Back to home
Privacy Notice

Privacy Notice

How BridgeMeet collects, uses, and protects personal data, both for the businesses that use us and for the customers who book with them.

Last updated: July 30, 2026

1. Who We Are and the Legal Framework

This Privacy Notice is issued by AUDAWORKS, operating commercially as BridgeMeet, with registered address in Mexico City. It is governed by the Mexican Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), published in the Federal Official Gazette on March 20, 2025, and its applicable regulations. The competent authority for the private sector is the Ministry of Anti-Corruption and Good Governance.

We process personal data lawfully, fairly, and transparently, and we apply security measures to protect it throughout its lifecycle.

2. Personal Data We Process

The data we handle depends on who you are and how you use the service:

Customers who book over WhatsApp
Name, WhatsApp phone number, any optional contact details shared such as email, appointment details including a free-text notes field, and the content of the WhatsApp messages exchanged with the business.
Business owners and staff
Name, email, profile image, role, and organization membership, handled through our authentication provider.
The business account
Business name, description, timezone, contact details, and WhatsApp number.
Billing
Subscription and customer identifiers, plan, and status. We never receive or store card numbers.
Security
Technical records such as IP addresses in sign-in and rate-limit logs, used to protect the service.
To provide the service, the content of WhatsApp messages is stored so the conversation and the appointment history stay available to the business. We do not sell it, and we do not use it to advertise to you.

3. How and Why We Use Data

3.1 Primary purposes

  • Providing the service: scheduling, rescheduling, cancelling, and sending appointment notifications and reminders over WhatsApp.
  • Managing accounts for owners and staff, including sign-in, access control, and permissions.
  • Processing payments, billing, and subscription renewal through our payment provider.
  • Maintaining and improving the service using aggregated or anonymized data.
  • Keeping the platform secure, preventing unauthorized access, and complying with the law.

3.2 Secondary purposes

  • Suggesting available times and tailoring the scheduling experience based on the appointment and preference data already held for the business.

You may object to the processing of your data for these secondary purposes through the process in the Privacy Rights section, without affecting the core service.

3.3 Legal basis

  • Performance of the legal relationship with the data subject, including sending appointment reminders, under Article 9, section IV, of the LFPDPPP.
  • Implied consent for identification and contact data, under Article 7 of the LFPDPPP.
  • Express consent for sensitive personal data, under Article 8 of the LFPDPPP.

4. When We Are Processor and When We Are Controller

For the personal data of a business's own customers, the business is the Data Controller and BridgeMeet acts as its Data Processor, handling that data only to provide the service and on the business's instructions.

For the personal data of business owners and staff who register on the platform, BridgeMeet is the Data Controller, since we determine how and why that data is processed.

5. Automated Processing and AI Assistant

When a business enables our AI assistant, the content of the customer's WhatsApp messages, the business's list of services and staff, and the customer's name are sent to our AI provider, Anthropic, for the sole purpose of generating a scheduling reply.

The assistant helps schedule appointments. It does not make legally significant decisions about a person without human oversight, and the business can review and correct how it behaves.

The AI assistant is off by default. Each business turns it on with a single switch and can turn it off at any time.

6. Service Providers and Subprocessors

We rely on a small set of trusted providers to run the service. Each one receives only the data it needs for its specific job, and none of them may use it for their own purposes.

  • Twilio

    Delivers WhatsApp messages to and from customers. Receives the customer phone number and message content.

    United States
  • Meta (WhatsApp)

    Platform that delivers WhatsApp messages and reminders to the customer's device. Receives the customer phone number and message content.

    United States
  • Anthropic

    Powers the optional AI scheduling assistant. Receives message content, the service and staff catalog, and the customer name when the assistant is on.

    United States
  • Google

    Two-way calendar sync. We read staff availability and create the events for the appointments you book.

    United States
  • Clerk

    Sign-in and account authentication.

    United States
  • Stripe

    Subscription billing. Card details are entered on Stripe and never reach our servers.

    United States
  • Neon

    Database hosting for the platform data.

    United States
  • Vercel

    Application hosting and basic page-view analytics.

    United States
  • ipwho.is

    Best-effort timezone detection from IP address on first visit.

    Third-party service
We contract each provider to protect the data and to process it only to deliver their part of the service.

7. Google API Services and Limited Use

BridgeMeet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We request access to your Google Calendar only to provide the scheduling features you enable. Specifically, we read your calendars and their events, including busy and free times, to find open slots, and we create, update, and delete calendar events for the appointments booked through BridgeMeet. Those events include the customer's name, the selected service, and the appointment notes.

The Google Calendar authorization (access and refresh tokens) is held securely in BridgeMeet's own encrypted credential store, isolated per business account, and is used only while you keep the calendar connected. You can disconnect it at any time. We do not use Google Calendar data for advertising, we do not sell it, and we do not use it to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models. We do not transfer this data to others except as needed to provide the feature at your request, to comply with applicable law, or as part of a merger or acquisition, consistent with the Limited Use requirements.

8. Sensitive and Health Data

Because clinics, dental offices, and veterinary practices use BridgeMeet, appointment notes and messages may include health-related information. We treat this as sensitive data, apply enhanced safeguards, and use it only to manage the appointment.

When a business processes health data, it does so as Data Controller and is responsible for obtaining the customer's express consent, in accordance with Article 8 of the LFPDPPP and other applicable provisions on sensitive personal data.

9. Information Security

We keep each business's data logically separated so one business cannot access another's, encrypt sensitive credentials so that not even our own team can read them, and restrict internal access to what each role needs.

If a security incident affecting personal data occurs, we will act to contain it and notify affected parties as required by applicable law.

10. How Long We Keep Data

We keep personal data for as long as your account and our relationship are active, and for any additional period the law requires us to retain it, for example tax records.

You can ask us to access, correct, or delete your data at any time through the process in the Privacy Rights section, and we respond as the law provides. When a team member is removed, their record may be kept in a deactivated state for continuity and audit.

11. Your Privacy Rights (ARCO)

You may exercise your rights of Access, Rectification, Cancellation, and Objection (ARCO), and withdraw consent you previously gave.

Owners and staff can update their profile details from the dashboard. Customers of a business exercise their rights directly with that business, which acts as the Data Controller.

To make a formal request, write to privacidad@bridgemeet.com and include valid official identification so we can verify who you are. If you have questions about the process you can ask us on WhatsApp at +52 998 695 8160, though the request itself must arrive by email so we can verify your identity.

12. International Data Transfers

Some of our providers operate in the United States, so using BridgeMeet involves transferring personal data there. We limit these transfers to what the service requires and bind each provider by contract to protect the data.

13. Our Commitments

  • We do not sell or rent your customers' phone numbers, and we do not use them for our own marketing.
  • Card details are handled by Stripe and never touch our servers.
  • Each business's data is logically isolated from every other business.
  • Sensitive credentials are encrypted so they cannot be read, even internally.

14. Cookies and Tracking

We use a small number of cookies and an audience measurement that stores nothing on your device. The first time you arrive we ask for your decision with a banner, and you can change it at any time from the "Cookie preferences" link at the bottom of any page. For the full detail, see our Cookies and Tracking policy.

15. Changes to This Notice

We may update this Privacy Notice from time to time. The current version is always published here with its last updated date.

Privacy policy | BridgeMeet