Privacy Policy

Privacy policy (starter template)

RCW Concepts LLC · Last updated [DATE]

1. Who We Are & Scope

This Privacy Policy explains how RCW Concepts LLC (“VenuePal,” “we,” “us”) collects, uses, and shares information in connection with the VenuePal platform, websites, and mobile/web applications (the “Service”). It applies to (a) event organizers and their staff who use the Service, and (b) attendees who use an organizer’s branded event app.

For attendee information that an organizer inputs or collects through the Service, the organizer is the controller and VenuePal acts as its processor/service provider. If you are an attendee, please also review the organizer’s own privacy notice.

2. Information We Collect

Account & staff information.

When you create an account or are invited to a workspace, we collect your name, email address, password credentials, role, and workspace membership.

Event & attendee information.

Organizers use the Service to store event information and information about attendees, which may include names, contact details, company/title, ticket and registration responses, session selections, check-in/attendance records, and optional dietary or accessibility notes. Organizers decide what to collect.

Usage & device information.

We collect standard log and device data (for example, IP address, browser/device type, pages viewed, and timestamps) to operate and secure the Service.

Information from integrations.

If an organizer connects a third-party service (for example, a CRM or calendar), we may receive information from that service as configured by the organizer.

On-device attendee data.

The attendee app stores certain preferences locally on the attendee’s own device (for example, saved sessions, notification and dietary preferences, and saved networking contacts). This data lives on the device and is not tied to an account.

3. How We Use Information

We use information to: provide, operate, secure, and improve the Service; authenticate users and manage workspaces; enable event operations such as registration, check-in, badges, streaming, and attendee communications; provide support; comply with legal obligations; and detect and prevent fraud, abuse, and security incidents.

We do not sell personal information. [Confirm with counsel; adjust for CCPA/CPRA “sale”/“share” definitions.]

4. How Information Is Shared

We share information: with service providers and subprocessors who host and support the Service (see “Subprocessors”); with the organizer of an event (for attendee information related to that event); with third-party services you or the organizer choose to connect; when required by law or to protect rights, safety, and the integrity of the Service; and in connection with a merger, acquisition, or sale of assets, subject to this Policy.

5. Attendee Data & the Organizer Relationship

Attendee personal information processed through the Service is handled on behalf of, and under the instructions of, the event organizer. We process it to provide the Service and do not use it for our own independent marketing. Requests from attendees to access, correct, or delete their information are generally directed to the organizer; we will assist organizers in responding as required by law.

6. Cookies, Local Storage & Analytics

We use cookies and similar technologies (including browser local storage) to keep you signed in, remember preferences, and understand usage. The attendee app relies on device local storage for the per-device features described above. You can control cookies through your browser settings; some features may not work without them. [List any analytics providers and cookie categories; add a cookie banner/consent mechanism where required.]

7. Data Retention

We retain account and event information for as long as the workspace is active and as needed to provide the Service, then for [RETENTION PERIOD] or as required by law. Organizers can delete event data through the Service; we may retain limited records as needed for legal, security, and accounting purposes.

8. Security

We use reasonable administrative, technical, and physical safeguards designed to protect information, including encryption in transit and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your Rights & Choices

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise a right, contact us at [PRIVACY EMAIL]; attendees should typically contact the event organizer first. We will respond as required by applicable law. [Add specific CCPA/CPRA, GDPR/UK GDPR, and other state-law disclosures as advised by counsel.]

10. International Data Transfers

We operate in the United States and may process information in the United States and other countries. Where required, we use appropriate safeguards for cross-border transfers. [Confirm hosting locations and transfer mechanisms with counsel.]

11. Children’s Privacy

The Service is not directed to children under [13/16], and we do not knowingly collect personal information from them. If you believe a child has provided personal information, contact us and we will take appropriate steps.

12. Subprocessors & Third-Party Services

We rely on third-party subprocessors to provide the Service, which may include cloud hosting/database, live-streaming, mobile-wallet pass, email/communications, CRM, and analytics providers. A current list is available at [SUBPROCESSOR LIST URL]. These providers are authorized to process information only as needed to provide their services to us.

13. Changes to This Policy

We may update this Policy; material changes will be posted with a new “Last updated” date and, where required, communicated to you. Your continued use of the Service after changes take effect means you accept the updated Policy.

14. Contact

Questions or requests about privacy: [CONTACT NAME], RCW Concepts LLC — [PRIVACY EMAIL] — [MAILING ADDRESS].