Legal
Privacy Policy
This Privacy Policy explains how Blastak collects, uses, stores, and protects personal data when businesses use Blastak and when customers book appointments through Blastak booking pages and WhatsApp messages.
Effective date: March 4, 2026 · Version: 2026-03-04
1. Who We Are
Blastak is a software platform that helps appointment-based businesses manage bookings, reminders, and customer communication, including transactional WhatsApp messages.
Blastak acts as technology infrastructure and does not provide medical, legal, financial, or other professional services to end customers.
Data controller for the Blastak platform operations: Blastak.app.
Contact email: hello@blastak.app
Postal address: Available on request via hello@blastak.app
2. Roles and Responsibility
Blastak serves two types of users:
- Businesses using Blastak (for example salons, clinics, studios) who manage their appointments and customer communications.
- Customers of those businesses who book, confirm, reschedule, or cancel appointments.
For customer booking data processed on behalf of a business, the business is generally the primary controller of that customer relationship. Blastak acts as a service provider / processor for the booking infrastructure.
3. Data We Collect
Business account data may include:
- Name, email address, login credentials (hashed password), role
- Business profile details (business name, category, address, city, timezone)
- WhatsApp business phone number and related configuration metadata
Customer booking data may include:
- Name
- Phone number (stored in E.164 format)
- Preferred language (for messaging / booking experience)
- Appointment details (service, date/time, assigned staff, status, notes)
Messaging and communication data may include:
- Outbound transactional WhatsApp confirmations and reminders
- Inbound WhatsApp replies related to booking management (for example confirm, reschedule, cancel)
- Message delivery status metadata (sent, delivered, failed, read where available)
Technical and usage data may include:
- Request logs, error logs, and operational telemetry for service reliability and security
- Timestamps and event records for booking and messaging actions
4. How We Use Data
We use personal data to:
- Provide booking pages and booking management links
- Create, update, cancel, and reschedule appointments
- Send transactional WhatsApp confirmations and reminders requested by the business workflow
- Process inbound WhatsApp replies related to appointment management
- Support business dashboards, customer records, and reporting features
- Secure the platform, prevent abuse, troubleshoot issues, and improve reliability
Blastak does not use customer booking data for unrelated third-party advertising.
5. Legal Bases (Where Applicable)
Depending on jurisdiction, processing may rely on one or more of the following legal bases:
- Performance of a contract (providing booking and messaging services requested by the business)
- Legitimate interests (service security, abuse prevention, operational monitoring)
- Compliance with legal obligations
- Consent, where required by applicable law (for example, specific messaging or marketing uses)
For Morocco operations, data handling is aligned with the framework of Law 09-08.
6. WhatsApp and Meta Processing
Blastak uses Meta’s WhatsApp Business Platform (Cloud API) to send and receive WhatsApp messages for booking-related communications.
When a business enables WhatsApp messaging in Blastak, message content and metadata may be processed by Meta Platforms Technologies in accordance with Meta’s terms and privacy documentation.
Blastak currently uses WhatsApp primarily for transactional messages such as booking confirmations, reminders, and customer replies related to booking management.
Meta / WhatsApp may independently process data as a separate controller for service operation, security, fraud prevention, legal compliance, and platform analytics under its own policies.
8. Data Retention
Blastak retains data for as long as needed to provide the service, maintain business records, resolve disputes, enforce agreements, and meet legal obligations.
Retention may differ by data type, for example:
- Business account and configuration data while the account is active
- Appointment and customer records for ongoing business operations and history
- Message logs and delivery metadata for reliability, support, and audit purposes
If a business requests account closure or deletion, Blastak will process deletion requests subject to legal and operational constraints.
9. Security Measures
Blastak applies technical and organizational measures designed to protect personal data, including measures such as:
- Authentication and role-based access controls for business users
- Tenant isolation controls in business-scoped APIs
- Operational logging and monitoring for errors and abuse detection
- Protection of sensitive secrets and API credentials
No internet-based system is 100% secure. We encourage businesses to use strong passwords and protect admin access.
10. Data Subject Rights
Depending on applicable law, individuals may have rights such as access, correction, deletion, objection, restriction, and data portability.
Customers should generally contact the business they booked with first, because that business controls the customer relationship. Blastak may assist the business in responding where applicable.
For requests about Blastak platform account data, contact: hello@blastak.app
11. International Transfers
Blastak and its service providers may process data in countries other than the country where the data was collected. Where required, appropriate safeguards are used for international transfers in line with applicable law.
12. Children
Blastak is a business software service and is not intended for children to use independently. Businesses using Blastak are responsible for collecting and processing customer information in compliance with applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect product changes, legal requirements, or operational changes. We will update the effective date at the top of this page when changes are made.
14. Contact Us
For privacy questions, legal notices, or data requests relating to Blastak, contact:
Blastak
Email: hello@blastak.app
Legal entity: Blastak.app
Address: Available on request via hello@blastak.app