Privacy Policy

Last Updated: July 26, 2026

Slate ("we," "us," "our," or the "Company") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your data when you interact with our services, including our website, mobile applications, booking platform, and messaging services across various communication channels.

By accessing or using our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of our services immediately.

Table of Contents

  1. Information We Collect
  2. How We Use Your Information
  3. Messaging Services & Communication Channels
  4. AI-Powered Features
  5. Third-Party Service Providers
  6. Data Sharing & Disclosure
  7. Data Retention
  8. Data Security
  9. Your Rights & Choices
  10. Cookies & Tracking Technologies
  11. Children's Privacy
  12. California Privacy Rights (CCPA/CPRA)
  13. International Data Transfers
  14. Changes to This Policy
  15. Contact Us

1. Information We Collect

1.1 Information You Provide Directly

1.2 Information Collected Automatically

1.3 Information from Third Parties

2. How We Use Your Information

3. Messaging Services & Communication Channels

3.1 Facebook Messenger

When you message us through Facebook Messenger, we receive and process your messages through Meta's Messenger Platform API. This includes your Facebook Page-Scoped ID (PSID), message content (text, images, attachments you send), and message timestamps and delivery/read status.

Human Agent Messaging: When a salon staff member takes over a Messenger conversation from our AI assistant, their replies may be sent using Meta's Human Agent message tag. This allows staff to respond to an ongoing customer service conversation outside the standard 24-hour Messenger window — for example, when a client messages late in the evening and staff respond the next business morning. The Human Agent tag is applied exclusively to messages composed and sent by a real human staff member as part of an active customer service conversation. It is never used for marketing messages, promotional content, or AI-generated replies.

We do not access your Facebook friends list, photos, or any other Facebook data beyond what you send us through Messenger. Our use of Messenger data complies with Meta's Platform Terms and Developer Policies.

3.2 Instagram Direct Messages

When you send us a Direct Message on Instagram, we process your messages through Meta's Instagram Messaging API. This includes your Instagram-Scoped ID, message content, and story reply context when applicable.

3.3 SMS (Text Messages)

SMS communications are processed through Twilio. We collect your phone number and message content. Standard messaging rates from your carrier may apply. You may opt out of SMS communications at any time by replying STOP.

3.4 Email

Email communications may be processed through SendGrid (for transactional emails) or Gmail API (for conversation-based email threads). We collect your email address, message content, and email threading metadata. You may unsubscribe from marketing emails at any time using the unsubscribe link in each email.

3.5 Website Chat Widget

Our website features an AI-powered chat widget. Conversations are processed in real-time and associated with a temporary session. No personally identifiable information is collected through the chat widget unless you voluntarily provide it during the conversation.

3.6 Social Media Analytics & Insights (read_insights)

When a business connects their Instagram Business Account or Facebook Page, we request read-only access to account and post performance metrics via Meta's Graph API. This includes account-level metrics (impressions, reach, profile visits, follower count and growth), post-level metrics (impressions, reach, saves, likes, and comments per post), and story metrics where available. This data is displayed in the business owner's analytics dashboard so they can review social content performance without leaving their business management tool. We never write to, modify, or delete any Instagram or Facebook account data through these analytics permissions. Insights data is scoped exclusively to the authenticated business's own connected account.

3.7 Facebook Page Visitor-Posted Content (pages_read_user_content)

When a business connects their Facebook Page, we request read-only access to visitor-posted content on that Page using the pages_read_user_content permission. This includes comments left by third parties on the Page's posts, and reviews written by clients on the Facebook Page (star ratings and review text). This data is surfaced in the business's comment management dashboard so staff can read client feedback, and synced into our review management feature so business owners can monitor ratings and draft responses. We never read comments or reviews from Pages the business does not own or control. We do not store comment content beyond what is needed to display it, and we never retain it for advertising or analytics purposes. This permission is strictly read-only. Staff-composed replies are sent via the separate pages_manage_engagement permission (see Section 3.9).

3.8 Facebook Page Post Publishing (pages_manage_posts)

When a business connects their Facebook Page, our platform can publish posts on their behalf using the pages_manage_posts permission. Data involved includes post caption and text composed or approved by the business owner or their staff, media files uploaded by the business, scheduled publish date and time, and post IDs returned by Meta's Graph API after publishing. We never publish posts automatically. Every post must be explicitly approved by the business owner or a designated manager within our platform before it is sent to Facebook. All publishing actions are performed exclusively on the authenticated business's own connected Facebook Page.

3.9 Facebook Review & Page Post Replies (pages_manage_engagement)

When a business connects their Facebook Page, our platform can post replies on their behalf using the pages_manage_engagement permission. This enables two features: (1) Review responses — staff can compose and send replies to Facebook Reviews directly from our review management dashboard; the reply is posted as a comment on the review's public story on the business's Facebook Page. (2) Post comment replies — staff can reply to comments left on the business's Facebook Page posts from within our social media management dashboard. Data involved includes reply text composed by the business owner or their staff, and the external Facebook Review ID or post comment ID the reply addresses. No reply is ever posted automatically. Every response requires explicit human action before it is submitted. We do not use pages_manage_engagement to read data — reading is handled by the separate pages_read_user_content permission (see Section 3.7). All reply actions are performed exclusively on Pages the authenticated business owns and controls.

3.10 Facebook Ad Account Data (ads_read)

When a business owner connects their Facebook account and grants the optional ads_read permission, our platform requests read-only access to their Facebook ad account performance data via the Meta Marketing API, solely to power the "Paid Ads" section of the analytics dashboard. The data accessed includes ad account identifiers, campaign-level performance for the last 30 days (spend, impressions, clicks, reach), publisher platform breakdown (Facebook, Instagram, Audience Network, Messenger), and booking conversion events attributable to ad campaigns. We never use this data for advertising, re-targeting, or any purpose other than displaying it to the business owner, and we never share it with third parties or store it beyond the current session. Ad account access is scoped exclusively to accounts owned by or explicitly granted to the authenticated Facebook user. The long-lived access token is stored encrypted at rest (AES-256-GCM) and is permanently deleted when the business disconnects the Facebook integration.

3.11 Instagram Business Account Insights (instagram_business_manage_insights)

When a business connects their Instagram Business Account through Instagram Business Login, we request read-only access to account and post performance metrics — impressions, reach, saves, profile visits, and follower growth — via the Instagram API with Instagram Login. This is the Instagram Business Login equivalent of the analytics described in Section 3.6, and powers the same analytics dashboard. We never write to, modify, or delete any Instagram account data through this permission. Insights data is scoped exclusively to the authenticated business's own connected Instagram Business Account.

3.12 Instagram Business Content Publishing (instagram_business_content_publish)

When a business connects their Instagram Business Account through Instagram Business Login, our platform can publish photos, videos, carousels, and Reels on their behalf using this permission. Data involved includes captions and media the business owner uploads or approves, the scheduled publish date/time, and the resulting Instagram media ID. We never publish content automatically. Every post requires explicit human approval within our platform — the business owner or a designated manager must approve the draft — before it is sent to Instagram. Publishing is scoped exclusively to the authenticated business's own connected Instagram Business Account.

3.13 Instagram Business Comment Management (instagram_business_manage_comments)

When a business connects their Instagram Business Account through Instagram Business Login, our platform can read comments left on their Instagram posts and post replies on their behalf using this permission. Comments are surfaced in the business's comment management dashboard alongside the post they were left on. Staff may optionally view an AI-suggested reply, which they must review and edit before sending. No reply is ever posted automatically — every response requires explicit human action. Comment reading and replying is scoped exclusively to the authenticated business's own connected Instagram Business Account; a comment on one business's post is never visible to any other business on our platform.

4. AI-Powered Features

5. Third-Party Service Providers

ProviderPurposeData Processed
StripePayment processingPayment card details, billing info
HelcimIn-person payment terminalsPayment card details
Meta PlatformsFacebook & Instagram messaging incl. Human Agent extended-window follow-up; social analytics (read_insights, instagram_business_manage_insights); visitor-posted Page comments and reviews (pages_read_user_content); Facebook Page and Instagram Business post publishing (pages_manage_posts, instagram_business_content_publish); Facebook review, Page post, and Instagram comment replies (pages_manage_engagement, instagram_business_manage_comments); Facebook ad account performance data (ads_read)Messages, user Page-Scoped IDs, message delivery status; post and account metrics; visitor-posted comments and review text; post captions, media, and publish status; reply text for reviews and post/Instagram comments; ad campaign performance data
TwilioSMS messagingPhone numbers, message content
SendGridTransactional emailEmail addresses, email content
Google (Gmail API)Conversational emailEmail addresses, email content
Anthropic (Claude)AI conversation processingMessage content (not used for training)
Cloudflare R2File & image storageUploaded files, photos
Neon (PostgreSQL)Database hostingAll application data (encrypted at rest)
Amazon Web Services, Inc. (AWS)Application hostingApplication logs, request data
SentryError monitoringError details, stack traces (no PII)

6. Data Sharing & Disclosure

We do not sell, rent, or trade your personal information to third parties. We may share your information only in these circumstances:

7. Data Retention

When you request deletion, we anonymize your personal information within 30 days. You may request deletion of your data at any time by contacting us (see Section 15) or visiting our Data Deletion page.

8. Data Security

9. Your Rights & Choices

10. Cookies & Tracking Technologies

11. Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children.

12. California Privacy Rights (CCPA/CPRA)

13. International Data Transfers

Our services are primarily operated in the United States. By using our services, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy on this page with a revised "Last Updated" date.

15. Contact Us

Slate

Privacy Inquiries

Email: [email protected]

We will acknowledge your request within 5 business days and aim to resolve all inquiries within 30 days.