LLOKAL Back to home

Privacy Policy

Last updated: August 4, 2026

Template — not legal advice. This plain-language template describes how LOKAL currently handles data. It has not yet been reviewed by a lawyer and must be reviewed by qualified privacy counsel for your jurisdiction before you rely on it.

1. Overview and our role

This Privacy Policy explains how LOKAL (“LOKAL,” “we,” “us”) handles personal data when you use our platform, websites, and apps (the “Service”). We designed LOKAL to collect only the data needed to run your business.

Two roles matter here. For your own account and business data, LOKAL is the data controller. For the personal data of your customers that you collect through LOKAL — for example, people who place an order, book an appointment, join your loyalty program, or call your AI receptionist — you are the controller and LOKAL is your processor, handling that data on your behalf and under your instructions. If you are a customer of a business that uses LOKAL, please also see “If you are a customer of a LOKAL business” below.

2. Information we collect

Account and business data

Your name, email, phone, business details, team members you add, settings, and billing status. We use this to create and run your workspace.

Customer and ordering data

When your customers order online or in person, book appointments, or join loyalty, we process the data needed to complete those actions — such as name, contact details, order and appointment details, and loyalty history. This is the data of your customers, handled on your behalf.

AI phone receptionist calls

If you enable the AI phone receptionist, we process the caller’s phone number and the audio of the call, and we may create a recording and transcript, in order to take orders, answer questions, and provide call records and analytics to you. To personalize service, the assistant may match a caller to an existing customer or loyalty record.

Payment data

Payments are handled by our payment processor (Stripe). We receive limited details such as the card brand, last four digits, and transaction status — we do not collect or store full card numbers. Card data is handled by the processor under PCI-DSS standards.

Messaging

Direct and team messages are end-to-end encrypted; we store only ciphertext and cannot read their contents.

Device and usage data

Diagnostics such as IP address, device and browser type, pages viewed, and error logs, used to keep the Service secure and reliable.

3. How we use data

We use personal data to:

  • Provide, maintain, and secure the Service and your workspace.
  • Process orders, bookings, loyalty, payments, notifications, and calls.
  • Operate the AI phone receptionist, including recognizing returning customers where you have enabled it.
  • Provide customer support and communicate about your account and billing.
  • Detect fraud and abuse, and comply with legal obligations.
  • Improve reliability and accuracy of the Service.

We do not sell your personal data, and we do not sell the personal data of your customers. We do not use the contents of your customers’ data or your encrypted messages to train third-party advertising models.

4. AI phone calls and recordings

The AI receptionist identifies itself as an automated virtual assistant and discloses that the call may be recorded. Recordings and transcripts are used to fulfill and record orders and to provide you with call history and analytics.

Because recording and automated calling are regulated differently across states and countries, you, as the business receiving the calls, are responsible for ensuring recording and disclosure are lawful for your callers. See the AI phone receptionist section of our Terms of Service. You can manage or disable recording in your settings.

5. Cookies and similar technologies

We use strictly necessary cookies to sign you in and keep the Service secure (for example, a session cookie), and a limited set of cookies or local storage to remember preferences and measure performance. We aim to minimize non-essential tracking. Where required by law, we ask for your consent before setting non-essential cookies, and you can control cookies through your browser settings.

6. Providers we share data with (subprocessors)

We share data with a small number of trusted providers strictly to run the Service, under contracts that require them to protect it. The main ones are:

  • Google Cloud / Firebase — hosting, database, authentication, and storage.
  • Google (Vertex AI / Gemini) — the AI models that power the receptionist and assistant.
  • Stripe — subscription billing (your LOKAL plan).
  • Square — customer card payment processing for your orders.
  • Twilio — voice telephony for the phone receptionist and SMS notifications.
  • Optional delivery partners you enable (for example, DoorDash or Uber Eats).
  • Meta (Facebook and Instagram) — only if you connect a social account so we can publish your own promotional posters. We send Meta the poster image and its caption, and we store your Page and Instagram account details along with an access token so we can post on your behalf. Disconnecting deletes that token.

We may also disclose data if required by law, to protect rights and safety, or in connection with a merger or acquisition (with notice where required). We do not otherwise sell or rent personal data. To request our current subprocessor list, contact privacy@lokal.business.

Deleting a connected social account: to remove a connected Facebook or Instagram account and everything we hold for it, open Dashboard → AI Promo Studio and press Disconnect, or remove LOKAL from Settings → Apps and Websites inside Facebook. Either action deletes the stored access token immediately. Posts already published to your own Instagram or Facebook belong to you and stay there until you delete them in those apps. To have our record of what was posted removed as well, email privacy@lokal.business and we will delete it within 30 days.

7. Data retention

We keep personal data for as long as your account is active and as needed to provide the Service, then for a limited period afterward to meet legal, tax, accounting, and security obligations, after which we delete or anonymize it. You can delete records within the product, and call recordings and transcripts can be managed or removed in your settings. When you close your account, we delete or anonymize your data within a commercially reasonable period, except where we must retain it by law.

8. How we protect data

We encrypt data in transit and at rest, host on hardened cloud infrastructure with access controls and audit logging, and keep regular backups. Team and customer messaging is end-to-end encrypted. No system is perfectly secure, but we work continuously to protect your data and will notify you of a breach affecting your data as required by law.

9. Your privacy rights (GDPR / CCPA and others)

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. Under the CCPA/CPRA, California residents have the right to know, delete, correct, and opt out of the “sale” or “sharing” of personal data — and we do not sell or share personal data as those terms are defined. We do not discriminate against you for exercising your rights.

You can exercise many rights directly in the product (export and delete). For other requests, contact privacy@lokal.business and we will respond within the timeframe required by law. If your request concerns data held by a business that uses LOKAL, we may direct you to that business, since they control that data.

10. International data transfers

We operate primarily in the United States, and our providers may process data in the U.S. and other countries. Where we transfer personal data across borders, we rely on appropriate safeguards (such as standard contractual clauses) where required by law.

11. Children

LOKAL is a business tool and is not directed to children. We do not knowingly collect personal data from children under 16 (or the age required by local law). If you believe a child has provided us data, contact privacy@lokal.business and we will delete it.

12. If you are a customer of a LOKAL business

If you ordered from, booked with, called, or joined the loyalty program of a business that uses LOKAL, that business controls your data and decides how it is used. LOKAL processes it on their behalf. To access, correct, or delete your data, please contact that business directly. You may also contact us at privacy@lokal.business and we will help route your request.

13. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “last updated” date and, where appropriate, provide additional notice.

14. Contact us

Privacy questions or requests: privacy@lokal.business. For security concerns: security@lokal.business.

See also our Terms of Service.