Privacy Policy

Last updated: 30 September 2026

This policy explains how SPARE CHAIR LTD ("Spare Chair", "we", "us") uses personal data in the Spare Chair dashboard at app.sparechair.io. Our website at sparechair.io has its own privacy policy at sparechair.io/privacy.

1. Who we are

We do not have a Data Protection Officer. We are not required to have one. Our privacy contact handles all data protection questions.

2. Two roles we play

We are a controller for data about:

We are a processor for data about a salon's own clients and staff that we read from the salon's booking platform. The salon is the controller for that data. Our contract with the salon (the Data Processing Agreement) governs how we use it. If you are a client of a salon, please contact the salon first. We will help them answer you.

3. What we collect and why

Who What data Where it comes from Why we use it Lawful basis
Dashboard users Name, work email, phone, role, login and session data, settings you choose You, your booking platform, our login provider To give you an account and run the service Contract; legitimate interests
Salon account contacts Business name, owner or admin email, phone, address, website You, or your booking platform when you install our app To set up and support your account; to send service emails Contract; legitimate interests
Error reports Technical error data The dashboard To find and fix bugs Legitimate interests

We do not ask for special category data. Please do not put health or similar details in free-text fields.

4. Automated pricing

Our service sets prices for appointment slots. These decisions are about time slots, not about any person. We do not profile salon clients or make decisions about them that have legal or similarly significant effects. So Article 22 of the UK GDPR does not apply to the pricing. The salon controls the rules and limits.

5. Who we share data with

We use trusted providers to run the service. They act on our instructions.

Provider What they do Location
Amazon Web Services Hosting, database, storage, secrets UK (London, eu-west-2)
Stytch Login and sessions USA
Resend Sending service emails USA
Sentry Error monitoring EU (Germany)
Datadog Logs and monitoring USA

We also connect to your booking platform (for example Timify) when you ask us to. We may share data if the law requires it, or with a buyer if we sell the business. We never sell personal data.

6. International transfers

Some providers are in the USA. When data leaves the UK we use one of these safeguards:

Ask us for a copy at team@sparechair.io.

7. How long we keep data

Data How long
Account data While your account is open, then 90 days
Booking and pricing data for a salon While the salon is a customer, then deleted or returned within 90 days
Invoices and tax records 6 years
Logs 30 days
Error reports 90 days

8. Your rights

You have the right to:

Email team@sparechair.io. We will reply within one month. We may ask you to prove who you are.

9. Complaints

Please tell us first at team@sparechair.io. We will handle your complaint and reply within 30 days. You can also complain to the Information Commissioner's Office (ICO): ico.org.uk, 0303 123 1113.

10. Security

We use encryption in transit, access controls, secret storage and least-privilege access. We remove names and contact details from booking data we receive where we can.

11. Children

Our service is for businesses. We do not knowingly collect data from children.

12. US residents

If we serve US businesses, some US state laws may give you extra rights. Contact us at team@sparechair.io. We do not sell or share personal data for cross-context behavioural advertising.

13. Changes

We will post changes here and update the date at the top. We will tell account holders about big changes by email.