Privacy Policy

Effective date: April 6, 2026 | Last updated: April 6, 2026

1. Who We Are

ProChair is operated by Michai Media LLC ("Company", "we", "us"). This Privacy Policy explains how we collect, use, share, and protect your personal information when you use prochair.app and related services (the "Platform").

2. Information We Collect

Information you provide:

  • Account information: name, email address, phone number, business name
  • Profile information: photos, service descriptions, pricing, availability
  • Client information: names, contact details, appointment history (entered by Pros)
  • Lead/notification signups: name, email, phone, city, service interest
  • Payment information: processed by Stripe (we do not store card numbers)
  • Communications: support messages, feedback

Information collected automatically:

  • Device information: browser type, operating system, screen size
  • Usage data: pages visited, features used, time spent (via Google Analytics)
  • Location data: approximate location from IP address; precise location only with your explicit consent (for map features)
  • Cookies: essential cookies for authentication; analytics cookies with your consent

3. How We Use Your Information

  • To provide, operate, and improve the Platform
  • To process bookings and payments
  • To send booking confirmations, reminders, and receipts
  • To notify you when new pros join your area (if you opted in)
  • To provide customer support
  • To detect and prevent fraud, abuse, and security threats
  • To comply with legal obligations
  • To send marketing communications (with your consent, which you can withdraw at any time)

4. How We Share Your Information

We do not sell your personal information. We share data only in these circumstances:

  • With Pros and Clients: When you book an appointment, your contact information is shared with the relevant Pro (and vice versa) to facilitate the service.
  • Service providers: Stripe (payments), Resend (email), Twilio (SMS), Supabase (database), Mapbox (maps), Google (analytics, places data). These providers process data on our behalf under their own privacy policies.
  • Legal requirements: When required by law, court order, or to protect rights, safety, or property.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users.

5. Data Security

We implement industry-standard security measures including: HTTPS/TLS encryption in transit; encrypted database storage; Row Level Security (RLS) on all database tables; rate limiting on public API endpoints; secure authentication via Supabase Auth; Stripe PCI-DSS compliant payment processing; security headers (HSTS, XSS protection, CSP, clickjack prevention). No system is 100% secure. We cannot guarantee absolute security but we take commercially reasonable steps to protect your data.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data ("right to be forgotten")
  • Portability: Export your data in a machine-readable format
  • Opt-out: Unsubscribe from marketing communications at any time
  • Restrict processing: Request we limit how we use your data

To exercise any of these rights, email privacy@prochair.app. We will respond within 30 days.

7. California Privacy Rights (CCPA)

If you are a California resident, you have the right to: know what personal information we collect and how it is used; request deletion of your personal information; opt out of the sale of personal information (we do not sell personal information); not be discriminated against for exercising your privacy rights. To make a CCPA request, email privacy@prochair.app.

8. GDPR (European Users)

If you are in the European Economic Area, our legal basis for processing your data is: (a) contract performance (providing the service you signed up for); (b) legitimate interests (improving the Platform, preventing fraud); (c) consent (marketing communications, analytics cookies). You may withdraw consent at any time. You may lodge a complaint with your local data protection authority.

9. Cookies

Essential cookies: Required for authentication and basic functionality. Cannot be disabled.

Analytics cookies: Google Analytics (GA4) to understand how the Platform is used. You can opt out through our cookie consent banner or your browser settings.

Advertising/analytics pixels: If you accept non-essential cookies, we may load Meta (Facebook/Instagram) Pixel and TikTok Pixel to measure the effectiveness of our advertising campaigns. These pixels collect anonymized interaction data (page views, sign-ups) and are governed by Meta's Privacy Policy and TikTok's Privacy Policy. You can opt out at any time by declining non-essential cookies.

10. Data Retention

We retain your data for as long as your account is active or as needed to provide services. After account deletion, we retain anonymized usage data for analytics but delete all personally identifiable information within 30 days. We retain financial records as required by law (typically 7 years for tax purposes). Lead/notification signups are retained until you unsubscribe or request deletion.

11. Children's Privacy

ProChair is not intended for users under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email. The "Last updated" date at the top reflects the most recent revision.

13. Contact Us

For privacy-related questions or data requests:

Email: privacy@prochair.app

Michai Media LLC
St. Louis, MO