Skip to content

legal

Privacy notice

Effective 25 September 2026.

This notice explains what Held Software Limited (“Held”) collects, why we need it, who processes it, and what you can ask us to change or delete. It covers people who create a Held page and people who book through one. Held is booking software. We are not a marketplace. We do not sell personal data.

Controller: Held Software Limited, Ilorin, Kwara Nigeria. hello@bookheld.app.

1. Who this covers

A professional is anyone who creates a Held page to take bookings. A client is anyone who uses that page to reserve time and pay a deposit.

2. What we collect

From professionals: display name, public link, country, timezone, currency, availability, packages, optional intro and photo, WhatsApp number if provided, payout bank details, plan and billing status, and optional client reviews published on the page. Login uses Supabase Auth (email and password, or Google). You may enable an authenticator app in Settings. A session cookie keeps you signed in on this device. If you connect Google Calendar or Zoom, we store a refresh token so bookings can sync. Password and account change notices are sent by Held through Resend.

From clients: name, email, phone or WhatsApp if provided, package and time booked, deposit amount, payment status, manage link token, and optional visit review (rating and comment). We do not store full card numbers. Paystack processes the card or transfer.

We also keep technical logs needed to operate the Service (for example sign in time and basic device data for session security). We do not use that data to build advertising profiles. Language and dashboard theme preferences may use cookies on this device only. Public booking pages stay light.

3. Why we collect it

We use this information to run the booking page, take and confirm deposits, show the professional who is booked, send transactional booking mail (confirmation, reminder, balance due, cancellation, reschedule, review invitation, book again), display a WhatsApp link when configured, and show verified client ratings on the public page. We do not use client details to market unrelated products.

4. What the public page shows

The public page shows the professional’s name, photo if added, packages, prices, open times, storefront content the professional publishes, and published client ratings and reviews. It does not show bank account numbers, login details, or a client’s private contact information to strangers.

5. Processors

Paystack processes payments. Supabase stores application data and auth. Resend sends transactional mail when connected. Google Calendar and Zoom receive booking times only if the professional connects those accounts. Optional package drafting may send pasted text to a writing provider solely to suggest packages, then discard it. Those providers process data to provide that function, not to sell it for us.

6. Google user data

Held uses Google in two separate ways. Signing in with Google (through Supabase Auth) receives the Google account email and name to create or open a Held login. Connecting Google Calendar is optional and separate in Settings. That connection uses the Google Calendar API scope https://www.googleapis.com/auth/calendar.events. With that scope Held can create, read, update, and delete calendar events that Held itself writes: paid bookings and dates added by hand. Held does not read the rest of the calendar to build a profile, send ads, or train models.

Held stores a Google refresh token on the professional’s profile so the server can write those events later. Access tokens are requested when needed, then discarded. Tokens never go to the browser and are omitted from data exports. Disconnect Google in Settings deletes Held’s copy of the token. You may also revoke Held in your Google Account.

Held does not sell Google user data. We do not share it with advertisers or data brokers. We transfer it only as needed to Google (Calendar events), Supabase (storage of tokens and booking records), and Resend (Meet join links in transactional mail when applicable). Held’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use. Held does not use Google user data to train AI models.

7. Protection of sensitive data

Sensitive data includes Google and Zoom refresh tokens, payout bank details, passwords, authenticator secrets, and recovery codes. Pages and APIs use HTTPS (TLS in transit). Application data sits in Postgres hosted by Supabase (encryption at rest). Row Level Security restricts professional rows to that account. Calendar and Zoom API calls run on the server. Bank and password changes may require a second authenticator factor when enabled. Recovery codes are stored as hashes.

8. Retention and your choices

Account and booking records stay while the page is open and as long as needed for history, disputes, accounting, or law. In Settings, professionals can download a copy of page data or close the account. Closing deletes the page, bookings we hold, the photo, and the login. Payment processors and banks may keep records they are required to keep. Clients can use the manage link from checkout mail where still allowed. You may ask what we hold, ask us to correct it, or ask us to delete it, subject to records we must keep.

9. Children

Held is for adults who offer or book professional time. Do not create an account or book on behalf of a child without a lawful basis. If we learn we hold a child’s data without that basis, we will delete it.

10. Changes

If this notice changes in a material way, we update the effective date on this page. The current text applies. This notice is in English.

Held Software LimitedRC 9797907Ilorin, Kwara Nigeriahello@bookheld.appMon to Sat, 9:00 to 18:00 WAT