slayd

Consumer Health Data Privacy Policy

Last updated August 4, 2026

This is a separate policy about one narrow thing: health information. It exists because Washington's My Health My Data Act and Nevada's SB 370 require a standalone document for it. Everything else about how Slayd LLC ("Slayd," "we") handles your information is in our Privacy Policy, which this policy sits alongside rather than replaces.

Slayd is a booking product for beauty and fitness services. We did not build it to collect health information and we do not want more of it than the service needs. But a hair colourist needs to know about a scalp allergy, a waxing studio needs to know about a retinoid, and a studio needs to know if you are pregnant before you take a hot class — so some health information passes through Slayd, and this document is about exactly that.

Throughout, Provider means the beauty or fitness professional, studio or salon you book, and consumer health data means information that identifies your past, present or future physical or mental health status, in the broad sense those two laws use.

01What Health Data We Collect, and Why

Three routes, and no others. If you take all three away, we hold no consumer health data.

WhatHow it reaches usWhy
Answers on a Provider's intake or consent form Your Provider writes their own forms. We do not restrict the questions, so a form can ask about allergies, sensitivities, medical history, medication, skin or scalp conditions, pregnancy, or a date of birth. You fill it in and type your name as a signature. So the Provider can perform your service safely and keep the consent record their trade requires. We hold it to deliver their tools; the Provider decides what to ask.
Notes you write on a booking A free-text box on the appointment. We ask for this directly — the placeholder text in the app and on slayd.ai suggests allergies as an example of what to write. So the Provider knows before you are in the chair. It is sent to the Provider you booked and to nobody else.
A Provider's own notes about you Your Provider types them into their client record — a colour formula, a reaction you had, a product to avoid. The Provider's own book of business, so your next visit goes well.
One derived use you should know about rather than discover. Inside the Provider tools, Slayd scans the notes on a client record for allergy and sensitivity wording — words like "allergic", "reactive", "sensitive", and instructions such as "no ammonia" — and shows the matching sentences as a safety flag at the top of that client's profile, so the Provider does not scroll past it. That is Slayd deriving a health signal from text, not just storing it. It happens only inside the book of business of the Provider who wrote the note, and it is visible only to them.

What we never do with it

02Where It Comes From

We do not buy health data, and we do not receive it from data brokers, advertising networks or any other third party.

03Who It Is Shared With

Two kinds of recipient, and that is the whole list.

Category of recipientWho, specificallyWhat they get
The Provider you booked The beauty or fitness professional, studio or salon — and, where they work as part of a team, the business whose roster they are on. Your form answers and your booking notes. This is the purpose of writing them.
Our infrastructure provider Google (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions), which hosts essentially all of Slayd's data in the United States. Whatever is stored, as our processor, under contract, for no purpose of its own.

We have no affiliates, and there are none to list. We do not share consumer health data with Stripe, Apple, Twilio SendGrid, or any advertising, analytics or attribution service. We would disclose it if the law compelled us to, or to protect someone's safety, and we would tell you unless we were forbidden to.

04How You Agree, In Plain Terms

We would rather describe the mechanism than characterise it.

Being straight with you about one thing. Washington's law contemplates a health-data consent step that is presented separately from everything else you agree to, and a separate signed authorization before health data is shared. Slayd does not currently present either as a distinct step — you type the information into a labelled field, and it goes to the Provider you booked. We are telling you what happens rather than implying a formality we have not built. If you would rather no health information reached us at all, Section 04 above says how, and Section 06 says how to have anything already recorded deleted.

05How Long We Keep It

Where a record is the Provider's rather than ours, we will tell you so and point you to them — see Section 06.

06Your Rights, and How to Use Them

If you are in Washington or Nevada — and in practice we will do this for anyone who asks — you have the right to:

How to ask

Email support@slayd.ai from the address on your account and say what you want. We may need to confirm it is you first. We will answer within 45 days, and if we genuinely need longer we will tell you why and take at most another 45.

One honest limit: where the record belongs to a Provider — their notes about you, their signed form — we will act on what is ours, tell you plainly what is theirs, and point you to them. We will not pretend a Provider's record is ours to erase.

If we say no

You can ask us to look again by replying to our decision. If you are still not satisfied you can complain to the Washington State Attorney General or, in Nevada, to the Nevada Attorney General.

07Changes, and Contact

If we change what health information we collect, why, or who receives it, we will update this page, revise the date at the top, and — where the change is significant — tell you in the app or by email before it takes effect.

Questions, or a request under Section 06? Email support@slayd.ai. The controller of the data described in this policy is Slayd LLC, at 27101 N Dixboro Rd, South Lyon, MI 48178.