Boutique Hub OS
Boutique Hub OS

Privacy Policy

Last updated: August 21, 2026

1. Who we are

Boutique Hub OS (“BHOS”) is a business operating platform for boutique retailers, provided by The Boutique Hub. This policy describes how the BHOS application (boutiquehub.bhos.ai) collects, uses, and protects your information. It supplements The Boutique Hub’s general privacy policy, available at theboutiquehub.com/privacy-policy. Questions? Contact us at HappyPeople@theboutiquehub.com.

2. Information we collect

  • Account information — your name, email address, and store details when you create a BHOS account.
  • Store and commerce data — data from integrations you choose to connect (for example Shopify, Meta, or Google services), used solely to power the BHOS features you use.
  • Usage data — how you interact with BHOS, used to operate, secure, and improve the product experience.

3. Google user data

If you choose to connect a Google account, BHOS requests only the scopes needed for the specific feature you are connecting:

  • Google Calendar (calendar.readonly, calendar.events) — to view your calendar availability and create or update events so coaching calls and appointments can be scheduled from BHOS.
  • Google Analytics (analytics.readonly) — to read your own Google Analytics 4 reports (sessions, traffic sources, device breakdowns) so BHOS can show your website traffic alongside your commerce data and answer your questions about it.

BHOS’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

BHOS’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

In practice, this means:

  • We use Google user data only to provide and improve the user-facing features described above — never for advertising, and we never sell it.
  • We do not use Google user data — raw, aggregated, anonymized, or derived — to develop, train, or improve foundational or generalized artificial intelligence or machine learning models.
  • When BHOS’s AI assistant answers a question using your connected Google data (for example, a question about your own site traffic), that data is processed only to generate the answer for you. Our AI model providers are not permitted to retain it or use it to train their models.
  • We transfer Google user data to third parties only as necessary to provide these features (for example, our hosting and database providers), for security purposes, to comply with applicable law, or with your explicit consent.
  • No human reads your Google user data unless you ask us to for support, it is required for security or abuse investigation, or we are required to by law.

4. Meta (Facebook and Instagram) data

If you choose to connect a Meta account, BHOS requests only the permissions needed to show you your own advertising results and to build ads on your behalf:

  • ads_read — to read your ad accounts, campaigns, ad sets, and their performance metrics (impressions, clicks, spend, reach, conversions) so BHOS can show your advertising results alongside your commerce data and answer your questions about them.
  • ads_management — to create an ad in an ad account you already own, when you ask BHOS to publish one you have built in the Ad Wizard.
  • pages_show_list — to list the Facebook Pages you manage, so you can choose which Page an ad or a scheduled post belongs to.

That is the whole list. BHOS does not ask to read your Page posts or their engagement, and does not ask to manage your Business Manager assets.

What we store, and what we do with it:

  • We store your Meta user ID and name, the list of ad accounts and Pages you have access to, and the access tokens needed to make those requests. Tokens and Page tokens are encrypted at rest and scoped to your individual store.
  • We use Meta data only to provide the features described above, for the store that connected the account. We do not sell it, and we do not use it to target advertising to you.
  • We do not use Meta data — raw, aggregated, anonymized, or derived — to develop, train, or improve foundational or generalized artificial intelligence or machine learning models.
  • When BHOS’s AI assistant answers a question using your connected Meta data (for example, “how did last month’s campaign perform?”), that data is processed only to generate the answer for you. Our AI model providers are not permitted to retain it or use it to train their models.
  • We transfer Meta data to third parties only as necessary to provide these features (for example, our hosting and database providers), for security purposes, to comply with applicable law, or with your explicit consent.
  • No human reads your Meta data unless you ask us to for support, it is required for security or abuse investigation, or we are required to by law.

5. Storage and security

OAuth tokens and integration credentials — including Google tokens and Meta user and Page tokens — are encrypted at rest and scoped to your individual store, so no other BHOS store can access them. All data is transmitted over encrypted (TLS) connections. Access to production systems is restricted to authorized The Boutique Hub personnel.

6. Retention, disconnection, and deletion

Disconnecting a single integration. You can disconnect any integration at any time from Settings → Integrations in BHOS. Disconnecting deletes the stored credentials for that integration, including any access tokens.

You can also revoke BHOS’s access from the provider’s own settings:

Deleting your whole account. In the BHOS mobile app, open Settings and choose Delete account. This signs you out of every device straight away and schedules your account and all associated store data — including any connected-integration credentials — for permanent deletion. There is a short grace period before the erasure runs, so an accidental tap can be undone: contact us within that window and we will cancel it.

You can also request deletion at any time by emailing HappyPeople@theboutiquehub.com, and we will action it for you.

7. Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the “Last updated” date above, and we will notify you of significant changes through the app or by email.