Gonia

Privacy Policy

Last updated 25 August 2026

Gonia is a customer relationship management platform operated by Berkshire Valley Group LLC. Businesses use it to manage their own customers, which means two very different people end up covered by this policy. Work out which one you are first — the answer changes who decides what happens to your data.

1. Which half of this policy is about you

You signed up for Gonia.

You or your employer use the platform to run a business. We decide how your account data is handled, so this policy applies to you directly. Section 2 is yours.

A business you deal with uses Gonia.

Your details are in Gonia because a salon, studio or shop put them there, or because you filled in their booking or sign-up page. That business decides what is collected, why, and how long it is kept — we hold it and act on their instruction, nothing more. Section 3 is yours, and that business is who to ask first.

2. If you signed up for Gonia

Your account record holds:

  • Email address, first and last name, time zone, language preference, and a profile photo if you upload one.
  • We also record which user made which change inside an organization — an audit trail the business itself can read.

That is the whole account record, plus the dates it was created and last changed. We are responsible for this data, and you can have it deleted (section 8). We do not process payments, so Gonia holds no payment details of any kind.

3. If a business holds your details in Gonia

The business chose what to collect and why. The platform stores what it is given, and here is everything it can hold about you:

  • Contact details the business entered: name, email address, phone number, birthday, notes, and any custom fields it decided to add.
  • What you typed into its booking or sign-up page: first name, last name, phone number, an optional email address, and an optional note.
  • A consent record, if you agreed to receive marketing: the exact wording you were shown, the language it was in, the channel, the time, and — as evidence — your browser’s user-agent string and a one-way hash of your IP address.
  • Messages the business sent you through the platform: the address, subject, body, and whether it was delivered.
  • Files it uploaded against your record.

The platform has no field for payment card details or government identifiers. Free-text notes and custom fields accept whatever the business types, so what ends up in them is its decision, not ours.

4. Technical data, either way

We do not store raw IP addresses. Where we need one — to limit how often an anonymous form can be submitted, and as consent evidence — it is hashed with a secret key held on the server, so it can show that two submissions came from the same visitor without revealing the address.

Cookies keep you signed in, remember your language, and remember whether the sidebar is collapsed. We do not use advertising cookies, and no Gonia page loads advertising or social tracking scripts.

5. WhatsApp

A business can connect its own WhatsApp Business account to message people who agreed to hear from it.

  • The connection uses that business’s own Meta credentials. Gonia does not message anyone on its own behalf, and one business’s credentials are never used for another.
  • Incoming messages are checked for one thing: whether they ask to stop. We record the opt-out and the sender’s number. The text of incoming messages is not stored.
  • We record whether a message the business sent was delivered, read, or failed.
  • Access tokens and app secrets a business gives us are encrypted (AES-256-GCM) before they are stored.

6. Who else handles the data

We rely on these providers to run the platform:

  • Supabase — database, sign-in, and file storage.
  • Vercel — hosting, plus anonymous traffic and performance measurement on our public marketing site only, not inside the app and not on booking pages.
  • Sentry — error diagnostics, which can include the IP address of the browser an error happened in and a replay of the session. Replays are recorded with all text masked and images blocked, so they do not capture what is typed into a form.
  • Meta (WhatsApp Business Platform) — only for businesses that connect WhatsApp.
  • Each business’s own email provider — outgoing mail goes through the mail server that business configures.

7. Where the data lives, and who can reach it

The database and file storage are hosted in São Paulo, Brazil (Supabase, sa-east-1), and the application runs in the same region (Vercel, gru1). The providers above may process data elsewhere.

Reaching any business’s data requires signing in, and each organization’s data is separated in the database itself by row-level security, so one business’s account cannot read another’s. Access tokens, app secrets and mail-server passwords are encrypted before they are stored.

8. How long data is kept, and how to delete it

  • Your Gonia account: email support@goniacrm.com from that address. Requests are handled by a person rather than by a button in the app.
  • Your details in a business’s CRM: ask that business — it controls the record and can delete it itself. You can write to us as well, and we will act on its instruction.

A record deleted in the app stops being visible immediately; the underlying row is kept until the account is removed.

Consent records are the exception. They are deliberately permanent for as long as the business’s account exists, because they are the evidence of what someone agreed to, and they cannot be edited or deleted.

9. Changes and contact

If this policy changes, we update the date shown at the top.

Questions: support@goniacrm.com — Berkshire Valley Group LLC, 7901 4th St N Ste 300, St. Petersburg, FL 33702, USA.