This Privacy Policy explains how Hey Happy, LLC ("Hey Happy", "we", "us", or "our") handles personal information in connection with the HeyHappy service, the heyhappy.io website, and the emails we send.
Effective Date: September 17, 2026
We handle personal information in two different roles, and your rights depend on which one applies.
As a business ("controller"). When you visit our website, create an account, or communicate with us, we decide how your information is used. That includes the names, email addresses, and billing details of the people who administer a HeyHappy account.
On behalf of our customers ("processor"). HeyHappy is a tool that service businesses use to survey their own customers. Our customers send us their contact records and job or ticket history, and we send surveys and collect responses on their instruction. In that case the customer decides what is collected and why, and we only act on their instructions.
If you received a survey, a reminder, or a review request from HeyHappy, the business that served you is responsible for that data. Contact that business to access, correct, or delete your information, or to stop receiving messages. If you contact us instead, we will forward your request to them and help them respond. Our handling of that data is governed by our Data Processing Addendum.
Account information. Name, business email address, job title, team name, and password (stored only as a cryptographic hash).
Billing information. Billing contact details, plan, and subscription history. Payments are processed by Stripe. Card numbers go directly to Stripe and we do not receive or store them.
Customer data submitted by our customers. Contact names, email addresses and phone numbers, company names, ticket and job records including titles, assigned technicians, status and dates, survey responses and ratings, free-text comments, and Google reviews imported for locations a customer has connected.
Integration data. When a customer connects ConnectWise, ServiceTitan, or Google Business Profile, we store the credentials or authorization tokens needed to keep that connection working, and we exchange data with that system on the customer's behalf. Usage and device data. IP address, browser and device type, pages and features used, timestamps, and error logs. For survey emails we also record whether a message was delivered, opened, and answered, because response rate is a feature of the product.
Support communications. Messages you send us and our replies.
We use information to operate, secure, support, and improve the Service; to authenticate users; to send surveys, reminders, notifications, and review requests configured by our customers; to process payments and manage subscriptions; to provide reporting, dashboards, and AI-assisted summaries to the customer whose data it is; to detect and prevent fraud, abuse, and security incidents; to respond to support requests; to send service and billing notices; and to comply with law.
We send marketing email only to business contacts who signed up or asked to hear from us, and every marketing message includes an unsubscribe link. Service, billing, and security notices are not marketing and cannot be unsubscribed from while you have an account.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use our customers' data to advertise to their customers.
We may create aggregated, de-identified statistics that do not identify any person or business, and use them to improve and describe the Service.
Where the GDPR or UK GDPR applies to our own processing, we rely on: performance of a contract, to provide the Service and manage your account; legitimate interests, to secure the Service, prevent abuse, understand product usage, and communicate with business contacts; consent, where we ask for it, such as non-essential cookies; and legal obligation, where the law requires us to keep or disclose information. Where we act as a processor for a customer, that customer is responsible for the legal basis of the processing it instructs.
We share information with vendors who help us run the Service, under contracts that limit them to processing it on our behalf:
We also exchange data with ConnectWise and ServiceTitan when a customer connects those systems, at that customer's direction.
We may disclose information if required by law or legal process, to enforce our agreements, to protect the rights, safety, or property of any person, or in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy or give you notice of any material change.
We use cookies that are necessary for the Service to work, including session and authentication cookies and a CSRF token. We also use a self-hosted analytics script on our marketing pages to measure page views and traffic sources. We do not use third-party advertising cookies or advertising trackers.
You can block or delete cookies in your browser, but the application will not function correctly without its essential cookies. We honor Global Privacy Control signals on our website where technically feasible.
We keep account and billing records for as long as your account is active and afterward as needed for tax, accounting, and legal purposes. Customer data is kept while the customer's account is active. After an account terminates, we retain it for 30 days so the customer can reactivate or export, then delete or de-identify it within 90 days, except where we must keep it to comply with law, resolve a dispute, or enforce our agreements. Routine backups are purged on our standard schedule.
Usage and security logs are kept for a limited period appropriate to their purpose, then deleted or aggregated.
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, encryption at rest for stored data, hashed passwords, access controls that limit staff access to what their role requires, logging, and regular patching of our systems and dependencies. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a breach affecting personal information, we will notify affected customers without undue delay and will cooperate with them so they can meet their own notification obligations.
We operate in the United States and our infrastructure and vendors are located there. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country. Where required, we use European Commission Standard Contractual Clauses or another approved transfer mechanism for transfers from the EEA, UK, or Switzerland.
Depending on where you live, you may have the right to know what personal information we hold about you, to access a copy or receive it in a portable format, to correct inaccurate information, to delete information, to restrict or object to certain processing, to withdraw consent you previously gave, and to appeal a decision we make about your request.
We do not sell personal information or share it for cross-context behavioral advertising, and we do not use it for automated decision-making that produces legal or similarly significant effects about you. We will not discriminate against you for exercising a privacy right.
To make a request about information we hold as a business, email chris@heyhappy.io from the address associated with your account, or tell us enough for us to verify who you are. We will respond within the time the applicable law allows, generally 30 to 45 days, and will tell you if we need longer. An authorized agent may submit a request on your behalf with proof of authorization.
If you received a survey or review request from a business using HeyHappy, that business holds your information as the controller, and requests about it should go to them. Every survey email identifies the business that sent it.
If you are in the EEA or UK, you may also lodge a complaint with your local data protection authority.
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
We may update this Policy. We will post the revised version here with a new effective date, and for material changes we will notify account administrators by email or in the Service.
Questions, requests, or concerns about privacy can be sent to chris@heyhappy.io.
Hey Happy, LLC Michigan, United States
Last updated: September 17, 2026