Privacy Policy

Last updated September 4, 2026

1. What we collect
From Salon owners: name, email, password (stored as a salted hash, never in plain text), salon name, phone, and the services/staff/hours you configure.
From Customers booking an appointment: name, email, phone number (optional), and the appointment details you select (service, staff member, time).
Automatically: IP address and basic request metadata, used only for rate limiting and bot protection (Cloudflare Turnstile) to keep the booking system usable and abuse-free — not for tracking or advertising.
2. How we use it
Customer contact information is used only to send the confirmation and reminder for the specific appointment booked, and is visible to the Salon the appointment was booked with (each Salon can only see its own Customers and appointments — data is isolated per Salon in our database). Salon owner account data is used to operate your account, dashboard, and booking page, and to email you about your account (e.g. verification, password resets).
3. Payment data
Card details are entered directly into Stripe Checkout and never touch Chairtime's servers. Chairtime stores only the resulting Stripe checkout/payment identifiers, not card numbers. See Stripe's own privacy policy for how they handle payment data.
4. SMS data and opt-out
Phone numbers are used solely to send appointment confirmations and reminders via Twilio. Replying STOP to any message immediately and permanently suppresses future SMS to that number across Chairtime, until START is sent again. We do not sell or share phone numbers with third parties for marketing.
5. Who we share data with
We use a small number of infrastructure providers to operate Chairtime: Cloudflare (hosting, database, bot protection), Stripe (payments), Resend (email delivery), and Twilio (SMS delivery). Each only receives the data necessary to perform its function (e.g. Twilio receives phone numbers and message text, not full appointment history). We do not sell personal data.
6. Data retention and deletion
We retain account and appointment data for as long as a Salon's account is active, so booking history remains useful to the Salon. A Customer or Salon owner can request deletion of their data by emailing privacy@chairtime.titung.com; we'll remove personal data not required for legal/financial recordkeeping (e.g. completed payment records) within 30 days.
7. Cookies
Chairtime uses a single, first-party session cookie to keep Salon owners logged in. It's essential to the dashboard functioning and isn't used for advertising or cross-site tracking. We don't use third-party analytics or advertising cookies.
8. Contact
Privacy questions or data requests: privacy@chairtime.titung.com.