This Privacy Policy explains what information Slayd LLC ("Slayd," "we") collects through the Slayd iOS app and the Slayd website at slayd.ai, how we use it, who receives it, and the choices you have. It also covers people who book and pay on slayd.ai without signing up, and people whose details a beauty or fitness professional enters into Slayd. By using Slayd, you agree to this Policy.
Throughout this Policy, Provider means a beauty or fitness professional, studio, or salon that offers services through Slayd, and Client means someone who books them.
01Information We Collect
| Category | What that means |
|---|---|
| Account & profile | Name, username, email address, date of birth, bio, profile photo, account role, the city and ZIP code you type during sign-up, your interests, and Instagram / TikTok handles if you add them. |
| Phone number | If you verify a phone number at sign-up, the number and the time it was verified are stored on your account. On the website and at guest checkout we store the number you typed without verifying it. We also keep a private internal record linking a phone number to the accounts that claimed it, so one number cannot be used to open unlimited accounts. |
| Provider & business details | Business name, business phone and email, exact street address and exact map coordinates, services, prices, hours, deposit and cancellation settings, and your team roster. See Section 08 — most of this is public. |
| Content you create | Photos and videos you capture or upload, post captions, comments, reviews and star ratings, and your profile bio. Reviews carry your display name. |
| Messages | Direct messages between you and another account, including any photos you attach. |
| Social connections & activity | Who you follow and who follows you, follow requests you send or receive, accounts you have blocked, posts and reveals you liked, shared or saved, the posts and reveals in your saved collections, and your in-app notification history. |
| Bookings & purchases | Appointments and classes, the service, price, date and time, notes you write for your Provider, notes your Provider writes about the appointment, deposits, prepaid packages, class passes and memberships. |
| Payment information | Handled by Stripe. We receive amounts, status and identifiers — never your full card number. For Providers, we store the last four digits of the bank account Stripe pays out to. |
| Subscription records | For Providers: subscription status, renewal dates and the transaction identifiers Apple or Stripe gives us. |
| Location | The city and ZIP you type. Separately, with your permission, your device's precise location — used on your device only. See Section 05. |
| Contacts | With your permission, we read names and phone numbers from your address book on your device to suggest people to invite. We do not upload them. See Section 03. |
| Calendar | With your permission, we add your booked appointments to your device calendar. We write events; we do not read your existing ones. |
| Device & push identifiers | Your device's vendor identifier, your push notification token, and the platform ("ios"), stored against your account so we can notify the right device. |
| Crash & error diagnostics | Crash reports and handled-error records sent to Firebase Crashlytics. See Section 12. |
| Usage timestamps | Two timestamps on your account: when you were last active (updated at most once an hour) and when you last booked. We do not run an analytics SDK — see Section 12. |
| Forms & signatures | Answers to intake, consent and policy forms a Provider sends you, the name you type as a signature, and the fact and time you agreed. A Provider can build a form that asks for health information such as allergies or a date of birth. |
| Reports & support | If you report content or a person: your account ID, what you reported, the reason and your written description. If you contact us: your name, email, business name and message. |
| Waitlist & applications | Consumer waitlist: email address only. Business early-access application: business name, contact name, email, phone, street address, city, state, ZIP, services, team size, booking system, Instagram, website and notes. |
| IP address | Read to rate-limit sign-ups, bookings and forms. Not stored in readable form — see Section 16. |
| Provider business records | If you are a Provider: the book of business you keep in Slayd — your client list, invoices, receipts, expenses, refunds, retail inventory, payroll entries, booth-renter records, rent payments, open slots, daily deals and personal tasks. These are backed up to our servers. See Section 09. |
Where we get your information
Most of what we hold, you gave us. Not all of it:
- From you — what you type when you sign up, build a profile or storefront, book, pay, post, message, or fill in a form.
- From your device, with your permission — camera, microphone, photo library, location, contacts and calendar, as described in Sections 02, 03 and 05.
- From a Provider — a beauty or fitness professional can add you to their client list, or bulk-import a client list from another booking system, whether or not you have ever used Slayd. See Section 09.
- From a business you work for — if you are a staff member, contractor or booth renter, your employer or host may enter your details, pay and rent records.
- From our payment and platform providers — Stripe tells us the status of a payment or payout and the last four digits of a payout account; Apple tells us the status of a subscription bought on iPhone; Google tells us that a phone number verified.
- From other Slayd users — someone can name you in a review, a comment, a message or a safety report.
Some things stay on your phone. Your beauty journal entries, saved looks and recent searches are stored on your device and are not uploaded to us. If a Provider enters a tax identifier (EIN or SSN) in the Tax Center, it is stored in the iOS Keychain on that device and is never transmitted to us — see Section 10.
02Permissions We Request
- Camera — capture photos and videos for posts.
- Microphone — record audio with the videos you capture.
- Photo Library — choose photos and videos to post.
- Photo Library (add) — save content back to your library when you download it.
- Location (while using the app) — sort Providers by distance from you.
- Contacts — suggest friends to invite.
- Calendar (full access) — add your booked appointments to your calendar.
- Face ID — confirm it is you before switching to a saved account. Face ID data never leaves your device and is never seen by us; iOS only tells the app pass or fail.
- Notifications — send booking and account updates.
You can grant or revoke any of these in your device Settings at any time. Declining a permission disables the related feature; it does not block the rest of the app.
03Contacts, In Detail
There are two places Slayd touches your address book, and they behave differently.
- Find friends. If you allow Contacts access, the app reads first name, last name and the first phone number for up to 200 contacts, to show you a list of people to invite. That list is held in memory on your device. We do not upload your contacts, and we do not build a social graph from them.
- Invite by message. Elsewhere, the app opens Apple's own contact picker. That picker runs outside the app, needs no permission, and hands back only the people you tap. The invite is then sent from your phone, as a message from you. Slayd does not send it and never sees the recipient.
04Booking Without an Account
Before you pay, we store the name, email address, phone number and any notes you entered, along with the Provider, service, price and time slot, in a record only our servers can read. That record is written when you fill in the form — not when you pay — so it exists even if you close the tab. Your email address is also passed to Stripe so Stripe can send the receipt.
Guest checkout always charges the full price up front. If the time slot is taken while you are paying, the charge is refunded in full and no appointment is created.
05Location, In Detail
We use location two different ways, and only one of them involves our servers.
Your location as a Client
When you allow location access, the app requests your device's precise location — not a coarse or city-level fix — and, if iOS has restricted the app to approximate location, it may ask you to allow full accuracy once. We use that fix to sort Providers by distance and to fill in an address field, and we convert it to a street, city and ZIP using Apple's geocoding service, which means Apple receives those coordinates.
Your device location is not sent to Slayd's servers and we do not store it. It stays on your phone. The city and ZIP saved on your profile are the ones you typed at sign-up, not ones taken from your device.
When you type an address anywhere in the app, the characters you type are sent to Apple to generate autocomplete suggestions.
A Provider's business location
A Provider's business address and coordinates are a different matter entirely, because they are published. See Section 08.
06How We Use Information
- To create and run your account and provide the app's features.
- To take bookings, hold deposits, and connect Clients with Providers.
- To process payments and Provider payouts through Stripe and Apple.
- To show you Providers near you and to power search and discovery.
- To send booking confirmations, reminders and account notifications.
- To keep Slayd safe: rate-limiting, abuse prevention, reviewing reports, and a keyword filter that runs over post captions, comments and messages when they are created.
- To fix crashes and errors.
- To meet legal, tax and accounting obligations.
We do not use your information to build advertising profiles, and we do not sell it.
Aggregated and de-identified data
We may produce aggregate statistics that describe the platform as a whole — how many bookings happened in a category, typical prices in a region — and use or publish them. Figures like those are not personal information: they do not identify you and cannot reasonably be linked back to you. Where we hold information in de-identified form we keep it that way: we do not attempt to re-identify it, and we require the same of anyone we give it to. None of this is a licence to sell your personal information, and we do not sell it.
07Who Receives What
The table below maps each category of information to why we handle it and who else sees it. "The public" means anyone on the internet, including people with no Slayd account.
| Category | Purpose | Recipients |
|---|---|---|
| Account & profile | Run your account; sign-in; age gate | Google (Firebase Auth, Firestore). Your name, username, photo, bio and role: the public — see Section 08 |
| Phone number | Verify sign-up; let a Provider reach you; limit duplicate accounts | Google (Firebase Auth sends the verification SMS; Firestore stores it). Your Provider, for appointments you book |
| Provider & business details | Public storefront; booking; payouts | The public. Stripe, for payout onboarding |
| Posts, comments, reviews | Show your content in the app | Any signed-in Slayd user. Google (Firestore, Storage) |
| Direct messages | Deliver your messages | The other participant. Google (Firestore, Storage). A preview appears in the push notification — see Section 11 |
| Bookings & purchases | Deliver the appointment; refunds; records | Your Provider and, for team bookings, the business they work for. Stripe. Twilio SendGrid, for confirmation email |
| Payment information | Take payment; pay Providers | Stripe. Apple, for in-app subscription purchases. Google (Firestore, for amounts and status) |
| Device location (Client) | Sort Providers by distance; fill an address field | Apple (geocoding and address autocomplete). Not sent to Slayd |
| Contacts | Suggest people to invite | Nobody. Read on your device, not uploaded |
| Calendar | Put appointments in your calendar | Nobody. Written to your device |
| Device & push identifiers | Deliver notifications to the right device | Google (Firebase Cloud Messaging). Apple (APNs) |
| Device attestation | Confirm requests come from the real Slayd app | Apple (App Attest). Google (Firebase App Check) |
| Crash & error diagnostics | Find and fix defects | Google (Firebase Crashlytics) |
| Usage timestamps | Show whether an account is active; internal support | Google (Firestore). Slayd staff — see Section 17 |
| Forms & signatures | Consent and intake records for your appointment | The Provider who sent the form. Google (Firestore, Storage) |
| Reports & support | Review safety reports; answer you | Slayd staff only. Google (Firestore) |
| Waitlist & applications | Tell you when we launch near you; assess business applications | Slayd staff only. Google (Firestore) |
| IP address | Rate limiting and abuse prevention | Google — Cloud Functions and Hosting receive it with every request. On slayd.ai your browser also sends it to Stripe and to Google Fonts on every page load — see Section 13. We keep only a hash — see Section 16 |
| Social connections & activity | Build your feed and follower list; deliver in-app notifications; enforce blocks | Other Slayd users, where the action is visible to them — a follow, a like, a share or a comment carries your name. Your blocks, your saves and your saved collections are private to you. Google (Firestore) |
| Client records entered by a Provider | Provider's own book of business | That Provider and their team. Google (Firestore) — see Section 09 |
| Provider business records | Back the Provider's book up so a lost or reinstalled phone does not destroy the salon's history | That Provider. Google (Firestore) — see Section 09 |
Our service providers
- Google — Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, App Check and Crashlytics. Google hosts essentially all of Slayd's data and sends the phone-verification SMS.
- Stripe — card payments, Apple Pay, Provider payouts through Stripe Connect, and subscription billing on the card route. We give Stripe your name and email address when we create a customer record for you, and a Provider's email address when they onboard for payouts.
- Apple — the App Store and in-app subscription purchases, push notification delivery, App Attest device checks, and the geocoding and address-autocomplete services described in Section 05.
- Twilio SendGrid — transactional email such as booking confirmations and receipts, carrying your email address, name, the Provider and salon name, the service, the date and time, and any attached document.
We also disclose information for legal reasons — to comply with law or to protect the rights, safety and security of Slayd and its users — and in connection with a merger, acquisition or sale of assets, subject to this Policy.
We do not use analytics, advertising or attribution services. See Section 12.
08What Is Public
Some of Slayd is deliberately open so people can find a Provider without signing up. Please read this section before you decide what to put on your profile.
- Every profile is publicly readable. Your user ID, display name, username, profile photo, bio and account role can be retrieved by anyone on the internet who knows your username or user ID, with no Slayd account. This applies to Client accounts as well as Providers. Browsing the full member directory does require signing in.
- Provider storefronts are fully public. Anyone can read the whole Provider directory without an account, including business name, description, photos, services and prices, ratings and reviews.
- Reviews carry your display name and are visible to anyone signed in. You cannot delete a review once you have left it; contact us if one needs to come down.
- Posts and comments are visible to every signed-in Slayd account — not only to your followers.
- The "private account" setting does not currently restrict who can read your posts. It changes how the app presents your profile, but the underlying data is readable as described above. We are stating this plainly rather than letting the label imply more than it does.
- Photos and videos are served over long, unguessable links stored alongside the post. Anyone who obtains such a link may be able to open the file directly. Treat anything you upload as shareable.
- Photo metadata. Still photos are rewritten before upload to remove embedded location and camera metadata, including any GPS tag. This applies to posts, profile photos, message photos, booking reference photos and business storefront photos alike. Videos are uploaded as-is, so any metadata already inside a video file you picked from your library is preserved — if a video was recorded at home with location tagging on, assume it still says so.
09Information Providers Enter About Other People
Providers keep a book of business in Slayd. That includes people who have never used Slayd — walk-ins, existing clients, and staff.
- Client records. A Provider's client list is stored on our servers and includes each client's name, phone number, email address, visit count, no-show and cancellation counts, lifetime spend, last visit, whether they are blocked from booking, and free-text notes — including notes only that Provider can see. Before-and-after photo galleries stay on the Provider's device and are not uploaded.
- Imports. Providers can bulk-import a client list from another booking system.
- Team records. Staff and contractor records include name, role, email, phone, home address, pay arrangement and permissions.
- Business records. Invoices, receipts, expenses, refunds, retail inventory, payroll entries, booth-renter records, rent payments, open slots, daily deals and personal tasks that a Provider keeps in Slayd are backed up to our servers, so a lost or reinstalled phone does not destroy the salon's history. Two of these hold other people's details: payroll entries carry a staff member's name and pay, and booth-renter records carry a renter's name, an email address or phone number, and the rent they paid. Each of these collections is readable and writable only by the Provider whose book it is.
- Forms. Intake, consent and policy forms are authored by the Provider. A Provider can create fields that ask for health information such as allergies, medical history or a date of birth. Answers, the typed signature name and the time of signing are stored, and are locked once signed.
For this information, the Provider decides what to collect and why, and Slayd handles it on the Provider's behalf to deliver Provider tools. The Provider is responsible for having the right to use it and for handling it lawfully.
If you are on a Provider's client list and want your details corrected or removed, ask that Provider first — they control the record. You may also email us and we will act on what we hold.
If you have never used Slayd
You may be reading this because a Provider added you to their book, imported you from another booking system, recorded you as a staff member or a booth renter, or because you booked and paid on slayd.ai without signing up. In that case we did not get your details from you, and you are entitled to know the same things anyone else is. The categories we hold about you are in Section 01; why we hold them and who else sees them is in Section 07; how long is in Section 14; your rights, and how to exercise them, are in Section 15. The Provider who entered your details decided what to collect and why; we hold it to run their tools. Email support@slayd.ai and we will tell you what we hold about you and, where the record is ours to change, act on it — or point you to the Provider where it is theirs.
09AConsumer Health Data
Slayd is a beauty and fitness product, and some of what passes through it is health information even though we never set out to collect any. Washington's My Health My Data Act and Nevada's SB 370 treat that kind of information specially, so it gets its own section and its own document.
In short, health information can reach Slayd three ways:
- A Provider's intake or consent form. Providers write their own forms and we do not restrict the questions, so a form can ask about allergies, medical history, medication, pregnancy or a date of birth. Your answers go to that Provider.
- The notes on a booking. The notes box asks you for exactly this — the placeholder text on both the app and the website suggests allergies — and what you write goes to the Provider you booked.
- A Provider's own notes about you, kept in their client record.
We do not sell health information, we do not use it for advertising, and we do not use it to infer anything about you for our own purposes. One thing you should know rather than discover: the Provider tools scan a client's notes for allergy and sensitivity wording and surface the matching sentences as a safety flag on that client's profile, so the Provider does not miss it. That happens inside the Provider's own book of business and is visible to them, not to other users.
If you would rather no health information reached us at all: leave the booking notes blank, and tell your Provider in person instead of on a form. If some has already been recorded, email support@slayd.ai and we will delete what is ours to delete and tell you what belongs to the Provider.
10Payments
Payments are processed by Stripe. Card details are entered inside Stripe's own payment sheet. Slayd never receives or stores your full card number. We receive the amount, the status, and identifiers that let us match a payment to a booking. Your payment information is also handled under Stripe's own privacy policy.
Provider subscriptions purchased on iPhone are billed by Apple. We store the subscription identifiers and status Apple sends us so we know your subscription is active.
Providers
- Payouts run through Stripe Connect. Stripe collects your identity and bank details directly in its own hosted flow — we never see or store your bank credentials. We do store the last four digits of the account a payout landed in, so you can recognise it in your records.
- Tax identifiers stay on your device. An EIN or SSN, legal business name and filing address entered in the Tax Center are stored in the iOS Keychain on that iPhone and are never transmitted to Slayd's servers. If you delete the app or lose the device, they are gone.
11Notifications and Device Identifiers
To deliver push notifications we store your device's vendor identifier, your notification token and the platform against your account. The vendor identifier is assigned by iOS, is shared only with other apps from the same developer, and resets when you delete all of our apps.
Two things worth knowing:
- A notification token is registered when the app launches, whether or not you allowed notification alerts. If you declined alerts you will not receive any, but the token still exists.
- Notification text contains real content. A message notification carries the sender's name and roughly the first 100 to 120 characters of the message; a comment notification carries the commenter's name and a preview of the comment; booking notifications carry appointment details. That text passes through Google and Apple to reach your lock screen.
You can turn notifications off in your device Settings at any time.
12Analytics, Tracking and Diagnostics
We do not track you across other companies' apps or websites. The app contains no advertising identifier, no App Tracking Transparency prompt, and no analytics, advertising or attribution SDK. We do not build advertising profiles and we run no third-party trackers on slayd.ai.
That is about tracking, not about record-keeping. The things you do in Slayd — the accounts you follow, the posts you like, share or save, the appointments you book — are recorded on your account, because they are the product; they are listed in Section 01 and mapped in Section 07. Beyond those account and activity records, the only diagnostic data we collect is:
- Two usage timestamps on your account — when you were last active and when you last booked. We do not log screen views, taps or a browsing history.
- Crash and error diagnostics through Firebase Crashlytics (Google). This records crashes, and certain handled failures such as a payment call that errored, together with the device and app version. We do not attach your Slayd account ID to these reports, and we do not deliberately put personal information in them.
- Server logs for the sign-up, waitlist and contact endpoints deliberately record only the domain of an email address, never the address itself.
13Cookies and the Website
slayd.ai does not use advertising or analytics cookies, and does not run a consent banner because there is nothing to consent to on that front. Two things do happen on every page load, before you interact with anything, and you should know about them:
- The page loads fonts from Google and the Firebase software library from Google. Google therefore receives your IP address and browser user-agent.
- The page loads Stripe's payment library on every visit, including visits where you never pay. Stripe receives a request from your browser and uses it for fraud prevention.
Signing in creates a session in your browser's local storage so you stay signed in. If you start a guest booking, your name, email and phone are kept temporarily in your browser's session storage so the booking survives a bank verification redirect; closing the tab clears it. Simply browsing slayd.ai does not create a Slayd account or assign you an account identifier.
14Data Retention and Deletion
We keep your information while your account is active and as needed to run the service, comply with legal and tax obligations, resolve disputes and enforce our agreements.
How long we keep each category
Where a period is not fixed, the criterion we apply is stated instead. Some of these say "indefinitely" — that is the truth about the system today, not an aspiration, and where we intend to change it we say so.
| Category | How long |
|---|---|
| Account & profile, phone number, Provider & business details | While your account exists. Removed when you delete your account. |
| Posts, comments, reviews, and their photos and videos | Until you delete them, or until you delete your account. |
| Social connections & activity | Until you undo the action (unfollow, unlike, unsave) or delete your account. Notifications you caused in other people's inboxes are removed with your account. |
| Direct messages | Indefinitely. Messages cannot be deleted by either party and survive account deletion — see below. |
| Bookings & purchases | Indefinitely. An appointment has two sides; deleting your account does not remove it from the other party's history. |
| Payment, payout and subscription records | For as long as tax, accounting, audit and chargeback-defence obligations require, which is several years and longer than your account. |
| Forms & signatures | While the Provider's record of you exists. A form is locked once signed, and your signed forms are deleted when you delete your account. |
| Provider business records and client records | While the Provider's account exists. They belong to that Provider's book of business, so deleting your account does not remove their record of you. |
| Guest checkouts that were never paid | Indefinitely, today. The record is written when you fill in the form, not when you pay, and nothing currently deletes an abandoned one. If you started a guest checkout and walked away, email us and we will delete it. We intend to put an automatic limit on this. |
| Crash & error diagnostics | Held by Firebase Crashlytics under Google's own retention schedule, which we do not control. No Slayd account ID is attached to them. |
| IP address (abuse prevention) | Two hours, as a hash — see Section 16. |
| Device & push identifiers | While your account exists, or until the token is replaced. |
| Reports & support correspondence | Kept after your account is deleted, so a pattern of abuse cannot be erased by deleting an account. |
| Waitlist & business applications | Until we launch in your area and tell you, or until you ask us to remove you. |
Deleting your account
You can delete your account yourself — in the app under Settings, or on the website from your account page. Deletion runs on our servers shortly afterwards and removes:
- your posts and their photos and videos, likes, comments and shares;
- every comment and like you left anywhere;
- notifications you caused in other people's inboxes;
- your follows, in both directions;
- reviews you wrote;
- your username and business name reservations;
- your signed forms;
- your public profile and your uploaded files;
- and, if you are a Provider, your storefront together with your client list, invoices, receipts, expenses and payroll records.
Deleting also cancels your Slayd subscriptions and team seats. If a Provider deletes their account, we automatically refund clients for unused prepaid package credits and notify them.
What deletion does not remove
We would rather tell you this than let you discover it:
- Appointment records. Bookings you were part of stay in the other party's history, including the names, the service, the price and the time. An appointment involves two people and neither can erase it from the other's records.
- Direct messages. Conversations and the messages inside them are retained, including messages you sent. Messages cannot be deleted, by you or by the recipient.
- Payment and transaction records, which we keep for accounting, tax and dispute-resolution purposes.
- Safety reports you filed, including your account ID and what you wrote.
- A Provider's own record of you. If a Provider added you to their client list, that record — name, phone, email and their notes — belongs to their book of business and is not removed when you delete your Slayd account. Ask the Provider directly.
- Packages and passes you sold, if you are a Provider, because they are the buyer's proof of purchase.
Deletion runs step by step and a step can fail. If you need confirmation that a specific piece of information is gone, email us and we will check rather than assume.
If you delete a single post, that post's photos and videos, comments and likes are removed too.
Guest bookings that were started but never paid for are currently retained. If you began a guest checkout and abandoned it and want those details removed, email us.
15Your Rights & Choices
- Access & update — view and edit your profile in the app or on the website.
- Delete your account — in the app under Settings, or on the website from your account page. See Section 14 for exactly what that removes.
- Get a copy of your data — automated export is not built yet. Email support@slayd.ai from the address on your account and we will assemble it for you.
- Permissions — control camera, microphone, photos, location, contacts, calendar, Face ID and notifications in your device Settings.
- Marketing — every marketing email has an unsubscribe link. Booking confirmations and receipts are transactional and are not marketing.
If you are in the EU, UK or Switzerland
You have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to complain to your local supervisory authority. Where we rely on consent — device location, contacts, calendar and notifications — you can withdraw it in your device Settings at any time, without affecting processing already carried out.
We rely on these legal bases: performance of a contract for your account, bookings and payments; consent for the device permissions above; legitimate interests for security, abuse prevention and fixing defects; and legal obligation for tax and accounting records.
Health information. Where a Provider's intake form, or the notes you write for an appointment, contain information about your health, we handle it on the basis of your explicit consent, given when you choose to write it or to sign that form. You can decline: leave the notes blank, and tell your Provider in person rather than on a form. Section 09A and the Consumer Health Data Privacy Policy explain this in full.
Whether you have to give us this. The account and booking details we ask for are needed to enter into and perform our agreement with you — without them we cannot create an account or take a booking. Everything else, including device permissions, your bio, your social handles and the notes on a booking, is optional; declining costs you the related feature and nothing more.
Automated decisions. We do not make decisions about you solely by automated means, and we do not profile you. Automated rules do exist for safety — rate limits, a keyword filter over captions, comments and messages, and the allergy-wording flag described in Section 09A — but they surface things for a person to look at; they do not decide anything about you on their own.
Where your information goes. Our infrastructure providers (Google, Stripe, Apple, Twilio SendGrid) are based in the United States, and your information is processed there. For transfers out of the EEA, the UK or Switzerland we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies), which are part of our agreements with each of those providers.
If you are in California or another US state with a privacy law
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so. You may request access to, correction of, or deletion of your personal information, and you may ask what we have disclosed and to whom. We will not discriminate against you for exercising any of these rights.
The categories we collect, our purposes and the recipients are set out in Sections 01 and 07. Where we get each category is set out at the end of Section 01 — note that we receive information about you from Providers and from our payment providers, not only from you. How long we keep each category is set out in Section 14.
Sensitive personal information. Some of what we collect is treated as sensitive under California and other state laws — your date of birth, your precise device location, and any health information a Provider's form or your booking notes contain. We use and disclose these only for the purposes state law permits without a right to limit: performing the service you asked for, security and abuse prevention, and keeping our systems working. We do not use them to infer characteristics about you, we do not sell or share them, and we do not use them for advertising. Because we do not use sensitive personal information for any other purpose, we do not offer a "Limit the Use of My Sensitive Personal Information" control — there is nothing for it to switch off. If that ever changes, this Policy changes with it and we will publish the control.
Washington and Nevada residents: consumer health data is covered separately — see Section 09A and the Consumer Health Data Privacy Policy.
How to make a request
Email support@slayd.ai from the address on your account. We may need to confirm it is you before we act. You may use an authorised agent. Note that where a Provider entered information about you, the Provider controls that record and we will direct you to them.
16Abuse Prevention
To stop automated sign-ups, spam bookings and form abuse, we count requests against the sender. Your IP address is read for this purpose and is not stored in readable form — we store a cryptographic hash of it together with a count and a timestamp, and the record expires after two hours. We do not use it for any purpose other than abuse prevention, and it is not linked to your account.
We describe that hash as pseudonymised rather than anonymous, and we would rather be precise than flattering: a hash of something drawn from a small, known set of possible values is not beyond reversing, so we treat these records as personal data and protect them accordingly. Separately, your IP address reaches Google with every request you make to our servers, and reaches Stripe and Google on every page load of slayd.ai — see Sections 07 and 13.
The iOS app also uses Apple's App Attest so our servers can confirm a request came from a genuine, unmodified copy of the Slayd app. This produces a device attestation seen by Apple and Google; it does not identify you.
17Security and Internal Access
We use reasonable technical and organisational measures to protect your information: data is held in Google Cloud with per-record access rules, payment credentials never touch our systems, and secrets are held in a managed secret store. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Inside Slayd, an administrator console can look up an account and see the name, username, email address, phone number, date of birth, role, bio, city, ZIP, social handles, whether the account is banned or restricted, whether the email is verified, and the last sign-in, activity and booking times. This is used for support and safety work. Administrators can also ban, restrict or delete an account. Administrator access requires a separate privileged credential.
If you report content or a person, the report is anonymous to the person you reported — they are not told who reported them. It is not anonymous to us: your account ID is stored with the report so we can follow up and detect abuse of the reporting system.
18Children's Privacy
Slayd is not intended for anyone under 17. We ask for your date of birth when you sign up and we do not create accounts for people who tell us they are under 17. We do not knowingly collect information from children under 17. If you believe a child has provided us information, email support@slayd.ai and we will remove it.
19Changes to This Policy
We may update this Policy from time to time. We will revise the "Last updated" date and, where the change is significant, notify you in-app or by email. Continued use after changes take effect means you accept the updated Policy.
20Contact
Questions about your privacy, or a request under Section 15? Email support@slayd.ai.
The controller of the personal data described in this Policy is Slayd LLC, at 27101 N Dixboro Rd, South Lyon, MI 48178.