Privacy policy
Chairside Beauty (“the operator”, “we”) runs a booking service for independent beauty & wellness pros (“pros”) and the students training to become them. Each pro is responsible for their own clients' information; the operator runs the service that stores it.
Information about pros
When a pro signs up we store their Google account identifier and email address, the page details they enter (name, bio, location, services, prices, hours, photos and social links), their billing status, and records of payments they report.
Information about clients
When you book, we collect your name, phone number and — only if you choose — your email address and notes. These are used only to schedule your appointment, let the pro contact you, and send you a confirmation. Each pro only sees their own clients.
Google data
With the pro's permission, the service:
- reads free/busy times only (not event titles or details) from their Google Calendar, to hide times they're unavailable;
- creates, updates and deletes one calendar event per booking made through the service.
It does not read, send or access Gmail. Google user data is not sold, not used for advertising, not used to train AI models, and not shared except as needed to provide the service. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Booking confirmations and updates are sent by the service through Resend, our email delivery provider. Replies from clients go directly to the pro. If an address bounces or reports an email as spam, we stop sending to it; we keep only a one-way hash of that address for this purpose.
Social media images
Pros can turn portfolio photos into images for their own social media posts. These images are generated in the pro's browser and are not uploaded to or stored by the service. Each pro is responsible for getting their client's consent before posting a photo on social media.
Service providers
We use these providers (subprocessors) to run the service:
- Netlify (website hosting)
- Render (API hosting)
- Neon (database)
- Cloudinary (images)
- Resend (email)
- Cloudflare Turnstile (bot protection)
- Google (sign-in and calendar)
Retention and deletion
Client names, phone numbers, emails and notes are deleted automatically 2 years after the appointment. Anonymous appointment counts are kept for school records.
Pros can delete their account at any time in Settings. This revokes the service's Google access and deletes their page and all of their clients' data. Clients can ask their pro, or contact us, to have their information deleted. Database backups (Neon point-in-time history and encrypted GitHub Actions backups) may keep deleted data for up to 90 days before it is gone for good.
Security
The service uses HTTPS everywhere, encrypts Google access tokens at rest, uses a bot check on booking forms, and sets no tracking cookies.
Contact
Questions or deletion requests: [email protected]. You can also contact your pro directly.