Privacy Policy

What information we collect, how we use it, and who we share it with.

Effective August 8, 2026 · Version 2026-08-08

1. Overview

momentarily is a marketplace where neighbors rent things to each other. It is offered in the United States only.

Who is responsible for your information. momentarily is a service of Project Kaz, LLC, a California limited liability company, doing business as momentarily. That company decides what information momentarily collects and what is done with it, and it is the company answerable for it — the role privacy laws call the controller. Everywhere this policy says "momentarily", "we", "us", or "our", it means Project Kaz, LLC. It is also the company you contract with under our Terms & Conditions. You can write to it — Section 28 has the address.

This policy explains what information momentarily collects, why we collect it, who else sees it, and what you can do about it. It covers everything you do on the site: browsing, creating an account, listing an item, booking, messaging, paying, and asking us for help.

Two things are worth saying at the top, because they shape everything below. We do not sell your personal information, and momentarily carries no advertising of any kind — no ad network, no tracking pixels, no retargeting. We collect what the product needs to work, and not much else.

2. Acceptance and Use

By creating an account, you agree to this policy and to our Terms & Conditions. If you do not agree with it, please do not use momentarily.

When you register we record that you accepted this policy and the Terms, which version of each document you accepted, when, and the version of the 18-or-older confirmation you made. If we publish a materially updated version, that record goes stale on purpose, and we ask you to accept the new version the next time you book or list an item.

momentarily is for adults. You must be at least 18 years old to hold an account — see Section 23.

3. Data Protection Principles

These are the rules we hold ourselves to. Each one describes something the product already does, not something we intend to get around to.

  • Collect only what the product needs. There is no field on momentarily that exists purely to enrich a profile. We do not ask for your date of birth, your government ID, your income, or your contacts.
  • Show the least that works.A listing's public map pin is deliberately offset from where the item actually is. The real street address is released to one person, once a booking is confirmed — the borrower who is coming to pick it up.
  • Keep card data out of our hands. Card numbers go straight to Stripe. We could not leak your card number if we tried, because we never have it.
  • Separate what is public from what is not. Email addresses, phone numbers, and street addresses are locked at the database level so the public parts of the site cannot read them at all, by any query.
  • Never sell it, never advertise on it. Your data is not a revenue stream for us. Our revenue is the service fee on rentals, and that is the whole business model.
  • Let you leave. You can delete your account yourself, from your own settings page, without asking us first.

4. Types of Data We Collect

Nearly everything we hold comes from you, as you use the product.

  • Your account: name, email address, and password. Your password is stored in hashed form by our authentication provider and is never visible to us. You can also add a profile photo, and a mobile number if you choose to verify one.
  • Your listings: title, description, photos, prices, deposit, rules, and the street address where the item is kept.
  • Your bookings and money: dates, prices, fees, deposits, refunds, late fees, payouts, and the status of each payment. Card details go to Stripe, not to us.
  • What you write: messages to other members, reviews and responses, booking request notes, and anything you report to us.
  • Damage claims and disputes: the photos and descriptions either side submits as evidence.
  • Convenience data: saved searches and favorites.
  • Records we keep as proof: which version of the Terms and this policy you accepted and when, and the version of the 18-or-older confirmation you made. If you verify a phone number, we also record the number, the exact consent wording you were shown, the time, your browser type, and the network address the request came from — so we can show that a text was sent with your permission.

About that street address.We need it to make pickup work, but we treat it as the most sensitive thing on the listing. The map on a public listing page does not show it. It shows a point we generate by shifting the real location a quarter to a half mile in a fixed direction, drawn inside a half-mile circle, so the pin never averages back toward the truth no matter how often it is loaded. Public search results show only a locality, like “Pasadena, CA.” The actual address is revealed only to the borrower on a confirmed or in-progress booking, and it disappears again once the item comes back.

5. Non-Personal Information

Some of what we hold is not tied to you, or stops being tied to you once it is added up: how many listings sit in a category, how often a page is viewed, how many searches run in an area, how often a particular error fires. We use this to understand what is working, to fix what is not, and to decide what to build next.

We may publish or share aggregate figures like these — for example, the number of items available in a city. We do not try to re-identify information once it has been aggregated or stripped of identifiers, and we do not ask anyone else to.

6. Information Collected Through Technology

We use cookies to keep you signed in. They are set when you log in, refreshed while you use the site, and cleared when you log out — they are how the site knows a request is coming from your browser and not someone else's. Blocking them will stop you from signing in.

That is the only thing our cookies do. We set no advertising cookies, no cross-site tracking cookies, and no third-party marketing cookies. Your light or dark theme choice is kept in your browser's own local storage and never sent to us.

7. Other Information You May Submit

You may also share information directly with us, such as when you contact support. Whatever you put in that email — screenshots, booking details, an explanation of what went wrong — we keep with the support conversation so we can help you and so we have a record of how the issue was handled.

Please do not send us your card number, your Social Security number, or a photo of your ID. We do not need any of them, and we will ask you to delete the message if you do.

8. Payment Processing and Payment Processor

Payments are processed through Stripe, our payment processor. Card details are collected by Stripe's own form and sent directly to Stripe. We do not store your full card details ourselves, and we never see your card number, security code, or bank credentials. What we keep is the outcome: the amount, the status, and a token Stripe gives us that lets us charge the same card again for a deposit or late fee, within the limits described in our Deposit & Damage Policy.

Owners who want to get paid set up a Stripe account through momentarily. The identity, bank account, and tax information Stripe needs for that goes to Stripe directly — we receive only the account identifier and whether it is cleared to accept charges and payouts. Stripe handles that information as its own controller, under its privacy policy.

9. Automatically-Collected Information

We use Vercel Analytics, which is built into our hosting, to understand how momentarily is used: which pages get visited, roughly where visitors come from, and what sort of device and browser they use. It is not connected to any ad network, and we do not use it to build a profile of you or to follow you onto other sites.

Our hosting and database providers also keep ordinary server logs — IP address, time, the page or query requested, and error details. We use those to keep the service running, to investigate abuse, and to work out what broke when something breaks.

10. How We Use Your Data

We use the information we collect to operate momentarily: creating and securing accounts, processing bookings and payments, facilitating messages between members, sending notifications about your bookings and listings, preventing fraud, and improving the product.

We also use it to review damage claims and disputes, to enforce our Terms and Community Guidelines, and to meet our own legal, tax, and accounting obligations.

Messages between members. Messages you send through momentarily pass through our systems and are stored there, and momentarily staff may read them when we need to investigate a report, a damage claim, a dispute, a payment problem, or a safety concern. That is the same use asserted in Terms Section 14, stated here so it appears in both places. Outside an investigation we do not read your messages, and we never use them for advertising, profiling, or training, and never sell or share them.

Some of that is automatic: a refund amount follows from when you cancelled, and a late fee follows from when the item came back. That is arithmetic applied to the published policy you agreed to — the formulas are set out in full on our Cancellation & Refund Policy and Deposit & Damage Policy pages. Decisions that take judgment rather than arithmetic — a damage claim, a dispute, whether an account should be suspended — are made by a person, and you can always ask us to look again.

11. Remarketing on the Website and Services

momentarily does not do remarketing. We do not place advertising or retargeting tags on any page, we do not build audience or lookalike lists from your activity, and we do not hand your browsing to an ad network so it can show you momentarily ads elsewhere on the internet.

This is not a policy preference we might quietly drop — there is no advertising code in the product at all. If that ever changes, we will rewrite this section and publish the new version of this policy before the first ad tag goes live, and it will say exactly what gets collected, who receives it, and how to opt out.

12. Google AdWords

We do not use Google Ads (formerly Google AdWords), the Google remarketing tag, Google Analytics, Similar Audiences, or the Facebook pixel. None of them appear anywhere in momentarily.

Google is involved in momentarily in exactly one optional way: you may choose to sign in with a Google account, which is covered in Section 17. The fonts on this site are served from our own domain, so loading a page sends nothing to Google.

If we start advertising, this section will be rewritten before we do, on the same terms described in Section 11.

13. With Whom We Share Your Data

Your name, profile photo, and listing details are visible to other members. Your contact details are not.

More precisely, here is what other members can see. Anyone can see your display name, profile photo, your active listings, the reviews you have written and received, and whether your phone is verified. Your email address and your phone number are never released to another member, at any stage of a booking. They are not withheld by convention — the database will not hand those two columns to any member-facing query at all, so there is no page, no export, and no request that could surface them to another member. Owners and borrowers arrange pickup, delivery, and everything else through momentarily's own messaging.

One thing is released when a booking is confirmed, and only one: the item's pickup address becomes visible to the borrower on that booking, so they can come and get it. Nobody else sees it. Before confirmation, and to everyone else after it, the listing shows only a deliberately offset map pin. Listing addresses are never shown on a public page.

We also rely on a small number of companies to run the service. Each one gets only what its job requires, and we do not authorize any of them to use your information for their own marketing:

  • Supabase — our database, sign-in system, and file storage. Effectively everything in this policy lives there.
  • Stripe — all payments, deposit holds, refunds, and payouts to owners.
  • Resend — delivers the email we send you, so it handles your email address and the contents of those messages.
  • Twilio — delivers the one-time verification code when you verify a phone number, so it handles that number.
  • Mapbox — draws our maps and turns an address you type into coordinates. When a map loads, your device talks to Mapbox directly.
  • Vercel — hosts the site and provides the analytics described in Section 9.

Beyond that, we share information only in three situations: when the law requires it or we receive a valid legal request; when we believe in good faith that sharing is necessary to prevent fraud, harm, or a safety emergency; and if momentarily is ever sold or merged, in which case the buyer receives the data and stays bound by this policy until you are told otherwise. If we receive a government or law enforcement request for your information, we will tell you unless we are legally prohibited from doing so.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We never have. We do not sell or share the personal information of consumers under 16, and we have no actual knowledge of doing so.

14. Data Retention

We retain account and booking information for as long as your account is active and as needed for legal, tax, and dispute-resolution purposes.

In practice that means:

  • Account details — kept while your account is open.
  • Bookings, payments, and payouts — kept after your account closes, because they are financial records we are required to be able to produce for tax and accounting purposes.
  • Reviews and completed booking history— kept, because they belong to the other member's record as much as yours. After deletion they are attributed to “Deleted member.”
  • Dispute evidence — kept while the dispute is open and for a reasonable period afterward, in case it is reopened or challenged.
  • Consent records — the record that you accepted the Terms, or consented to a verification text, is kept for as long as it could be needed as proof.
  • Profile photos, phone number, and email address — removed or replaced with a placeholder when you delete your account.

When you delete your account we anonymize rather than erase. Your listings are deactivated, your photo is deleted, your name becomes “Deleted member,” your phone number is removed, your email is replaced with an unusable placeholder, your sessions are ended, and sign-in is permanently blocked. The transaction and review records that other members depend on survive, without your identity attached. This is described again in Section 15.

15. Your Privacy Choices

You can review and update most of your account information from your account settings — your name, your photo, your email address, and your phone number. Listings can be edited or deactivated at any time from your dashboard.

You also control the following:

  • Email. Booking, message, and review emails each have their own switch in your notification settings. Account-integrity email — such as a suspension notice — and security email such as a password reset are always sent, because you need to receive them.
  • Text messages. We only text you a verification code you asked for. Reply STOP to any message to stop them entirely. See our SMS Terms.
  • Your phone number. Verifying one is required to list an item or request a booking, but not to create an account or browse.
  • Deleting your account. There is a delete button in your account settings. You do not have to ask us. You cannot delete while a booking is still live on either side — finish or cancel it first. Deletion cannot be undone, and what survives it is described in Section 14.
  • Everything else. To ask what we hold about you, to have something corrected, or to make any of the requests in Section 22, email us at hello@momentarily.com.

16. Security Measures for Safeguarding Your Information

We use industry-standard safeguards to protect your information, but no online service can guarantee absolute security.

Concretely, the measures that matter most here are:

  • Every connection to momentarily is encrypted in transit.
  • Passwords are stored hashed by our authentication provider. Nobody at momentarily can read your password, and we will never ask you for it.
  • Card numbers never reach our servers, so a breach of momentarily cannot expose them.
  • The database enforces per-row and per-column access rules, so one member cannot read another member's private data even by crafting an unusual request. Email addresses, phone numbers, and listing addresses are excluded from the public interface entirely.
  • Administrative access is limited to the operator of momentarily, and significant administrative actions are recorded in an append-only audit log.

18. California / Delaware Do Not Track Disclosures

Some browsers can send a “Do Not Track” signal. There is still no agreed industry standard for what a site should do when it receives one, so momentarily does not respond to Do Not Track signals. California and Delaware law require us to tell you that plainly, so we have.

What matters more is that we do not do the thing Do Not Track was invented to stop. We do not track you across other websites. We do not allow any third party to collect personally identifiable information about your activity across different sites through momentarily, because there is no third-party tracking code on our pages to do it with.

The same goes for the Global Privacy Control signal. Since we do not sell or share personal information, there is nothing for it to switch off. If we ever start, we will honor it as an opt-out.

19. Emails Communications

Today, momentarily sends email for one reason: to tell you about something that happened in your account. That includes booking requests, approvals, declines, and cancellations; payment receipts, refunds, and payout notices; messages another member sent you; review notices; and account notices such as a suspension or a listing being removed. Sign-in and security email — password resets, email-change confirmations — comes from our authentication provider.

You can switch off booking, message, and review email in your notification settings. Account and security email is always sent, because an account you cannot be told about is worse than an inbox with one more message in it.

We do not send newsletters, promotions, or marketing email, and we do not maintain a marketing list. If that changes, see Section 25 for what we commit to.

We will never email you asking for your password, your card number, or a verification code. If you receive a message like that claiming to be from momentarily, it is not from us — please forward it to hello@momentarily.com.

20. Data Security

We use industry-standard safeguards to protect your information, but no online service can guarantee absolute security. Section 16 lists the specific measures; this section covers what happens if they fail, and what we need from you.

If there is a breach. If personal information is exposed in a security incident, we will investigate, fix the cause, and notify the people affected without unreasonable delay — by email to the address on the account — along with any regulator the law requires us to inform. We will tell you what happened, what information was involved, and what we recommend you do. We will not quietly sit on it.

What we need from you. Use a password you do not use anywhere else, and do not share it. Keep your verification codes to yourself — we will never ask for one. Keep booking conversations on momentarily rather than moving them to another app, both because it is safer and because it means we can actually help if something goes wrong. If you think someone has your password, change it and email us.

21. GDPR Statement (EEA Users)

momentarily is a United States service. Listings are US-only, payouts are US-only, and verification texts go only to US and Canadian numbers. We do not market the service in the European Economic Area, the United Kingdom, or Switzerland, we do not offer it there, and we have not appointed a representative in those regions.

We would rather be useful than technical about this. If you are in the EEA or the UK and you hold a momentarily account, write to us and we will handle your request the way the GDPR describes: tell you what we hold, correct it, delete it, give you a copy in a portable format, restrict a particular use, or stop it. We will do that whether or not we are required to.

The controller of that information, in the GDPR's sense of the word, is Project Kaz, LLC, a California limited liability company, at the address in Section 28. We have not appointed an Article 27 representative in the EEA or the UK, for the reason given above.

Where we do process the information of someone in those regions, our grounds are: performing the contract you entered into when you booked or listed an item; our legitimate interest in preventing fraud and keeping the service working; our legal obligations, particularly around payment and tax records; and your consent, where you gave it — for example, verification texts, which you can withdraw at any time by replying STOP.

22. California Resident Rights (CCPA)

We are based in California, and California has the strongest consumer privacy law in the country. Rather than argue about whether momentarily is yet large enough for that law to apply to it, we give every momentarily user the rights it describes. If you are a California resident, these are yours by law; if you are not, we will honor them anyway.

You can ask us to:

  • Tell you what personal information we have collected about you, and why.
  • Give you a copy of it.
  • Correct anything that is wrong.
  • Delete it, subject to the records described in Section 14.
  • Stop selling or sharing it — which is already the case, since we do neither.
  • Limit how we use sensitive personal information, described below.

What we collect, in the law's categories. Identifiers (your name, email address, phone number, account identifier, IP address); commercial information (your listings, bookings, and transactions); internet activity (pages you view and searches you run on momentarily); geolocation (the address on a listing, and the approximate area an IP address suggests); financial information (handled by Stripe, not held by us); and visual information (photos you upload). We do not collect biometric data, health data, precise device location, or information about your race, religion, politics, union membership, sex life, or immigration status, and we do not generate inferences or profiles about you. We collect it from you, from your device as you use the site, from Stripe when a payment succeeds or fails, and from Google or Microsoft if you choose to sign in that way. Who receives it is listed in Section 13.

Sensitive personal information.Two things we hold fall into that category: your account credentials, and the exact address on a listing. We use your credentials to sign you in, and the address to generate the offset public map pin and to give a confirmed borrower pickup details — nothing else. We never use either to infer characteristics about you, and we never disclose either for advertising, which is why there is no separate “limit” switch to offer you.

We have not sold or shared personal information in the last twelve months, and we have never disclosed it to a third party for that party's own direct marketing — which also answers California's “Shine the Light” law.

How to make a request. Email hello@momentarily.com and say what you want, or write to us at the address in Section 28 — a request on paper carries exactly the same weight as one by email, and we answer both on the same clock. We will confirm we received it within 10 business days and answer within 45 days. If a request is genuinely complicated we may take up to another 45 days, and we will tell you why before the first 45 are up. To verify it is really you, we will ask you to send the request from the email address on the account, or to confirm details only the account holder would know; if we cannot verify you, we will say so rather than guess. An authorized agent may act for you with your written permission.

We will not treat you differently for exercising any of this. No price change, no worse service, no penalty of any kind.

23. Children's Online Privacy Protection Act (COPPA)

momentarily is for adults. You must be 18 or older to create an account, and you confirm that when you register. The service is not directed to children, it is not designed to appeal to them, and we do not knowingly collect personal information from anyone under 18 — and certainly not from anyone under 13, which is what the Children's Online Privacy Protection Act specifically covers.

We do not ask for a date of birth, so the age requirement rests on what you tell us when you sign up. If we learn that an account belongs to someone under 18, we suspend it and take any listings on it down, and we delete or anonymize the personal information we hold — except records we are required to keep, such as a completed payment.

If you are a parent or guardian and you believe your child has created an account or given us information, email hello@momentarily.com and we will take care of it promptly. You do not need to prove anything first — tell us, and we will act.

24. Fair Information Practices

The Fair Information Practice Principles are the backbone of most privacy law in the United States. Here is how each one shows up in momentarily.

  • Notice. This page tells you what we collect before you give it to us, and we update it before we start collecting something new — not after.
  • Choice. You choose what to list, what to write, and whether to verify a phone. You control which emails you get, and you can delete your account yourself. See Section 15.
  • Access and accuracy. Most of what we hold is editable from your settings. For the rest, ask us and we will tell you what we have and fix what is wrong.
  • Security. Described in Section 16, with our breach commitment in Section 20.
  • Enforcement and redress. If you think we have handled your information badly, Section 26 explains how to complain to us and where to go if our answer is not good enough.

25. CAN-SPAM Act

The CAN-SPAM Act sets the rules for commercial email. We collect your email address to run your account — to sign you in, to send booking and payment notices, and to answer you when you write to us.

momentarily sends only transactional email today. Every message we send is about something that happened in your account, as described in Section 19. We do not run promotions, we do not send a newsletter, and we do not have a marketing list to put you on.

If we ever do send marketing email, we commit to all of the following, and this section will be updated before the first one goes out:

  • Honest sender names, subject lines, and headers — no tricks to get it opened.
  • A clear label that the message is an advertisement, where that applies.
  • Our physical mailing address in the message — the one in Section 28.
  • A visible, working unsubscribe link in every one.
  • Unsubscribes honored promptly and in any event within 10 business days, with no attempt to talk you out of it.
  • Your address never sold, rented, or handed to anyone else for their own marketing.

Unsubscribing from marketing would never stop the transactional email you need — a booking confirmation is not an advertisement, and you would still get it. To reduce email now, use the switches in your notification settings; to stop all of it, delete your account.

26. Privacy Complaints Procedure

If you think momentarily has mishandled your information, tell us. Email hello@momentarily.comwith “Privacy” in the subject line, or write to us at the address in Section 28, and include what happened, when, and what you would like us to do about it. Writing from the email address on your account is the fastest way for us to confirm it is you. A complaint sent by post is handled the same way and on the same clock as one sent by email.

We will confirm we received your complaint within 10 business days and give you a substantive answer within 45 days. If we need longer, we will tell you why before those 45 days are up, and take no more than another 45. If we decide we cannot do what you asked, we will explain the reason rather than just declining.

If we deny a privacy request, you can ask us to reconsider by replying to our decision. We'll review it and answer within 45 days.

If our answer does not satisfy you, you can escalate. California residents can complain to the California Privacy Protection Agency (cppa.ca.gov) or the California Attorney General's office (oag.ca.gov). Anyone in the United States can complain to the Federal Trade Commission (ftc.gov). If you are in the EEA or the UK, you can complain to your local data protection authority.

Complaining costs you nothing and will not affect your account, your listings, or how we treat you.

27. Changes to This Privacy Policy

We will update this page as momentarily changes. The effective date and version number at the top always tell you which version you are reading.

For small changes — clearer wording, a provider swapped for another doing the same job — we update the page and the date, and that is it.

For material changes — a new category of information, a new purpose, a new kind of sharing, or anything to do with advertising — we will tell you before it takes effect, by email to the address on your account or by a notice in the app. We will also raise this policy's version, which means you will be asked to accept the new version the next time you book or list an item.

We will not apply a materially new use to information we already collected without giving you that notice first. If you would like a copy of the version you originally accepted, ask us and we will send it.

28. Contact momentarily

momentarily is a service of Project Kaz, LLC, a California limited liability company, doing business as momentarily. That company is responsible for the information described in this policy — see Section 1.

Questions about this policy or your data can be sent to hello@momentarily.com, or written to us at:

Attn: Privacy
Project Kaz, LLC
4001 S Inglewood Ave

Bldg 101, PMB 248

Redondo Beach, CA 90278, US

Every request, complaint, and appeal this policy describes can be made either way. Post is slower, but it is not lesser: we treat a letter exactly as we treat an email, and the deadlines in Section 22 and Section 26 run from the day it reaches us. Please put a reply address on it, because a letter with no way to answer it is one we cannot act on.

Formal service of process does not come to this address — it goes to our registered agent, published in Terms & Conditions Section 2.

momentarily is a service of Project Kaz, LLC, a California limited liability company. On this page, "momentarily", "we", "us", and "our" mean that company.

Written notices go to:

Project Kaz, LLC
4001 S Inglewood Ave

Bldg 101, PMB 248

Redondo Beach, CA 90278, US

Formal service of process goes to our registered agent instead — see Terms & Conditions Section 2. How notice works in both directions, and when a notice counts as given, is in Section 28.