1. What We Collect
We collect only what we need to run the Service.
- Account data. Name, email address, sign-in credentials (passwords are stored hashed, never in plain text), and workspace role for people who sign in to a business account.
- Business data. The information spas and salons (“Merchants”) enter to run their business: services and prices, staff and schedules, rooms, gift cards, client records, settings, and website content.
- Guest booking data. When a guest books with a Merchant: name, email address, phone number, appointment details (service, date and time, staff member, and any notes), and intake responses where the Merchant uses intake forms.
- Usage data. Technical logs such as IP address, browser and device information, and actions taken in the product - used for security, debugging, and improving the Service.
- AI feature data.If you use Kelsie Copilot or a Merchant's booking concierge, we process the prompts and recent messages you submit, the tenant-scoped business information needed to answer, tool results, approval decisions, action results, and token or usage totals. Do not enter medical histories, payment-card data, passwords, government identifiers, or other information that is not needed for the request.
We do not collect or store full payment-card numbers. Payments are handled by third-party payment processors, and card details go directly to them.
2. How We Use Information
- To provide and operate the Service - calendars, bookings, client records, gift cards, staff schedules, and reports.
- To send transactional email, such as booking confirmations, appointment reminders, receipts, and account notices.
- To respond to support requests and help resolve problems.
- To keep the Service secure - detecting abuse, preventing fraud, and investigating incidents.
- To understand how the product is used, in aggregate, so we can improve it.
- To provide AI-assisted answers, booking guidance, analysis, and approval-gated business actions requested by an authorized user.
We do not sell personal information, and we do not use it for third-party advertising.
3. Merchants and Guests: Who Is Responsible
For guest booking data, the Merchant is in charge of the relationship: the spa you book with decides what information to collect and how it is used, and acts as the data controller. Kelsie processes that information on the Merchant’s behalf - to run the calendar, send confirmations and reminders, and maintain the Merchant’s client records.
For Merchants’ own account information and for platform usage data, we act as the controller.
If you are a guest with questions about how a particular spa handles your information, contact that spa directly. We support Merchants in responding to those requests.
4. When We Share Information
We share personal information only with service providers that help us run the platform, and only so they can provide their service to us:
- Hosting and database infrastructure that stores and serves the Service’s data.
- Email delivery providers that send transactional messages such as confirmations and reminders.
- Payment processors (for example, HandyPay or Stripe) that handle payments between guests and Merchants. Payment details are provided directly to the processor.
- AI service providers that generate responses and tool calls for AI-assisted features. We currently use the OpenAI API and request that response application state is not stored by setting
store: false. OpenAI states that API data is not used to train its models unless the customer opts in, and that abuse-monitoring logs may retain content for up to 30 days by default. See OpenAI's current API data controls.
These providers are bound by contract to protect personal information and to use it only on our instructions. We may also disclose information where the law requires it, to protect the rights or safety of users or the platform, or as part of a business transfer - in which case this policy continues to apply and we will give notice of any material change. We never sell personal data.
5. Cookies and Sessions
We use cookies to keep you signed in and to keep sessions secure - for example, an authentication cookie after you sign in, and protections against request forgery. These are essential cookies: the Service does not work without them.
We do not use third-party advertising cookies or cross-site tracking. If you block essential cookies in your browser, you will not be able to sign in.
6. Data Retention
- Account and business data is kept for as long as the account is active.
- Guest booking records are kept while the Merchant’s account is active - they are the Merchant’s business records, and clients’ booking history is part of how a spa serves returning guests.
- After an account closes, we delete or de-identify its data within 90 days, except where the law requires us to keep specific records longer, or where residual copies persist briefly in encrypted backups before being cycled out.
- We may keep aggregated, de-identified data that no longer relates to any person or business.
- We do not currently keep Copilot conversation transcripts as a separate business record after the active browser conversation. Usage totals and the audit record for requested, approved, denied, completed, or failed AI actions may be retained for security, billing controls, accountability, and support.
7. Security
- All connections to the Service are encrypted in transit (TLS).
- Passwords are hashed; we never store them in plain text.
- Access controls and role-based permissions limit what each user can see and do inside a workspace.
- Tenant isolation keeps each Merchant’s data scoped to that Merchant - one business cannot read another’s records.
- Internal access follows least privilege and is logged and monitored.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as required by applicable law.
8. International Data Transfers
Some providers that support the Service may process information outside Jamaica. Where personal information is transferred across borders, we use contractual, technical, and organizational safeguards designed to protect it and review the destination and provider in light of applicable data-protection requirements.
9. Your Rights
Depending on the circumstances and applicable law, you may have the right to be informed about processing; access personal information; correct inaccurate information; request deletion or restriction; withdraw consent where processing relies on consent; object to certain processing; and object to a decision based solely on automated processing where it has a legal or similarly significant effect.
- Merchants can view and edit most of their information directly in the dashboard. For anything else, contact us at support@usekelsie.com.
- Guests should start with the spa they booked with, since it controls their booking data. You can also contact us and we will route the request to the Merchant and assist with it.
We honor the rights granted by applicable data-protection law, including the Data Protection Act, 2020 (Jamaica) where it applies, and we respond to requests within a reasonable time - normally within 30 days. You may also raise a concern with Jamaica's Office of the Information Commissioner.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us at support@usekelsie.com and we will delete it.
11. Changes to This Policy
We may update this policy from time to time. If a change is material, we will give notice before it takes effect - for example, by email or by a notice in the dashboard. The “Last updated” date above reflects the current version.
12. Contact
Questions or requests about privacy can be sent to support@usekelsie.com. We read everything and aim to respond quickly.