Privacy Policy
What we hold, and what you can actually do about it.
Written from what Slate actually does, rather than from a template. Slate does collect and hold data — it is a booking system — and everything it holds is set out below. Where Slate cannot yet do something a privacy policy would normally promise, this page says so instead of promising it.
Facts checked 14 August 2026
Two relationships — pick yours below
On this page
- Who we are
- If you booked something through a business on Slate
- If you run a business on Slate
- Cookies, and what is kept in your browser
- We do collect data. Two counters are always our host's; two more run only if you say yes.
- Text messages
- Who else can see it
- How long it is kept, and how deletion actually works
- Your rights, and how to use them today
- How it is protected, and where that stops
- Things you might expect us to collect, and we do not
- Children
- Changes to this policy
- Contact
If you booked something
You are a guest of a business that uses Slate.
The business collected your details and decides what happens to them. Slate stores them on that business's instruction and does nothing else with them. Your fastest route to a change, a refund or a deletion is the business itself — but you can write to us too, and we will act with them.
Read the guest sectionIf you run a business on Slate
You are an operator with an account and a console.
Your own account details are held by us, and we decide what is held. Your guests' details are held by you, through us. Both are covered below, and the difference matters when somebody asks you to delete something.
Read the operator sectionWho we are
Slate is booking software operated by Calibrate Holdings LLC. This policy covers the Slate marketing site, the operator console, the public websites and booking pages we host for operators, and the manage links guests use to change a booking.
One address reaches a person for anything on this page: legal@slate-booking.com
If you booked something through a business on Slate
What is held about you
- Your name, email address and phone number, as you typed them at checkout.
- How you heard about the business, if it asked and you answered. It is free text, so whatever you wrote is what is stored.
- Your booking: the reference, the experience, the date and time, what you selected, the prices at the moment you booked, and the status.
- Payment records, if the business takes payment through Slate: amounts, the method, and identifiers from the payment processor. Never your card number — cards are entered on the processor’s own page and Slate never receives one.
- What you wrote when you cancelled. If you give a reason, it is kept in an audit record that cannot be edited or deleted afterwards. Worth knowing before you type something.
- Gift cards, if one was bought for you: the recipient address, the sender’s name and their message. You may never have touched Slate at all — somebody gave us your address.
- The names of everyone in your party, but only if the business uses waivers and somebody typed them in on the booking link. Whoever holds that link can add or change these names, so they are only ever as accurate as the person who entered them.
- Waiver signatures, if the business asks for one. Each signature records the name typed, the moment it was signed, the internet address it was signed from, which version of the waiver it was signed against, whether it was signed at checkout or from the manage link, and whether the signer confirmed they were agreeing on behalf of minors in their party. When the waiver is a PDF, the signature also records that exact file’s SHA-256 fingerprint, so it can prove which bytes were signed even if the document is later replaced. The IP address is recorded because a signature without one is much weaker evidence that it happened. A signature cannot be edited or deleted afterwards — not by you, not by the business, not by us — which is what makes it a record. It can go with the whole organization, and not otherwise, as described in section 8.
- A logo, service photos and website photos, if the business uploaded them. An operator can upload its logo, a picture for each thing it offers, and photos for the website Slate hosts for it. Slate makes and stores three copies of each website photo in a public file store and publishes them on the business's booking page or website. These are the only types of files a business can upload to Slate. The business also writes alt text for each website photo, which is published with it. Website photos may show identifiable people. Slate does not review the photos or check permissions. The business must have the right to upload and publish each photo, including any permission the law requires from people shown in it. Before upload, the operator's browser makes new copies containing only the image pixels. The original file and its camera and location metadata are not uploaded to Slate. Removing or replacing a website photo in the editor does not delete its stored copies; they remain publicly reachable at their file addresses unless separately deleted. If you appear in a photo and want it removed, ask the business or write to Slate at the contact address on this page.
Three things Slate does not ask for
How many people are coming. Booking stores no headcount. The form asks how much of a boat or a room you are taking, not how many humans will be on it — a four-berth cabin and four people look identical to the software. Waivers are the one exception: if your host uses them and somebody enters your party’s names, those names are stored, and counting them obviously gives a headcount. Nothing does that unless a person types the names in.
Your IP address, on a booking. Making a booking never writes one into the records that hold your booking. It is held briefly, in the memory of whichever machine answered you, purely to stop one browser hammering the booking page, and it goes away with that machine. Like any site, the company that runs our servers keeps short-lived request logs that include it; that is on the subprocessors page too. Signing a waiver is the one place an IP address is written down and kept — see the signature entry above.
Anything about you elsewhere on the internet. There is no tracker on the booking page. See section 5.
What you can do right now, without asking anyone
The manage link you were given at checkout is your route in. Under What is held about you it shows you the name, the email address and the phone number stored for this booking, alongside the reservation itself — and it lets you reschedule or cancel, subject to the cutoff the business set, which is theirs, not ours.
That link is a key. Anyone holding it can see and change the booking, because there is no password on it. We store only a scrambled version, so we cannot recover it for you and cannot show it to anyone. Treat it like a ticket.
How to make a request
To correct your details, write to us or to the business. There is no edit button on the manage page and no “edit customer” screen in the operator console; booking again with the same email address overwrites the name and phone we hold, but not the address itself, which is what we match on.
To delete anything — your booking, your customer record, or both — write to us or to the business. Deletion is a manual operation performed by a person; section 8 says how to ask for one and what it does and does not reach.
Who to ask
Ask the business you booked with first. They hold your booking, they hold the money, and they can act immediately. If you cannot reach them, or the request is about Slate itself, write to us and a person will pick it up — we act with the business, because the data is theirs.
If you run a business on Slate
Your own account
- Your email address and password. The password is hashed by our authentication service — Slate never sees it and cannot recover it.
- Your name, your organization, and your role in it.
- Your phone number and your company website, if you give them when you create your account. Both are held on the account itself and never on a booking; the website is read once, to pre-fill your setup.
- A record of each sign-in: the IP address and the browser, kept by our authentication service. Every IP address Slate holds is an operator's, recorded at sign-in — a guest booking never records one. There is more than one such record: the session itself carries an address, and the authentication service keeps its own security log alongside it.
- Auth0 sign-in has been on since 7 September 2026: the login page itself is hosted by Auth0 (Okta). For the length of the sign-in it sets its own strictly necessary cookies on its own domain, and it holds the email address, name and hashed password of accounts created there. Slate's own session is unchanged: Auth0 tells us who you are and nothing else. It is listed on the subprocessors page with its current status.
- An audit trail of significant actions in the console — who did what, when. It cannot be edited or deleted after the fact, which is the point of it.
- Billing identifiers at our payment processor, if Slate ever bills you. Nobody is billed today: the one plan is free.
Emails about your account
Slate emails the address on your account about the account itself: a welcome when you create your account, before you have set up a business; a second welcome when your organization is created; a nudge or two if setup stalls; a note when your booking page goes live; and sign-in and password-reset links. They travel through our email provider, and a reply lands in a mailbox Google hosts for us. None of it is marketing, and there is no list you can be on without an account.
The console assistant and the setup interview
Both talk to a language model run by Anthropic. What you type, and the setup it builds from that — services and prices, boats, rooms and gear, hours, team names — is sent to Anthropic’s API to get an answer back, and only while you are using it. Never a guest, a booking or a customer record: the assistant has no way to read them, and it cannot cancel, refund or change a booking. Under Anthropic’s commercial terms, what is sent is not used to train its models. Anthropic is on the subprocessors page with the rest.
Your staff
A staff record can name someone who has no Slate login at all, because a schedule needs names on it. Those are your employees and your responsibility — we hold the name because you put it there.
If you connect Google Calendar
Slate stores the account you connected and the access tokens for it, and reads your calendar so existing commitments block out booking slots. The permission requested is read-only: Slate cannot create or change an event in your calendar, and did not ask Google for the ability to. Event titles come back into Slate as busy blocks, and an event title can say anything, so it is worth knowing they land here. Calendar tokens are stored alongside the rest of your organization’s data, under the same access separation, and disconnecting at Google’s end revokes them immediately.
Your guests’ data is yours
You decide what to collect and why; we store and process it for you. That means your guests’ requests come to you first, and where you need us to act on one, you ask and we do it. Section 8 of the Terms of Service covers what that puts on you, including how to get a data processing agreement if your business needs one.
We do collect data. Two counters are always our host's; two more run only if you say yes.
Slate collects and stores real information about real people, because a booking system that held nothing could not hold your booking. Section 2 sets out what is held about a guest and section 3 what is held about a business. Nothing on this page is trying to tell you otherwise.
What matters is the second half: where it goes afterwards. All of it is first-party and internal. It stays inside Slate, it belongs to the business you booked with, and the only companies that ever see any of it are the providers who make the product work — every one of them named, with what they receive and why, on the subprocessors page. Beyond those, it is not passed to anybody. It is never sold, never shared for advertising, and never used to build a profile of you.
On a booking page, an embed, a manage link or inside the console, none of that has changed: there is still no advertising technology of any kind there, and nothing on those pages follows you from one site to another. No PostHog, Segment, Mixpanel, Amplitude, Hotjar, LogRocket or session replay, anywhere in Slate, ever.
There are two analytics counters that need no asking, and both are narrow, and both are our host’s: Vercel Web Analytics, our host’s own page-view counter, on the marketing pages only — this page, the home page, pricing, the demo form and the rest of the public site. It sets no cookie and stores nothing in your browser. It receives the path of the page, the site you came from, your country and the kind of device, and stands in for “the same visitor” with a hash of your connection and browser that our host discards after a day. It never receives the query string, so a campaign label or a search term on a link never reaches it. Vercel already answers every request Slate serves, so this adds no company to the list; what it adds is written into Vercel’s row on the subprocessors page.
The second is Vercel Speed Insights, which measures Core Web Vitals — how fast a page actually loaded and became usable, not who loaded it. It runs on the marketing site, the same pages the page-view counter runs on, and separately inside the operator console, once an operator is signed in with a workspace. It sets no cookie either.
Both counters are, like the first always was, not loaded on any booking page, a manage link or an embedded widget, and the page-view counter is not loaded in the console either. Speed Insights is not loaded in the console either, until an operator has a workspace — the layout that would carry it is the fence itself, and it redirects before rendering anything to anyone without one. Opening a booking page still makes no request to anything but Slate itself. The typefaces are served from our own domain rather than a font host for the same reason.
Added 26 September 2026: two more run, only if you accept
The marketing site — these public pages about Slate, never a business’s own booking page — asks first. A bar at the bottom of the screen offers Accept or Decline; nothing below is requested from Google or Meta until you choose Accept, and choosing Decline, or never choosing at all, means neither is ever requested. See section 4 for exactly what accepting stores in your browser.
If you accept, Google Analytics (Google LLC) counts your visit on this page and every other marketing page. On the get-started page only, accepting also loads a Meta Pixel (Meta Platforms, Inc.), which sends Meta the visit — the page, your browser and device details and your IP address — so Slate can measure and target its own advertising. If you are signed in to Facebook or Instagram in the same browser, Meta can connect that visit to your Meta account. Google Analytics likewise receives the pages you view, your browser and device details and your approximate location. Neither ever receives a guest’s or an operator’s booking data, and neither runs until you say yes.
Both are gated by the same rule as everything above: never on a booking page, an embed, a manage link, or in the console — there is no cookie banner there because there is nothing on those pages that could ask for consent in the first place.
What we do measure: which channel filled the booking
When you make a booking, Slate stores which channel it came from: the host of the site you arrived from — “instagram.com”, not the page you were on — and any campaign labels the business put in their own link. That is it, and it goes no further than the business.
Nothing is recorded if you do not book. There is no session, no identifier, no cookie, and no record of any kind for somebody who opens a booking page and leaves. Nothing follows you anywhere, and the business can see which channels bring them bookings without anyone learning anything about you.
The rest of the address you arrived from — the exact page, and anything you typed into a search box to get there — is thrown away before anything is written down, because that is where a search phrase or a private address would be. Slate keeps the site you came from and nothing else.
If you ask us for a demo, we record which advert sent you
Slate buys advertising. When one of those adverts brings you to our demo request form and you fill it in and send it, we store the campaign labels that were on the link you followed and the host of the site that linked you, alongside the details you typed. That is how we know which advert was worth buying.
Nothing is recorded if you do not send the form. Reading this site, opening the demo page, changing your mind and closing the tab — none of that is written down anywhere, because there is no session, no identifier and no cookie to write it with. The labels are only ever attached to a form somebody chose to submit.
This applies to businesses enquiring about Slate. It has nothing to do with booking a boat, a room or a tour: section 2 covers that, and a guest is never part of any of it.
The subprocessors page lists the 5 ways that was verified, so you do not have to take our word for it.
Text messages
Slate can text you — but only if you asked it to, and only about your own dealings with us. If you tick the box on the demo request form, Slate holds your mobile number, the moment you ticked it, which form it was on, the exact wording you saw next to the box, and a log of every outgoing text and every reply. That is the whole record.
We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. The carrier that delivers the messages sees the number and the text, for delivery and nothing else; it is on the subprocessors page like everyone else. The texts themselves are about your demo, your support requests and service notices. There is no marketing over text, and there is no list you are on by default.
Reply STOP to any message and they stop — at the carrier immediately, and in our record when your reply reaches us. The full terms of the program — who sends, how often, what it costs, how to get help — are on the text messages page.
Who else can see it
Slate’s own owners can see what each business owes in booking fees, and the name of the account it came from. That is how the company knows what it earns. It does not include guests, bookings, customer records or anything else a business would consider theirs, and every look at it is recorded.
11 outside companies, and 1 of them has never been handed anything at all. The full list — what each one does, what it can see, where it is, and whether it is live or dormant — is on its own page, dated and checked against the code:
We do not sell personal data, and we never will. We do not use one operator’s data for another. Operators’ and guests’ booking data — names, contact details, reservations, payments — is never shared for advertising, by us or by anyone we hand it to. The one exception is not that data at all: if you accept the marketing site’s cookie banner, the Meta Pixel on the get-started page sends Meta that visit, with your browser and device details, so Slate can measure and target its own advertising — see section 5. Nothing is shared if you decline, and this has nothing to do with a booking, a guest, or an operator’s own business data. We hand data to a provider when it is needed to run the product for you, or when the law requires it of us.
Where it lives
Slate's database — which holds operator accounts and guest bookings — sits in the United States, in the AWS us-east-1 region in Northern Virginia. Logos, service photos and website photos are stored separately in Supabase Storage, in the same project and region, rather than in the database. That location is measured from the live project, not assumed.
The requests themselves are answered from Washington, D.C. That is measured too, and here is how, because a page that asks you to check its facts should tell you where to look: our host stamps the region it ran in on every response, in the x-vercel-id header, and on 14 August 2026 a request to a booking page and a request to the support page both came back stamped iad1 — the same geography as the database.
Washington, D.C. is Vercel's hosting default for this project, not something pinned in configuration, and Slate's application static files come from Vercel's global edge network. Uploaded photos are delivered separately through Supabase's global content delivery network and may be cached on a server near the visitor. A visitor outside the United States may therefore have the page and an uploaded photo served from outside the United States, while the database and the photo's origin storage remain in Northern Virginia.
Slate's database and the origin storage for uploaded files are in the United States. Vercel's edge network and Supabase's content delivery network operate globally as described above. If your business or your guests are in the UK or EU, sending data to Slate and serving public photos through those networks involves international transfers; write to us about the safeguards your business needs.
How long it is kept, and how deletion actually works
How long: indefinitely, with one exception
There is no retention schedule in Slate. Bookings, customer records, payments and audit entries are kept until somebody asks us to delete them. Nothing expires on a timer, nothing is anonymised after a period, and closing or abandoning an account deletes nothing whatsoever.
The one exception is a short-lived record that holds an email address to stop the same person hammering the booking form. It is cleared two hours later, by a sweep that runs every five minutes. That is the only automatic deletion of personal data in the entire product.
Deletion: real, complete, and done by a person
There is no delete button — not for a guest, not for an operator, not anywhere in the console. Deletion is done by hand, by one of us, and we would rather describe it accurately than dress it up:
- Deleting a whole organization removes it and everything belonging to it, including the permanent records nothing else can touch — the audit log, the message log, signatures. It is the widest erasure the product has, and it is what we do when an owner asks us to erase their business. It does not reach the owner’s own login; see below.
- Deleting a single booking is narrower than it sounds. It removes the booking and what hangs off it, but the customer record — name, email, phone — belongs to the organization rather than to the booking, and it stays. So does the log of any message addressed to that person. If somebody wants their details gone rather than just their reservation, say so, because those are two different operations.
- Some records cannot be edited or partially removed at all. The audit log, the message log and signature records can only ever be added to, never rewritten — that is what makes them worth having. They can go with the whole organization, and not otherwise.
We will complete a deletion within 30 days of establishing that the request is genuine and came from someone entitled to make it — an owner for an organization, or the business for one of its guests.
What deletion covers
An operator's own login is not part of their business. Deleting an organization takes the business with it — every booking, customer, payment, session and audit entry — and leaves the account the owner signs in with. The email address, the hashed password, the name on the profile and the record of each sign-in, including its IP address, belong to the person rather than to the organization, and nothing in the organization delete reaches them. Deleting the login is a second, separate request. Ask for it by name if you want it, and we will do it on the same 30-day footing — we would rather you knew that than assumed it was included.
Deletion clears our own database. Records held by a payment processor stay with the payment processor, and a Google token is revoked at Google, by the operator. Our database host keeps its own backups on its own schedule, and a deleted row ages out of those backups on that schedule.
Your rights, and how to use them today
Depending on where you live you may have rights to see, correct, delete, export, or object to the use of your personal data. We are not going to list statutes we have not had checked. What we can tell you exactly is which of these Slate can perform today and how:
| You want to | Self-serve? | How it actually happens |
|---|---|---|
| See what is held about you | Partly | A guest's manage link shows the name, the email address and the phone number held for them, plus the booking. Anything beyond that: ask, and a person puts it together. |
| Correct something | No | No edit screen exists for a customer record. Ask the business, or ask us, and a person changes it by hand. |
| Delete your data | No | Manual, by a person, within 30 days. The retention section below sets out exactly what each kind of deletion reaches, and what it does not. |
| Get a copy of your data | Operators only | An operator can export their own reports as CSV from the console. A guest asks, and a person prepares it. |
| Object, or ask us to stop | No | Ask. For a booking, the business decides — it is their data and their contract with you. |
| Stop marketing messages | N/A | Slate sends no marketing of any kind, to anyone. There is no list to leave. |
| Stop text messages | Yes | Reply STOP to any text from Slate. It takes effect at the carrier immediately and is recorded against your contact when your reply reaches us. Reply START to opt back in. |
To make any of these requests, write to legal@slate-booking.com. It reaches a person answering from an ordinary mail account and does not run through Slate. Tell us enough to find you: the booking reference, or the business name and the address you booked with.
If you are unhappy with how we handled it, you can complain to your local data protection authority. We would rather you told us first.
How it is protected, and where that stops
- Somebody who has not signed in cannot browse our records. A public booking page and a manage link can ask Slate only a short, fixed list of questions, and each answer is decided one at a time. There is no general way in behind them to fall through to.
- One business can never see another business’s data. That separation is enforced where the records themselves are kept, not by the screens in front of them, so it holds even if a page asks for something it should not.
- Manage links are stored scrambled. We keep a one-way hash of the token, never the link itself, and it can be revoked.
- Error reports are scrubbed before they are written. Email addresses, booking references, tokens, keys, card-length digit runs and phone numbers are stripped, and the web address of the page is reduced to its general shape, so a business name or a manage link never rides along inside it.
What is not protected
A human name written in free text has no pattern to match, so it survives the scrubbing described above. Google calendar tokens are stored without an encryption layer of their own. And a manage link is a bearer key: whoever holds it can act on that booking.
No system is perfectly secure and we are not going to claim this one is.
Things you might expect us to collect, and we do not
For some of these, the space is set aside and the feature that would fill it has not been built. Space set aside collects nothing, and a privacy policy that describes intentions rather than behaviour is worthless, so:
- Acceptance of terms at checkout. Other than a required waiver, Slate does not record that a guest accepted any checkout terms and does not record a consent IP address. If the business requires its waiver before booking, Slate records the name typed, the time, the IP address from the request, the waiver version, whether the signer confirmed that they are agreeing for minors, and, for a PDF waiver, the file’s SHA-256 fingerprint. Slate keeps that record as evidence of the signature, on the business’s behalf. Ask the business first to access it or request deletion, or write to the contact address on this page; a signature record cannot be edited or deleted on its own, as the retention section explains.
- Marketing profiles, lead scores, cross-site identifiers. None of it. A completed booking records the host you arrived from and the business’s own campaign label, and nothing links one booking to another or to you. See section 5.
Children
Slate is business software and a booking page for adults arranging trips. It is not directed at children and we do not knowingly collect data from one. A child’s name might reach a booking if an adult typed it in — that is the operator’s collection, and their responsibility. If you believe a child gave us information directly, write to us and we will remove it.
Changes to this policy
When this policy changes, the new version is published on this page with a new check date at the top. That date is the record.
Slate has no working way to reach you about a change. Our email provider rejects everything, so there is no announcement list we could honestly point you at. Until that is fixed, checking this page is the mechanism, and we would rather say that than imply a channel that does not work.
Contact
The same address handles privacy and data-rights requests. If your question is about a specific booking, name the business and the reference and it will get to the right place faster.