Help

If Session became unavailable

What happens to your bookings, your money and your data if the platform or the person behind it stopped - and why you don't have to take any of it on trust.

4 min read

Session is a small, founder-led company, and any venue running a proper risk assessment should ask what happens if that founder is unavailable. This page answers it plainly, because the answer is better than most people expect and none of it rests on a promise you would have to take on trust.

Four things are worth separating, because they carry very different levels of risk.

The platform keeps running on its own

Session runs on mainstream managed infrastructure - Vercel for the app, Supabase for the database, Stripe for payments and Clerk for sign-ins. There is no server in anyone's flat and no daily manual step at our end.

Your booking page, your checkout, confirmation emails, reminders, waiting-list notifications and reports all run automatically. If the person behind Session were unavailable for a month, your venue would keep taking bookings and keep getting paid exactly as it does now. What you would lose in that window is support and new features, not the service.

Your money is never ours to lose

Payments run through your own Stripe account under Stripe Connect. Money goes from your customer straight into your account. Session never holds it and it never passes through us.

That means your payment history, your payouts, your disputes, your customers' saved cards and your live membership subscriptions all sit in Stripe in your name. Nothing that happens to Session touches any of it.

Note

This is a genuinely different position from a booking platform that collects on your behalf and pays you out on a schedule. There, a shutdown traps the money. Here, there is no money of yours for us to trap. See connecting Stripe.

Your data is one button away, today

You can take a complete copy of everything Session holds for your venue at any time, without asking anyone: Settings → Data, then Download export.

One button, no date range and no form. Every booking, every customer, every signed waiver, your whole timetable, your prices and your settings, as spreadsheets plus a full database copy a developer could import elsewhere.

That is deliberate. Leaving should never depend on us being reachable, so the honest answer to "what if you disappear?" is a button you already have rather than a process you would have to start. See exporting all your data.

There is a second person

Session is a one-person company day to day, and pretending otherwise would be worse than useless in a risk assessment. So: a second person, a former business partner who knows the business, holds full access to the codebase and to every platform account behind Session, and would step in if the founder were unavailable for an extended period.

It also helps that nothing here is exotic. Session is built on a standard, widely used stack, the code lives in a private repository with its full history, and the database is backed up twice over - the hosting provider's own daily backups plus a separate weekly copy kept outside that provider, so the host is not a single point of failure either. Picking it up is a job for a competent web developer rather than a specialist.

What we commit to in writing

Our Data Processing Agreement puts the important parts into a contract rather than a page like this one:

  • Section 13 - business continuity, covering the second person's access, the independent off-platform backup, and the fact that we never hold your funds.
  • Section 10.4 - if Session ever stops providing the platform, you get at least 90 days' notice and a complete export available throughout that period.
  • Sections 10.1 to 10.3 - you can export at any time during your term and for 30 days after it ends, after which your data is deleted, apart from records we are required to keep for tax.

If you need a signed copy for your records or your risk register, ask and we will send one.

Common questions

  1. Who else has access to the code and infrastructure? The founder, and a second person who holds full access to everything and could take the platform over. We don't name them publicly, but the arrangement is written into section 13 of our Data Processing Agreement.

  2. What happens to bookings already taken if Session goes down for a day? Nothing is lost. Bookings and payments are stored in the database and in your Stripe account, both of which sit with established providers and are backed up independently of us.

  3. Could we move to another booking system? Yes, and the export is designed for it. Your customers, bookings, waivers, timetable and prices all come out in open formats. Your Stripe account and its subscriptions stay yours regardless, so the payment side needs no migration at all.

  4. What is the hardest thing to replace? Your booking page address. Pages live at bookasession.org/your-venue, so posters, QR codes and search results point at us. Anything printed would need reprinting on a move. Everything else is portable.

  5. Where is our data held? Customer and booking data is stored in the European Economic Area (Republic of Ireland). See data protection for the full list of providers and where each one sits.

  6. Can we get a copy of the DPA to sign? Yes - it is published in full at bookasession.org/dpa, and we will send a signed copy on request.