Privacy Policy

Last updated: July 12, 2026

1. Who we are and how this policy works

Tansify ("Tansify", "we", "us") is a booking and business-management platform for local service businesses such as salons, barbershops, spas, clinics, and studios. The platform is operated by Tansify Inc., 106 Twin Pines Cres, Brampton, Ontario, Canada. This policy explains what information we handle, why, and the choices you have.

Two kinds of people use Tansify, and our role differs for each:

  • Merchants — the businesses that sign up to run their operations. For your account and your use of the platform, we are the "controller" of your information.
  • Clients of those merchants — the people who book appointments. When a merchant stores its clients' details, notes, intake responses, and booking history in Tansify, the merchant is the controller of that information and we act as its "processor" (service provider), handling it only on the merchant's instructions. If you are a client, please contact the business you booked with about your data; this policy still describes how we safeguard it.

2. Information we collect

Account and profile: your name, email address, phone number, a hashed password, business details (name, location, hours, services, team), and any avatar or portfolio images you upload.

Authentication and security: one-time email codes, optional Google or Apple sign-in identifiers, two-factor (TOTP) secrets and passkeys, session tokens, IP address, device/browser information, and a log of security-relevant events (sign-ins, 2FA changes, sign-out-all) so you can review account activity.

Business and booking data: services, providers, schedules, appointments, client records (name, contact details, notes, tags, marketing-consent status, birthday, and how they found the business), reviews, and messages sent to clients.

Intake information: where a merchant uses intake or consultation forms, the responses clients provide — which may include health-adjacent details. Intake responses are encrypted at rest.

Payments: your own subscription to Tansify is processed by Stripe. We do not receive or store full card numbers — Stripe handles card data directly — and we retain only the subscription metadata (plan, status, renewal) needed to run your account. We do not process card payments between merchants and their clients, so we hold no client payment or payout data.

Communications: appointment reminders and notifications sent by email (via Resend), SMS (via Twilio), and push, along with delivery status and your notification preferences.

Usage and technical data: log data, approximate location derived from IP, and essential cookies used to keep you signed in and secure.

3. How we use information

We use information to provide and operate the platform — creating and managing bookings, sending reminders, running the calendar, processing payments, and powering reports; to authenticate you and keep accounts secure (including fraud and abuse prevention and rate limiting); to provide support; to send service and, where you have opted in, marketing communications; to improve and develop the product; and to comply with legal obligations.

4. Legal bases for processing

Where the GDPR or similar laws apply, we rely on: performance of our contract with you (to provide the service you sign up for); your consent (for example, marketing messages and optional SMS — which you can withdraw at any time); our legitimate interests (securing and improving the platform, preventing abuse); and compliance with legal obligations. Canadian users' information is handled in accordance with PIPEDA and applicable provincial law.

5. How we share information — our processors

We share information only with service providers that help us run the platform, under contracts that require them to protect it and use it only for that purpose:

  • Stripe — subscription billing for your own Tansify plan.
  • Resend — transactional and reminder emails.
  • Twilio — SMS reminders and messages.
  • Google and Apple — optional sign-in, if you choose to use it.
  • Reserve with Google — only if a merchant enables it, to publish availability and receive bookings.
  • Our cloud hosting and infrastructure provider — to store and serve data securely.

We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users and the public. If our business is involved in a merger or acquisition, information may be transferred subject to this policy.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

6. Data retention

We keep information for as long as your account is active and as needed to provide the service. When you delete your account, we delete or de-identify the associated personal information within a reasonable period, except where we must retain certain records to meet legal, tax, accounting, or dispute-resolution obligations. Merchants control the retention of their own client and intake data within the platform and can delete it at any time.

7. Security

We protect information with encryption in transit (HTTPS) and encryption at rest for sensitive data such as intake responses and two-factor secrets; hashed passwords; strict per-account and per-business access controls; optional two-factor authentication and passkeys; and monitoring for abuse. No system is perfectly secure, but we work to safeguard your data and to notify affected users and regulators of qualifying breaches as required by law.

8. Your privacy rights and choices

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. You can update your profile and manage notification and marketing preferences in your account settings, and you can delete your account — which removes your associated data — from the app. Marketing messages include an unsubscribe option, and you can reply STOP to opt out of SMS.

To exercise a right or ask a question, contact us using the details below. If you are a client of a business that uses Tansify, direct requests about that business's records to the business; we will assist it as its processor. We will not discriminate against you for exercising your rights.

9. Health-adjacent and intake information

Some merchants (for example clinics or wellness providers) collect health-adjacent information through intake forms. Where such information is regulated health information — for example under Ontario's PHIPA — the merchant is the health-information custodian and Tansify acts as its agent/service provider, processing the information on the merchant's behalf and under its instructions. We encrypt intake responses at rest and restrict access to them. Merchants are responsible for their own obligations as custodians, including obtaining any required consents.

10. Cookies and international transfers

We use a small number of strictly necessary cookies — primarily secure, httpOnly cookies that keep you signed in. We do not use them for advertising.

We and our providers may process information in Canada, the United States, and other countries where our providers operate. Where required, we put appropriate safeguards in place for cross-border transfers.

11. Children's privacy

Tansify is intended for businesses and is not directed to children. We do not knowingly collect personal information directly from children. Merchants are responsible for any information about minors they enter on behalf of their own clients and for obtaining the necessary consents.

12. Changes to this policy

We may update this policy from time to time. If we make material changes, we will update the date above and, where appropriate, notify you. Your continued use of the platform after an update means you accept the revised policy.

13. Contact us

Questions or requests about this policy or your information: privacy@tansify.com. You can also write to us at Tansify Inc., 106 Twin Pines Cres, Brampton, Ontario, Canada.