Privacy Policy

Chair by ArtifactCurrent Product, WhatsApp, and Chair Concierge Notice
Effective Date: August 20, 2026 · Last Updated: August 20, 2026

1. Introduction

This Privacy Policy explains how Artifact (“we”, “us”, or “our”) collects, uses, stores, and discloses information in connection with Chair (the “Service”).

Chair is a business-management platform for salons, barbershops, and similar personal-care operators. This policy applies to:

  • Operators: business owners, admins, and staff who create and manage accounts on Chair
  • End-clients: customers of those businesses whose data Operators enter into Chair

If you are an Operator, please also ensure your own clients are appropriately informed about how their information is handled.

This policy covers the current Chair product, including WhatsApp Business connectivity and Chair Concierge, Chair's AI-powered WhatsApp assistant, where Artifact has enabled them for a shop. Those features do not apply to shops that are not connected.

This policy also applies to end-clients who message a Chair-connected shop WhatsApp number, not only to information an Operator typed into the dashboard.

2. Data Roles: Who Is Responsible for What

2.1 Operator Account and Shop Data

For operator account data, shop setup data, subscription data, team-management records, and similar business-account information, Artifact is the party operating the Service and determines how such information is processed to provide and secure the platform.

2.2 End-Client Data Entered by Operators

When an Operator stores customer information in Chair, the Operator is responsible for deciding why that information is collected and used for their business operations. Artifact processes that information on the Operator's behalf so the Service can provide CRM, appointment, checkout, reporting, package, and membership functionality.

Operators are responsible for ensuring they have any notice, consent, authorisation, or other lawful basis required under applicable law, including the Digital Personal Data Protection Act, 2023 (DPDP Act), to collect, store, and use their own clients' information.

2.3 WhatsApp Messages and Chair Concierge

When a customer messages a connected shop WhatsApp number, Artifact processes that conversation to operate Chair Concierge and, if a booking is created, to record the appointment for that shop. The Operator remains responsible for the client relationship and for any notice, consent, or other lawful basis required to use WhatsApp with their clients.

A name typed in WhatsApp is conversation context. It does not, by itself, unlock another person's private history. Private appointment or membership information is used only when Chair has already associated that WhatsApp number with a client record for that shop.

3. Information We Collect

3.1 Operator Account and Identity Data

CategoryCurrent Examples
AuthenticationEmail address used for passwordless email sign-in (magic link, 60-minute expiry, server-side PKCE code exchange)
ProfileFirst name, last name, phone number (E.164 format), role, display name, active/deactivated state, theme preference
SubscriptionSubscription tier, subscription status, trial end date, owner-account identifiers, subscription-event history
Session DataSession identifier, profile ID, creation timestamp, used for concurrent session management (default limit: 1 session per profile)

3.2 Shop and Business Data

CategoryCurrent Examples
Shop IdentityShop name, shop phone number, shop email (optional), address (optional), country, timezone
Shop SettingsDefault country, scheduling settings, operating hours, default payment method, holiday overrides
BrandingShop logo image files (JPEG, PNG, or WebP) and related storage paths
Team ManagementTeam-member roles, invite records, preauthorisation records, inviter metadata, invite status

3.3 End-Client CRM and Appointment Data

CategoryCurrent Examples
Client CRMClient name, phone number (optional), notes
Client StatisticsTotal visits, total spend, average spend, first/last visit timestamps
AppointmentsCustomer name and phone at booking, services, assigned professionals, status, type, channel, timestamps, duration, cancellation reason
Checkout RecordsTotal amount, paid status, payment method (cash / UPI / card), immutable checkout and cancellation snapshots

3.4 Packages, Memberships, and Offer Data

The current implementation also stores package definitions, purchase records, session balances, expiry dates, redemption history, membership tiers, pricing, discounts, freebies, and freebie redemption records.

3.5 Aggregated Analytics Data

Chair stores and computes aggregated operational analytics derived from appointment and transaction data, such as:

  • Daily shop revenue, total value delivered, completed appointment count, new client count
  • Daily and cumulative revenue and session counts per professional and per service
  • Daily unique client visit counts
  • Payment-method breakdowns (cash, UPI, card revenue totals)

3.6 Logo and Media Data

The currently supported upload flow is for shop logos only. Accepted formats are JPEG, PNG, and WebP. New logo uploads are stored in Cloudflare R2 object storage.

3.7 Technical and Usage Data

To operate and secure the Service, we or our infrastructure providers may process:

  • IP address and request metadata
  • Browser or device user-agent information
  • Authentication and session timestamps
  • Error details and operational logs

Chair does not currently include third-party advertising trackers, analytics pixels, or social-media tracking beacons. Where WhatsApp is enabled, Chair uses Cerebras to generate Chair Concierge replies.

3.8 WhatsApp and Chair Concierge Data

CategoryExamples
ConversationShop association, WhatsApp phone number, optional display name, link to an existing client when that number is already recognised
MessagesInbound and outbound text, message type, provider identifiers, sent / delivered / read / failed timestamps
IntegrationProvider (Gupshup), app / phone / WhatsApp Business Account identifiers, display number
Working memoryTemporary conversation context, typically discarded after about 30 minutes of inactivity
Current booking offerA current slot offer, typically expiring after about 15 minutes if not agreed
Booking recordsAppointments created with help from Chair Concierge (ordinary Chair appointments)
Sanitized operational logsTechnical events used to operate and secure the service. Selected logs do not include message body, phone, name, or draft text
Encrypted review artifactsEncrypted operational artifacts stored with Cloudflare to operate and debug Chair Concierge. These are not advertising profiles. They are not immediately removed when a shop is deleted in the database

4. How We Use Information

PurposeData Used
Providing the ServiceAll account, shop, appointment, client, transaction, and catalog data
Authentication and SessionsEmail address, session tokens, active-session records, PKCE auth state
Real-Time SyncOperational data broadcast via secure, shop-scoped Supabase Realtime channels
Reports and AnalyticsAggregated statistics derived from appointment and transaction records
Subscription ManagementSubscription tier and status to govern feature access
Customer SupportAccount and shop information to diagnose and resolve issues
Legal ComplianceWhere required by applicable law
WhatsApp / Chair Concierge repliesMessage text, recent conversation context, and shop or client facts needed for that request
WhatsApp bookingsRecognised or newly provided customer details, requested services and time, catalog and availability
Operating and securing Chair ConciergeSanitized logs, delivery status, diagnostics

In the current version, we do not use operator or end-client data for:

  • Sale or rental to third parties
  • Advertising or marketing to end-clients
  • Third-party ad-tech profiling
  • Training Chair's own models on operator or end-client information, including WhatsApp content

5. Legal and Operational Basis

Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian law:

  • Operators' own data: Processed on the basis of your consent (at sign-up) and as necessary to provide the Service
  • End-client data entered by Operators: Processed by Artifact on the Operator's behalf. The Operator is responsible for lawful basis from their own clients
  • Technical and usage data: Processed to maintain platform security, performance, and reliability

6. Third-Party Infrastructure Providers

ProviderPurposeData Processed
SupabaseAuthentication, database, and real-time shop syncAccount, shop, appointment, client, WhatsApp conversation and message, and related operational data
VercelApplication hosting and deliveryHTTP request metadata and IP addresses
CloudflareApplication runtime, temporary conversation context, and object storage (shop logos and encrypted review artifacts)Runtime and request metadata; temporary conversation context; logo files; encrypted review artifacts
GupshupWhatsApp business solution providerPhone numbers, message payloads, webhook events, delivery/status metadata, related identifiers
Meta / WhatsAppWhatsApp Business PlatformConnected-number identifiers, message content, customer replies, delivery/status events
CerebrasAI inference for Chair Concierge repliesConversation context and shop or client facts needed to generate a reply

These providers process information under their applicable agreements and policies. Distributed providers may process data outside India.

We do not share personal data with advertisers or data brokers. We share data with the providers above to operate Chair, WhatsApp delivery, and Chair Concierge.

We may disclose data if required by law, court order, or government authority.

7. Data Retention

7.1 While a Shop Is Active

Shop operational data is retained while the shop remains active in the Service.

7.2 What Happens When a Shop Is Deleted

The in-app destructive flow executes an atomic database transaction that deletes the shop and all dependent operational data, including appointments, client CRM records, snapshots, service catalog, packages, memberships, analytics, and team-member profiles. Shop deletion in the database removes that shop's Chair-held WhatsApp conversations, messages, and integration records (they are deleted with the shop). Shop-logo cleanup in Cloudflare object storage is best-effort and outside the database transaction.

Encrypted Chair Concierge review artifacts stored with Cloudflare are not immediately removed by database shop deletion.

7.3 What Survives Shop Deletion

Shop deletion is not full identity erasure. The following survive:

  • The Owner's login identity and profile (with shop association removed)
  • Owner account and subscription history records
  • Subscription event logs
  • A fresh re-onboarding preauthorisation row

For a broader personal-data deletion request, contact the privacy contact listed below.

7.4 Other Retention Points

  • Pending team invitations may remain until used, revoked, or deleted with the shop
  • Trial and subscription metadata are not automatically purged on trial expiry
  • A self-serve data export or archival workflow is not currently available before deletion
  • WhatsApp message and conversation rows held in Chair are kept while the shop is active and are removed by the current database shop-deletion flow
  • Chair Concierge working memory typically expires after about 30 minutes of inactivity
  • A current booking offer typically expires after about 15 minutes if not agreed
  • Completed WhatsApp-originated appointments remain ordinary appointment records until shop deletion or a valid deletion request

8. Data Security

The current implementation includes:

  • Row-Level Security (RLS): All database tables enforce shop-scoped data isolation
  • HTTPS / TLS: All communication is encrypted in transit
  • Passwordless Authentication: No passwords stored; time-limited magic links with PKCE
  • Bearer Token Authentication: All API routes require a valid JWT
  • Session Limits: Configurable max concurrent sessions per profile (default: 1)
  • Realtime Isolation: Shop-scoped Supabase Realtime channels
  • Team Access Revocation: Immediate session termination on deactivation
  • Presigned Storage Access: Presigned URLs for logo operations
  • Atomic Destructive Operations: Shop deletion is a single database transaction

No system can guarantee absolute security. If you suspect unauthorised access, contact us immediately.

9. Your Rights and Choices

9.1 Operator Rights

RightHow to Exercise
AccessContact us at the privacy email below
CorrectionUpdate profile information directly in the app, or contact us
DeletionUse the in-app “Delete Shop” feature, or contact us for a broader identity-level request
Withdrawal of ConsentDelete your account or contact us. Withdrawal does not affect prior lawful processing
Data PortabilityContact us to request an export. No self-serve export is currently available; requests are handled manually on a reasonable-effort basis

9.2 End-Client Rights

End-clients whose information was entered by an Operator should first contact that Operator. If you are unable to obtain a response and believe your rights are being violated, contact Artifact at the privacy email below.

Data requests are subject to identity and authority verification. End-clients who used WhatsApp should first contact the salon. They may also email privacy@chairapp.co. We process requests for Chair-held data we control, subject to verification and applicable legal retention. Providers may retain copies under their own terms. Chair Concierge cannot cancel or reschedule in chat.

10. Cookies, Local Storage, and Browser-Side State

MechanismPurpose
Supabase auth / session stateLogin session persistence, including PKCE auth state
sidebar_state cookieUI navigation sidebar state (open / collapsed)
balbro-theme-palette (localStorage)Theme palette preference
auth_refresh (localStorage)Cross-tab auth refresh signalling

Chair does not use third-party advertising cookies, social-media tracking pixels, or third-party analytics beacons.

11. Children's Data

Chair is a business management platform intended for adult business operators, not for children. However, Operators may enter customer records relating to their own clients, which could include minors, if doing so is lawful and they have any required legal authorisation. Artifact does not market Chair directly to children.

12. Cross-Border Data Processing

The primary structured database is hosted in Mumbai, India (AWS ap-south-1). Vercel, Cloudflare, Gupshup, Meta / WhatsApp, and Cerebras are distributed providers and may process data outside India.

13. WhatsApp, Chair Concierge, and Inference

Where enabled, customers may message a Chair-connected shop WhatsApp number. Chair may process phone numbers, message content, provider identifiers and status events, temporary conversation context, booking records, sanitized operational logs, and encrypted review artifacts.

Chair Concierge can answer supported inquiries, check availability, and help create a booking after clear agreement to a current booking offer, subject to current service and availability limits. Trusted Chair systems validate booking-critical information and record the appointment. Chair Concierge cannot currently cancel, reschedule, take payment, or send automated reminders. Cancellation or rescheduling must currently be handled by the salon or through the Chair dashboard.

A recorded appointment may exist even if WhatsApp delivery fails.

The Concierge is designed to use shop data. Customers and Operators should verify important booking details. Artifact does not guarantee that every reply is complete or error-free.

Artifact does not use operator or end-client information, including WhatsApp content, to train Chair's own models. Cerebras and other providers process data under their applicable agreements and policies.

Per-shop Embedded Signup, Operator template libraries, and reminder campaigns are not generally available.

14. Changes to This Privacy Policy

Artifact may update this Privacy Policy from time to time. When material changes are made, we will update the “Last Updated” date and notify you via your registered email or via an in-app notice.

If you do not agree to the updated policy, you may terminate your account before the effective date.

15. Grievance Officer

In accordance with the Information Technology Act, 2000, the IT (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023:

Name: Sharwin Rahul Harkal
Email: privacy@chairapp.co
Location: India
Response time: We will acknowledge your request within 72 hours and endeavour to resolve it within 30 days

16. Governing Law

This Privacy Policy is governed by the laws of India, including:

  • The Digital Personal Data Protection Act, 2023 (DPDP Act)
  • The Information Technology Act, 2000 and the IT (Amendment) Act, 2008
  • The Information Technology (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011

17. Contact

For any privacy-related questions, requests, or concerns:

Artifact / Sharwin Rahul Harkal
Email: privacy@chairapp.co
India

Chair Logo
Chair by Artifact

© 2026 Artifact. All rights reserved.

Operated by Artifact / Sharwin Rahul Harkal, India