Skip to content

ChairBack

Privacy Policy

Effective date: June 12, 2026

This Privacy Policy explains how ChairBack, a product of Eric Supply LLC (“ChairBack”, “we”, “us”) collects, uses, and shares personal information when you use our websites, dashboards, public shop pages, rewards pages, text-message programs, and related services (the “Service”). It is incorporated into our Terms of Service.

1. The two hats we wear

ChairBack is used by barbershops, salons, and similar personal-care businesses (“Shops”) to run loyalty and rebooking programs for their clients (“Clients”). We handle personal information in two distinct roles:

  • For Shop accounts and our own websites, we decide how data is used — we act as the data controller / business.
  • For Client Data (information about a Shop’s clients — names, phone numbers, emails, visit history, punch balances, notes), we process it on behalf of the Shop as a service provider / processor. The Shop decides why and how that data is used; we follow the Shop’s instructions as expressed through the Service.
If you are a Shop's client and want your information corrected or deleted, the fastest path is to contact that shop directly. You can also email us at support@getchairback.com and we will assist or forward your request to your shop.

2. Information we collect

From Shop owners

  • Account data: your name, email address, and a password (stored only as a salted hash — we cannot read it). If you sign in with Google, we receive your name, email, and Google account identifier instead of a password.
  • Shop profile data: shop name, booking link, timezone, logo, photos, bio, hours, social handles, themes, reward and promotion configuration, and SMS templates.
  • Scheduling integration data: if you connect Acuity Scheduling, we store encrypted access tokens and sync appointment and client records from your Acuity account.

About Clients (on behalf of their Shop)

  • Name, phone number, and email address (from the Shop’s scheduling system or entered by the Shop).
  • Appointment and visit history: dates, status, service names, and prices.
  • Loyalty activity: punches earned and redeemed, reward redemptions, promotion usage, and visit-cadence estimates derived from visit history.
  • Messaging records: the content, time, and delivery status of texts sent on the Shop’s behalf, and opt-out status.
  • Private notes the Shop records about a client.

Automatically

  • Log data: IP address, browser type, pages requested, and timestamps, used for security, rate limiting, and debugging.
  • Cookies: we use a single signed, httpOnly session cookie to keep Shop owners logged in. We do not use advertising cookies or third-party tracking pixels.

3. How we use information

  • Provide, operate, secure, and improve the Service.
  • Sync visits from scheduling providers, compute punch balances, and render rewards and public pages.
  • Send text messages that Shops initiate or configure (rebooking nudges, promotion blasts), enforce opt-outs, and keep delivery records.
  • Communicate with Shop owners about their account and important Service changes.
  • Detect, prevent, and respond to fraud, abuse, and security incidents.
  • Comply with legal obligations.

4. Text messaging data — no marketing use, ever

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Mobile phone numbers and SMS opt-in data and consent are never sold, rented, or shared with any third party for their own marketing. Text-messaging originator opt-in data and consent will not be shared with any third parties, except with vendors that help us deliver messages (such as our SMS provider), and only for that purpose.

Clients can opt out of texts at any time by replying STOP, and can get help by replying HELP or emailing support@getchairback.com. Opt-outs are enforced platform-wide for the opted-out phone number. See the SMS Messaging Policy.

5. How we share information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only with:

  • Service providers (subprocessors) that host and run the Service under contractual confidentiality obligations — currently: Supabase (database hosting), Vercel (web hosting), Railway (API hosting), Twilio (SMS delivery), Squarespace / Acuity Scheduling (scheduling data sync, only for Shops that connect it), Anthropic (AI model processing — only for Shops that enable the AI receptionist, whose client text-message conversations are processed to generate replies), and Google (only if you sign in with Google).
  • The Shop you patronize: if you are a Client, your information is visible to your barbershop — that is the point of the Service.
  • Legal and safety: when required by law, subpoena, or to protect the rights, safety, or property of ChairBack, our users, or the public.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

6. Security

We use safeguards appropriate to the data we handle, including TLS encryption in transit, encryption of scheduling-provider access tokens at rest (AES-256-GCM), password hashing with argon2id, signed httpOnly session cookies, per-tenant database isolation enforced at both the application and database (row-level security) layers, and rate limiting. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify affected parties as required by law.

7. Data retention and deletion

  • Shop account data and Client Data are retained while the Shop’s account is active.
  • When a Shop closes its account (or asks us to), we delete the Shop’s data, including its Client Data, within a reasonable period, except where we must retain records to comply with law, resolve disputes, or enforce agreements (for example, opt-out records are kept so opt-outs stay honored).
  • Shops can delete individual client records from their dashboard; Clients can request deletion through their Shop or via support@getchairback.com.

8. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to opt out of certain processing. State privacy laws (such as the California Consumer Privacy Act and similar laws in other states, including Delaware) may grant some or all of these rights. We honor valid requests regardless of where you live:

  • Shop owners: you can view and edit most of your data in the dashboard, and can request an export or deletion at support@getchairback.com.
  • Clients: because we process your data on your barbershop’s behalf, we may refer your request to your shop, or fulfill it with their direction. We will never discriminate against you for exercising your rights.
  • Texts: reply STOP to any message to stop receiving texts.
  • Authentication of requests: we may need to verify your identity before acting on a request, and you may use an authorized agent where the law allows.

9. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child’s information has been provided to us, contact support@getchairback.com and we will delete it.

10. Where data is processed

The Service is operated from the United States and intended for U.S. businesses and their clients. If you access it from elsewhere, you understand your information will be processed in the United States.

11. Changes to this Policy

We may update this Policy from time to time. If a change is material, we will give notice (for example by email to Shop owners or a notice in the dashboard) before it takes effect. The “Effective date” above shows when this Policy was last revised.

12. Contact us

Privacy questions or requests: support@getchairback.com.