Legal

Privacy Policy

v1.0-gdpr

Effective April 16, 2026 · Last updated April 16, 2026

GDPR Article 17 — Right to Erasure (“Right to be Forgotten”)

Under Article 17 of the EU General Data Protection Regulation, you have the right to request the erasure of your personal data. We honor this right by suppressing your data from all active systems within 48 hours and completing permanent deletion within 30 days. You may exercise this right at any time from your account settings.

Read Article 17 in full (gdpr-info.eu) ↗

Data Collection

We collect information you provide directly, usage data, and data from connected platforms (Google Business Profile, Meta, Square, QuickBooks). This includes account information, business data, communication data, and connected platform data.

Your GDPR Rights

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of Access (Article 15): Request a copy of your personal data.
  • Right to Rectification (Article 16): Correct inaccurate personal data.
  • Right to Erasure (Article 17): Request deletion of your personal data. We suppress data within 48 hours and complete deletion within 30 days.
  • Right to Data Portability (Article 20): Receive your data in a machine-readable format (JSON + CSV export).
  • Right to Object (Article 21): Object to processing of your personal data.

To exercise any of these rights, email us at help@hirecoral.com. We will respond within 30 days.

Data Retention Policy

Data retention periods by tier
Data TierRetention PeriodLegal Basis
Operational data1–3 yearsLegitimate interest / Contract performance
Compliance records7 yearsLegal obligation
Legal hold dataIndefiniteLegal obligation / Court order

We retain your data according to the following schedule. Upon account deletion, active systems are suppressed within 48 hours and all data is permanently deleted within 30 days.

Deletion Procedures

When you request account deletion:

  1. 48 hours: Your account is immediately deactivated and removed from all active systems.
  2. 30 days: All remaining personal data is permanently deleted from our databases, backups, and associated storage.
  3. Your Google Business reviews and responses remain on Google's platform, as the Google API does not support deletion of public reviews.
  4. You may recover your account within the 30-day window by visiting /account/recover. Recovery requires fresh Google authorization.

This process complies with GDPR Article 17 (Right to Erasure) — erasure must occur "without undue delay."

Third-Party Services

We share data only with the following third-party services to operate our platform:

  • Vercel: Hosting and edge runtime
  • Supabase / PostgreSQL: Database storage
  • Resend: Transactional email delivery
  • Anthropic: AI model API — your prompts are processed but not used to train public models
  • Google: OAuth authentication and Google Business Profile API
  • Meta: Facebook and Instagram APIs (when connected)
  • Square / QuickBooks: Sales and financial data (when connected)
  • Twilio: SMS text-message delivery (only when you opt in to texting)

We do not sell your personal information. All third-party providers are contractually bound to protect your data.

SMS / Text Messaging

Coral offers an optional text-messaging channel. If you opt in, we use your mobile number solely to send and receive messages related to your account and business — check-ins, content drafts for your approval, account notifications, and replies to texts you send.

We do not share your mobile opt-in information, phone number, or SMS consent with any third parties or affiliates for marketing or promotional purposes. Your number is shared only with our SMS delivery provider (Twilio) to transmit the messages you have requested.

Message frequency varies. Message and data rates may apply. Reply STOP at any time to opt out, or HELP for help. You can also manage or disable texting anytime from your dashboard Connections settings. Consent to receive texts is not a condition of using Coral.

Contact Us

For privacy inquiries, data requests, or GDPR-related questions, contact us at:

Bug Byte LLC
Email: help@hirecoral.com

We will respond to all privacy requests within 30 days as required by GDPR.

Privacy Policy version 1.0-gdpr — effective April 16, 2026, last updated April 16, 2026.

Questions? Email help@hirecoral.com