Privacy Policy
Last updated: July 30, 2026
ChairTime is operated by ZEF SOFTWARE SRL. This policy explains what we collect, how we use it, who else processes it on our behalf, and the choices you have. It covers the ChairTime app and website, and every salon-branded (white-label) app powered by ChairTime — currently Exquisite Salon. Everything in this policy applies equally to those apps.
Who we are
ChairTime is a private booking system for beauty salons. Salon owners subscribe to ChairTime and their clients book appointments through the mobile app by scanning a QR code provided by the salon. We are not a marketplace and do not sell appointments to third parties. The service is operated by ZEF SOFTWARE SRL (CUI: 30975520, Str. Ep. dr. Vasile Coman, nr.3, bl.2, sc.B, et.7, ap.58, Oradea, Romania). ZEF SOFTWARE SRL is the data controller. ZEF SOFTWARE SRL also operates the salon-branded (white-label) apps built on the ChairTime platform — currently Exquisite Salon — and is the data controller for those apps in the same way.
What we collect
We collect only the data we need to run the service:
- Account details from sign-up — name, email address, and phone number (optional — used so salons can contact you about your appointments). Authentication is handled by our provider, Clerk.
- For salon owners — business name, address, services offered, working hours, and pricing.
- For clients — booking history, service preferences, and the salons you have linked to your account.
- Device push tokens, used to send appointment reminders and confirmations.
- Your language preference (English or Romanian).
What we don't collect
We have deliberately kept the data footprint small:
- We never see your payment card details. Stripe handles all payment processing on its own infrastructure.
- We don't track your location in the background. Coarse location is only requested if you use the address picker during salon onboarding.
- We don't run advertising or marketing trackers. There are no third-party ad pixels in the app or on this website.
- We don't sell, rent, or share your personal data with data brokers.
How we use your data
We use the data we collect to:
- Run your account and let you sign in.
- Show salons their bookings and let clients view, change, or cancel their appointments.
- Send appointment reminders, confirmations, and other transactional messages.
- Process subscription payments for salon owners.
- Keep the service secure, debug problems, and improve features over time.
Legal bases (GDPR)
We process personal data on the following legal bases:
- Performance of a contract — most of what we do (creating your account, processing bookings, billing salon owners) is necessary to deliver the service you signed up for.
- Consent — if we introduce optional features in the future (such as marketing emails or promotional notifications), we will ask for your separate, explicit consent. You will always be able to withdraw that consent.
- Legitimate interest — for security, fraud prevention, and modest anonymized analytics that help us understand how the service is used.
Sub-processors
We rely on a small number of trusted vendors to operate the service. Each acts as a sub-processor under GDPR. We have Data Processing Agreements (DPAs) in place with each provider, as required by GDPR Article 28.
- Clerkclerk.com/privacy
User authentication and account management.
- Convexconvex.dev/legal/privacy
Database and application backend.
- Stripestripe.com/privacy
Payment processing for salon owner subscriptions.
Web hosting and anonymized usage analytics for this website.
Transactional email (confirmations, password resets, receipts).
- Expoexpo.dev/privacy
Mobile push notification delivery.
- Google Mapspolicies.google.com/privacy
Address autocomplete during salon onboarding only.
International transfers
Some of our sub-processors are based outside the EU/EEA, primarily in the United States. For transfers of personal data outside the European Economic Area, we rely on the safeguards provided by these processors — including the EU-US Data Privacy Framework (where the provider is certified) and Standard Contractual Clauses (SCCs) approved by the European Commission. You can request details about the specific transfer mechanisms in place by contacting us.
How long we keep data
We keep your account and related data for as long as your account is active. When you ask us to delete your account, we delete your personal data immediately and irreversibly, apart from limited records we are legally required to retain — see the next section.
Account deletion
You can delete your account from inside the ChairTime app. Deletion is immediate and final:
- All data tied to your account is purged — appointments, customer links, services, salon details, push tokens, language preference, everything.
- If you are a salon owner, the entire organization is removed along with its services and all associated records.
- There is no grace period and no soft delete, and we keep no anonymized copy of your data for our own use.
- The only data we retain is what we are legally required to keep, as permitted by Article 17(3)(b) GDPR (compliance with a legal obligation): for salon owners who had a paid subscription, invoices and transaction records are kept for the statutory retention periods set by applicable tax and accounting legislation, and are also held by our payment processor (Stripe) under its own legal obligations. Client accounts have no payment records, so nothing financial is retained for them.
- We cannot recover an account after deletion. If you change your mind you will need to sign up again from scratch.
- If a salon owner deletes their account, the booking history that clients had with that salon is also removed, since it is part of the salon's data.
Your rights under GDPR
If you are in the EU, you have the following rights:
- Access — ask what data we hold about you.
- Rectification — ask us to correct inaccurate data. Most fields you can edit yourself in the app.
- Erasure — delete your account at any time (see above).
- Restriction — ask us to limit how we process your data.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — where processing is based on consent, you can withdraw it at any time by contacting us or adjusting your preferences in the app.
- Portability — receive a copy of your data in a portable format. This is on our roadmap but not yet available. Until it ships, you can email us and we will export your data manually within 30 days.
Children
ChairTime is not intended for users under 16. If you believe a child has created an account, please contact us and we will remove it.
Security
Data is encrypted in transit over HTTPS and at rest with our sub-processors. We follow least-privilege access for our own team. No service can promise perfect security, but we take it seriously and regularly review our practices.
Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ANSPDCP within 72 hours as required by GDPR Article 33. If the breach is likely to result in a high risk to you, we will also notify you directly, as required by Article 34, with information about the nature of the breach and the steps we are taking.
Cookies
ChairTime uses only essential cookies that are strictly necessary for the application to function (such as session cookies for authentication). These do not require consent under the ePrivacy Directive because the service cannot operate without them. We do not use any advertising, tracking, or third-party marketing cookies. Vercel Analytics, which we use on the chairtime.studio website, operates without cookies and collects only anonymized, aggregate data.
Changes to this policy
If we make material changes to this policy we will update the "last updated" date at the top and, where appropriate, notify you in the app or by email. Continued use of ChairTime after a change means you accept the updated policy.
Supervisory authority
If you are unhappy with how we handle your data, you can lodge a complaint with the Romanian data protection authority — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), www.dataprotection.ro, anspdcp@dataprotection.ro.
Contact
Questions about this policy, or about your data? Contact ZEF SOFTWARE SRL at contact@chairtime.studio.