Legal
Privacy Policy
How AD Supply NY Corp, operating AD Appoint ("AD", "we"), collects and uses personal information.
Version 2026-09-27 · Effective September 27, 2026 · All legal documents
1. Who this policy covers
This policy covers everyone who interacts with AD Appoint: customers who book appointments, staff at a business that uses AD Appoint to run its calendar, and anyone who submits our for-business or advertise form, even without creating an account. It does not cover a business's own website, social media, or how a business uses information you give it in person.
2. What we collect
- Account data: first name, last name, email address, and phone number if a business you book with requires it.
- Booking data: the business, service, staff member, location and time you book, and any note you add to a booking.
- Notes: free-text fields a business may keep about a booking or client. AD Appoint is not designed to hold health information — businesses agree not to put health details into any note or field (see the Business Terms), and you should never include your own health details in a note either.
- Reviews: the rating and text you write about a completed, verified appointment.
- Lead and advertiser data: the company, contact name, email, phone and message you submit through the for-business or advertise form.
- Sign-in security data: when you sign in, we store the session's IP address and browser/device (user agent) — this helps us detect abuse and keep accounts secure.
- Location — two separate signals:
- A location you choose (tapping “Near me”, or typing a city/ZIP) — remembered for up to 30 days in the
ada_loccookie, rounded to about 1 km, so results stay relevant on your next visit (only until you close your browser if you choose Essential only). See the Cookie Notice. - An approximate location inferred from your IP address, automatically, for that one request only — used to show nearby results by default when you haven't chosen a location. It is not saved unless you separately choose to save a location.
- A location you choose (tapping “Near me”, or typing a city/ZIP) — remembered for up to 30 days in the
- Google sign-in: if you choose “Continue with Google”, we receive only your name, email address and profile photo URL from Google — nothing else, and only if you choose that option.
- Usage data: basic technical data (device/browser type, pages viewed) to keep AD Appoint secure and working.
We never ask for a password (sign-in uses an emailed code or Google), and AD Appoint never collects or stores payment card details — there are no payments inside AD Appoint at all.
3. Cookies
AD Appoint sets a small number of first-party cookies and nothing else — no third-party advertising or tracking cookies. See the full Cookie Notice for every cookie's name, purpose and lifetime.
4. How we use it
- To create your account, sign you in, and let you book, reschedule or cancel appointments.
- To send transactional email only: sign-in codes, booking confirmations and reminders, changes to a booking, and review-request emails. We do not send marketing email or text messages today — those are switched off platform-wide until we've done the compliance work for them, and we will update this policy before that changes.
- To follow up on a for-business or advertise request you submit.
- To show and measure ads on discovery pages, if a business or brand is advertising: we count views and clicks in aggregate, first-party only — never a per-visitor record, never shared or sold (see Advertising Terms).
- To keep AD Appoint secure, prevent abuse, and fix problems.
5. Who we share it with
When you book an appointment, we share what the business needs to serve you — your name, contact details, and the booking itself — with that specific business. We do not sell or share your personal information with anyone else, and we honor Global Privacy Control browser signals.
We use a small number of subprocessors to run AD Appoint, each limited to what it needs to do its job:
- Vercel — application hosting and file storage (e.g. gallery photos).
- Neon — our Postgres database.
- Resend — sends transactional email on our behalf.
- OpenFreeMap / OpenStreetMap — map tiles shown on business location maps.
- US Census Bureau geocoder — turns a business's address into map coordinates.
- Google — only if you choose “Continue with Google” to sign in.
We may also share information when required by law, or to protect the rights, safety or property of AD, our users or the public.
6. How long we keep it
- Your account and booking history: kept while your account is open.
- Expired sign-in sessions: deleted daily.
- Stored copies of emails we've sent (e.g. a confirmation email's content): trimmed after 90 days; the booking record itself is unaffected.
- Reviews: kept even after the reviewer's account is deleted (the byline changes to “Former customer”) — other customers and the business rely on genuine review history.
- A closed business's data: deleted on request within 30 days, unless the law requires us to keep it longer.
7. Your choices and rights
- Review and update your name, email and phone from your profile at any time.
- Remove a business from your favorites at any time.
- Download my data: get a copy of your profile, appointments, reviews, waitlist entries and favorites as a file, from your profile page.
- Delete my account: a self-service button on your profile page removes your login and personal details immediately; a business's own record of your past visits stays with that business (that record belongs to them, not us — see the Business Terms).
- Can't sign in, or need help with a request above? Write to info@adwebdesignny.com.
We honor requests to access, correct, delete or export personal information for everyone who asks, regardless of which state you live in or whether a particular state's privacy law would otherwise require it of a business our size.
8. Children
You must be at least 13 years old to create a AD Appoint account, and anyone under 18 needs a parent's or guardian's permission to use it. We do not knowingly collect personal information from anyone under 13; if we learn that we have, we delete it.
9. Security and breach notification
We use encryption in transit, role-based database access with row-level security, and passwordless sign-in to reduce the risk to your account. No system is perfectly secure. If a breach affects your information, we will notify you as required by law, including New York's SHIELD Act.
10. Changes to this policy
We'll update the version and effective date above whenever this policy changes, and post material changes here before they take effect. If you're signed in when we make a material change, you'll be asked to review and re-accept it once.
11. Contact / privacy requests
For general support, a privacy or data request, an accessibility issue, a copyright/DMCA notice, or a security report, write to info@adwebdesignny.com — please say which of these it is so it reaches the right person. Contact is by email only today; we do not yet publish a mailing address (see Copyright / DMCA Notice for why that matters for copyright agent registration).