Document
Privacy Policy
Chairflow ("we", "us", "our") builds and hosts websites for barbers, salons, spas, and related businesses. This Privacy Policy explains what personal information we collect, how we use it, the lawful bases we rely on, and your choices. It covers our marketing site at chairflow.site and our client portal at admin.chairflow.site.
Who we are
Chairflow is the data controller for personal data collected through our marketing site, client portal, billing, and support channels. For personal data that appears on a customer's live shop website (for example, visitor analytics or booking details handled through a third-party booking tool), the shop owner is typically the controller and Chairflow acts as a processor — see our Data Processing Addendum.
Privacy questions and data-rights requests: james@chairflow.site.
Information we collect
- Account information: name, email address, phone number, and shop name when you sign up.
- Business information: address, opening hours, services, team details, design preferences, and content you upload for your website build.
- Payment information: processed by Stripe. We do not store full card numbers on our servers.
- Usage data: pages visited, device type, browser, and approximate location derived from IP address, collected through analytics only when you consent to analytics cookies.
- Communications: messages you send us via contact forms, email, or support channels.
- Marketing subscriptions: the email address, consent record, subscription status, and source you provide when you choose to receive Chairflow updates.
- Technical logs: security and error logs needed to keep the service running (for example, authentication events).
How we use your information
- Provide, build, host, and maintain your website and account dashboard.
- Process subscriptions and one-time payments through Stripe.
- Send service updates, build progress notifications, and support replies.
- Send Chairflow updates to people who have explicitly opted in. You can unsubscribe from any marketing email.
- Improve our product, fix bugs, and prevent fraud or abuse.
- Comply with legal obligations where required.
Lawful bases (UK GDPR / GDPR)
- Contract: creating your account, building and hosting your site, billing, and delivering support you request.
- Legitimate interests: securing the service, improving reliability, and responding to general enquiries — balanced against your rights.
- Consent: marketing emails and non-essential cookies/analytics. You can withdraw consent at any time.
- Legal obligation: tax, accounting, and regulatory requirements.
Sharing your information
We do not sell your personal information. We share data only with service providers that help us operate Chairflow (hosting, database/auth, email, analytics, payment processing) under contracts that require them to protect your data. See our subprocessors list. We may disclose information if required by law or to protect our rights and users.
Data retention
- Active accounts: account and website data while your subscription or build relationship is active.
- After account deletion: we remove or anonymize personal data within 30 days, except where retention is required for legal, billing, dispute, or secure backup purposes (typically up to 7 years for financial records).
- Marketing subscribers: until you unsubscribe or we delete the list entry after a prolonged inactive period.
- Support messages: generally up to 24 months after the last relevant contact, unless a longer period is needed for an open issue.
- Analytics:retained according to our analytics provider's settings, and only collected when analytics consent is given.
Your rights
Depending on your location (including the UK and EEA), you may have the right to access, correct, delete, or export your personal data; to object to or restrict certain processing; and to withdraw consent where we rely on it. Contact james@chairflow.site to make a request. You can also delete your portal account from account settings.
If you are in the UK and unhappy with how we handle your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk. EEA residents may contact their local supervisory authority.
International transfers
Your information may be processed in countries other than your own, including where our subprocessors operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent transfer mechanisms.
Children
Chairflow is a business service for shop owners and is not directed at children. We do not knowingly collect personal data from anyone under 18.
Changes
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date.
Contact
Questions about this policy: james@chairflow.site or via our contact page.
Document
Terms of Service
These Terms of Service ("Terms") govern your use of Chairflow's website-building service, client dashboard, hosting, and related tools. By creating an account or paying for a plan, you agree to these Terms and our Privacy Policy. If you use Chairflow to process personal data on your shop website, our Data Processing Addendum also applies.
Our service
Chairflow provides custom website design, hosting, and a dashboard for barbers, salons, spas, and similar businesses. We aim to deliver your website within 7 business days after you submit complete onboarding details, subject to the scope of your plan. Design gallery looks are starting points for a custom build — not off-the-shelf templates.
Accounts
- You must provide accurate information when signing up.
- You are responsible for keeping your login credentials secure.
- You must be at least 18 years old and authorized to represent the business on the account.
Plans and payment
Subscription and one-time plans are billed through Stripe. Fees, renewal dates, and cancellation terms are shown at checkout and on our pricing page. Monthly plans renew automatically until cancelled. One-time build fees cover the initial website build as described on our pricing page. See Refunds & Cancellation for more detail.
Your content
You retain ownership of logos, photos, copy, and other materials you upload. You grant Chairflow a license to use that content to build, host, and maintain your website. You confirm you have the rights to all content you provide and that it does not infringe third-party rights or violate applicable law.
Acceptable use
You may not use Chairflow to host illegal content, malware, spam, phishing, or material that violates intellectual property, privacy, or publicity rights. You may not attempt to disrupt the service, probe systems without permission, or resell access except as we expressly allow. We may suspend or terminate accounts that breach these rules.
Website delivery and revisions
Build timelines start once required onboarding information is submitted. Preview and revision windows are defined in your plan. Material scope changes outside the agreed build may incur additional fees.
Third-party booking tools
We can help connect booking providers you already use (for example Fresha, Vagaro, Square, or Booksy). Those tools are operated by their own providers under their terms and privacy policies. Chairflow is not responsible for outages, pricing, or data practices of third-party booking platforms.
Termination
You may cancel your subscription or delete your account at any time through your account settings or Stripe customer portal. We may suspend or terminate service for non-payment, abuse, or breach of these Terms. Upon termination, your live website may be taken offline.
Disclaimer of warranties
Chairflow is provided "as is" to the fullest extent permitted by law. We do not guarantee uninterrupted service or specific business results such as booking volume or revenue. Nothing in these Terms limits rights you cannot waive under consumer or other mandatory law.
Limitation of liability
To the maximum extent permitted by law, Chairflow's total liability for any claim arising from the service is limited to the amount you paid us in the 12 months before the claim. We are not liable for indirect, incidental, or consequential damages, including lost profits or lost bookings.
Governing law
These Terms are governed by the laws of England and Wales. Courts of England and Wales have exclusive jurisdiction, except that you may bring mandatory consumer claims in your local courts where the law requires.
Changes
We may update these Terms from time to time. We will post the revised version on this page and update the "Last updated" date. Continued use after changes constitutes acceptance of the updated Terms.
Contact
Legal inquiries: james@chairflow.site.
Document
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Chairflow Terms of Service when you use Chairflow to process personal data in connection with your shop website or portal account. It is designed to meet UK GDPR and EU GDPR Article 28 requirements for processor relationships.
Roles
- You (the customer) are the controller of personal data relating to your clients, staff, and website visitors that you instruct us to process for your website and related services.
- Chairflow is the processor for that customer-instructed processing, and the controller for our own account, billing, marketing, and product operations data (as described in the Privacy Policy).
Subject matter and duration
We process personal data to build, host, maintain, and support your Chairflow website and dashboard for the duration of your agreement with us, plus any short wind-down or backup period described in the Privacy Policy.
Nature and purpose of processing
Hosting website content, storing onboarding assets, operating the client portal, sending transactional emails related to your build, and providing support. Booking systems connected to your site may process appointment data under their own terms; Chairflow only processes what is necessary to integrate or display those tools as you instruct.
Types of personal data
May include names, contact details, images, service descriptions, staff bios, and other content you upload; technical data about visitors to your site as enabled by tools you choose; and support correspondence. You should not upload special category data unless strictly necessary and lawful.
Our obligations as processor
- Process personal data only on your documented instructions, including these Terms and portal settings, unless required by law.
- Ensure people authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures.
- Assist you, where reasonably possible, with data subject requests, security incidents, and DPIAs related to the service.
- Delete or return personal data at the end of the service, subject to legal retention needs.
- Make available information reasonably necessary to demonstrate compliance with this DPA.
Subprocessors
You authorize Chairflow to engage the subprocessors listed on our Subprocessors page. We will impose data-protection terms no less protective than this DPA. We will post material changes to the list on that page.
International transfers
Where personal data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses or equivalent).
Security incidents
We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, and provide information reasonably available to help you meet your own notification duties.
Your responsibilities
You are responsible for the lawfulness of your instructions, for providing required notices to your clients and website visitors, and for configuring third-party booking tools in line with applicable law.
Contact
Privacy and processing questions: james@chairflow.site.
Document
Subprocessors
Chairflow uses carefully chosen service providers to operate the product. Depending on how you use Chairflow, these providers may process personal data on our behalf (or on your behalf when we act as processor).
| Provider | Purpose | Typical location |
|---|---|---|
| Netlify | Application hosting and delivery | United States / EU (provider network) |
| Supabase | Database, authentication, and file storage | As configured for our project region |
| Stripe | Payment processing and billing portal | United States / EU |
| Resend | Transactional and notification email delivery | United States / EU |
| Umami Cloud | Privacy-focused analytics (marketing site, with consent) | Provider cloud region |
We may update this list as our stack changes. Material updates will be reflected on this page with a revised "Last updated" date on the Legal hub.
Questions: james@chairflow.site.
Document
Refunds & Cancellation
This policy explains how cancellations and refunds work for Chairflow plans. It forms part of our Terms of Service. Pricing details live on our pricing page.
Monthly plans
Monthly subscriptions renew automatically until you cancel. You can cancel anytime through your Stripe customer portal or by contacting us. Cancellation stops future renewals. Access typically continues through the end of the paid period. We do not prorate refunds for unused days in a billing cycle unless required by law or we agree otherwise in writing.
One-time build + hosting
The one-time build fee covers the agreed initial website build. Hosting and support fees billed after launch follow the hosting plan terms shown at checkout. If we have not started your build and you cancel promptly, contact us for a refund of the unused build fee. Once design or build work has started, build fees are generally non-refundable because the work has already been allocated.
Delivery timeline
Our 7-business-day target starts when complete onboarding details are submitted. Delays caused by missing content, delayed approvals, or third-party booking providers are outside that clock.
Chargebacks
Please contact james@chairflow.site before filing a payment dispute so we can help resolve the issue quickly.
Contact
Billing questions: james@chairflow.site.
Document
Accessibility Statement
Chairflow aims to make our marketing site and client portal usable for as many people as possible. We design with clear typography, strong contrast in our neutral palette, keyboard-friendly controls where we can, and respect for reduced-motion preferences.
Conformance goal
We work toward WCAG 2.2 Level AA on chairflow.site and admin.chairflow.site. Some third-party embeds (for example payment or booking widgets) are outside our full control.
Known limitations
Inspiration preview pages and client websites may use custom layouts that differ from the marketing site. If you hit a barrier on Chairflow itself, tell us and we will do our best to fix it or provide the information another way.
Feedback
Accessibility feedback: james@chairflow.site or our contact page. Please include the page URL and what you were trying to do.