Privacy, in plain English.
We collect only what is needed to set up a session, record an adult’s paid spot, show the organizer one list, and send session texts after that adult replies YES.
Held a Spot takes reservations and payments together, so you never have to ask. Your people know a paid spot is a held spot.
What we collect
- For organizers: adult display name, session details, public contact link, payout-setup state, and private management links.
- For participants: adult name, optional mobile number, session response, payment state, consent record, and technical request data used for security.
- For returning adult participants, we set a random first-party browser token. The server stores only its one-way SHA-256 hash, not the raw token, so the same browser can recover its place in that organizer’s group without an account.
- Card details are handled on a hosted payment page. We do not store full card numbers.
- For a run of the “what to charge” tool: the activity and metro chosen, and the price rounded to a band such as $25 to $39, under an identifier generated for that run alone. No name, no address, no browser token, and never the exact figure typed.
Analytics
We use Google Analytics and Microsoft Clarity to see how these pages are used — which pages load, where people give up, what breaks. Clarity records how a page is used; every field that carries a name or a phone number is masked from those recordings, so they show that a field was filled in, never what was typed. Nothing about this changes what the page does, and the page works the same with tracking blocked.
No children’s data
Our forms are for adult identity only. We do not provide fields for a child’s name, age, date of birth, grade, photo, medical information, allergy, or pickup details. Do not enter a child’s information into an adult-name field. The service is not directed to children under 13.
How we use information
We use the information to run the selected session: record payment, count paid spots, show the adult list to the organizer, apply the organizer’s cancellation rule, secure private links, and provide session-change notices.
Text consent
Entering a mobile number allows one YES request. Session texts are eligible only after the adult replies YES. Consent is recorded with the time, request address, and exact prompt. Consent is not a condition of purchase. Message frequency varies with session activity. Reply STOP to opt out across the service or HELP for help. Message and data rates may apply. No marketing texts and no ads.
Sharing and separation
Participants are scoped to the organizer’s group; we do not build a shared participant directory across groups. We disclose data to service providers only as needed to host the service, process a payment, prevent abuse, or send an eligible transactional notice.
We do not sell mobile numbers or messaging opt-in data. We do not share them with third parties or affiliates for those parties’ own marketing or promotional purposes.
List and calendar
The organizer can make a screenshot list containing adult name, paid state, and whether that adult gets session texts. Phone numbers never appear on that list. Calendar files contain session details and a signed read-only session-status link, not a private receipt or cancellation link.
Measurement
We use Google Analytics and Microsoft Clarity to understand how the site is used. Clarity records how a page is interacted with, so name and phone fields are masked before anything leaves the browser and their values are never recorded. These load only where we have set them up, and only after the choice below allows it. Where we ask, nothing loads until you say yes. Where the law lets us measure by default, a Global Privacy Control signal from your browser turns it off before the page renders.
When measurement is on, the analytics cookie's identifier is stored with the payment so a completed payment can be matched to the visit that led to it. That identifier is not a name, a number, or an address, and we do not use it to build a profile or to advertise to you.
The “what to charge” tool
Working out a price records what was asked, not who asked. Each run stores the activity and the metro that were chosen and the price as a band rather than a figure, under an identifier made for that one run. There is no browser token on it, no address, and nothing that ties one run to another. We use it to see which activities and places people are pricing for, which is what tells us where to build next.
If you then leave your email in the form at the bottom of that page, that run is linked to the address you gave us, because you chose to attach it. Leaving the tool without doing that leaves the run unattached to anyone, and it stays that way.
Choices
STOP suppresses future texts. HELP requests help. You can accept or decline measurement where we ask, and we honour a Global Privacy Control signal without being asked. For another privacy request, use the support link provided with the service. We may retain payment and consent records when required for security, accounting, disputes, or law.
Effective August 28, 2026. This notice may be updated as the service moves through review.