Warm HandoffSign in

Warm Handoff · Effective September 23, 2026

Privacy Policy

Warm Handoff is a booking experience layer for med spas and wellness practices, made by Captive Demand. This policy explains what we collect, why, and the choices you have. It is written in plain language on purpose.

1. Who this covers

Warm Handoff touches two kinds of people, and the rules differ for each.

  • Customers are the practices, brands, and agencies that sign in to the admin at https://app.warmhandoff.io to configure a booking widget. For customers, Captive Demand is a service provider.
  • Guests are the people who book an appointment through a widget on a customer's website. The customer decides what the widget asks for and where the booking goes. For guests, the customer is the party responsible for the data, and the customer's own privacy notice governs. We process guest data only on the customer's behalf and under their instructions.

If you are a guest with a question about a booking, contact the practice you booked with. They can see and manage your booking; we act on their instructions.

2. What we collect

Account information. When a customer signs in with Google or an emailed link, we receive their name, email address, and profile picture from the sign-in provider, and we keep a record of their organization, role, and activity in the admin.

Booking platform credentials. Customers connect their booking platform (for example, Boulevard) by entering a business ID and an API key. API keys are stored in an encrypted secrets vault and used only to perform the actions the customer configures.

Booking information. When a guest completes a booking, the widget sends us the guest's first and last name, email address, phone number, the location, service, add-ons, and appointment time, and the page and button the booking started from. Contact fields are encrypted at rest.

Payment information. We never receive card numbers. When a booking requires a card, the guest's card details go directly from the guest's browser to the customer's booking platform's payment vault. Our servers only learn whether the booking was completed.

Usage events. The widget records which step of the booking flow a guest reached, a random session identifier, the page URL, campaign parameters in the URL (such as UTM tags), and the type of error if one occurred. These events power the completion rate the customer sees in the admin. They never contain the guest's contact details.

Cookies. The admin sets one cookie to keep a customer signed in. The widget sets no cookies of its own and does no cross-site tracking. If a customer enables the HubSpot integration, the widget reads the HubSpot tracking cookie that the customer's site already set, so the booking can be attributed in the customer's HubSpot account.

3. How we use it

  • To operate the booking flow and confirm appointments with the booking platform.
  • To keep a verified record of bookings that customers can review and export.
  • To send booking details to the integrations a customer turns on, such as a HubSpot form or a webhook to the customer's own systems.
  • To show customers how their widget performs, in aggregate and per booking.
  • To secure the service, prevent abuse, and troubleshoot problems.
  • To communicate with customers about their account and the service.

We do not sell personal information, and we do not use guest data for advertising.

4. Who we share it with

We share information only with the providers that run the service and with the services a customer chooses to connect.

  • Booking platforms such as Boulevard, which hold the actual appointment and payment.
  • Customer-configured integrations such as HubSpot or a customer's own webhook endpoint. The customer controls which fields are sent.
  • Infrastructure providers: Supabase (database, authentication, and secrets storage), Vercel (application hosting and the widget's content delivery network), and Google (sign-in). All are hosted in the United States.
  • Legal reasons, when required by law or to protect the rights and safety of guests, customers, or Captive Demand.

5. Health information

Warm Handoff schedules appointments. It is not designed to collect medical history, diagnoses, or treatment details, and customers agree not to configure it to do so beyond what is needed to book a visit. Captive Demand is not a HIPAA covered entity. Where a customer needs a business associate agreement, it must be signed separately before any protected health information is handled through the service.

6. How long we keep it

Account information is kept while the customer's account is active. Booking records and usage events are kept while the customer's account is active so the customer can review history and performance. When a customer closes their account, we delete their data within 30 days, except where we must keep it for legal or security reasons. Backups roll off on their own schedule after that.

7. How we protect it

  • All traffic to and from the service uses TLS.
  • Guest contact fields are encrypted at rest with a key held in a secrets vault.
  • Booking platform API keys are stored in the same vault and never shown in full.
  • Access to a customer's data is limited to members of that customer's organization, enforced by row-level permissions in the database.
  • Card details never pass through our systems.

No system is perfectly secure. If we learn of a breach affecting your data, we will notify affected customers without undue delay.

8. Your choices and rights

Customers can view, edit, export, and delete their data in the admin, or by writing to us. Guests should contact the practice they booked with; the practice can ask us to update or delete a booking record, and we will act on that instruction.

Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal information, and to complain to a supervisory authority. We honor those rights and will not treat you differently for exercising them. To make a request, email hello@captivedemand.com.

9. Children

The service is not directed to children under 13, and we do not knowingly collect information from them. Customers are responsible for any age requirements that apply to their own services.

10. Changes to this policy

We will post any changes here and update the effective date. If a change materially affects how we handle customer data, we will tell customers by email before it takes effect.

11. Contact

Captive Demand, maker of Warm Handoff. Email hello@captivedemand.com.