Privacy Policy — Tapchair
Effective September 1, 2026
Tapchair LLC ("Tapchair", "we", "us") provides booking and payment software to barbershops, salons and independent barbers. This policy explains what we collect, why, and what we do not do with it.
Two kinds of people use Tapchair, and the answers differ:
- Operators — barbers, stylists and shop owners who run their business on Tapchair. They are our customers.
- Clients — people who book appointments with, and pay, those operators. Clients do not need a Tapchair account and are never charged a Tapchair fee.
1. What we collect
From clients
| Data | Why |
|---|---|
| Mobile phone number | To verify you, confirm your appointment and send reminders |
| First name and last initial (or full name, if you give it) | So your barber knows who is booking |
| Appointment history with that operator | To manage bookings and no-show policies |
| Payment amount, tip, date, and the last four digits and brand of your card | Receipts, refunds and dispute evidence |
We never see or store your full card number. Card details are entered directly into Stripe's payment fields and go to Stripe, not to us. Tapchair's servers never receive raw card data.
From operators
Name, mobile number, email address, business details, service menu, working hours, and the identity and banking information required by Stripe to pay you. Identity verification (KYC) is performed by Stripe, not by Tapchair — we receive only the status of that check, never the documents.
From people who join the waitlist
| Data | Why |
|---|---|
| Email address | To contact you about onboarding when a place is available. We do not add you to a marketing list, and we do not share it. |
Automatically
Standard server logs (IP address, browser type, pages requested) and, where you consent, basic analytics. We do not use advertising trackers.
2. Text messages
Full detail is in our SMS Messaging Terms. In summary:
- You opt in by verifying your mobile number with a one-time passcode.
- We send transactional messages only — passcodes, appointment confirmations and reminders, cancellations, and receipts.
- Message and data rates may apply. Reply HELP for help, STOP to stop.
- We do not send between 9:00pm and 8:00am in your local time, except for a passcode you requested yourself.
- STOP applies across every business on Tapchair, not just the one that messaged you.
We keep a record of when and how you consented, and of every message we attempted to send, as evidence that we were entitled to contact you. We store a cryptographic hash of each message rather than its text — enough to prove what was sent, without keeping the content.
3. Who we share data with
We share only what a service needs to do its job:
| Recipient | What | Why |
|---|---|---|
| Stripe, Inc. | Payment and payout data; operator identity for KYC | To process payments and pay operators. Stripe's own privacy policy applies |
| Twilio Inc. | Mobile number and message content | To deliver text messages |
| The operator you booked with | Your name, number and appointment history | They are the business providing your service |
| Hosting and infrastructure providers | Data at rest and in transit | To run the service |
| Law enforcement or regulators | Only what is legally required | Legal obligation |
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
4. What operators can and cannot see about each other's clients
This is a deliberate design choice, not a side effect.
Barbershops on Tapchair often contain independent businesses under one roof. A barber who rents a chair owns their own client relationships.
- Where a barber rents a chair, the shop owner sees that an appointment exists and that money moved. They cannot see that client's contact details, notes, spending or history. The calendar shows a first name and last initial only.
- Where a stylist is employed on commission, the shop is the business of record and sees full client detail.
- Where a front desk collects payment on a barber's behalf, they see the ticket, never that barber's balances or earnings.
5. How long we keep data, and deletion
You may ask us to delete your personal information at any time by writing to privacy@tapchair.app.
We delete by anonymization. We remove your name, phone number and any notes, and we keep the financial record of the transaction — amount, date, tax category — with no identifying information attached. We do this because businesses are legally required to keep financial records, and because deleting a payment record would corrupt an operator's books and their tax position. The remaining record cannot be tied back to you.
Message delivery records are retained for two years as evidence of consent, then purged.
6. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to withdraw consent. Texas residents have rights under the Texas Data Privacy and Security Act; residents of California, Colorado, Virginia and other states have comparable rights.
Write to privacy@tapchair.app. We will respond within the period your law requires, and we will not treat you differently for asking.
To withdraw consent for text messages, reply STOP to any message.
7. Security
Payments use Stripe and are subject to PCI DSS; Tapchair is SAQ-A eligible because card data never reaches our servers. Data is encrypted in transit. Access to production data is limited to personnel who need it.
No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you as required by law.
8. Children
Tapchair is not directed to children under 13 and we do not knowingly collect their personal information. A parent or guardian may book on a child's behalf using their own contact details. If you believe a child has provided us information, write to privacy@tapchair.app and we will delete it.
9. Changes
We will post any change here and update the effective date. If a change is material, we will notify affected users before it takes effect.