Privacy Policy
Effective Date: July 1, 2025 · Pivot Habit, LLC d/b/a Grab My Slot
PLEASE READ THIS POLICY CAREFULLY. By creating an account, booking an appointment, or otherwise accessing or using the Platform, you acknowledge that you have read, understood, and agreed to this Privacy Policy.
1. Introduction and Scope
Pivot Habit, LLC d/b/a Grab My Slot ("Grab My Slot," "Company," "we," "our," or "us") operates the website located at GrabMySlot.com and any associated mobile applications or platforms (collectively, the "Platform"). Grab My Slot provides a service that enables licensed contractors—including, without limitation, plumbers, electricians, HVAC technicians, and other tradespeople ("Contractors")—to collect deposits and trip charges from consumers who book service appointments ("Customers").
This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal information in connection with the Platform. It applies to all Users and to visitors who browse the Platform without creating an account.
2. Information We Collect
2.1 Information Contractors Provide
- Identity and Contact Information: Full legal name, business name, trade license number(s), business address, phone number, and email address.
- Payment and Banking Information: Bank account or payout destination details collected and transmitted directly to Stripe, Inc. We do not store full bank account numbers on our servers.
- Business Profile Information: Trade category, service area, scheduling preferences, deposit or trip-charge amounts, business logo, and other public-facing profile information.
- Calendar and Scheduling Data: When a Contractor connects Google Calendar or Microsoft Outlook/Exchange, we access calendar event data solely for availability synchronization and appointment management.
- Government-Issued Identification: Collected through Stripe's identity verification services to satisfy KYC and AML obligations. Processed and stored by Stripe.
- Communications: Messages, support tickets, and other communications you send to us.
2.2 Information Customers Provide
- Identity and Contact Information: Full name, email address, and phone number provided at the time of booking.
- Payment Card Information: Collected directly by Stripe through a secure, PCI-DSS-compliant embedded form. We do not receive or store raw card data — only a Stripe payment token and the last four digits.
- Appointment Details: Service address, requested service type, preferred appointment date and time, and any notes provided to the Contractor.
- Communications: Messages and other communications you send to us or that we transmit on your behalf.
2.3 Information We Collect Automatically
- Log Data: IP address, browser type and version, operating system, referring URL, pages visited, time and date of access, and duration of session.
- Device Information: Device type, device identifier, mobile network information, and device location (with your permission).
- Cookies and Similar Technologies: Used to authenticate sessions, remember preferences, analyze usage patterns, and support advertising where applicable.
- Usage Data: Feature interactions, button clicks, form completion rates, and similar behavioral data used to improve the Platform.
2.4 Information We Receive from Third Parties
- Stripe, Inc.: Transaction status, payment confirmation, refund status, dispute notifications, and for Contractors, identity verification results and payouts eligibility.
- Google and Microsoft: Calendar availability data when a Contractor enables calendar integration.
- Identity Verification Providers: Verification status returned after document review.
- Analytics Providers: Aggregated usage metrics.
3. How We Use Your Information
3.1 To Operate and Deliver the Platform
- Create, authenticate, and manage User accounts.
- Process deposit and trip-charge payments between Customers and Contractors through Stripe.
- Issue booking confirmations, receipts, and appointment reminders via email or SMS.
- Synchronize appointments with connected calendar services.
- Facilitate Customer cancellations, refund requests, and dispute resolution.
- Enable Contractors to manage their profiles, availability, and pricing.
3.2 To Comply with Legal and Financial Obligations
- Verify Contractor identities and satisfy KYC/AML requirements.
- Maintain transaction records required by tax, accounting, and financial recordkeeping laws.
- Respond to lawful legal process, court orders, subpoenas, or government inquiries.
- Investigate and prevent fraudulent transactions, identity theft, and other illegal activity.
3.3 To Improve and Personalize the Platform
- Analyze aggregated usage patterns to improve user experience, fix bugs, and develop new features.
- Conduct A/B testing and user research (in anonymized or aggregated form where possible).
- Provide Contractors with dashboard analytics about their bookings and revenue.
3.4 To Communicate with You
- Send transactional communications (booking confirmations, payment receipts, appointment reminders, policy updates).
- Respond to customer service inquiries and support requests.
- With your consent, send promotional communications about new features, offers, or services. You may opt out at any time.
4. Disclosure of Your Information
We do not sell your personal information to third parties for their own marketing purposes. We may share information in the following limited circumstances:
4.1 Third-Party Service Providers
- Payment Processing: Stripe, Inc. processes all payment card transactions and Contractor payouts. Stripe's use of personal information is governed by the Stripe Privacy Policy (stripe.com/privacy).
- Calendar Integration: Google LLC and Microsoft Corporation process calendar data when a Contractor enables integration. Governed by their respective privacy policies.
- SMS Communications: Twilio, Inc. transmits appointment reminders and notifications on our behalf.
- Cloud Infrastructure: Vercel Inc. and Supabase host Platform data within the United States.
- Analytics: We may engage analytics providers to help us understand Platform usage in aggregated form.
4.2 Business Transfers
If we are involved in a merger, acquisition, asset sale, or bankruptcy proceeding, personal information may be transferred as a business asset. We will notify affected Users via email or a prominent notice on the Platform before personal information becomes subject to a materially different privacy policy.
4.3 Legal Requirements and Safety
We may disclose personal information if required to do so by law or in the good-faith belief that such disclosure is reasonably necessary to comply with legal process, protect our rights, prevent fraud, or protect the safety of any person.
5. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law:
- Active account data is retained for the life of the account.
- Transaction records are retained for a minimum of seven (7) years to satisfy financial recordkeeping obligations.
- Appointment and calendar data is retained for two (2) years following the appointment date.
- Marketing and communication preferences are retained until you withdraw consent or request deletion.
- Log data and analytics are retained for up to two (2) years in identifiable form, then anonymized.
6. Data Security
We implement and maintain reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, disclosure, alteration, and destruction. These measures include encryption of data in transit using TLS, access controls limiting data access to personnel with a need to know, and regular security assessments.
No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect personal information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
7. Your Rights and Choices
7.1 Access, Correction, and Portability
You may access and update most of your personal information directly through your account settings. To request a copy of your personal information in a portable format, please contact us at privacy@grabmyslot.com.
7.2 Deletion
You may request deletion of your personal information by contacting us at privacy@grabmyslot.com. We will honor deletion requests subject to our legal obligations to retain certain records, our legitimate interests in preventing fraud, and technical limitations of our systems.
7.3 Opt-Out of Marketing
You may opt out of marketing communications at any time by clicking "unsubscribe" in any marketing email or by contacting us at privacy@grabmyslot.com. Opting out of marketing communications does not affect our ability to send transactional communications.
7.4 Do Not Track
Our Platform does not respond to browser "Do Not Track" signals at this time. We will update this Policy if our practices change.
8. Tracking Technologies and Cookies
We use cookies and similar technologies including session cookies (deleted when you close your browser), persistent cookies (remain until deleted or expired), and web beacons to authenticate users, remember preferences, analyze usage, and support advertising where applicable.
Most browsers allow you to control cookies through their settings. Blocking cookies may affect the functionality of certain Platform features.
9. Children's Privacy
The Platform is not directed to children under 18 years of age, and we do not knowingly collect personal information from children. If we learn that we have inadvertently collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@grabmyslot.com.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: The categories and specific pieces of personal information we have collected about you.
- Right to Delete: Personal information we have collected, subject to exceptions.
- Right to Correct: Inaccurate personal information we maintain about you.
- Right to Opt-Out: We do not sell or share personal information for cross-context behavioral advertising.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact us at privacy@grabmyslot.com with the subject line "California Privacy Request."
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Revised" date, posting a prominent notice on the Platform, and/or sending an email to the address on file. Your continued use of the Platform after the effective date of any change constitutes acceptance of the updated Policy.
12. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or our data practices, please contact us at:
Pivot Habit, LLC d/b/a Grab My Slot
Email: privacy@grabmyslot.com
Website: grabmyslot.com