Privacy & Data Policy
Who this covers
This policy covers two groups: organizers — people who create accounts, build previews, and launch event platforms with us — and attendees — people who open an event's web app that an organizer publishes through our platform.
What we collect from organizers
- Account details: name, email address and/or phone number, and sign-in provider (Google, email, or phone). We never see or store your Google password.
- The event content you create: names, schedules, images, vendor lists, colors, copy, and configuration.
- Basic usage records (page views, saves, publishes) to keep the service working and diagnose problems.
What we collect from attendees
- Attendees browse published events without creating an account.
- We record aggregate, non-identifying usage — total page views, device installs, and feature usage — so organizers can see how their event app performed. We do not build individual attendee profiles and we do not sell or share data for advertising.
- If an attendee opts in to push notifications, we store a device token to deliver them. Tokens are deleted when the attendee unsubscribes or the token expires.
- If an attendee submits something voluntarily (a photo, a lost-and-found report, an email signup), that content goes to the event's organizer.
Where data lives
Data is stored on Google Firebase (authentication, database, and file storage) in the United States, with web hosting on U.S. servers. Traffic is encrypted in transit (HTTPS). Access to production data is limited to The Coop HQ platform operators and to each event's own organizers and staff for their event only.
Who owns what
- Organizers own their event content and their attendee data. We operate the platform; we don't claim your content.
- We own the platform software, templates, and builder.
- We may reference your event's name and public appearance as a portfolio example unless you ask us not to.
Export & deletion
Organizers can request a full export of their event content and collected attendee data (JSON/CSV) at any time, and can request deletion of their account and event data when the relationship ends. We confirm deletions in writing. Some minimal records (invoices, legal correspondence) are kept as required by law.
Retention & what happens after your event
Published events stay live per your plan. After an event ends, its platform can remain online as an archive, roll forward to next year, or be taken down — your choice. Aggregate statistics may be retained after content deletion; they contain no personal information.
Cookies & analytics
We use functional storage (sign-in session, saved drafts, preferences) and first-party aggregate analytics. We do not run third-party advertising trackers on the builder or on published event pages.
Children
Our organizer accounts are for adults. Published event pages are general-audience websites and do not knowingly collect personal information from children.
Changes & contact
If this policy changes materially, we'll note it here with a new date. Questions, export requests, or deletion requests: contact us through the form on the builder page or the contact details in your service agreement.