Privacy Policy
Last updated 7 August 2026
Frontmat is studio-management software operated by Star Hero AI LLC. This policy explains what we collect, why, and what you can do about it.
Two relationships, and the difference matters. When a studio signs up, we decide how their account data is handled — we are the controller. When members book classes, the studio decides what is collected and why; we only process it on their instructions. If you are a member, the studio is who to ask about your record.
What we collect
From studios
- Business name, web address, timezone, branding, and locations.
- Staff names and email addresses used to sign in.
- Your schedule, class templates, floor plans, products, and pricing.
- Your Stripe account identifier once you connect it. We never receive your bank details or your customers’ card numbers.
From members (on a studio’s behalf)
- Email address, and a mobile number only if provided.
- Bookings, waitlist entries, attendance, class credits, and purchase history.
- A record that a waiver was signed: the typed name, timestamp, and a fingerprint of the waiver text as it stood.
- Notification preferences and, if enabled, a browser push subscription.
From guests (people a member brings to a class)
A member can add a named friend to their own booking. For that guest we hold only a first name, an email address if the member chose to give one, and a record of the classes they attended and who brought them. A guest has no account and no password with us.
- The studio may record that the guest signed a waiver at the door, including which staff member recorded it and when. The signature itself stays with the studio.
- A guest who left an email receives at most one message from the studio: an invitation to set up their own account, sent the day after the class. Staff can send that invitation again from the studio’s guest list. Guests never receive class reminders or marketing.
- Guests are never included in a studio’s member exports or imports, and a studio can delete a guest’s name and email from its guest list at any time.
Automatically
- Standard server logs (IP address, browser, pages requested), kept briefly for security and debugging.
- A session cookie so you stay signed in, and a cookie remembering which studio you are viewing.
- On our marketing site and sign-up flow only, ad-measurement cookies (Meta’s pixel, Google Analytics) that tell us whether our own advertising led to a sign-up. Once you are a customer, we set no advertising cookies — we do not retarget our customers, and member-facing pages carry no trackers at all.
- Error diagnostics when something breaks, so we can fix it.
What we deliberately do not do
- We never see card numbers. Payment details are entered on pages hosted by Stripe and never touch our servers, logs, or browser code.
- We do not sell personal information. On our marketing site and sign-up flow we share limited funnel events (a page was viewed, a sign-up happened) with Meta and Google to measure our own advertising — never member data, never your customers, and never anything after you become one of ours.
- No analytics on member-facing pages. We use Google Analytics only on our marketing site, our sign-up flow, and the studio-side admin that owners and staff use. A studio’s members are the studio’s customers, and their booking activity is not analytics fodder.
- We do not market to your members. We contact them only to deliver what the studio asked us to send.
How we use information
- To run the service: schedules, bookings, credits, waitlists, receipts.
- To send booking-related messages by email, and — where a member has opted in — by text message or push notification.
- To keep the service secure, detect abuse, and fix faults.
- To bill studios for their subscription, and to answer support requests.
Messages
Booking confirmations, cancellations, waitlist offers, and similar are transactional: they are part of the service and are not marketing. Studio-configured messages of a promotional nature include an unsubscribe link and honour it.
Text messages are sent only to members who provide a mobile number and opt in, and only about bookings. Reply STOP to stop them, or HELP for help. Message and data rates may apply. Consent to texts is not a condition of booking.
Who we share it with
We use a small number of service providers, each handling only what their job requires:
| Provider | Purpose | Data involved |
|---|---|---|
| Amazon Web Services | Hosting, database, file storage, outbound email | All service data, stored in the United States |
| Stripe | Payments and studio payouts | Payment details, entered directly with Stripe |
| Twilio | Text messages | Mobile number and message content, for opted-in members |
| Sentry | Error diagnostics | Technical error data; may include a user identifier |
| Meta (Facebook/Instagram) | Ad measurement on the marketing site and sign-up flow | Funnel events on our own pages — never member pages, never after sign-up |
| Google Analytics | Marketing-site, sign-up and studio-admin analytics | Usage data on our own pages — never member app pages |
| Zoho Mail | Our support inbox | Anything you email us |
We also disclose information if the law requires it, or to protect the rights and safety of people using the service. If the business is ever sold, information transfers with it, and we will say so before that takes effect.
Where data lives
Service data is stored in the United States, in Amazon Web Services regions on the US east coast. If you use Frontmat from outside the US, you are sending your information to the US.
How long we keep it
- While a studio’s account is active, we keep their data so the service works — history is part of the product.
- After an account closes we keep data for 30 days so it can still be exported, then delete it. Backups roll off within a further 35 days.
- We keep records we must keep for legal, tax, or dispute reasons for as long as required.
- Server logs are kept briefly, then discarded.
Security
- Encrypted in transit (HTTPS everywhere) and at rest.
- Sign-in is passwordless: single-use links that expire, so there is no password to reuse or leak.
- Point-in-time backups, with restores exercised rather than assumed.
- Each studio’s data is isolated by design, and that isolation is tested — not merely intended.
No system is perfectly secure, but we would rather tell you what we do than promise magic.
Your choices and rights
Members: your record belongs to your studio. Ask them to see, correct, export, or delete it and we will act on their instruction. You can change notification preferences yourself in the member app, unsubscribe from marketing messages, and reply STOP to texts.
Studios: you can export your data at any time, correct it in the admin, and ask us to delete your account.
Depending on where you live you may have rights to access, correct, delete, or port your information, and to appeal a refusal. We do not discriminate against anyone for exercising them. Write to hello@frontmat.studio and we will respond within the time the law allows.
Children
Frontmat is not intended for children under 13, and we do not knowingly collect their information. If a studio enrols minors, the studio is responsible for obtaining the consent its jurisdiction requires. Tell us if you believe we hold a child’s information and we will delete it.
Changes
We will post updates here with a new date, and give notice by email for material changes.
Contact
Star Hero AI LLC — hello@frontmat.studio