Privacy Policy

Last updated: July 2, 2026

Welcome to Hailory. We take your privacy seriously. This policy explains how we collect, use, store, and protect the data you provide when using the service.

1. What data we collect

  • Account data: email, name, and profile picture obtained through Google / LINE / Facebook / Apple OAuth
  • Usage data: message history, rule settings, and audit logs
  • Channel data: identifiers and tokens for the Instagram / LINE accounts you authorize us to access (stored encrypted)
  • Customer interaction data: messages your customers send you, used to determine which auto-replies to trigger
  • Technical data: IP address, User-Agent, and cookies (used for sessions, CSRF protection, and anonymous traffic analytics; see Section 8)

2. How we use this data

  • To provide and operate the Hailory service itself (auto-replies, message history, dashboard)
  • Authentication and security (preventing abuse and tracking suspicious logins)
  • Billing and invoicing (your email and payment information)
  • Product improvement and debugging (aggregated usage statistics with no personally identifiable information)

We never sell your data to third parties.

3. Data storage and protection

  • Data is stored on Google Cloud Platform (asia-east1), which meets ISO 27001 standards
  • All access tokens are stored encrypted with AES in the database
  • All connections use HTTPS (HSTS enabled)
  • Sessions use httpOnly + Secure cookies that can't be read by JavaScript

4. Third-party services

We use the following third-party services to run the service:

  • Meta (Instagram): provides the Instagram messaging API and login
  • LINE Corp.: provides LINE OA and LINE Login
  • Google: provides OAuth login, and Google Analytics 4 via Google Tag Manager for anonymous traffic statistics (see Section 8)
  • Resend: sends system emails (invites, notifications)
  • ECPay (from Phase 2): processes subscription payments

5. Your rights

Under Taiwan's Personal Data Protection Act and related regulations, you have the right to:

  • Access or view your data
  • Request a copy (download a JSON file from Settings → Workspace → Data backup)
  • Request additions or corrections
  • Request that we stop collecting, processing, or using your data
  • Request deletion (do it yourself from Settings → Workspace → Danger zone, or contact us)

To exercise any of these rights, contact us.

6. Data retention

  • Account data: kept for as long as the account exists, and permanently deleted within 30 days of an account deletion request
  • Message history: kept for 90 days, or up to 365 days on paid plans
  • Payment records: kept for 5 years as required by Taiwan's Business Entity Accounting Act
  • Audit logs: kept for 365 days (1 year) for compliance and dispute resolution
  • Backups: made automatically every day and kept for 7 days for disaster recovery

The two deletion scenarios have different timelines: (1) for message and contact data of Meta (Instagram / Facebook) platform users, we delete it within 48 hours of receiving a Meta Data Deletion Callback request (see Section 7); (2) for full account deletion, we follow the 30-day process above. For the full deletion steps, see the data deletion page.

7. Meta platform user data deletion (Instagram / Facebook users)

When you (an Instagram or Facebook user) remove our app from your Meta account settings, Meta automatically notifies us to delete your data. Our Data Deletion Callback URL:

https://api.hailory.com/meta/deletion-callback

Within 48 hours of receiving the request, we delete everything related to your Meta account, including:

  • Message history (message_logs)
  • Conversation states (conversation_states)
  • Contact entries (leads)

Once deletion is complete, you can check its status at /meta/deletion-status/{confirmation_code} (the confirmation_code is returned by Meta).

8. Cookie policy

Hailory uses two types of cookies:

Essential cookies (required for the service to work and can't be turned off):

  • halo_ig_session — keeps you logged in
  • halo_oauth_state — used for OAuth CSRF protection (valid for 5 minutes)

Analytics cookies:

  • This service uses Google Analytics 4 (loaded via Google Tag Manager), which sets cookies such as _ga for anonymous traffic statistics and product improvement (for example, understanding which features are used and how pages load)
  • This analytics covers all pages, including public form pages and link-in-bio pages (the pages your customers visit)
  • We do not use analytics data for ad personalization, and we never sell data to third parties
  • You or your visitors can block analytics cookies through browser settings, tracking protection, or extensions (such as the Google Analytics Opt-out Browser Add-on) without affecting use of the service

9. Changes to this policy

If we make significant changes to this policy, we'll notify registered users by email. Previous versions are available on request.

10. Contact us

Hailory is operated by 艾睿思顧問有限公司 (VELOX DATA CONSULTING LIMITED).

  • Operated by: 艾睿思顧問有限公司 (VELOX DATA CONSULTING LIMITED, tax ID number 00215337)
  • Tax ID number: 00215337
  • Address: 5F, No. 186, Sec. 1, Keelung Rd., Xinyi Dist., Taipei City 110, Taiwan
  • Support email: [email protected]
  • Support phone: 0975-712307
  • Phone: +886 912 097 079