This Privacy Policy explains how MyChairHQ LLC, doing business as MyChairHQ ("MyChairHQ," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information in connection with MyChairHQ websites, applications, dashboards, professional-branded booking pages, customer booking flows, communications, support, integrations, and related services.
This Privacy Policy applies to:
This Privacy Policy does not govern a Professional's independent data practices outside the Platform. Professionals are independent businesses and may have their own privacy policies, consent forms, customer records, marketing systems, payment practices, staff records, and legal obligations.
MyChairHQ acts in different privacy roles depending on the data and context.
MyChairHQ as controller/business. MyChairHQ determines the purposes and means of processing for information relating to MyChairHQ accounts, subscriptions, billing, support, website visitors, Platform security, Platform analytics, provider management, legal compliance, and MyChairHQ marketing.
MyChairHQ as processor/service provider. For Customer Data processed on behalf of a Professional to provide booking, scheduling, reminder, customer-management, communication, payment-metadata, and related Platform services, MyChairHQ acts as a processor or service provider to the Professional. The Professional is responsible for determining why and how Customer Data is collected and used for the Professional's business and services.
Professional as controller/business. Professionals independently control their customer relationships, services, staff, premises, customer communications, privacy notices, lawful bases, consent, retention, deletion, and compliance obligations. Customers should contact the Professional for requests about Professional services or Professional-controlled Customer Data, and MyChairHQ will assist as described in the Data Processing Addendum.
We may collect:
When a Customer uses a Professional booking page, we may collect:
We may automatically collect:
We use strictly necessary cookies for authentication, session management, security, and cross-subdomain login. Where a Professional enables Google Analytics on their booking page, analytics cookies are set only after you grant analytics consent through our cookie banner. MyChairHQ does not currently use advertising or cross-context behavioral-advertising cookies. The Cookie and Tracking Policy describes these technologies and your available choices.
We may receive information from:
We use information to:
Where a legal basis is required, we process personal information based on one or more of the following:
When a Customer books through a Professional page, the booking information is made available to the Professional so the Professional can provide the appointment service, communicate with the Customer, manage scheduling, and handle its own customer relationship. Professional use of that information is governed by Professional's privacy practices and legal obligations.
Professional public booking pages may display Professional business information, staff profiles, prices, service descriptions, policies, photos, reviews, and other Professional Content configured by Professional.
We disclose information to providers that help us operate the Platform, including hosting, infrastructure, payments, email, SMS, media hosting, AI, authentication, calendar sync, error monitoring, job processing, caching, support, security, analytics, and legal or professional services. The Subprocessor List identifies key subprocessors and purposes.
Service providers may process personal information only for permitted business purposes, subject to contract terms and applicable law.
We may disclose information if we believe disclosure is necessary to comply with law, legal process, subpoenas, warrants, court orders, government requests, provider rules, payment rules, carrier rules, or regulatory obligations; to enforce agreements; to investigate fraud, abuse, security incidents, or policy violations; to protect MyChairHQ, users, providers, Customers, Professionals, or the public; or to preserve evidence.
Information may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, bankruptcy, dissolution, sale of assets, or similar transaction. The receiving entity may continue to process information consistent with this Privacy Policy unless notice is provided.
We may disclose information with consent or at the direction of the relevant user or Professional, including when Professional enables an integration, imports data, exports data, sends a campaign, or requests support.
MyChairHQ does not sell Customer Data to third parties for money. MyChairHQ does not share Customer Data with third parties for cross-context behavioral advertising unless expressly disclosed and legally permitted.
Professional booking pages may use Google Analytics where the Professional enables it, and only after you grant analytics consent through our cookie banner, as described in the Cookie and Tracking Policy. To the extent any analytics, advertising, retargeting, or similar feature may constitute a "sale," "sharing," or targeted advertising under applicable privacy law, MyChairHQ provides required notices and opt-out mechanisms, including recognition of legally required universal opt-out signals where applicable.
We may use and disclose aggregated or de-identified data that cannot reasonably be used to identify a person. We maintain de-identified data without attempting to re-identify it except as permitted by law.
When a Professional uses AI features, MyChairHQ may process prompts, business data, service data, appointment data, revenue metrics, staff information, customer names, booking trends, and related context to generate Professional-requested outputs. MyChairHQ uses AI data to provide the feature, maintain safety and security, debug errors, monitor usage, and improve the Platform.
MyChairHQ does not use Professional Content or Customer Data to train foundation AI models unless Professional expressly opts in or the Privacy Policy is updated to permit such use. Professional should not submit Sensitive Data to AI features unless expressly permitted by MyChairHQ and legally authorized.
MyChairHQ may use AI subprocessors, currently including Anthropic, to provide AI outputs. Where feasible, MyChairHQ limits the information sent to AI providers to what is needed for the feature.
If you connect Google sign-in or Google Calendar, MyChairHQ uses Google user data only to provide or improve the user-facing feature you enable, such as authentication or calendar synchronization. MyChairHQ does not sell Google user data, use it for advertising, or use it to train AI models. MyChairHQ transfers Google user data only as needed to provide the enabled feature, comply with law, protect security, or with user consent.
You may disconnect Google integrations through your account settings or Google account permissions. Disconnecting may stop calendar synchronization or authentication features.
MyChairHQ processes communications data to send appointment confirmations, reminders, cancellations, transactional notices, Professional-initiated campaigns, and Platform notices. Professionals are responsible for message content, recipient selection, consent, opt-outs, and legal compliance for Professional-initiated communications.
Customers may opt out of Professional marketing communications and SMS according to the instructions in the message. Opting out of marketing does not stop transactional or service-related messages where permitted by law, though Customers may cancel appointments or contact the Professional or MyChairHQ for assistance.
We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, the DPA, the Terms, legal obligations, security, fraud prevention, backups, disputes, accounting, tax, and enforcement.
| Category | Typical retention |
|---|---|
| Active Professional account data | While the account is active |
| Professional billing and subscription records | Active account plus up to 7 years, or longer if required for tax, accounting, disputes, or legal holds |
| Customer booking records | While the Professional account is active, plus a post-termination retention period needed for export, disputes, legal obligations, backups, fraud prevention, and security |
| Payment metadata, refunds, disputes, and chargebacks | Up to 7 years or longer if required by law, processor requirements, disputes, tax, or accounting needs |
| Security logs, audit logs, and abuse-prevention records | As long as reasonably necessary for security, fraud prevention, investigations, legal compliance, and platform integrity |
| Support communications | As long as needed for support history, quality, disputes, and legal compliance |
| AI prompts and outputs | As long as needed to provide the feature, maintain account history, debug, secure, comply with law, or as configured by MyChairHQ |
| Backups | Retained and overwritten on MyChairHQ's backup cycle; deletion from backups may be delayed until backups expire or are overwritten |
| Aggregated or de-identified data | May be retained indefinitely if it cannot reasonably identify a person |
When an account is terminated or deleted, MyChairHQ may disable access, export data where available, delete, de-identify, or retain data as described above. Deletion may not be immediate and may not remove data from backups, legal holds, transaction records, security records, or records MyChairHQ must retain.
Depending on where you live and how you use the Platform, you may have rights to request access, correction, deletion, portability, restriction, objection, opt-out of sale/share/targeted advertising, limitation of sensitive-data use, appeal of a denied request, and non-discrimination for exercising rights.
Submit requests to privacy@mychairhq.com. We may verify your identity, authority, account ownership, residency, or relationship to a Professional before responding. Authorized agents may submit requests where permitted by law, subject to verification.
If the request concerns Customer Data controlled by a Professional, MyChairHQ may direct the Customer to the Professional or assist the Professional in responding, as described in the DPA. We may deny or limit requests where permitted by law, including where data is needed for security, legal compliance, disputes, transactions, provider records, free expression, fraud prevention, or other lawful exceptions. If applicable law provides an appeal right, instructions will be provided in the response.
Where applicable, MyChairHQ may collect the following categories of personal information: identifiers; commercial information; internet or network activity; geolocation at a general IP-based level; professional or employment-related information; audio/electronic communications if you contact support; inferences; and sensitive personal information if provided or generated in limited contexts.
Sources include users, Professionals, Customers, devices, service providers, payment providers, communication providers, authentication providers, calendar providers, and public or complaint sources. Purposes and disclosures are described above. MyChairHQ does not knowingly sell or share personal information of minors under 16.
Where required, residents may exercise rights by contacting privacy@mychairhq.com. MyChairHQ will not discriminate against a person for exercising privacy rights.
The Platform is not intended for direct use by children under 13. MyChairHQ does not knowingly allow children under 13 to create Platform accounts or directly submit personal information to MyChairHQ.
A parent, guardian, or authorized adult may book an appointment for a minor through a Professional booking page. Professionals are responsible for obtaining any required parent or guardian consent and for complying with laws that apply to serving minors. If MyChairHQ learns that it collected personal information directly from a child under 13 without required consent, MyChairHQ will take appropriate steps to delete or disable the information.
MyChairHQ uses reasonable administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit, access controls, authentication, monitoring, logging, provider management, and incident response. No system is 100% secure. Users are responsible for maintaining secure credentials, limiting account access, and protecting exported data.
Security practices are described in the Security Statement.
MyChairHQ is operated from the United States. Information may be processed in the United States and other locations where MyChairHQ or its providers operate. If applicable law requires transfer safeguards, MyChairHQ will use appropriate safeguards such as standard contractual clauses, lawful transfer mechanisms, or provider commitments.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the privacy rights described in Section 12 include the rights afforded under the EU General Data Protection Regulation (GDPR) and corresponding United Kingdom law: access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), objection (Article 21), and withdrawal of consent. The legal bases on which MyChairHQ processes personal information are described in Section 5.
Where MyChairHQ acts as a processor for Customer Data on behalf of a Professional, the Data Processing Addendum governs the parties' GDPR obligations, including international data-transfer safeguards (Standard Contractual Clauses). MyChairHQ will assist Professionals in responding to verified GDPR requests from their Customers as described in the DPA.
You may submit GDPR requests to privacy@mychairhq.com. MyChairHQ will respond within the time required by law (generally one month, extendable in limited circumstances).
MyChairHQ may update this Privacy Policy from time to time. Material changes will be posted or sent by reasonable notice. The updated policy takes effect on the effective date stated above or when posted if no later date is stated.
MyChairHQ LLC d/b/a MyChairHQ MyChairHQ LLC Privacy: privacy@mychairhq.com Support: support@mychairhq.com Security: security@mychairhq.com