1. Scope and roles
This policy applies to Chairbase websites, applications, support, and booking notification services. Chairbase controls information about its own accounts, billing, security, and service operations. A business generally controls the customer information it enters into its workspace, while Chairbase processes that information to provide the service on the business's behalf.
2. Information we collect
- Account and workspace information, such as names, email addresses, business names, roles, login records, and subscription status.
- Business customer information entered by authorized users, such as contact details, booking history, service preferences, notes, and invoices.
- Information a customer submits through public booking or waitlist pages, including requested service, provider, time, contact details, consent choice, and booking-management activity.
- Support conversations and operational records needed to respond, secure accounts, diagnose errors, and prevent abuse.
- Billing identifiers and subscription events from our payment provider. Chairbase does not store complete payment-card numbers.
- For booking deposits, connected Stripe account identifiers, Checkout and Payment Intent identifiers, amount, currency, payment status, and refund status. Card numbers are entered on Stripe's hosted page and are not stored by Chairbase.
- Messaging information, including mobile numbers, consent status, consent time and method, disclosure version, delivery events, HELP requests, and opt-out events.
- Technical information such as IP address, device or browser characteristics, request timestamps, and security logs.
3. How we use information
We use information to provide and improve Chairbase; authenticate users; isolate and secure business workspaces; manage subscriptions and licenses; deliver requested emails and booking notifications; answer support requests; prevent fraud and abuse; back up and restore data; comply with law; and enforce our terms.
4. SMS and mobile opt-in information
Mobile numbers and consent records are used to deliver booking-related informational messages requested by the recipient, process HELP and STOP requests, demonstrate consent, and comply with messaging rules. SMS consent is optional and is not combined with consent for marketing, email, or unrelated programs.
In particular, mobile information, SMS opt-in data, and consent are not sold, rented, transferred, or shared with third parties, affiliates, or lead generators for marketing or promotional purposes. Technical messaging providers may process a mobile number solely on our behalf to transmit, secure, and operate the messaging service; they are not permitted to use it for their own marketing.
5. Service providers and other disclosures
We use service providers acting on our behalf for hosting, databases, backups, email, messaging delivery, payment processing, security, and support. They may process only the information necessary to perform those services under applicable contractual and legal restrictions. We may also disclose information when required by law, to protect rights and safety, or in a business transaction subject to appropriate safeguards. The SMS non-sharing commitments above continue to apply.
6. Retention and security
We apply the following normal retention periods, subject to a documented legal hold, security investigation, dispute, or longer period required by law:
- Active workspace and business-customer records are kept while the workspace is active. After a verified deletion request or final termination, we target deletion from the live service within 30 days.
- Resolved support conversations are normally kept for 24 months. Transactional email bodies and detailed delivery events are normally kept for 90 days.
- Security and administrative audit records are normally kept for up to 24 months. Subscription, invoice, tax, and dispute records may be kept for up to seven years where required.
- SMS consent and opt-out proof is kept while messaging is active and afterward only as needed to establish compliance or honor an opt-out.
- Deleted information may remain in encrypted rolling backups until the provider's recovery window expires. If a backup is restored, applicable deletion requests are reapplied before normal service resumes.
Chairbase uses access controls, encryption in transit, managed database protections, tenant isolation, logging, and backups, but no system can guarantee absolute security.
7. Choices and requests
Account holders may update workspace information through Chairbase and request access, correction, export, or deletion through support. Customers of a business should normally direct requests concerning their customer record to that business. For SMS, reply STOP to opt out or HELP for assistance. Opting out of SMS does not prevent a business from accepting a booking or providing a service. We acknowledge verified privacy requests within five business days and target completion within 30 days, subject to identity verification and lawful exceptions.
8. Children
Chairbase is a business service and is not directed to children. Workspace owners are responsible for obtaining any consent required before entering information about a minor.
9. Changes and contact
We may update this policy and will post the revised date on this page. Privacy and messaging questions may be sent to support@chairbase.studio.