Skip to content

held

Security

Effective 25 September 2026.

Held stores what is required to run a booking page and a deposit. Full card numbers do not pass through Held. This page summarizes the controls that matter most for professionals and clients.

Payments

Payments are processed by Paystack. Held does not store full card numbers. Deposits may pay out to banks in Nigeria, Ghana, Kenya, South Africa, and Côte d’Ivoire when a verified payout bank is on file.

Accounts and access

Login uses email and password, or Google. Professionals may enable two factor authentication with an authenticator app in Settings. Recovery codes are shown once when that feature is turned on. A session cookie keeps you signed in on this device. You can sign out other devices from Settings. Password reset mail and notices for password, payout bank, or WhatsApp changes go only to the address on the account.

Clients do not receive a professional Held account. They open a manage link emailed to the address used at checkout. Reminder, balance, and review invitation mail also go to that address.

Calendar and video

If you connect Google Calendar, Held stores a refresh token on the server so paid bookings and hand added dates can be written there (calendar.events scope). Meet packages may receive a join link on that event. Tokens never go to the browser. Disconnect Google in Settings to delete Held’s copy. Zoom works the same way for Zoom packages. A public recording of the Google connect flow is on Google Calendar demo.

Data protection

HTTPS and TLS encrypt data in transit. Supabase encrypts the database at rest. Row Level Security keeps one professional’s rows from another. Refresh tokens, bank details, and authenticator secrets stay on the server. Account exports omit OAuth tokens. Recovery codes are stored as hashes. Held does not sell Google user data and does not use it to train AI models. Details of Google data sharing are on Privacy.

Platform controls

Passwords are hashed by Supabase Auth. Database access uses parameterized queries through Supabase with Row Level Security on application tables. Public API routes are rate limited. Login, signup, and password reset are rate limited per IP. Cross origin API calls are blocked except from bookheld.app and localhost during development. Security headers (HSTS, CSP, frame denial, nosniff) are set on every page. Sessions refresh on each request and expire on Supabase’s JWT schedule.

Public page contents

Name, photo if added, packages, prices, open times, and published client reviews. Not bank numbers, not login details, not a client’s private contact information.

Account closure

In Settings, download a copy of your data or close the account. Closing removes the page, bookings we hold, the photo, and the login. You may also write from the email on that account to hello@bookheld.app.

Company

Held Software Limited
Ilorin, Kwara Nigeria
hello@bookheld.app

Held Software LimitedRC 9797907Ilorin, Kwara Nigeriahello@bookheld.appMon to Sat, 9:00 to 18:00 WAT