Legal

Privacy Policy

Last updated · October 2, 2026

This Privacy Policy explains how Chair (“Chair”, “we”, “us”), the software at usechair.app, collects, uses and shares personal information through our website, the Chair back office, the AI Receptionist and Quick Booking pages (the “Service”).

Chair is used by two groups of people, and we treat their information differently:

  • Shop owners and their teams (“you”) — who sign up for Chair and use the back office. For this information, Chair decides how it is used.
  • Barbershop customers (“Customers”) — who call, text, message or book with a shop that uses Chair. For this information, the barbershop is in control; Chair processes it on the shop’s behalf, following the shop’s instructions. If you are a Customer, the shop’s own privacy notice also applies, and you can contact the shop directly about your information.
01

Information we collect

From shop owners and team members

  • Account details: name, business name, email, mobile number, password (stored hashed), role and permissions.
  • Business setup: locations, addresses, opening hours, barbers and their working hours and time off, services, prices, policies, AI tone, greeting and escalation settings.
  • Billing: plan, billing contact and invoices. Card details are collected and stored by our payment processor; Chair does not store full card numbers.
  • Security and usage: sign-in times, devices, browser, IP address and approximate location (shown to you in Login history and Sessions), two-factor settings, and how you use the back office.
  • Connected accounts: when you connect Google Calendar, Outlook, Square, WhatsApp Business, Instagram or other services, the tokens and account identifiers needed to keep the connection working.
  • Support: what you send us when you contact us.

About Customers (processed for the shop)

  • Contact details: name, phone number, and email if they choose to give it.
  • Conversations: messages sent by SMS, WhatsApp, Instagram direct message or website chat, and the AI’s and team’s replies, including internal notes.
  • Calls: caller number, call times and duration, and — if the shop turns on recording — call recordings and transcripts. Callers hear a recording notice first.
  • Appointments: service, barber, location, date and time, and booking, cancellation, no-show and reminder history.
  • Customer memory: preferences learned from bookings and conversations (for example preferred barber, usual service, best times) and notes the team adds.
  • Photos: reference photos a Customer chooses to send, attached to the booking for the barber.
  • Quick Booking: name, mobile number, preferred confirmation channel (WhatsApp or SMS) and optional email. No account or password is created.
  • Messaging preferences: opt-outs, such as replying “STOP” to texts.

From our website

  • Basic technical information (IP address, browser, device and pages requested) kept in server logs to deliver and secure the website. We do not use analytics or advertising trackers. See Section 8.
02

How we use information

  • To run the Service: answer calls and messages, check availability, book and change appointments, send confirmations, reminders and follow-ups, recover missed calls, show the Operations Room, alert the right person when something needs a human, and produce Analytics.
  • To keep it secure: authenticate users, detect suspicious sign-ins, prevent abuse and fraud.
  • To bill you for your Chair subscription.
  • To support you and communicate about your account, service changes and security.
  • To improve Chair, using usage data and de-identified, aggregated information.
  • To meet legal obligations and enforce our Terms.

AI and your data. The AI Receptionist uses third-party AI model providers to understand requests and write replies. We send them only what is needed to handle the conversation, under contracts that prohibit them from using it to train their models. They may keep it for up to 30 days to detect abuse, then delete it. Chair does not use Customer Data to train general-purpose AI models.

Calendars. When a barber’s calendar is connected, Chair reads busy/free times only to avoid double-booking — it does not read event titles or details — and can add Chair bookings to that calendar. Chair’s use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell personal information and we do not share it for cross-context behavioral advertising.

03

How we share information

We share personal information only as needed to provide the Service:

  • With the shop. Customer information is available to the shop’s owner and team members, according to the roles and permissions the shop sets.
  • Service providers (sub-processors) that work on our behalf under contract, such as:
    • cloud hosting, storage and sign-in security;
    • telephony and text messaging (for example Twilio);
    • Meta, for WhatsApp Business and Instagram messages;
    • AI model providers (OpenAI);
    • email delivery (Resend);
    • payment processing for Chair subscriptions;
    • customer support tools.

A current list is available on request at privacy@usechair.app.

  • Services the shop connects, such as calendars and scheduling systems, when the shop turns on that integration.
  • Legal and safety, when required by law or to protect the rights, safety and security of Customers, shops, Chair or others.
  • Business transfers, in a merger, acquisition or sale of assets, subject to this Policy.
04

How long we keep information

  • While an account is active, we keep information for as long as the shop uses Chair, unless the shop deletes it sooner.
  • Call recordings and transcripts are kept for 12 months, unless the shop deletes them sooner.
  • Deleted records are removed from active systems right away and from backups within 30 days.
  • When an account is deleted, we delete the business, its locations, Customer profiles, conversations and recordings within 30 days, and from backups within 90 days. Phone numbers provided by Chair are released.
  • Billing records are kept as long as tax and accounting laws require.
  • Opt-out lists are kept so we can keep honoring them.
05

Security

We protect information with encryption in transit and at rest, access controls, role-based permissions, two-factor authentication, session management, login history and alerts for suspicious sign-ins. No system is perfectly secure; if we confirm a security incident affecting personal information, we will notify affected shops and, where required, individuals and regulators.

06

Your choices and rights

Shop owners and team members

  • Update your account details and notification settings in Settings.
  • Sign out of other sessions, change your password and manage two-factor authentication.
  • Delete your account in Settings › Account. This is permanent.
  • Contact us at privacy@usechair.app for access, correction, deletion or a copy of your information.

Customers

  • Stop texts: reply STOP to any text from a shop. Reply HELP for help.
  • Request access, correction or deletion: contact the shop you dealt with. If you contact Chair, we will forward your request to the shop and help them respond.
  • Recording: if you prefer not to be recorded, you can end the call and contact the shop another way.

State privacy rights (including California)

Depending on where you live, you may have the right to know what personal information we collect, access it, correct it, delete it, and not be discriminated against for exercising these rights. To make a request about information Chair controls, email privacy@usechair.app. We will verify your request before acting on it. You may use an authorized agent. Where Chair acts as a service provider to a shop, we will direct your request to that shop.

European Economic Area, United Kingdom and Switzerland (GDPR)

Where the GDPR or UK GDPR applies, the shop is the controller of Customer information and Chair is its processor. For information Chair controls, our legal bases are: performance of a contract (providing your account), legitimate interests (security, fraud prevention, improving the Service), consent (where we ask for it) and legal obligation (tax and accounting). You have the right to access, rectify, erase, restrict and port your information, to object to processing, to withdraw consent at any time, and to complain to your local data protection authority.

Brazil (LGPD)

Where Brazil’s Lei Geral de Proteção de Dados (Law 13,709/2018) applies, the shop is the controlador of Customer information and Chair is its operador. For information Chair controls, we rely on the legal bases of contract performance, legitimate interest, consent and legal or regulatory obligation. You have the right to confirm whether we process your information; access, correct, anonymize, block or delete it; port it; know who we share it with; be informed about the consequences of refusing consent; and withdraw consent. You may also petition Brazil’s data protection authority (ANPD).

Exercising these rights

Email privacy@usechair.app. We answer within the time required by the applicable law (for example, one month under the GDPR and 15 days under the LGPD). Requests about Customer information are passed to the shop that controls it, and we help them respond.

International transfers

Chair stores the Service’s data — including Customer Data, recordings and backups — in the United States (Northern Virginia). Some service providers (for example telephony, messaging or AI model providers) may process information in other countries to deliver their part of the Service. These countries may have different data protection laws from where you live. When we transfer personal information internationally, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, the UK Addendum, the standard contractual clauses approved by Brazil’s ANPD, or other mechanisms recognized by the applicable law.

Privacy contact

For privacy questions or to reach the person responsible for data protection at Chair (data protection officer / encarregado), email privacy@usechair.app.

07

Children

Chair is not directed to children under 13 and we do not knowingly collect their information directly. Appointments for children (for example a kids’ haircut) should be booked by a parent or guardian. If you believe a child has given us information, contact privacy@usechair.app and we will delete it.

08

Cookies

Our website and back office use only essential cookies and local storage — to sign you in, keep sessions secure and remember preferences such as theme and selected location. We do not use analytics or advertising cookies. If this changes, we will update this Policy and ask for consent where required.

09

Changes to this Policy

We may update this Policy. For material changes, we will notify account owners by email or in the Service before they take effect, and update the date above.

10

Contact

Chair · usechair.app · privacy@usechair.app