Privacy Policy
What we collect, why we collect it, who else sees it, and how to get it out or have it deleted.
Last updated 20 July 2026
This policy covers the ChairWatch provider console, the salon storefronts we host, and the APIs behind them. It is written to be read, not to be survived.
1. Who is responsible for your data
This matters, because the answer differs depending on whose data it is.
- Salon accounts. For the data of salons and their staff — names, emails, logins, billing — we are the controller.
- Client records. For the data a salon holds about its own clients — contact details, appointment history, notes — the salon is the controller and we are its processor. We act on the salon’s instructions. If you are a client wanting your record changed or erased, ask the salon first; we will help them do it.
Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Contact: privacy@chairwatch.com.
2. What we collect
- Account data — name, email, phone, password (hashed, never readable), passkeys, the salon you belong to and your role in it.
- Salon data — business name, locations, opening hours, staff, services and prices, branding.
- Booking data — appointments, the services booked, who performed them, status and history, and anything the salon notes on a client record.
- Payment data— amounts, currency, status, and the payment provider’s reference. We never receive or store full card numbers; those go straight to Stripe.
- Messaging data— the emails and SMS we send on a salon’s behalf, and whether they were sent, skipped or failed.
- Technical data — IP address, device and browser information, and logs needed to keep the Service secure and working.
3. Why we use it, and on what basis
- To provide the Service — taking bookings, processing payments, sending confirmations and reminders. Basis: performance of a contract.
- To keep it secure and working — fraud prevention, abuse detection, debugging, backups. Basis: our legitimate interests.
- To bill and account — subscriptions, invoices, tax records. Basis: contract and legal obligation.
- To send marketing — only where the recipient has not opted out, and always with a one-click unsubscribe link. Basis: consent or legitimate interests, depending on your country.
Booking confirmations and reminders are not marketing. Opting out of marketing never stops the message that tells you when your appointment is.
4. Who we share it with
We share data only with the providers that make the Service work:
- Stripe — card payments, payouts and subscriptions.
- Email and SMS providers — to deliver notifications and campaigns.
- Hosting and infrastructure — the servers and databases the Service runs on.
Each is bound to use the data only to provide their service to us. We do not sell personal data, and we do not share one salon’s data with another — the system is built so that a salon can only ever read its own records. We may disclose data where the law requires it.
5. Where it is stored
Data is stored in [REGION / DATA CENTRE LOCATION]. Where data is transferred outside your region, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
6. How long we keep it
- Account and salon data — while the account is open, and for a reasonable period afterwards.
- Booking and payment records — as long as tax and accounting law requires, typically several years.
- Message logs — pruned automatically after 400 days. We keep the counts, not the addresses: an address nobody will read again is a liability, not an asset.
- Technical logs — a short period, for security and debugging.
7. Your rights
Depending on where you live, you can ask to:
- get a copy of your data, or have it sent elsewhere in a portable format;
- correct it if it is wrong;
- delete it, where we have no overriding legal reason to keep it;
- restrict or object to how we use it;
- withdraw consent at any time, without affecting what was done before.
Write to privacy@chairwatch.com. If your data sits in a salon’s client records, we will pass the request to that salon and help them act on it. You also have the right to complain to your local data protection authority.
8. Marketing and unsubscribing
Every marketing message carries an unsubscribe link that works in one click, without signing in. Opting out is recorded with a timestamp and is honoured immediately.
Consent is per salon. Because each salon holds its own client records, unsubscribing from one salon does not unsubscribe you from another — you remain in control of each relationship separately.
9. Cookies
We use the minimum needed: a cookie to keep you signed in, and cookies our payment provider sets to process a payment securely. We do not use advertising trackers. Your browser can block cookies, but signing in will not work without the session cookie.
10. Security
Traffic is encrypted in transit. Passwords are hashed and never stored in readable form, and passkeys are supported so a password need not exist at all. Access to production data is limited to the people who need it. No system is perfectly secure, but if a breach affects you we will tell you and the relevant authority as the law requires.
11. Children
The Service is not intended for children. We do not knowingly collect data from a child beyond what a parent provides when booking an appointment for them.
12. Changes to this policy
We may update this policy. Material changes will be announced before they take effect, and the date at the top always shows the current version.
Privacy questions: privacy@chairwatch.com · Anything else: support@chairwatch.com