This Subprocessor List identifies key third-party providers that may process personal information for MyChairHQ. It is incorporated into the Privacy Policy and Data Processing Addendum.
MyChairHQ may add, replace, or remove subprocessors as needed to provide, secure, support, or improve the Platform. MyChairHQ will update this list when material changes are made. Where required by contract or law, MyChairHQ will provide notice of material subprocessor changes and a reasonable opportunity to object on data-protection grounds.
| Provider | Purpose | Data categories that may be processed |
|---|---|---|
| Stripe | Subscription billing, payment processing, Stripe Connect, connected-account status, payment metadata, refunds, disputes, chargebacks | Professional account and billing data, Customer payment metadata, transaction IDs, amounts, status, refund/dispute data, tax/billing details |
| Twilio | SMS delivery, appointment reminders, SMS campaigns, opt-out handling, delivery status | Customer names, phone numbers, appointment details, message content, delivery metadata, opt-outs, provider IDs |
| Resend | Email delivery, transactional emails, reminders, campaigns, delivery status | Names, email addresses, appointment details, message content, delivery metadata, unsubscribe or bounce data |
| Cloudinary | Image hosting, optimization, and delivery | Professional-uploaded images, logos, gallery photos, staff photos, booking-page media, related metadata |
| Anthropic | AI-powered content generation, business assistant, summaries, briefings, and other AI features where enabled | Professional business data, prompts, service data, appointment data, revenue metrics, limited Customer context where needed for requested outputs |
| Google OAuth sign-in, Google Calendar integration, and Google Analytics where a Professional enables it on their booking page | Google profile information, email address, OAuth tokens, calendar events, appointment metadata, Customer names in synced calendar events where enabled; booking-page traffic and usage data via Google Analytics where the Professional enables it and the visitor consents | |
| Vercel | Hosting, deployment, edge functions, infrastructure, logs, storage, and application delivery | Platform data, request data, IP addresses, logs, application data processed through infrastructure |
| Neon | Managed PostgreSQL database hosting — the primary application datastore | All Platform personal data stored in the database: Professional account and business data, staff data, Customer contact and booking data, appointment history, message metadata, and payment metadata |
| Inngest | Background job processing, scheduled tasks, notifications, campaigns, calendar sync, AI workflows | Customer contact data, appointment details, campaign data, task metadata, workflow status |
| Sentry | Error tracking, performance monitoring, diagnostics | Error logs, stack traces, device/browser data, diagnostic context; personal information may appear incidentally in logs |
| Upstash Redis | Rate limiting, caching, session support, abuse prevention | Session identifiers, rate-limit keys, cache data, request metadata, de-identified or limited operational data |
Subprocessors may process information in the United States and other locations where they or their affiliates, infrastructure providers, or support personnel operate. MyChairHQ uses contractual and operational safeguards appropriate to the service and data involved.
Questions or objections regarding subprocessors may be sent to privacy@mychairhq.com.