Back to home

Privacy Policy

Last updated: 11 August 2026

1. Who we are

CHAIR SOFTWARE LTD(“CHAIR”, “we”, “us”) provides a booking platform for professionals and their clients. We are the data controller for the personal data described in this policy. Contact us at support@getchair.co.uk for any data-related questions.

We are registered with the UK Information Commissioner's Office (the ICO, the UK's independent regulator for data protection) and pay the data protection fee required by the Data Protection (Charges and Information) Regulations 2018.

2. What we collect

  • Account data: name, email address, password (hashed), profile details you choose to provide (bio, photo, social links).
  • Business data (professionals only): business name, address, service catalogue, opening hours, photos, bank details (via Stripe, see below).
  • Booking data: appointment date, time, service, customer name, customer email, optional notes.
  • Messages: the content of messages you exchange with professionals or customers through our in-app messaging, including any attachments you send.
  • Payment data: we do not store card numbers. Payments are processed by Stripe; we store transaction IDs and amounts to reconcile your bookings.
  • A saved card for no-show protection: if a professional requires a card to confirm a booking, Stripe stores the card and gives us a reference to it, plus the card brand and its last 4 digits. We keep those against that booking so the professional can charge their no-show fee if you do not attend and do not cancel in time. Nothing is charged when you book, the amount is shown to you before you confirm, and no charge is ever automatic: the professional has to trigger it.
  • Technical data: IP address (anonymised before analytics are processed), browser type, device information, pages visited. Used for security, abuse prevention, and aggregate analytics.
  • Waitlist sign-up data: if you join our pre-launch waitlist, we store your email and, to gauge where early interest is coming from, your approximate location (country only, derived from your IP, never precise location), device/browser type, and how you reached us (the referring website and any campaign tags in the link you followed). This is read from the request your browser already sends, needs no cookies, and is collected whether or not you accept analytics. Legal basis: our legitimate interest (UK GDPR Art. 6(1)(f)) in planning the launch.
  • Cookies: a session cookie (chair_session), a theme preference cookie (chair_theme), and, only if you accept them, Google Analytics, Google Ads and (on our pre-launch page only) Meta pixel cookies. See our Cookie Policy for the full list.
  • Advertising attribution data: if you arrive from one of our ads and then create a professional account, we store the ad click identifier that Google appends to the link (gclid or its equivalent) alongside any campaign tags, against your account. It tells us which ad led to which sign-up so we can judge our own marketing spend. It is not a cookie, it is not shared onward, and it is recorded whether or not you accept advertising cookies. Legal basis: our legitimate interest (UK GDPR Art. 6(1)(f)) in measuring our marketing. You can ask us to erase it at any time using the contact details below.

2a. Analytics (Google Analytics 4)

When you accept analytics cookies, we use Google Analytics 4(provided by Google Ireland Limited, our data processor for this purpose) to understand how people use the platform: which pages they visit, which features they engage with, where they drop off. We use this in aggregate to prioritise what to improve.

  • Legal basis: consent (UK GDPR Art. 6(1)(a)). You can withdraw at any time via the Cookie settings link in the footer.
  • IP anonymisation: enabled. Google truncates the last octet of your IP before storing it.
  • Google Signals: disabled. We do not opt into Google's cross-device user-graph.
  • Data retention: we use Google's minimum retention setting (2 months for event data).
  • Data transfers: Google may transfer data outside the UK/EEA. Google's standard contractual clauses and UK adequacy regulations cover this transfer.

If you reject analytics cookies, GA still receives anonymised pageviews from your browser (in “cookieless” mode via Google Consent Mode v2) so we can count visits in aggregate, but it cannot identify you, set cookies, or link your visits across sessions or devices.

3. How we use it

  • To provide the booking platform itself (you cannot use the service without your account data).
  • To process payments and reconcile bookings via Stripe.
  • To send you transactional emails (booking confirmations, payment receipts, subscription renewal reminders).
  • To enable messaging between customers and professionals about their bookings.
  • To protect the platform from abuse (rate limiting, fraud detection, audit logging).
  • To comply with legal obligations (HMRC, anti-money-laundering requirements where applicable).

4. Who we share with

We use the following third-party processors, each with their own privacy policies:

  • Stripe (payment processing and identity/KYC verification, for professional subscriptions and for bookings via Stripe Connect): stripe.com/privacy
  • Cloudflare (hosting, security, content delivery): cloudflare.com/privacypolicy
  • Google Ireland Limited: optional sign-in via Google OAuth, and (with your consent) Google Analytics 4 for aggregate usage statistics and Google Ads to measure which of our ads led to a sign-up. policies.google.com/privacy
  • Meta Platforms Ireland Limited: if, and only if, you accept advertising cookies, the Meta pixel on our pre-launch page tells Meta that a visit or a waitlist sign-up came from one of our Facebook or Instagram ads. It runs on that page only, it is not loaded at all until you accept, and Meta acts as a joint controller for this measurement rather than as our processor. facebook.com/privacy/policy
  • Apple: optional “Sign in with Apple” (available in our mobile apps). apple.com/legal/privacy
  • Twilio (sending one-time sign-in codes and booking notifications by SMS; receives your phone number and the message content): twilio.com/legal/privacy
  • Expo (delivering push notifications to our mobile apps, and serving app updates; receives your device push token): expo.dev/privacy

We do not sell your personal data. We advertise CHAIR on Google and on Meta, and with your consent we let those platforms tell us which of our ads led to a sign-up, but we do not upload our client or customer lists to any advertising network and we do not build audiences from your activity on the platform.

5. How long we keep it

  • Active accounts: for as long as your account is open.
  • Deleted accounts: personal data is removed within 30 days of account deletion, except where retention is required by law (e.g. transaction records for HMRC for 6 years).
  • Booking data: retained for 6 years after the booking date to support tax and accounting obligations of the professional.
  • Audit logs: retained for 1 year for security and fraud-prevention purposes.

6. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data (subject to legal retention requirements).
  • Export your data in a portable format.
  • Object to processing or restrict it in certain circumstances.
  • Complain to the Information Commissioner's Office if you believe we have mishandled your data. You can raise a complaint at ico.org.uk/make-a-complaint or by calling their helpline on 0303 123 1113. You do not have to raise it with us first, though we would rather have the chance to put it right.

To exercise any of these rights, email support@getchair.co.uk.

7. Security

We use industry-standard security measures: HTTPS for all traffic, secure session cookies (HttpOnly, Secure, SameSite), salted password hashes (PBKDF2 with 100,000 iterations), and audit logging of administrator actions. No system is perfectly secure, so we will notify affected users within 72 hours of becoming aware of a personal data breach affecting them.

8. Changes to this policy

We may update this policy occasionally. Material changes will be communicated by email or a banner on the platform. The “Last updated” date above tracks the most recent revision.

9. Contact

Questions about this policy or your data: support@getchair.co.uk.