Skip to content
*The Space Place
HomeThe House / GalleryMeet the HostsGuidesContact / FAQManage ReservationBook Now
HomeThe House / GalleryMeet the HostsGuidesContact / FAQManage ReservationBook Now

Legal

Privacy Policy

Last updated: July 9, 2026

On this page

Who Controls DataInformation We CollectHow We Use InformationCookies & AnalyticsBrowser StorageID & AddressGoogle OAuthService ProvidersRights & SignalsContact
On this page
Who Controls DataInformation We CollectHow We Use InformationCookies & AnalyticsBrowser StorageID & AddressGoogle OAuthService ProvidersRights & SignalsContact
Check AvailabilityContact Host

Who Controls Your Data

The Space Place operates this website and related booking workflows. We are based in Broken Arrow, Oklahoma, United States.

Information We Collect

We collect information needed to run reservations, support guests, and maintain website security. This includes:

  • Booking and contact details such as name, email, phone number, stay dates, and guest count.
  • Address information needed for reservation security, taxes or accounting where applicable, chargeback response, damage recovery, and lawful claims. This may come from Stripe, Hospitable, a booking platform, or direct guest communication.
  • If you choose optional guest autofill, identity profile fields from your OAuth provider (such as Google account subject identifier, name, and email).
  • Reservation and transaction records required to process and support bookings, including accepted terms version, cancellation-policy acceptance, timestamps, checkout session identifiers, Stripe payment identifiers, and reservation identifiers.
  • Identity-verification records for direct bookings, including Stripe Identity verification session identifiers, verification status, and related audit metadata. Stripe may collect government ID images, extracted document data, and selfie/face-match information inside its verification flow.
  • Technical and interaction data such as IP address, device/browser type, referrer, routes visited, scroll milestones, and link interactions.
  • Privacy preference data used to remember your optional analytics choice.
  • Booking telemetry such as checkout session identifiers, stay dates, guest counts, quote values, and booking-status events.
  • Security and anti-abuse signals such as rate-limit outcomes, Turnstile verification outcomes, and pseudonymized operational identifiers used for reliability monitoring.

How We Use Information

  • Process reservations, confirmations, and stay-related communication.
  • Respond to pre-booking and post-booking support requests.
  • Prevent abuse, enforce policies, and protect website security.
  • Verify guest identity, maintain chargeback/dispute evidence, and support lawful damage recovery or small-claims processes when needed.
  • Measure and improve site performance when analytics consent is granted.
  • Analyze how visitors navigate the site, how they reached the site, and which outbound booking links they use.
  • If you choose guest autofill, apply returned profile fields to speed up checkout and keep fraud/replay safeguards tied to your checkout session.

Legal Bases

  • Contract performance for booking-related processing.
  • Legitimate interests for site security and operational reliability.
  • Consent for optional analytics technologies.
  • Legal compliance for tax, accounting, and regulatory requirements.

Cookies and Analytics

We use essential storage/technologies for security and session behavior, plus optional analytics technologies for measurement. On first visit, you can accept or decline optional analytics; this preference is stored in browser local storage and can be changed later from the Privacy settings control shown on the site.

  • When optional analytics is enabled, we send site analytics events to PostHog and Google (via Google Tag Manager / GA4), including page/route views, referrer data, route transitions, scroll milestones, click interactions, and outbound destination links.
  • Sensitive checkout query parameters (including sessionId, checkout_session_id, stripe_checkout_session_id, statusToken, and redirectToken and snake_case variants) are redacted before client analytics payloads are sent.
  • Separate server-side operational analytics events are also sent to PostHog for checkout reliability, abuse prevention, and conversion monitoring. These events may include checkout/session/reservation identifiers and pseudonymized IP or email identifiers. These operational events are used even when optional analytics is declined.
  • Advertising-related consent signals are set to denied (ad_storage, ad_user_data, and ad_personalization).

Browser Storage and Session Data

  • We use localStorage to remember your optional analytics consent setting.
  • During checkout, we use sessionStorage to keep short-lived checkout status tokens and redirect tokens on your current browser session.
  • If you use price alerts, we may store alert preferences and an alert contact token in localStorage so you can manage alerts without re-entering details each time.
  • You can clear browser storage in your browser settings at any time, which may require re-entering preferences or restarting checkout steps.

Identity, Address, and Dispute Records

Direct bookings require identity verification. We use Stripe Identity where available so Stripe can collect and verify a government-issued photo ID and a matching selfie/photo through Stripe's secure flow. Our system stores the verification session identifier, verification status, checkout session, policy-version acceptance, and related audit metadata. We do not ask guests to send ID photos by email or text.

Stripe Identity may retain verification reports and collected verification data under Stripe's own policies. We may access provider records or reports when needed for fraud prevention, reservation security, chargeback response, damage recovery, legal compliance, or lawful claims.

We may collect or receive a current guest address from Stripe, Hospitable, booking platforms, or direct guest communication. Our preference is to write address details into the reservation provider record when the provider supports it. If we must store address details in our own booking records, access should be limited to authorized operations, support, accounting, and dispute/legal users with a need to know.

Google OAuth and Google API Services

When you choose Use Google Autofill during checkout, The Space Place requests Google account data through OAuth under scope openid email profile. This request is made by our checkout application on our domain and configured Google OAuth client.

  • Data requested/received: Google account subject identifier (sub), email address, first/last name, and display-name profile claims needed to complete checkout autofill.
  • Primary use: fill missing checkout guest fields (name and email) and connect the OAuth response to the active checkout session.
  • Secondary operational use: prevent replay/abuse and maintain reliable booking audit records.
  • We do not request Gmail, Drive, Calendar, Contacts, or other non-profile Google API scopes in this guest autofill flow.
  • We store a hashed Google subject identifier plus checkout-linked profile records (email and first/last name claims) used for autofill reliability, replay/abuse safeguards, and booking audit records. We do not store Google access tokens or refresh tokens after the exchange completes.
  • Google autofill data follows the sharing and retention rules in this policy and is not sold.

Google autofill is optional. You can always continue checkout manually, and you can revoke The Space Place access in your Google account security settings.

If we plan to request new Google data types or use Google user data for a new purpose, we will update this policy and request consent before that new use.

Service Providers We Use

  • Hospitable for booking checkout, quotes, reservation records, and reservation operations.
  • Stripe for embedded checkout payments, payment events, phone/address collection where configured, chargeback/dispute records, and Stripe Identity verification.
  • Cloudflare for hosting, edge security, and request handling.
  • Cloudflare Turnstile for bot-detection checks in checkout flows.
  • PostHog for consented client analytics and server-side operational analytics.
  • Google Tag Manager and Google Analytics (GA4) for optional analytics measurement.
  • Google OAuth for optional guest autofill using basic profile and email scopes.
  • Resend for transactional and price-alert email delivery.
  • Twilio for transactional SMS delivery and SMS reply handling.
  • Accounting, tax, smart-lock, and stay-operations providers used for booking operations.

How Information Is Shared

We share data only with service providers required to operate the site and reservation workflow. If you continue to third-party booking pages, we may pass limited technical context, such as a checkout session identifier, to preserve booking continuity. We may share booking, payment, identity-verification, address, and evidence records with payment processors, booking platforms, insurers, accountants, legal advisors, courts, or service providers when needed to process a reservation, respond to disputes, recover documented damages, comply with law, or protect the property and guests. We do not sell personal information.

Data Retention

We retain data only as long as needed for booking operations, support, fraud prevention, dispute response, damage recovery, tax/accounting, and legal obligations. This includes checkout-linked OAuth profile records used for guest autofill and replay/fraud safeguards, identity-verification status records, address records when required, and terms-acceptance audit records. Some booking, transaction, identity-reference, and audit records may be retained for up to seven years where required or reasonably needed.

Your Privacy Rights

Depending on your location, you may have rights to access, correct, delete, or obtain a copy of personal information, and to appeal certain decisions. To make a request, contact us using the details below.

Where required by law, we also process recognized browser-based opt-out preference signals (such as Global Privacy Control) as requests to opt out of optional analytics and related data sharing.

Children's Privacy

This website and booking process are intended for adults arranging travel. We do not knowingly collect personal information directly from children under 13.

Contact and Updates

We may update this policy when business or legal requirements change. For privacy requests, email support@thespaceplace.us.

The Space Place

Tulsa's immersive galactic getaway in Broken Arrow, Oklahoma.

Explore

  • The House / Gallery
  • Meet the Hosts
  • Local Guides
  • Book Now

Planning Help

  • Contact / FAQ
  • Privacy Policy
  • Terms of Service