or where the data has been aggregated and anonymised.

A staff member can disconnect at any time from Settings in the dashboard, which deletes the stored tokens — after that the platform can no longer reach their calendar. Access can also be revoked directly at myaccount.google.com/permissions. Calendar entries already written stay on the calendar and can be deleted there like any other event.

5. Who we share it with

  • Meta / WhatsApp — every message necessarily passes through Meta's WhatsApp Business Platform to reach us and to reach you back.
  • Our AI processing provider — the assistant calls a language-model provider (via OpenRouter) to read each message and extract the booking details above. Message content is sent there for that one purpose; we don't use it to train any model, and it is not used for advertising.

We never sell your information and never share it for advertising or marketing lists.

6. How long we keep it

Booking requests, appointment records and message text are kept as part of your booking history with the business — long enough to honor a booking, follow up, or resolve a dispute about it. Voice audio follows the shorter window in section 3 above and is deleted automatically regardless of the rest of the record. That is how long data lives if you leave it alone; a deletion request overrides all of it, with nothing kept back. You can ask us to delete your data sooner at any time — see section 8.

7. Security

  • WhatsApp access credentials are encrypted at rest (AES-256-GCM)
  • Inbound messages are verified against WhatsApp's own request signature, so only genuine WhatsApp traffic is accepted
  • Each business on this platform is data-isolated from every other business
  • The staff dashboard requires sign-in; nothing here is publicly browsable

8. Your rights

You can ask what we hold about you, ask us to correct it, or ask us to delete it, at any time — message us on the same WhatsApp number you used to contact us. Once a member of staff has recorded your deletion request, we carry it out within 30 days, and it is total — nothing about you is kept back beyond our internal note that a request was made and carried out, which no longer identifies you.

9. Children

This assistant is a booking channel for gym and physiotherapy services and isn't directed at children.

10. Changes to this policy

If this policy changes, we'll update the effective date at the top of this page. Continuing to message the business after a change means you accept the update.