Legal · Privacy
Privacy Policy
Effective: July 24, 2026 · Last updated: July 24, 2026
Third Space is an insurance broker and risk manager for bars, venues, clubs, and other hospitality businesses. We lower what these businesses pay for insurance by helping them run more safely, and we place and service their coverage. This policy explains what information we handle, why we handle it, and the choices you have. We have written it to be read. The legal substance is here, but we have tried not to bury it.
1. Who we are and what this covers
This policy describes how Third Space Holdings, Inc., a Delaware corporation (“Third Space,” “we,” “us,” or “our”), handles information in connection with:
- our brokerage services (assessing your coverage, preparing submissions, obtaining quotes, and placing and servicing insurance policies);
- our risk-management platform (loss control, document storage, incident capture over SMS and web, camera-footage preservation, shift reports, and your Savings Score);
- our website; and
- related services (together, the “Services”).
Third Space Holdings, Inc. is a licensed New York insurance broker (BR-1956934) and excess line broker (EX-1956934).
Our Services are designed for hospitality businesses in the United States. We do not direct the Services to individuals outside the United States and do not knowingly handle their information in connection with the Services.
2. Our role with your data
Third Space works with two broad kinds of information, and our legal role differs between them.
When we act on your behalf (service provider). When a customer uses the platform to manage its own operations, such as running incident reports about its staff or storing its documents, the customer decides what to collect and why. For that information the customer is the controller, and Third Space acts as a service provider (processor) under a written agreement, using the information only to provide the Services to that customer.
When we act for ourselves (controller). When we use information to give you brokerage advice, prepare and send submissions to insurers, place and service coverage, price and reduce risk, operate and secure the platform, and run our own business, Third Space is a controller of that information. This policy governs that processing.
What this means if you are an individual. If you are a staff member, patron, or other individual whose information a business gave us to manage on its behalf, and you want to access, correct, or delete that information, please contact that business first. It is best positioned to respond, and we will support it. If you interact with Third Space directly (for example, as a platform user, a website visitor, or someone who emails us), you can contact us using the details in Section 13.
3. Information we handle
From customers, to provide brokerage and risk services. To assess your risk, place your coverage, and help you run more safely, we collect business and operational information such as: business and ownership details; licenses, permits, and certificates; current and prior insurance policies and loss runs; financial information relevant to your coverage; premises information; and operating data from systems you choose to connect, which may include point-of-sale, scheduling, or human-resources systems.
Risk-management and evidence data. Through the platform we handle: incident reports (descriptions, dates and times, locations, witnesses, photographs, and documents); camera footage that you or we preserve in connection with an incident; scanned identity documents where your operations capture them, for example ID checks at the door; shift reports; and the contents of your document vault.
Information about staff, patrons, and other individuals. Because footage and incident files capture real events at a venue, the information we handle can include personal information about a customer’s staff, its guests and patrons, and other third parties, such as names, images, contact details, and the details of an incident. The business that operates the venue is responsible for providing these individuals any notice they are owed, and we support it in doing so.
From authorized platform users. For the people at a customer who log in (managers, HR, risk administrators, owners), we collect account information including name, work email, work phone number, role, and authentication data.
From SMS. For incident messaging we handle mobile phone numbers, message content, records of consent, and delivery and opt-out status. See Section 4.
From our website. When you visit our website we automatically collect limited technical information needed to run it, including IP address, browser type, and pages visited. We use only essential cookies required for the site and platform to function, such as authentication and session cookies. We do not use advertising cookies, marketing pixels, or third-party tracking.
When you contact us. If you email us or reach out through the website, we receive what you choose to provide, such as your name, email, company, and the contents of your message.
Sensitive information. Some of what we handle, such as identity documents and images, can be sensitive, and we handle it with corresponding care.
4. SMS messaging
Third Space delivers SMS text messages to staff members on behalf of their employers, for the purpose of workplace incident reporting. These messages may include a manager’s request for more detail about an incident, follow-up questions, status updates, and links to complete incident forms.
How consent is collected. SMS messaging is opt-in. Employers must collect express written consent from each staff member before adding that person’s mobile number to the platform, using a standard consent form provided by Third Space and signed as part of onboarding. A number is added only after consent has been signed and recorded.
Opting out. You may opt out at any time by replying STOP (or STOPALL, UNSUBSCRIBE, CANCEL, END, or QUIT) to any message. We will send one final confirmation and will not message that number again. Reply HELP for help, or START to re-subscribe.
What we do with phone numbers. Phone numbers and message content are used only to deliver the incident communications described above and to run the underlying service, such as recording delivery and opt-out status. We do not sell mobile phone numbers or SMS content. Mobile information is not shared with third parties or affiliates for their own marketing or promotional purposes. To deliver messages we use a telecommunications provider (currently Twilio Inc.) that handles the message and number as a service provider on our behalf.
5. How we use information
We use information to:
- Provide brokerage services: assess your coverage needs, prepare and send submissions to insurers, obtain quotes, place policies, and manage servicing and renewals.
- Provide risk-management services: operate loss control, capture and preserve incident evidence, generate your Savings Score, and assemble defense-ready incident files.
- Assess and price risk, and improve our models: we use loss, incident, and operating data to understand and reduce risk, to support underwriting and pricing, and to improve our own risk models. We do not sell this information, and we do not use customer content to train general-purpose AI models. Where we use it to develop or improve our own risk models, we work with aggregated or de-identified information where feasible.
- Support you: respond to requests, troubleshoot, and help configure accounts.
- Keep the Services secure: detect and prevent unauthorized access, fraud, and abuse, and maintain audit logs.
- Meet legal and regulatory obligations: including our obligations as a licensed insurance producer, and responding to lawful requests.
6. How we share information
We share information only in the circumstances below.
- With the customer. Information tied to a customer is available to that customer’s authorized users in the platform. We do not share one customer’s information with another.
- With insurers and insurance intermediaries. To obtain quotes and to place and service your coverage, we share the information insurers need with carriers, wholesalers, managing general agents, and reinsurers. Those parties handle your information under their own legal and regulatory obligations.
- With service providers (sub-processors). We use a limited set of vetted vendors to run the Services, including Amazon Web Services, Inc. (cloud hosting) and Twilio Inc. (SMS delivery), along with providers of authentication, monitoring, and support tooling. These vendors are bound by written agreements that limit their use of information to providing services to us.
- For legal reasons. We may disclose information when we believe in good faith that it is required by law, legal process, or a lawful government request, or to protect the rights, property, or safety of Third Space, our customers, or others.
- In a business transaction. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of it, subject to confidentiality protections and this policy.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
7. Data retention
Insurance and incident records often must be kept to meet insurance, employment, workplace-safety, and other legal obligations. These periods commonly run seven years or longer from the relevant date. We keep insurance and incident-related information for the period we or the customer are required or reasonably need to keep it, plus a short additional period for archival, audit, and dispute-resolution needs.
Camera footage and identity documents are kept only as long as needed for the incident or legal obligation they relate to, and then deleted. For other information, such as platform accounts, website inquiries, and SMS opt-out records, we keep it for as long as needed for the purpose it was collected and then delete or de-identify it. We keep opt-out records for as long as needed to honor the opt-out, which may be indefinite.
8. Security
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include encryption of data in transit and at rest, role-based access controls, multi-factor authentication for platform access, audit logging, regular security reviews, and vendor due diligence. Our infrastructure is hosted on Amazon Web Services in the United States. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security, but we work continuously to maintain strong practices.
9. Your choices and rights
Depending on where you live and your relationship with us, you may have rights to access, correct, delete, or restrict the use of your personal information, to opt out of certain processing, and to complain to your state regulator.
- If you are a staff member, patron, or other individual whose information a business manages through us, please direct requests to that business first. It is the controller and is best positioned to respond, and we will support it.
- If you are a platform user, website visitor, or otherwise deal with us directly, contact us using the details in Section 13 and we will respond as applicable law requires. We may need to verify your identity first.
10. State privacy disclosures
California. This section provides disclosures under the California Consumer Privacy Act, as amended (the “CCPA”). In the preceding twelve months we have collected these categories of personal information: identifiers (such as name and contact details); commercial information (records of customer relationships); employment-related and other information contained in incident reports, footage, and operating data provided through the Services; financial information relevant to insurance; audio and visual information (camera footage); identity-document information where captured; internet or network activity (limited website technical data); and inferences drawn from the above to operate the Services. Sources, purposes, and recipients are described in Sections 3, 5, and 6.
We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA. Subject to exceptions, California residents may request to know, correct, or delete personal information, limit the use of sensitive personal information, and not be discriminated against for exercising these rights. To exercise them, contact us using Section 13. You may use an authorized agent.
Other states. Residents of other states with comprehensive privacy laws may have similar rights, which we honor as those laws require.
11. Insurance privacy
As a licensed insurance producer, Third Space handles nonpublic personal information in connection with insurance transactions, and that information is also subject to federal and state insurance privacy laws. Where those laws require a separate privacy notice, we provide it.
12. Children
The Services are not directed to children under 16, and we do not knowingly collect their personal information. Footage taken at a venue may incidentally capture minors, and we handle that footage under the same protections and retention limits described in this policy. If you believe a child has provided us information directly, contact us and we will take steps to delete it.
13. Changes and contact
Changes. We may update this policy from time to time. When we do, we will update the “Last updated” date, and for material changes we will provide reasonable additional notice, for example by notifying customers through the platform or by email.
Entity
Third Space Holdings, Inc.
Privacy email
Mailing
134 North 4th St.
Brooklyn, NY 11249