Privacy Policy

How we collect, use, and share information.

What we collect

Account details for organizers (name, email, organization). For attendees, vendors, and donors: the contact details and information you provide when buying a ticket, applying for a booth, or donating. Card details are collected and stored by Stripe, not by us.

How we use it

To run events you participate in - process orders, check people in, issue receipts, send transactional and (with consent) promotional messages, and provide each organizer their own data.

Who we share it with

Service providers that make the platform work: Stripe (payments and payouts), Resend (email delivery), Twilio (SMS, when an organizer enables texting), MongoDB Atlas and Railway (database and application hosting), and Sentry (error monitoring - configured to exclude personal details from error reports). We don’t sell personal information. An organizer only sees the people in their own audience.

Dance Seekers

If an organizer switches on the Dance Seekers connection, we publish their events to the Dance Seekers dancer app and send back a summary of sales so their door list and revenue line up. What crosses is deliberately narrow: event details, the organizer’s own business contact, and order-level totals - the order id, how many tickets, the amount and the time. Attendee names, emails and phone numbers are NOT sent, and class registrations carry no student email. The one exception is a giveaway prize claim, where the winner’s email crosses so the prize can be delivered. An organizer can turn the connection off in Settings, and it is off until they turn it on.

The Dance Command app

The app signs you in to the same account you use on the web: email and password, and the same second factor if your account has one. You can also use Sign in with Apple or Sign in with Google, which tell us a verified identifier and, the first time, your email address - both are used only to find the account you already have. We never receive your Apple or Google password, and the app cannot create an account. On the phone, your session token is kept in the iOS Keychain or the Android Keystore, and a copy of tonight's schedule, your requests and your payment figures is cached in app storage so the app still works without signal. Android's cloud backup is switched off for this app deliberately, so those cached files are not copied off the device. If you allow notifications, Apple or Google issues a push token for that device, which we use only to tell you about your own events, requests and messages. Your device list shows a model name you will recognize; it is not anything that identifies your handset to us. Signing out removes the token from the device and ends that session on our side.

What the app does not collect

The app asks for no microphone - blocked in the app itself, not merely unused - and it reads no advertising identifier, no contacts, no photos and no calendar. It asks for your location only at the moment you take a card payment on the phone: the card networks require it for Tap to Pay, it is checked by Stripe's software on the device, and we never receive or store it. Decline it and everything except taking a card still works. It contains no third-party analytics, no advertising SDK and no cross-app tracking of any kind. Nothing you do in the app is used to build a profile or sold to anyone.

Cookies

We use a session cookie to keep organizers signed in and a door cookie for event-day check-in stations. No advertising or cross-site tracking cookies.

Messaging consent

We send SMS or email only for transactions you initiate, or when you opt in to updates. Reply STOP to unsubscribe from texts; every marketing email carries an unsubscribe link that works with one click and stops all future campaigns. Message and data rates may apply.

Retention and your rights

We keep information as long as needed to provide the Service and meet legal/tax obligations. To access or delete your information, contact hello@eventscommand.com.

Last updated: on deploy. ⬢ Dance Command