DRAFT — NOT LEGAL ADVICE. Starting draft for review by a licensed attorney before publication. Bracketed items marked [CONFIRM] need decisions or verification. Accuracy matters here: a privacy policy that describes practices you don't actually follow is worse than none. Verify every claim below against what the app really does before publishing.
Last updated: [DATE] Effective: [DATE]
1. Introduction
This policy explains what information [LEGAL ENTITY NAME] ("ShowDay," "we") collects when you use the ShowDay platform, why we collect it, who we share it with, and what choices you have.
ShowDay serves two kinds of users: Promoters, who run shows, and Vendors, who book tables at those shows. Some sections apply differently to each.
2. Information we collect
You give us:
- Account information — name, email address, password (stored hashed, never in plain text), and organization name.
- Venue and show information — venue names, addresses, floor plan images you upload, layouts, table pricing, show dates and details.
- Booking information — when a Vendor books, we collect the name, email address, and business name provided at checkout, along with the tables selected.
- Support communications — anything you send us by email.
Payment information. Card details are collected and processed directly by Stripe. ShowDay does not receive or store full card numbers. We store Stripe-generated identifiers and non-sensitive details such as the last four digits, amount, and status of a payment.
Collected automatically:
- Authentication and session data — two cookies, both set by ShowDay itself: an authentication cookie (issued through Supabase) that keeps you signed in, and a small preference cookie named `sd-remember` that stores only a single "1" or "0" recording your "remember me" choice. With "remember me" checked (the default), the authentication cookie lasts up to about 13 months; unchecked, it becomes a session cookie that expires when you close your browser.
- Technical and usage data — IP address, browser and device type, pages visited, and timestamps, collected by our hosting and infrastructure providers in ordinary server logs.
We use no analytics product of any kind. No Google Analytics, no advertising pixels, no session recording, no third-party trackers. Fonts are served from our own servers, so pages do not contact Google Fonts or any other third-party font service. The server logs above are the only automatically collected data.
We do not intentionally collect sensitive categories of personal information such as government ID numbers, health information, or precise geolocation. We also do not collect personal home addresses, dates of birth, or payment card numbers — card details go directly to Stripe and never touch ShowDay's servers.
3. How we use information
- To provide the platform: create accounts, design layouts, publish shows, take bookings, process approvals and payments
- To send transactional email through Resend — booking received, approved, declined, hold expired
- To prevent double-booking, fraud, and abuse
- To provide support and respond to questions
- To maintain security and diagnose problems
- To improve the platform
- To comply with legal obligations
[CONFIRM: whether marketing email will be sent, and if so, add lawful-basis and opt-out language.]
4. Who sees your information
Promoters see Vendor booking data. When a Vendor books a table, the Promoter of that show receives the Vendor's name, email, business name, table selection, and payment status. This is necessary to run the show. Promoters are independently responsible for how they handle that information.
Vendors see limited show information. Vendors see public show and floor plan details, not other Vendors' contact information. [CONFIRM: whether the planned public "find your vendor" map will display vendor business names publicly — if so, disclose it here.]
Service providers. We share data with vendors who help us run ShowDay:
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage | Account, venue, show, booking data |
| Netlify | Website hosting | Technical/log data |
| Stripe | Payment processing | Card details (entered directly with Stripe), plus from ShowDay: the Vendor's email address for receipts, the amount, and booking/show reference identifiers — not the Vendor's name, phone, or business name |
| Resend | Transactional email | Names and email addresses, plus the contents of each email: table selections, amounts, and any note a Promoter writes when approving or declining a booking |
[CONFIRM this list stays current as infrastructure changes.]
Legal and safety. We may disclose information if required by law, valid legal process, or to protect the rights, safety, or property of ShowDay, our users, or the public.
Business transfers. If ShowDay is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. We will provide notice.
We do not sell personal information. [CONFIRM this remains true, including under the broad definitions of "sale" and "sharing" in some state laws.]
5. Data retention
We keep account, venue, and show data for as long as your account is active. Booking and payment records are retained longer where needed for financial, tax, dispute, and legal purposes. [CONFIRM specific retention periods with counsel and state them concretely — vague retention language is a common weak point.]
6. Your choices and rights
You may:
- Access and correct your account information from within the app
- Request deletion of your account and associated data by contacting [SUPPORT EMAIL]
- Request a copy of your data
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act or similar state laws, including rights to know, delete, correct, and opt out of certain sharing, and the right not to be discriminated against for exercising them. [CONFIRM which state privacy laws apply based on where users are located, and add the required disclosures and a verified-request process.]
Some data cannot be deleted immediately where we must retain it for legal, tax, or dispute-resolution purposes.
7. Security
We use industry-standard measures including encryption in transit, hashed passwords, row-level database access controls that isolate each organization's data, and restricted administrative access. No system is perfectly secure, and we cannot guarantee absolute security.
[CONFIRM: whether a breach-notification commitment and timeline should be stated.]
8. Children
ShowDay is not directed to children under 13 and we do not knowingly collect their personal information. If you believe a child has provided us information, contact [SUPPORT EMAIL] and we will delete it. [CONFIRM whether attendee ticketing (planned) changes this analysis — event attendees may include minors.]
10. International users
ShowDay is operated from the United States and data is processed there. If you access it from outside the U.S., you consent to that transfer. [CONFIRM: if EU/UK users are expected, GDPR obligations apply and this policy needs substantial additions — lawful bases, data subject rights, transfer mechanisms, and possibly a representative.]
11. Changes to this policy
We may update this policy. If changes are material, we will provide reasonable notice. The "Last updated" date above always reflects the current version.
12. Contact
[LEGAL ENTITY NAME] [MAILING ADDRESS] [SUPPORT EMAIL]
Open items for counsel
1. Verify every factual claim here against the app's actual behavior before publishing. 2. Determine which state privacy laws apply and add required disclosures. 3. Set concrete retention periods. 4. Decide breach-notification commitments. 5. Confirm whether the planned public vendor map, attendee ticketing, and vendor accounts change what is collected and displayed. 6. Decide whether a Data Processing Agreement is needed with Promoters, since they receive Vendor personal information through the platform.