Privacy Policy
Saay AI ("Saay AI", "we", "us", or "our") operates an AI-powered review management platform designed for restaurants, hospitality businesses, and the marketing agencies that serve them. This Privacy Policy explains how we collect, use, store, share, and protect information when you use our website, platform, or services (collectively, the "Services").
By accessing or using our Services, you agree to the terms of this Privacy Policy. If you do not agree, please do not use our Services.
Introduction
This policy applies to:
- Restaurant owners and operators using Saay AI directly
- Hospitality groups and multi-location businesses using Saay AI
- Marketing agencies and their authorized users accessing Saay AI on behalf of their clients
- Visitors to our website at saayai.com
Who We Are: Data Controller and Data Processor
Saay AI operates in a dual capacity depending on the context:
As a Data Controller: Saay AI determines the purposes and means of processing personal data that you provide directly to us — such as account registration information, billing details, and direct communications.
As a Data Processor: When Saay AI accesses your Google Business Profile data or processes review data on your behalf, we act as a data processor. You — the business owner or authorized agency user — are the data controller responsible for that data. We process such data strictly on your instructions and for the purposes described in this policy.
Agency and Multi-Tenant Accounts
Saay AI supports agency accounts where a single organization manages multiple client businesses and their associated Google Business Profiles. In this model:
- The agency is responsible for ensuring they have obtained the necessary authorizations from their clients to connect and manage their Google Business Profiles through Saay AI.
- Each client's data is logically isolated within the platform. Users from one business or client account cannot access data belonging to another.
- Revoking an agency's access through Google Account settings will immediately remove Saay AI's ability to access or act on that client's Google Business Profile data.
- Saay AI is not responsible for any unauthorized access that results from an agency's failure to manage permissions appropriately on their end.
Information We Collect
We collect information in the following ways:
Account Information
When you register for Saay AI, we collect:
- Full name and email address
- Company or restaurant name
- Job title or role
- Billing and payment information (processed by our payment provider; we do not store full card details)
- Account credentials (passwords are stored in hashed, non-reversible form)
Platform Usage Data
We automatically collect certain technical data when you use our platform:
- IP address and approximate geographic location
- Browser type, version, and operating system
- Pages and features accessed, and timestamps of access
- Session duration and interaction patterns
- Device identifiers
This data is used for security, platform improvement, and analytics purposes. It is not linked to personally identifiable information unless required for security investigations.
Direct Communications
If you contact us via email, our contact form, or other channels, we collect:
- Your name and email address
- The content and metadata of your message
- Any attachments or additional information you voluntarily provide
Google Business Profile Data
When you connect your Google account to Saay AI, we access data from your Google Business Profile as described in detail in Section 4 of this policy.
Information You Input Into the Platform
We collect content you create or upload within the platform, including:
- Review response templates and drafted replies
- Response Anchor phrases and SEO keyword configurations
- Brand voice settings, tone preferences, and do/don't rules
- Ticket and task notes created for managing negative reviews
- User roles and permission assignments within your organization
How We Use Your Information
We use the information we collect to:
- Provide, operate, maintain, and improve our platform and Services
- Authenticate users and manage access controls
- Process your transactions and send billing-related communications
- Enable the AI-powered review response and scoring features
- Generate insights on customer sentiment and review performance
- Send service updates, security alerts, and administrative messages
- Respond to your support requests and direct communications
- Conduct internal analytics to understand platform usage and improve features
- Detect, prevent, and investigate fraud, abuse, or security incidents
- Comply with applicable legal obligations
We do not use your information to serve you third-party advertisements. We do not sell your personal information to any third party.
Google API Services and Google Business Profile Data
Saay AI provides centralized review management tools for restaurants and hospitality businesses. Our application accesses and processes data from your Google Business Profile via the Google Business Profile API and other Google APIs.
Google OAuth Scopes We Request
We request only the permissions necessary to deliver our Services. The Google API scopes we request include:
https://www.googleapis.com/auth/business.manage— to read and manage your Google Business Profile, including reviews and business information
We request only the minimum scopes required. We do not request access to your Gmail, Google Drive, Google Contacts, or any other Google services beyond those necessary for the features described in this policy.
Information We Access from Google
When you authorize our application, we may access:
- Your Business Profile name, address, phone number, category, and contact details
- Customer reviews, star ratings, reviewer names (as publicly visible), and review text
- Your existing review response history
- Business location data, hours of operation, and listing status
- Business performance insights (where available through the API)
How We Use Your Google Data
Information received from Google APIs is used solely to provide and improve our platform features. Specifically, we use it to:
- Display your reviews within the Saay AI dashboard for your team to manage
- Enable you to read, draft, and publish responses to customer reviews through our platform
- Power AI-generated review response suggestions based on review content
- Score AI-generated replies for tone, quality, and brand consistency before they are approved
- Identify unanswered reviews and surface them as priority items in your workspace
- Support the Ticket and Task system for managing issues raised by negative reviews
- Apply your configured Response Anchors and Brand Voice settings to AI-generated content
We do not use Google user data to train general-purpose AI models. AI processing applied to your Google data is used exclusively to generate responses and insights for your account.
Human Access to Google User Data
Saay AI personnel do not read or access individual Google user data except in the following limited circumstances:
- You have provided explicit written consent for us to access your data for support purposes
- Access is necessary to investigate a security incident, prevent fraud, or comply with a legal obligation
- Data is anonymized and aggregated in a manner that does not identify any individual user or business
All internal access to production data is logged, access-controlled, and subject to internal review.
Data Storage and Retention of Google Data
Google Business Profile data accessed through our platform is stored only as long as necessary to provide the Services or as required by your subscription settings.
- Review data and response history is retained for the duration of your active subscription to support your team's workflow
- Upon account termination or subscription cancellation, your Google Business Profile data will be deleted from our systems within 30 days, except where retention is required by law
- You may request immediate deletion of your data at any time by contacting us at saay@saayai.com
Revoking Google Access
You may disassociate your Google Account from Saay AI at any time through your Google Account security settings at myaccount.google.com/permissions. You may also contact us at saay@saayai.com to request disconnection. Upon revocation, we will cease accessing your Google Business Profile data and will initiate deletion of the associated data from our systems.
Google API Limited Use Disclosure
Saay AI's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In accordance with these requirements:
- We use Google user data only to provide or improve user-facing features that are described in this policy
- We do not use Google user data for serving advertisements of any kind
- We do not allow humans to read Google user data except as described in Section 4d above
- We do not sell, transfer, or disclose Google user data to third parties except as necessary to provide our Services (e.g., to sub-processors as described in Section 6), and never for advertising or unrelated purposes
Automated Processing and AI-Generated Content
Saay AI uses artificial intelligence to assist in generating review responses and evaluating reply quality. The following disclosures apply:
- AI Response Generation: When a review is received, our AI may draft a suggested response based on the review content, your Brand Voice settings, and your configured Response Anchors. This is a suggested draft only.
- AI Quality Scoring: A second AI evaluates each generated reply and assigns a quality score based on tone, relevance, empathy, and brand alignment.
- Human Approval Required: By default, no AI-generated response is published to your Google Business Profile without explicit approval by an authorized member of your team. Saay AI does not autonomously post responses on your behalf unless you have explicitly configured automated posting within your account settings.
- No Solely Automated Decisions with Legal Effect: Our AI systems do not make decisions about individuals that produce legal or similarly significant effects. All consequential actions (such as publishing responses or escalating tickets) require human authorization.
Sub-Processors and Third-Party Services
To deliver our Services, we engage trusted third-party sub-processors who may process your data on our behalf. These include:
| Category | Purpose |
|---|---|
| Cloud Infrastructure & Hosting | Secure server hosting and data storage |
| AI / Large Language Model Providers | Generating and scoring AI review responses |
| Payment Processors | Processing subscription billing securely |
| Analytics Providers | Understanding platform usage and improving features |
| Email & Communication Providers | Sending transactional and support emails |
| Security & Monitoring Tools | Detecting and preventing security incidents |
All sub-processors are bound by data processing agreements that require them to protect your data to standards at least equivalent to those in this policy. We evaluate sub-processors for security and compliance before engagement.
We do not permit sub-processors to use your data for their own purposes beyond delivering the services they provide to us.
An up-to-date list of sub-processors is available upon request by contacting saay@saayai.com.
Data Storage and Security
Your data is stored on secure cloud infrastructure with the following protections:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher
- Encryption at rest: All stored data is encrypted using AES-256 encryption
- Access controls: Access to production systems and customer data is restricted to authorized personnel only, governed by role-based access control
- Audit logging: All access to production data by internal personnel is logged and subject to review
- Regular security reviews: We conduct periodic security assessments of our infrastructure and application
- Incident response: We maintain an incident response plan and will notify affected users of any data breach as required by applicable law
While no method of data transmission or storage is completely secure, we implement commercially reasonable and industry-standard measures to protect your personal information. In the event of a security incident affecting your data, we will notify you without undue delay in accordance with applicable law.
Data Retention
We retain personal data for the following periods:
- Account data: Retained for the duration of your subscription and deleted from active systems within 30 days of account termination, unless retention is required by law (automated backups may be retained for an additional limited period).
- Billing and transaction records: Retained for a minimum of 7 years as required for financial and tax compliance
- Support communications: Retained for 3 years from the date of last communication
- Usage and analytics data: Retained in aggregated, anonymized form indefinitely; individually identifiable usage logs retained for up to 12 months
- Google Business Profile data: Retained for the duration of your active subscription and deleted within 30 days of account termination or Google account disconnection
You may request early deletion of your data at any time as described in Section 9.
Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
- Right of Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure: You have the right to request deletion of your personal data, subject to legal retention requirements. Requests can be submitted to saay@saayai.com.
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Restriction: You have the right to request that we restrict the processing of your personal data in certain circumstances.
- Right to Object: You have the right to object to processing of your personal data for certain purposes, including profiling.
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.
- Right to Lodge a Complaint: If you believe we have not handled your data appropriately, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.
To exercise any of these rights, please contact us at saay@saayai.com. We will respond to your request within 30 days. We may need to verify your identity before processing certain requests.
Cookies and Tracking Technologies
Saay AI uses cookies and similar tracking technologies on our website and platform. These include:
- Strictly Necessary Cookies: Required for the platform to function. These cannot be disabled. They include session authentication cookies and security tokens.
- Analytics Cookies: Used to understand how visitors use our website and platform. This data is aggregated and used to improve our Services. These cookies are set by us or our analytics providers.
- Preference Cookies: Used to remember your settings and preferences across sessions.
You can instruct your browser to refuse all cookies or to alert you when cookies are being set. However, disabling certain cookies may affect the functionality of our platform. Where required by law, we will obtain your consent before placing non-essential cookies.
Children's Privacy
Our Services are intended for business use and are not directed to individuals under the age of 18. We do not knowingly collect personally identifiable information from minors. If you believe we have inadvertently collected personal information from a minor, please contact us immediately at saay@saayai.com and we will take prompt steps to delete such information.
International Data Transfers
Saay AI may process your data in countries other than the country in which you are located. Where data is transferred internationally, we ensure appropriate safeguards are in place, which may include:
- Standard Contractual Clauses approved by the European Commission
- Data processing agreements with sub-processors that include equivalent protections
- Transfers only to jurisdictions deemed to provide adequate data protection
By using our Services, you acknowledge that your data may be transferred to and processed in countries with data protection laws that differ from those in your jurisdiction.
Third-Party Links and Services
Our platform may contain links to third-party websites or integrate with third-party services that operate independently and have their own privacy policies. We are not responsible for the privacy practices of these third parties and encourage you to review their policies before providing any personal information. This includes, but is not limited to, Google's privacy policy available at https://policies.google.com/privacy.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Post the revised policy on this page
- Notify you via email or a prominent notice within the platform where the changes are significant
Your continued use of our Services after the effective date of the updated policy constitutes your acceptance of the revised terms. We encourage you to review this policy periodically.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Saay AI
Email: saay@saayai.com
Phone: 337-739-0887
Website: saayai.com
Address: 4455 Nelson Rd, Lake Charles, LA 70607
For matters specifically relating to Google data or your rights regarding Google Business Profile data connected to our platform, you may also contact Google directly at https://support.google.com/business.
This Privacy Policy was last reviewed and updated on March 9, 2026.