Privacy Policy
1. What this covers
ChairCue is operated by Ragan Holdings LLC (“ChairCue”, “we”, “us”). This policy describes how we handle two different kinds of information:
- Barber data — information about the professional who runs a ChairCue account. For this, we act as the business deciding how the data is used.
- Customer data — information about the customers who book with that professional. For this, we act as a service provider handling data on the barber's behalf. The barber decides what is collected and why; we process it to run their booking system.
If you're a customer who booked an appointment and you want your information corrected or deleted, the fastest route is to contact the barber you booked with. You can also contact us at help@chaircue.com and we'll route it to them.
2. Information we collect
From the barber: name, email address, password (stored only as a cryptographic hash), business name, public booking slug, timezone, phone number if provided, business logo and branding if uploaded, and subscription and billing status. Card numbers are handled entirely by Stripe — we never see or store them.
From customers, on the barber's behalf: name, phone number, email address, appointment history, service and price details, any deposit paid, and SMS consent status including when and how consent was given or withdrawn.
Automatically: a session cookie needed to keep you logged in and to hold a booking slot while a form is completed; server logs including IP address, request paths, and error diagnostics; and rate-limiting counters. Rate-limit records store only hashed values, never raw phone numbers or email addresses.
We do not collect precise location, do not use advertising trackers, and do not run third-party analytics on the booking pages.
3. How we use it
- To operate booking, scheduling, walk-ins, standing appointments, and reminders.
- To send appointment confirmations, reminders, cancellation and reschedule notices, and deposit receipts by email and — only where the customer has opted in — by text message.
- To process barber subscription billing, and customer deposits where the barber has enabled them.
- To keep the service secure and available: rate limiting, abuse prevention, error monitoring, and backups.
- To provide support when you ask for it.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
4. Text messaging and consent
Customers opt in to SMS explicitly, by checking an unticked box on the booking form. Consent is recorded with a timestamp and its source. Replying STOP withdraws it immediately and applies to that phone number across the entire platform, not just one barber. We retain consent and opt-out records after the fact because messaging law requires us to be able to demonstrate them. See our SMS Terms.
A barber adding a customer manually does not create SMS consent. Only the customer can give it.
5. We don't operate a marketplace with your customers' data
Customer information is not shared with other barbers, not shown to other businesses on the platform, not used to build a shared customer directory, and not used to market competing professionals. It exists to serve one barber's relationship with their own customers — full stop.
6. Service providers we share data with
We use a small number of vendors to run the service. Each receives only what it needs:
- Stripe — subscription billing, and customer deposits where enabled. Receives billing and payment details.
- Telnyx — SMS delivery. Receives the recipient phone number and message content.
- ZeptoMail — transactional email delivery. Receives the recipient email address and message content.
- Sentry — error monitoring. Configured not to send personal data: user context is disabled and email and phone patterns are scrubbed from reports before they leave our servers.
- Backblaze B2 — encrypted off-site storage of database backups and uploaded logos.
- Healthchecks.io — uptime monitoring. Receives no personal data, only whether scheduled jobs ran.
- Our hosting provider — the servers the application and database run on.
We may also disclose information if legally required, to enforce our terms, or to protect the rights and safety of users — and in connection with a merger, acquisition, or sale of assets, in which case this policy continues to apply until replaced with notice.
7. Data security
Traffic is encrypted in transit with HTTPS and HSTS. Passwords are hashed and never stored in readable form. Administrative access requires two-factor authentication and is protected by brute-force lockout. Backups are taken nightly, verified for readability, and mirrored off-site; the credentials needed to restore them are stored encrypted. Every database query is scoped to a single barber so one account cannot reach another's records.
No system is perfectly secure. If a breach affects your personal information, we'll notify affected accounts and any regulator as required by applicable law, without undue delay.
8. Data retention and deletion
Appointment history is retained while the account is active, because it's the record the business runs on. After an account closes, data may be requested for export for 30 days and is then deleted in the ordinary course, except where we must keep it longer: SMS consent and opt-out records for messaging-compliance purposes, and payment and invoice records for tax and accounting purposes. Backups age out on a rolling schedule, so deleted data may persist in encrypted backups for a limited period after removal from the live system.
To request an export or deletion, email help@chaircue.com from the address on the account.
9. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information, to opt out of its sale or sharing (we do neither), and to be free from discrimination for exercising these rights. Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have these rights by statute.
To exercise them, email help@chaircue.com. We'll verify the request against the information we already hold and respond within the timeframe the applicable law requires. If we act as a service provider for a barber, we'll forward the request to them and assist as needed. If we decline a request, you may appeal by replying to our response.
10. Children's privacy
ChairCue is a business tool for professionals and is not directed at children. We don't knowingly collect personal information from anyone under 13. If a barber books an appointment for a minor, that information is collected under the barber's own relationship with that family, not ours. If you believe a child's information has reached us, contact help@chaircue.com and we'll delete it.
11. Where data is processed
ChairCue is operated from the United States and data is stored and processed there. If you access the service from elsewhere, you understand that your information is transferred to the United States, where privacy laws may differ from those in your country.
12. Changes to this policy
We may update this policy as the product changes. Material changes will be communicated to active accounts, and the effective date above will change.
13. Contact
Questions, or to exercise a privacy right: help@chaircue.com, or see our Contact page.