Privacy Policy
Last updated 20 August 2026
1. Overview
This policy explains what KreadivNext collects, why, and what control you have. It covers two groups: the professionals who run a business on the platform, and the clients who book with them.
2. Parent company
KreadivNext is a product of VBA. By using this service you also agree to VBA's Privacy Policy and Terms of Service, which govern how VBA processes and protects your information.
3. What we collect
- Account data — name, email, password hash, business name, location and contact details.
- Business data — services, prices, hours, time off, photos, brand settings and your public page content.
- Client data — the name, phone, email, appointment history and private notes you record for the people who book with you.
- Payment data — subscription and payout status. Card numbers are handled by Stripe and never stored on our servers.
- Technical data — log records, device and browser information, and security events needed to run the Service.
4. How we use it
- To provide the booking calendar, public page, client records and reporting.
- To send transactional messages: confirmations, reminders, changes, receipts and account emails.
- To take subscription payments and to route client payments to your payout account.
- To secure the platform, prevent abuse, and meet legal obligations.
We do not sell personal data, and we do not use your client lists for our own marketing.
5. Who is responsible for client data
For the clients who book with you, you are the data controller and KreadivNext is your processor: we hold and process that information on your instructions. Each business's data is isolated — no other business on the platform can see your clients, calendar or notes.
6. Service providers
- Stripe — subscription billing and Venovax Pay client payments.
- Email delivery — booking confirmations, reminders and account emails sent from notify.kreadiv.app.
- SMS providers — where you connect your own Twilio, Brevo or GatewayAPI account, messages and recipient numbers pass through that provider under your agreement with them.
- Hosting and database — infrastructure providers that store data encrypted in transit and at rest.
- AI generation — copy and image generation through the Lovable AI Gateway, used only when you explicitly request it inside the app.
7. Retention
We keep account and business data while your account is open. After closure, data is available for export for 30 days and then deleted from live systems, except records we must retain for tax, accounting or fraud prevention. You can delete individual client records at any time.
8. Your rights
Depending on where you live, you may request access, correction, deletion, restriction, or a portable copy of your personal data, and object to certain processing. Clients should contact the business they booked with first; we will support that business in responding.
9. Messaging choices
Booking confirmations and reminders are transactional and go out as part of the service the client requested. Clients can manage or cancel a booking from the secure link in their message. Businesses can turn reminders on or off in notification settings.
10. Cookies
We use only the cookies and local storage needed to keep you signed in and to remember basic preferences. We do not run third-party advertising trackers.
11. Contact
Privacy questions and data requests go to privacy@vbaspire.com (or privacy@kreadiv.app). We update this policy from time to time and will announce material changes in the app.