Who this covers
This policy explains how Foyer handles data about the businesses that use Foyer and about their clients who book through Foyer. For a business’s clients, that business decides how their data is used and Foyer handles it on the business’s behalf. Questions or requests: cullin@foyerkit.com.
What we collect
- Account details: your name, email, business name and password (stored only as a secure hash).
- Square data: when you connect Square, we read and update what Foyer needs to work: your services and prices, locations and hours, team members, customers, bookings, orders, payments and subscriptions.
- Bookings made through Foyer: what a client enters to book, such as name, email, phone, the service, time and notes.
- Card details: clients enter cards in Square’s secure card field and businesses pay us through Stripe. Foyer never sees or stores full card numbers.
- Email lists: the people a business adds to its newsletter, their subscription status, and opens, clicks, bounces and unsubscribes.
- Usage: anonymous booking steps in the widget (for example, “picked a time”) so businesses can see where clients drop off, and standard server logs.
How we use it
To run Foyer: take bookings and payments through Square, show your dashboard, send the emails you turn on (confirmations, reminders, review requests, newsletters), bill your subscription, keep the service secure, and support you. We do not sell personal data, and we do not use your clients’ data to market to them ourselves.
Who we share it with
Only the providers that run Foyer for us, each limited to what they need:
- Square (your bookings and payments)
- Stripe (billing for Foyer)
- Supabase (our database)
- Vercel (hosting)
- Resend (sending email)
- Google Fonts (fonts on our website, which receives your IP address)
We may also share data when the law requires it, or to protect Foyer and its users.
Cookies and tracking
Foyer uses one cookie to keep you signed in to the dashboard. Our marketing website does not use advertising or analytics cookies. If a business adds its own Google Analytics or Meta Pixel to its website, the Foyer widget sends booking events to those tools, under that business’s own policies.
Security
Data travels over HTTPS. Square access tokens are encrypted (AES-256-GCM) and never sent to the browser. Database access is limited to Foyer’s servers. No system is perfectly secure; we will tell affected businesses promptly if a breach affects their data.
How long we keep it
We keep your data while your account is open. When you disconnect Square, we stop using your Square access right away and delete the tokens. When you close your account, we delete your Foyer data on request within 30 days, except records the law requires us to keep, such as billing records.
Your choices and rights
You can see, correct, export or delete your data by emailing cullin@foyerkit.com. Clients of a business should contact that business first; we will help the business respond. Anyone can unsubscribe from a newsletter with the link in every email. California residents have the right to know, delete and correct personal information, and we do not sell or share it for advertising.
Children
Foyer is for businesses and is not directed to children under 13.
Changes
If we change this policy in a way that matters, we will update the date above and email account owners before the change takes effect.