Privacy
Last updated 29 August 2026
ChairOps operates ChairOps from Calgary, AB.
We are the organization for ChairOps accounts (your login, billing, support tickets). Each shop is the organization for its own client files. Under PIPEDA and Alberta PIPA, the shop is usually the one accountable to its clients. That split belongs in the order form.
Each sign-in owns its own desk. Client files, staff, calendars, and booking-system keys are scoped to that account. Notes, call transcripts, and API keys are encrypted at rest (AES-256-GCM). Opening or changing a client file writes an audit event. We do not sell caller data.
We collect: account identity (email), business profile, client names/phones/emails you enter or that public booking collects, appointments, support tickets, CASL consent ticks, and payment metadata if a processor is later connected in writing (not full card numbers).
Website scan and summaries use the xAI API. We do not send private client notes into those prompts. Keep client files to scheduling: names, phones, services, times.
Hosting runs on Vercel. Model calls go to xAI. Both are outside Canada. Do not treat personal information as stored in Canada.
CASL: we only send commercial email or SMS where you or the end client ticked consent, or where the message is a follow-up they requested (booking confirmation). You can withdraw consent by emailing the privacy contact when one is published.
Access, correction, and deletion: signed-in shops can export their desk from Security. Email the privacy contact for anything the export misses, when a contact is published. We keep billing records as tax law requires (generally six years in Canada).
Sample shops used to demonstrate ChairOps are fictional. They are not real clients or businesses and should not be treated as personal information.
This page is product documentation, not legal advice. Alberta counsel should review it before you rely on it with paying shops.