slayd

Privacy Policy

Last updated August 4, 2026

This Privacy Policy explains what information Slayd LLC ("Slayd," "we") collects through the Slayd iOS app and the Slayd website at slayd.ai, how we use it, who receives it, and the choices you have. It also covers people who book and pay on slayd.ai without signing up, and people whose details a beauty or fitness professional enters into Slayd. By using Slayd, you agree to this Policy.

Throughout this Policy, Provider means a beauty or fitness professional, studio, or salon that offers services through Slayd, and Client means someone who books them.

01Information We Collect

CategoryWhat that means
Account & profileName, username, email address, date of birth, bio, profile photo, account role, the city and ZIP code you type during sign-up, your interests, and Instagram / TikTok handles if you add them.
Phone numberIf you verify a phone number at sign-up, the number and the time it was verified are stored on your account. On the website and at guest checkout we store the number you typed without verifying it. We also keep a private internal record linking a phone number to the accounts that claimed it, so one number cannot be used to open unlimited accounts.
Provider & business detailsBusiness name, business phone and email, exact street address and exact map coordinates, services, prices, hours, deposit and cancellation settings, and your team roster. See Section 08 — most of this is public.
Content you createPhotos and videos you capture or upload, post captions, comments, reviews and star ratings, and your profile bio. Reviews carry your display name.
MessagesDirect messages between you and another account, including any photos you attach.
Social connections & activityWho you follow and who follows you, follow requests you send or receive, accounts you have blocked, posts and reveals you liked, shared or saved, the posts and reveals in your saved collections, and your in-app notification history.
Bookings & purchasesAppointments and classes, the service, price, date and time, notes you write for your Provider, notes your Provider writes about the appointment, deposits, prepaid packages, class passes and memberships.
Payment informationHandled by Stripe. We receive amounts, status and identifiers — never your full card number. For Providers, we store the last four digits of the bank account Stripe pays out to.
Subscription recordsFor Providers: subscription status, renewal dates and the transaction identifiers Apple or Stripe gives us.
LocationThe city and ZIP you type. Separately, with your permission, your device's precise location — used on your device only. See Section 05.
ContactsWith your permission, we read names and phone numbers from your address book on your device to suggest people to invite. We do not upload them. See Section 03.
CalendarWith your permission, we add your booked appointments to your device calendar. We write events; we do not read your existing ones.
Device & push identifiersYour device's vendor identifier, your push notification token, and the platform ("ios"), stored against your account so we can notify the right device.
Crash & error diagnosticsCrash reports and handled-error records sent to Firebase Crashlytics. See Section 12.
Usage timestampsTwo timestamps on your account: when you were last active (updated at most once an hour) and when you last booked. We do not run an analytics SDK — see Section 12.
Forms & signaturesAnswers to intake, consent and policy forms a Provider sends you, the name you type as a signature, and the fact and time you agreed. A Provider can build a form that asks for health information such as allergies or a date of birth.
Reports & supportIf you report content or a person: your account ID, what you reported, the reason and your written description. If you contact us: your name, email, business name and message.
Waitlist & applicationsConsumer waitlist: email address only. Business early-access application: business name, contact name, email, phone, street address, city, state, ZIP, services, team size, booking system, Instagram, website and notes.
IP addressRead to rate-limit sign-ups, bookings and forms. Not stored in readable form — see Section 16.
Provider business recordsIf you are a Provider: the book of business you keep in Slayd — your client list, invoices, receipts, expenses, refunds, retail inventory, payroll entries, booth-renter records, rent payments, open slots, daily deals and personal tasks. These are backed up to our servers. See Section 09.

Where we get your information

Most of what we hold, you gave us. Not all of it:

Some things stay on your phone. Your beauty journal entries, saved looks and recent searches are stored on your device and are not uploaded to us. If a Provider enters a tax identifier (EIN or SSN) in the Tax Center, it is stored in the iOS Keychain on that device and is never transmitted to us — see Section 10.

02Permissions We Request

You can grant or revoke any of these in your device Settings at any time. Declining a permission disables the related feature; it does not block the rest of the app.

03Contacts, In Detail

There are two places Slayd touches your address book, and they behave differently.

04Booking Without an Account

If you book and pay on slayd.ai as a guest, we create an account for you. When your payment succeeds, we create a Slayd sign-in for your email address and a profile holding your name, a generated username, your email address, and the phone number you typed. You do not choose a password; the confirmation email is your notice. We do this so the appointment has an owner, so you can see it, cancel it, and be contacted about it. If you do not want the account, email support@slayd.ai and we will delete it.

Before you pay, we store the name, email address, phone number and any notes you entered, along with the Provider, service, price and time slot, in a record only our servers can read. That record is written when you fill in the form — not when you pay — so it exists even if you close the tab. Your email address is also passed to Stripe so Stripe can send the receipt.

Guest checkout always charges the full price up front. If the time slot is taken while you are paying, the charge is refunded in full and no appointment is created.

05Location, In Detail

We use location two different ways, and only one of them involves our servers.

Your location as a Client

When you allow location access, the app requests your device's precise location — not a coarse or city-level fix — and, if iOS has restricted the app to approximate location, it may ask you to allow full accuracy once. We use that fix to sort Providers by distance and to fill in an address field, and we convert it to a street, city and ZIP using Apple's geocoding service, which means Apple receives those coordinates.

Your device location is not sent to Slayd's servers and we do not store it. It stays on your phone. The city and ZIP saved on your profile are the ones you typed at sign-up, not ones taken from your device.

When you type an address anywhere in the app, the characters you type are sent to Apple to generate autocomplete suggestions.

A Provider's business location

A Provider's business address and coordinates are a different matter entirely, because they are published. See Section 08.

06How We Use Information

We do not use your information to build advertising profiles, and we do not sell it.

Aggregated and de-identified data

We may produce aggregate statistics that describe the platform as a whole — how many bookings happened in a category, typical prices in a region — and use or publish them. Figures like those are not personal information: they do not identify you and cannot reasonably be linked back to you. Where we hold information in de-identified form we keep it that way: we do not attempt to re-identify it, and we require the same of anyone we give it to. None of this is a licence to sell your personal information, and we do not sell it.

07Who Receives What

The table below maps each category of information to why we handle it and who else sees it. "The public" means anyone on the internet, including people with no Slayd account.

CategoryPurposeRecipients
Account & profileRun your account; sign-in; age gateGoogle (Firebase Auth, Firestore). Your name, username, photo, bio and role: the public — see Section 08
Phone numberVerify sign-up; let a Provider reach you; limit duplicate accountsGoogle (Firebase Auth sends the verification SMS; Firestore stores it). Your Provider, for appointments you book
Provider & business detailsPublic storefront; booking; payoutsThe public. Stripe, for payout onboarding
Posts, comments, reviewsShow your content in the appAny signed-in Slayd user. Google (Firestore, Storage)
Direct messagesDeliver your messagesThe other participant. Google (Firestore, Storage). A preview appears in the push notification — see Section 11
Bookings & purchasesDeliver the appointment; refunds; recordsYour Provider and, for team bookings, the business they work for. Stripe. Twilio SendGrid, for confirmation email
Payment informationTake payment; pay ProvidersStripe. Apple, for in-app subscription purchases. Google (Firestore, for amounts and status)
Device location (Client)Sort Providers by distance; fill an address fieldApple (geocoding and address autocomplete). Not sent to Slayd
ContactsSuggest people to inviteNobody. Read on your device, not uploaded
CalendarPut appointments in your calendarNobody. Written to your device
Device & push identifiersDeliver notifications to the right deviceGoogle (Firebase Cloud Messaging). Apple (APNs)
Device attestationConfirm requests come from the real Slayd appApple (App Attest). Google (Firebase App Check)
Crash & error diagnosticsFind and fix defectsGoogle (Firebase Crashlytics)
Usage timestampsShow whether an account is active; internal supportGoogle (Firestore). Slayd staff — see Section 17
Forms & signaturesConsent and intake records for your appointmentThe Provider who sent the form. Google (Firestore, Storage)
Reports & supportReview safety reports; answer youSlayd staff only. Google (Firestore)
Waitlist & applicationsTell you when we launch near you; assess business applicationsSlayd staff only. Google (Firestore)
IP addressRate limiting and abuse preventionGoogle — Cloud Functions and Hosting receive it with every request. On slayd.ai your browser also sends it to Stripe and to Google Fonts on every page load — see Section 13. We keep only a hash — see Section 16
Social connections & activityBuild your feed and follower list; deliver in-app notifications; enforce blocksOther Slayd users, where the action is visible to them — a follow, a like, a share or a comment carries your name. Your blocks, your saves and your saved collections are private to you. Google (Firestore)
Client records entered by a ProviderProvider's own book of businessThat Provider and their team. Google (Firestore) — see Section 09
Provider business recordsBack the Provider's book up so a lost or reinstalled phone does not destroy the salon's historyThat Provider. Google (Firestore) — see Section 09

Our service providers

We also disclose information for legal reasons — to comply with law or to protect the rights, safety and security of Slayd and its users — and in connection with a merger, acquisition or sale of assets, subject to this Policy.

We do not use analytics, advertising or attribution services. See Section 12.

08What Is Public

Some of Slayd is deliberately open so people can find a Provider without signing up. Please read this section before you decide what to put on your profile.

Providers: your business address is public, and it is exact. The street address and the precise map coordinates you enter are published on your storefront, which anyone can read without an account — as are your business phone number and business email if you provide them. If you work from home, that is your home address on the public internet. If you do not want it published, leave the address blank or use a separate business location. We are working on publishing only an approximate area instead; until this Policy says otherwise, assume the exact address is public.

09Information Providers Enter About Other People

Providers keep a book of business in Slayd. That includes people who have never used Slayd — walk-ins, existing clients, and staff.

For this information, the Provider decides what to collect and why, and Slayd handles it on the Provider's behalf to deliver Provider tools. The Provider is responsible for having the right to use it and for handling it lawfully.

If you are on a Provider's client list and want your details corrected or removed, ask that Provider first — they control the record. You may also email us and we will act on what we hold.

If you have never used Slayd

You may be reading this because a Provider added you to their book, imported you from another booking system, recorded you as a staff member or a booth renter, or because you booked and paid on slayd.ai without signing up. In that case we did not get your details from you, and you are entitled to know the same things anyone else is. The categories we hold about you are in Section 01; why we hold them and who else sees them is in Section 07; how long is in Section 14; your rights, and how to exercise them, are in Section 15. The Provider who entered your details decided what to collect and why; we hold it to run their tools. Email support@slayd.ai and we will tell you what we hold about you and, where the record is ours to change, act on it — or point you to the Provider where it is theirs.

09AConsumer Health Data

Slayd is a beauty and fitness product, and some of what passes through it is health information even though we never set out to collect any. Washington's My Health My Data Act and Nevada's SB 370 treat that kind of information specially, so it gets its own section and its own document.

There is a separate Consumer Health Data Privacy Policy. It says what health information reaches us, why, who sees it, how long we keep it, and how to have it deleted — and it is candid about the controls we have not built yet. Read it at slayd.ai/health-data.

In short, health information can reach Slayd three ways:

We do not sell health information, we do not use it for advertising, and we do not use it to infer anything about you for our own purposes. One thing you should know rather than discover: the Provider tools scan a client's notes for allergy and sensitivity wording and surface the matching sentences as a safety flag on that client's profile, so the Provider does not miss it. That happens inside the Provider's own book of business and is visible to them, not to other users.

If you would rather no health information reached us at all: leave the booking notes blank, and tell your Provider in person instead of on a form. If some has already been recorded, email support@slayd.ai and we will delete what is ours to delete and tell you what belongs to the Provider.

10Payments

Payments are processed by Stripe. Card details are entered inside Stripe's own payment sheet. Slayd never receives or stores your full card number. We receive the amount, the status, and identifiers that let us match a payment to a booking. Your payment information is also handled under Stripe's own privacy policy.

Provider subscriptions purchased on iPhone are billed by Apple. We store the subscription identifiers and status Apple sends us so we know your subscription is active.

Providers

11Notifications and Device Identifiers

To deliver push notifications we store your device's vendor identifier, your notification token and the platform against your account. The vendor identifier is assigned by iOS, is shared only with other apps from the same developer, and resets when you delete all of our apps.

Two things worth knowing:

You can turn notifications off in your device Settings at any time.

12Analytics, Tracking and Diagnostics

We do not track you across other companies' apps or websites. The app contains no advertising identifier, no App Tracking Transparency prompt, and no analytics, advertising or attribution SDK. We do not build advertising profiles and we run no third-party trackers on slayd.ai.

That is about tracking, not about record-keeping. The things you do in Slayd — the accounts you follow, the posts you like, share or save, the appointments you book — are recorded on your account, because they are the product; they are listed in Section 01 and mapped in Section 07. Beyond those account and activity records, the only diagnostic data we collect is:

13Cookies and the Website

slayd.ai does not use advertising or analytics cookies, and does not run a consent banner because there is nothing to consent to on that front. Two things do happen on every page load, before you interact with anything, and you should know about them:

Signing in creates a session in your browser's local storage so you stay signed in. If you start a guest booking, your name, email and phone are kept temporarily in your browser's session storage so the booking survives a bank verification redirect; closing the tab clears it. Simply browsing slayd.ai does not create a Slayd account or assign you an account identifier.

14Data Retention and Deletion

We keep your information while your account is active and as needed to run the service, comply with legal and tax obligations, resolve disputes and enforce our agreements.

How long we keep each category

Where a period is not fixed, the criterion we apply is stated instead. Some of these say "indefinitely" — that is the truth about the system today, not an aspiration, and where we intend to change it we say so.

CategoryHow long
Account & profile, phone number, Provider & business detailsWhile your account exists. Removed when you delete your account.
Posts, comments, reviews, and their photos and videosUntil you delete them, or until you delete your account.
Social connections & activityUntil you undo the action (unfollow, unlike, unsave) or delete your account. Notifications you caused in other people's inboxes are removed with your account.
Direct messagesIndefinitely. Messages cannot be deleted by either party and survive account deletion — see below.
Bookings & purchasesIndefinitely. An appointment has two sides; deleting your account does not remove it from the other party's history.
Payment, payout and subscription recordsFor as long as tax, accounting, audit and chargeback-defence obligations require, which is several years and longer than your account.
Forms & signaturesWhile the Provider's record of you exists. A form is locked once signed, and your signed forms are deleted when you delete your account.
Provider business records and client recordsWhile the Provider's account exists. They belong to that Provider's book of business, so deleting your account does not remove their record of you.
Guest checkouts that were never paidIndefinitely, today. The record is written when you fill in the form, not when you pay, and nothing currently deletes an abandoned one. If you started a guest checkout and walked away, email us and we will delete it. We intend to put an automatic limit on this.
Crash & error diagnosticsHeld by Firebase Crashlytics under Google's own retention schedule, which we do not control. No Slayd account ID is attached to them.
IP address (abuse prevention)Two hours, as a hash — see Section 16.
Device & push identifiersWhile your account exists, or until the token is replaced.
Reports & support correspondenceKept after your account is deleted, so a pattern of abuse cannot be erased by deleting an account.
Waitlist & business applicationsUntil we launch in your area and tell you, or until you ask us to remove you.

Deleting your account

You can delete your account yourself — in the app under Settings, or on the website from your account page. Deletion runs on our servers shortly afterwards and removes:

Deleting also cancels your Slayd subscriptions and team seats. If a Provider deletes their account, we automatically refund clients for unused prepaid package credits and notify them.

What deletion does not remove

We would rather tell you this than let you discover it:

Deletion runs step by step and a step can fail. If you need confirmation that a specific piece of information is gone, email us and we will check rather than assume.

If you delete a single post, that post's photos and videos, comments and likes are removed too.

Guest bookings that were started but never paid for are currently retained. If you began a guest checkout and abandoned it and want those details removed, email us.

15Your Rights & Choices

If you are in the EU, UK or Switzerland

You have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to complain to your local supervisory authority. Where we rely on consent — device location, contacts, calendar and notifications — you can withdraw it in your device Settings at any time, without affecting processing already carried out.

We rely on these legal bases: performance of a contract for your account, bookings and payments; consent for the device permissions above; legitimate interests for security, abuse prevention and fixing defects; and legal obligation for tax and accounting records.

Health information. Where a Provider's intake form, or the notes you write for an appointment, contain information about your health, we handle it on the basis of your explicit consent, given when you choose to write it or to sign that form. You can decline: leave the notes blank, and tell your Provider in person rather than on a form. Section 09A and the Consumer Health Data Privacy Policy explain this in full.

Whether you have to give us this. The account and booking details we ask for are needed to enter into and perform our agreement with you — without them we cannot create an account or take a booking. Everything else, including device permissions, your bio, your social handles and the notes on a booking, is optional; declining costs you the related feature and nothing more.

Automated decisions. We do not make decisions about you solely by automated means, and we do not profile you. Automated rules do exist for safety — rate limits, a keyword filter over captions, comments and messages, and the allergy-wording flag described in Section 09A — but they surface things for a person to look at; they do not decide anything about you on their own.

Where your information goes. Our infrastructure providers (Google, Stripe, Apple, Twilio SendGrid) are based in the United States, and your information is processed there. For transfers out of the EEA, the UK or Switzerland we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies), which are part of our agreements with each of those providers.

If you are in California or another US state with a privacy law

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so. You may request access to, correction of, or deletion of your personal information, and you may ask what we have disclosed and to whom. We will not discriminate against you for exercising any of these rights.

The categories we collect, our purposes and the recipients are set out in Sections 01 and 07. Where we get each category is set out at the end of Section 01 — note that we receive information about you from Providers and from our payment providers, not only from you. How long we keep each category is set out in Section 14.

Sensitive personal information. Some of what we collect is treated as sensitive under California and other state laws — your date of birth, your precise device location, and any health information a Provider's form or your booking notes contain. We use and disclose these only for the purposes state law permits without a right to limit: performing the service you asked for, security and abuse prevention, and keeping our systems working. We do not use them to infer characteristics about you, we do not sell or share them, and we do not use them for advertising. Because we do not use sensitive personal information for any other purpose, we do not offer a "Limit the Use of My Sensitive Personal Information" control — there is nothing for it to switch off. If that ever changes, this Policy changes with it and we will publish the control.

Washington and Nevada residents: consumer health data is covered separately — see Section 09A and the Consumer Health Data Privacy Policy.

How to make a request

Email support@slayd.ai from the address on your account. We may need to confirm it is you before we act. You may use an authorised agent. Note that where a Provider entered information about you, the Provider controls that record and we will direct you to them.

16Abuse Prevention

To stop automated sign-ups, spam bookings and form abuse, we count requests against the sender. Your IP address is read for this purpose and is not stored in readable form — we store a cryptographic hash of it together with a count and a timestamp, and the record expires after two hours. We do not use it for any purpose other than abuse prevention, and it is not linked to your account.

We describe that hash as pseudonymised rather than anonymous, and we would rather be precise than flattering: a hash of something drawn from a small, known set of possible values is not beyond reversing, so we treat these records as personal data and protect them accordingly. Separately, your IP address reaches Google with every request you make to our servers, and reaches Stripe and Google on every page load of slayd.ai — see Sections 07 and 13.

The iOS app also uses Apple's App Attest so our servers can confirm a request came from a genuine, unmodified copy of the Slayd app. This produces a device attestation seen by Apple and Google; it does not identify you.

17Security and Internal Access

We use reasonable technical and organisational measures to protect your information: data is held in Google Cloud with per-record access rules, payment credentials never touch our systems, and secrets are held in a managed secret store. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Inside Slayd, an administrator console can look up an account and see the name, username, email address, phone number, date of birth, role, bio, city, ZIP, social handles, whether the account is banned or restricted, whether the email is verified, and the last sign-in, activity and booking times. This is used for support and safety work. Administrators can also ban, restrict or delete an account. Administrator access requires a separate privileged credential.

If you report content or a person, the report is anonymous to the person you reported — they are not told who reported them. It is not anonymous to us: your account ID is stored with the report so we can follow up and detect abuse of the reporting system.

18Children's Privacy

Slayd is not intended for anyone under 17. We ask for your date of birth when you sign up and we do not create accounts for people who tell us they are under 17. We do not knowingly collect information from children under 17. If you believe a child has provided us information, email support@slayd.ai and we will remove it.

19Changes to This Policy

We may update this Policy from time to time. We will revise the "Last updated" date and, where the change is significant, notify you in-app or by email. Continued use after changes take effect means you accept the updated Policy.

20Contact

Questions about your privacy, or a request under Section 15? Email support@slayd.ai.

The controller of the personal data described in this Policy is Slayd LLC, at 27101 N Dixboro Rd, South Lyon, MI 48178.