Privacy Policy

Last updated: May 18, 2026

This Privacy Policy explains how MyChairHQ LLC, doing business as MyChairHQ ("MyChairHQ," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information in connection with MyChairHQ websites, applications, dashboards, professional-branded booking pages, customer booking flows, communications, support, integrations, and related services.

1. Scope

This Privacy Policy applies to:

  1. Professionals who register for or manage MyChairHQ accounts.
  2. Professional staff and Authorized Users.
  3. Customers who visit or book through MyChairHQ-powered Professional booking pages.
  4. Visitors to MyChairHQ marketing websites.
  5. People who communicate with MyChairHQ for support, security, privacy, billing, sales, or other purposes.

This Privacy Policy does not govern a Professional's independent data practices outside the Platform. Professionals are independent businesses and may have their own privacy policies, consent forms, customer records, marketing systems, payment practices, staff records, and legal obligations.

2. MyChairHQ's Role and Professional's Role

MyChairHQ acts in different privacy roles depending on the data and context.

MyChairHQ as controller/business. MyChairHQ determines the purposes and means of processing for information relating to MyChairHQ accounts, subscriptions, billing, support, website visitors, Platform security, Platform analytics, provider management, legal compliance, and MyChairHQ marketing.

MyChairHQ as processor/service provider. For Customer Data processed on behalf of a Professional to provide booking, scheduling, reminder, customer-management, communication, payment-metadata, and related Platform services, MyChairHQ acts as a processor or service provider to the Professional. The Professional is responsible for determining why and how Customer Data is collected and used for the Professional's business and services.

Professional as controller/business. Professionals independently control their customer relationships, services, staff, premises, customer communications, privacy notices, lawful bases, consent, retention, deletion, and compliance obligations. Customers should contact the Professional for requests about Professional services or Professional-controlled Customer Data, and MyChairHQ will assist as described in the Data Processing Addendum.

3. Information We Collect

3.1 Professional account and business information

We may collect:

  1. name, email address, phone number, login credentials, account identifiers, and authentication information;
  2. business name, address, service area, categories, hours, website, social media profiles, business description, logo, photos, staff profiles, services, prices, policies, FAQs, and public booking-page settings;
  3. subscription plan, add-ons, billing status, invoices, payment method metadata, tax information, payment processor status, and transaction metadata;
  4. onboarding information, support messages, compliance documentation, license or business verification information provided by the Professional, and account preferences;
  5. staff names, roles, bios, photos, contact information, schedules, availability, permissions, and service assignments provided by Professional;
  6. custom-domain information, DNS verification records, SSL configuration, and related technical records; and
  7. calendar integration data, OAuth tokens, sync settings, appointment metadata, and integration status where the Professional enables integrations.

3.2 Customer booking information

When a Customer uses a Professional booking page, we may collect:

  1. first and last name;
  2. email address;
  3. phone number;
  4. selected service, appointment date and time, staff member (where applicable), price at booking, deposit status (where applicable), payment metadata, cancellation or rescheduling information, and booking status;
  5. optional booking notes entered by the Customer or Professional;
  6. communication preferences and appointment reminder consent;
  7. message delivery metadata, such as sent status, delivery status, bounce, error, opt-out, or unsubscribe status; and
  8. device, IP address, browser, and security data associated with the booking flow.

3.3 Technical, usage, and security information

We may automatically collect:

  1. IP address, browser type, operating system, device type, user agent, referral source, pages visited, feature usage, session events, timestamps, and diagnostic information;
  2. login history, account activity, API usage, request volume, storage usage, bandwidth usage, rate-limit data, error logs, performance logs, audit logs, and security events;
  3. email and SMS delivery metadata, such as timestamps, provider message IDs, delivery results, bounces, opt-outs, and errors;
  4. payment metadata, refund metadata, dispute metadata, chargeback metadata, subscription history, and provider status information;
  5. AI feature usage, such as prompts submitted, responses generated, token or usage counts, and feature interaction metadata, subject to the AI section below; and
  6. aggregated or de-identified statistics about Platform usage, performance, reliability, cost, and product improvement.

3.4 Cookies and similar technologies

We use strictly necessary cookies for authentication, session management, security, and cross-subdomain login. Where a Professional enables Google Analytics on their booking page, analytics cookies are set only after you grant analytics consent through our cookie banner. MyChairHQ does not currently use advertising or cross-context behavioral-advertising cookies. The Cookie and Tracking Policy describes these technologies and your available choices.

3.5 Information from third parties

We may receive information from:

  1. Stripe and other payment providers, including subscription status, connected-account status, payment metadata, dispute status, refund status, and billing information;
  2. Resend, Twilio, and other communication providers, including delivery status, bounces, opt-outs, errors, and provider message IDs;
  3. Google and other authentication or calendar providers, including authentication profile information and calendar-sync data where enabled;
  4. Cloudinary and other media providers, including image-storage and delivery information;
  5. Sentry and other error-monitoring providers, including diagnostic and performance data;
  6. hosting, infrastructure, security, analytics, and job-processing providers; and
  7. public sources, providers, law enforcement, complainants, or other users when needed for support, fraud prevention, security, policy enforcement, or legal compliance.

4. How We Use Information

We use information to:

  1. provide, operate, maintain, secure, and improve the Platform;
  2. create and manage accounts, subscriptions, booking pages, staff profiles, services, schedules, reminders, communications, payments metadata, and integrations;
  3. facilitate appointment booking, confirmation, reminders, cancellations, rescheduling, and Professional-Customer communication;
  4. process subscriptions, add-ons, SMS credits, invoices, refunds, billing support, tax records, and payment-provider interactions;
  5. provide customer support, onboarding, troubleshooting, service notices, policy notices, security notices, and administrative communications;
  6. monitor usage, performance, uptime, errors, resource consumption, third-party costs, abuse, fraud, and security threats, including through internal analytics tools that aggregate data across accounts for Platform administration, capacity planning, and cost management;
  7. enforce agreements, investigate violations, handle disputes, comply with law, respond to lawful requests, and protect rights, safety, property, and the Platform;
  8. provide AI features requested by Professional, subject to the AI section below;
  9. generate aggregated or de-identified analytics, benchmarks, reports, and product insights;
  10. send MyChairHQ marketing communications to Professionals and prospects where permitted, with opt-out rights; and
  11. perform other purposes disclosed at collection or with consent.

5. Legal Bases Where Required

Where a legal basis is required, we process personal information based on one or more of the following:

  1. performance of a contract, including providing the Platform and processing bookings;
  2. legitimate interests, including security, fraud prevention, product improvement, support, billing, and business operations;
  3. consent, including optional communications, integrations, and certain marketing or SMS choices;
  4. legal obligations, including tax, accounting, lawful requests, disputes, and compliance; and
  5. Professional instructions, where MyChairHQ acts as processor/service provider for Customer Data.

6. How We Disclose Information

6.1 Professionals and Customers

When a Customer books through a Professional page, the booking information is made available to the Professional so the Professional can provide the appointment service, communicate with the Customer, manage scheduling, and handle its own customer relationship. Professional use of that information is governed by Professional's privacy practices and legal obligations.

Professional public booking pages may display Professional business information, staff profiles, prices, service descriptions, policies, photos, reviews, and other Professional Content configured by Professional.

6.2 Service providers and subprocessors

We disclose information to providers that help us operate the Platform, including hosting, infrastructure, payments, email, SMS, media hosting, AI, authentication, calendar sync, error monitoring, job processing, caching, support, security, analytics, and legal or professional services. The Subprocessor List identifies key subprocessors and purposes.

Service providers may process personal information only for permitted business purposes, subject to contract terms and applicable law.

6.3 Legal, safety, and enforcement disclosures

We may disclose information if we believe disclosure is necessary to comply with law, legal process, subpoenas, warrants, court orders, government requests, provider rules, payment rules, carrier rules, or regulatory obligations; to enforce agreements; to investigate fraud, abuse, security incidents, or policy violations; to protect MyChairHQ, users, providers, Customers, Professionals, or the public; or to preserve evidence.

6.4 Business transfers

Information may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, dissolution, sale of assets, or similar transaction. The receiving entity may continue to process information consistent with this Privacy Policy unless notice is provided.

6.5 Consent or direction

We may disclose information with consent or at the direction of the relevant user or Professional, including when Professional enables an integration, imports data, exports data, sends a campaign, or requests support.

7. Sale, Sharing, Targeted Advertising, and Aggregated Data

MyChairHQ does not sell Customer Data to third parties for money. MyChairHQ does not share Customer Data with third parties for cross-context behavioral advertising unless expressly disclosed and legally permitted.

Professional booking pages may use Google Analytics where the Professional enables it, and only after you grant analytics consent through our cookie banner, as described in the Cookie and Tracking Policy. To the extent any analytics, advertising, retargeting, or similar feature may constitute a "sale," "sharing," or targeted advertising under applicable privacy law, MyChairHQ provides required notices and opt-out mechanisms, including recognition of legally required universal opt-out signals where applicable.

We may use and disclose aggregated or de-identified data that cannot reasonably be used to identify a person. We maintain de-identified data without attempting to re-identify it except as permitted by law.

8. AI Features

When a Professional uses AI features, MyChairHQ may process prompts, business data, service data, appointment data, revenue metrics, staff information, customer names, booking trends, and related context to generate Professional-requested outputs. MyChairHQ uses AI data to provide the feature, maintain safety and security, debug errors, monitor usage, and improve the Platform.

MyChairHQ does not use Professional Content or Customer Data to train foundation AI models unless Professional expressly opts in or the Privacy Policy is updated to permit such use. Professional should not submit Sensitive Data to AI features unless expressly permitted by MyChairHQ and legally authorized.

MyChairHQ may use AI subprocessors, currently including Anthropic, to provide AI outputs. Where feasible, MyChairHQ limits the information sent to AI providers to what is needed for the feature.

9. Google API and Calendar Data

If you connect Google sign-in or Google Calendar, MyChairHQ uses Google user data only to provide or improve the user-facing feature you enable, such as authentication or calendar synchronization. MyChairHQ does not sell Google user data, use it for advertising, or use it to train AI models. MyChairHQ transfers Google user data only as needed to provide the enabled feature, comply with law, protect security, or with user consent.

You may disconnect Google integrations through your account settings or Google account permissions. Disconnecting may stop calendar synchronization or authentication features.

10. Messaging, Email, and SMS

MyChairHQ processes communications data to send appointment confirmations, reminders, cancellations, transactional notices, Professional-initiated campaigns, and Platform notices. Professionals are responsible for message content, recipient selection, consent, opt-outs, and legal compliance for Professional-initiated communications.

Customers may opt out of Professional marketing communications and SMS according to the instructions in the message. Opting out of marketing does not stop transactional or service-related messages where permitted by law, though Customers may cancel appointments or contact the Professional or MyChairHQ for assistance.

11. Data Retention

We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, the DPA, the Terms, legal obligations, security, fraud prevention, backups, disputes, accounting, tax, and enforcement.

CategoryTypical retention
Active Professional account dataWhile the account is active
Professional billing and subscription recordsActive account plus up to 7 years, or longer if required for tax, accounting, disputes, or legal holds
Customer booking recordsWhile the Professional account is active, plus a post-termination retention period needed for export, disputes, legal obligations, backups, fraud prevention, and security
Payment metadata, refunds, disputes, and chargebacksUp to 7 years or longer if required by law, processor requirements, disputes, tax, or accounting needs
Security logs, audit logs, and abuse-prevention recordsAs long as reasonably necessary for security, fraud prevention, investigations, legal compliance, and platform integrity
Support communicationsAs long as needed for support history, quality, disputes, and legal compliance
AI prompts and outputsAs long as needed to provide the feature, maintain account history, debug, secure, comply with law, or as configured by MyChairHQ
BackupsRetained and overwritten on MyChairHQ's backup cycle; deletion from backups may be delayed until backups expire or are overwritten
Aggregated or de-identified dataMay be retained indefinitely if it cannot reasonably identify a person

When an account is terminated or deleted, MyChairHQ may disable access, export data where available, delete, de-identify, or retain data as described above. Deletion may not be immediate and may not remove data from backups, legal holds, transaction records, security records, or records MyChairHQ must retain.

12. Privacy Rights and Requests

Depending on where you live and how you use the Platform, you may have rights to request access, correction, deletion, portability, restriction, objection, opt-out of sale/share/targeted advertising, limitation of sensitive-data use, appeal of a denied request, and non-discrimination for exercising rights.

Submit requests to privacy@mychairhq.com. We may verify your identity, authority, account ownership, residency, or relationship to a Professional before responding. Authorized agents may submit requests where permitted by law, subject to verification.

If the request concerns Customer Data controlled by a Professional, MyChairHQ may direct the Customer to the Professional or assist the Professional in responding, as described in the DPA. We may deny or limit requests where permitted by law, including where data is needed for security, legal compliance, disputes, transactions, provider records, free expression, fraud prevention, or other lawful exceptions. If applicable law provides an appeal right, instructions will be provided in the response.

13. California and Other U.S. State Privacy Disclosures

Where applicable, MyChairHQ may collect the following categories of personal information: identifiers; commercial information; internet or network activity; geolocation at a general IP-based level; professional or employment-related information; audio/electronic communications if you contact support; inferences; and sensitive personal information if provided or generated in limited contexts.

Sources include users, Professionals, Customers, devices, service providers, payment providers, communication providers, authentication providers, calendar providers, and public or complaint sources. Purposes and disclosures are described above. MyChairHQ does not knowingly sell or share personal information of minors under 16.

Where required, residents may exercise rights by contacting privacy@mychairhq.com. MyChairHQ will not discriminate against a person for exercising privacy rights.

14. Children and Minors

The Platform is not intended for direct use by children under 13. MyChairHQ does not knowingly allow children under 13 to create Platform accounts or directly submit personal information to MyChairHQ.

A parent, guardian, or authorized adult may book an appointment for a minor through a Professional booking page. Professionals are responsible for obtaining any required parent or guardian consent and for complying with laws that apply to serving minors. If MyChairHQ learns that it collected personal information directly from a child under 13 without required consent, MyChairHQ will take appropriate steps to delete or disable the information.

15. Security

MyChairHQ uses reasonable administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit, access controls, authentication, monitoring, logging, provider management, and incident response. No system is 100% secure. Users are responsible for maintaining secure credentials, limiting account access, and protecting exported data.

Security practices are described in the Security Statement.

16. International Processing

MyChairHQ is operated from the United States. Information may be processed in the United States and other locations where MyChairHQ or its providers operate. If applicable law requires transfer safeguards, MyChairHQ will use appropriate safeguards such as standard contractual clauses, lawful transfer mechanisms, or provider commitments.

17. GDPR and EEA/UK Privacy Rights

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the privacy rights described in Section 12 include the rights afforded under the EU General Data Protection Regulation (GDPR) and corresponding United Kingdom law: access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection (Article 21), and withdrawal of consent. The legal bases on which MyChairHQ processes personal information are described in Section 5.

Where MyChairHQ acts as a processor for Customer Data on behalf of a Professional, the Data Processing Addendum governs the parties' GDPR obligations, including international data-transfer safeguards (Standard Contractual Clauses). MyChairHQ will assist Professionals in responding to verified GDPR requests from their Customers as described in the DPA.

You may submit GDPR requests to privacy@mychairhq.com. MyChairHQ will respond within the time required by law (generally one month, extendable in limited circumstances).

18. Changes to This Privacy Policy

MyChairHQ may update this Privacy Policy from time to time. Material changes will be posted or sent by reasonable notice. The updated policy takes effect on the effective date stated above or when posted if no later date is stated.

19. Contact

MyChairHQ LLC d/b/a MyChairHQ MyChairHQ LLC Privacy: privacy@mychairhq.com Support: support@mychairhq.com Security: security@mychairhq.com