Legal
Effective date: June 2025 · Last updated: July 2026
This Privacy Policy describes how we collect, use, disclose, and protect information when a business ("Customer") and its team members ("Authorized Users") use the Nabu website, platform, and related services (the "Service").
Nabu is a business-to-business platform. We provide the Service to Customers, who direct how the Service is used within their own business.
Account information: When a Customer or Authorized User creates an account or requests a demo, we collect name, email address, phone number, business name, role, and similar account details.
Business and contact information: Information provided through forms, demo requests, or support conversations, such as company details and communication preferences.
Usage and device information: Information about how the Service is accessed and used, including pages visited, features used, browser and device type, and session information.
Support and communication information: Information exchanged when a Customer or Authorized User contacts us for support or feedback.
Customer Data: Data that a Customer or its Authorized Users submit, import, sync, or generate through the Service — including data connected from a booking or point-of-sale platform (such as Zenoti), data uploaded by CSV, cost assumptions, and configuration settings.
Client Data: Where a Customer chooses to import, sync, upload, or enter information about its own patients, guests, or clients ("Clients"), that information is Client Data. Client Data may be used to support features like profitability, retention, and campaign reporting for the Customer.
Customers control what Customer Data and Client Data they submit to the Service.
We use the information described above to:
The Service includes an optional social media scheduler that lets Customer connect third-party social media accounts — currently Instagram, Facebook, TikTok, LinkedIn, and YouTube (each a "Connected Platform") — to schedule content, publish posts, and view performance metrics, at Customer's direction.
What we collect from a Connected Platform: basic account or Page information (such as name, username, profile photo, and account/Page ID); the content Customer submits through the Service for publishing; and, where the platform makes it available, performance metrics such as follower counts, impressions, reach, likes, comments, shares, and views.
Why we collect it: solely to provide the scheduling, publishing, and analytics features Customer requests. We do not use Connected Platform data to advertise to Customer or Customer's audience, do not sell it, and do not share it with any third party other than the Connected Platform itself (to publish the content Customer submits) and the service providers described in Section 7.
Access tokens: The credentials used to connect a Connected Platform are encrypted at rest and used only to perform actions Customer initiates through the Service, such as publishing a scheduled post or refreshing performance metrics.
Customer may disconnect a Connected Platform at any time from within the Service. Disconnecting immediately deletes the stored access credential for that account. See Section 10 and our Data Deletion page for how to request deletion of any remaining Connected Platform data.
Our platform is designed to support healthcare and med spa Customers that may handle protected health information. Where required, we enter into a Business Associate Agreement ("BAA") with eligible Customers. To the extent Customer Data or Client Data includes protected health information, our use and disclosure of that information is governed by the applicable BAA in addition to this Privacy Policy.
Customers are responsible for determining whether their use of the Service is subject to HIPAA or other applicable privacy laws. Customers are responsible for obtaining any rights, consents, and authorizations required before submitting data to the Service, and should not submit information they are not authorized to provide.
We process Client Data only to provide the Service to the Customer that submitted it. Specifically:
Any use of Client Data is subject to the Customer's instructions, the applicable agreement between us and the Customer, and applicable law.
The Service may provide analytics, forecasting, reporting, and other automated or AI-assisted features. These features are designed to use business, operational, aggregated, or de-identified data by default.
Raw Client Data is not used by AI-assisted features by default, unless a future workflow that uses it is separately reviewed, approved, and enabled.
Customers remain responsible for reviewing outputs before making business or clinical decisions. The Service is not a medical device and does not provide medical advice.
We use third-party service providers to help host, operate, secure, analyze, support, and improve the Service. These service providers may access information only as needed to perform services on our behalf and are required to protect it.
Where required for healthcare data, we use appropriate contractual safeguards with our service providers, including Business Associate Agreements.
We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit and at rest, access controls, audit logging, and security monitoring.
No method of transmission or storage is 100% secure. We encourage Customers and Authorized Users to use strong, unique credentials and to follow their own internal security practices.
We retain information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and as otherwise described in the applicable Customer agreement.
Customers may request deletion or export of their data in accordance with their agreement and the Service's capabilities. Some data may remain in backups or logs for a limited period where permitted or required by law.
Connected Platform data specifically: disconnecting a Connected Platform (Instagram, Facebook, TikTok, LinkedIn, or YouTube) from within the Service immediately deletes the stored access credential for that account. To request full deletion of any remaining data we hold about a Connected Platform account — including cached profile information and performance metrics — visit our Data Deletion page or email hello@joinnabu.com. We will complete verified deletion requests within 30 days.
We may disclose information:
Customers are responsible for:
We may use cookies and similar technologies on our website to support essential functionality, remember preferences, and understand aggregate site usage. You can control cookies through your browser settings.
Nabu is a business-to-business service. We do not knowingly collect personal information from individuals under 18 years of age.
We may update this Privacy Policy from time to time. We will notify Customers of material changes via email or through the platform. Continued use of the Service after changes become effective constitutes acceptance of the updated policy.
For questions about this Privacy Policy or to exercise your data rights:
Nabu
17705 140th Avenue NE, Suite A10
Woodinville, WA 98072