Draft for review — not yet in force. This document is being reviewed and may change before it takes effect.

Privacy Policy

Last updated: September 18, 2026 · Event Hub, by The Digital Third

This policy explains what personal information Event Hub collects, why, who we share it with, and the choices you have. Event Hub is operated by The Digital Third, based in British Columbia, Canada. Questions and requests go to josh@thedigitalthird.com.

Event Hub plays two roles. For the account you hold with us — your sign-in and your persistent attendee profile — we decide how the information is used and are responsible for it. For the registration and attendee data of a particular event, the event’s organizer decides what is collected and why, and we handle it on their behalf as their service provider. If your question is about one event (“why did I get this email?”, “please remove me from this guest list”), the organizer is usually the right person to ask first; their contact address is on the event page and in your pass email. We will help either way.

1.Information we collect from organizers

  • Account: your email address and name, when you sign in, and the times you signed in.
  • Your events: everything you enter to build a hub — event details, agenda, venue, branding, images, ticket tiers, guide and content, email messages you send, team members you add and their email addresses.
  • Payments setup: the identifier and status of the Stripe account you connect (whether it can accept charges). Stripe collects your identity, banking and tax details directly; we do not receive or store them.
  • Billing: a record of the hub fees and passes you have paid, the amounts, currency and the related Stripe references. Card details for fees paid by card are entered on Stripe’s checkout page and never reach us.
  • Sender domain: if you choose to send email from your own address, the address, the domain and its DNS verification records.
  • Setup drafts: the text or link you paste into AI-assisted setup, the draft it produced, and your answers to the follow-up questions (see section 5).

2.Information we collect from attendees

  • Registration: your name and email address, and your phone number if the organizer asks for it; your ticket type, order reference and amount paid; who bought your ticket if someone else did; and your answers to any questions the organizer added to their form. If an organizer adds or imports you, they give us these details.
  • Profile (optional): photo, business, title, location, bio, what you are working on, what people should ask you about, what you are looking for, and links to your website and social profiles.
  • Taking part: check-in times, questions and votes, board posts and replies, wins or commitments, pulse and survey answers, and video or written testimonials, including any private note you leave for the host.
  • Technical: the date and time you last opened a hub, and standard server logs (IP address, browser type, pages requested) kept by our hosting provider for security and troubleshooting.

We do not ask for, and events should not collect through Event Hub, government identifiers, health information or payment card details.

3.Who can see your profile

Other attendees of an event see your profile only if that event has a directory and you are opted in to it. The opt-in is per event, and you can turn it off at any time from your profile page in that hub. What they can see is limited to your name, photo and the profile fields listed above. They never see your email address, phone number, ticket type, order details, or the organizer’s notes about you.

The organizer of an event you join, and team members they authorize, can see your registration details, your profile, your check-in status and what you post or submit in that event. Door staff using an event’s team PIN see only what they need to check people in and moderate content.

Testimonials you submit go to the organizer. If you leave the “share publicly” box ticked when you submit, the organizer may publish your testimonial — on the event’s public testimonial wall once they approve it, and on their own website, social channels or future event pages. If you untick it, it stays between you and the organizer’s team. A private note to the host is never public.

Things you post in a hub’s shared spaces (questions, board posts, wins) are visible to the other attendees of that event.

4.Your profile across events

Event Hub keeps one account per email address, so the profile you write for one event can be carried into the next one instead of being typed again.

  • This only happens for a verified email address — verified because you opened a pass link that was sent to that address, or signed in with a one-time link sent to it. A profile is never carried into an event on the strength of someone simply typing your email into a form.
  • When you edit your profile from your account, the change applies to the hubs of the events you have joined.
  • Carrying your profile into a new event does not opt you in to that event’s directory automatically beyond the event’s normal setting, and you can opt out per event at any time.
  • Some things always stay with the single event they belong to: your ticket and role, what you are looking for at that event, your answers to that organizer’s questions, and the organizer’s notes.

You can see the events linked to your account, edit your profile, or ask us to delete it, from your account page or by writing to us.

5.AI-assisted setup

When an organizer (or someone trying Event Hub before signing up) pastes a description of their event or a link to an existing event page, we send that text — and the readable content of the linked page — to Anthropic, an AI provider, which returns a structured draft of the event. We store the pasted text, the link, the draft and the follow-up answers so that the draft can be previewed, edited and turned into an event.

Per Anthropic’s API terms, content submitted through its API is not used to train its models. That is their commitment, described in their terms, rather than a guarantee of ours; their handling of the content is governed by those terms.

The setup box is meant for information about an event, not about people. Please don’t paste guest lists or other sensitive personal information into it. Attendee data held in a hub is not sent to the AI provider.

To limit abuse of the free preview we store a one-way hash of the IP address that requested a draft, and count requests against it. We aim to delete drafts that are never claimed by an account within 30 days.

6.How we use information

  • to run events: issue passes and QR codes, register and check in attendees, show the schedule, directory, board and other modules, and deliver the organizer’s emails;
  • to sign you in and keep your account secure;
  • to carry your verified profile from one event to the next;
  • to bill organizers and keep financial records;
  • to send service messages — sign-in links, passes, receipts, and notices about an event’s status (such as the post-event and archive notices);
  • to prevent fraud, spam and abuse, and to troubleshoot and improve the service using aggregated, non-identifying usage statistics;
  • to meet legal obligations.

We do not sell personal information, we do not use it for advertising, and we do not send our own marketing to attendees. Emails you receive about an event are sent on behalf of that event’s organizer.

7.Who we share information with

We share personal information with the organizer of each event you join (section 3), and with the service providers that run Event Hub for us:

ProviderWhat it does for usWhat it handles
SupabaseDatabaseAccounts, events, registrations, profiles and activity
VercelHosting, file storage, analyticsThe site itself; uploaded images, avatars and testimonial media; server logs; aggregated, cookieless page analytics
StripePayments (Stripe Connect)Ticket purchases on the organizer’s account; hub fees and passes paid to us. Card details go to Stripe only
ResendEmail deliveryRecipient address, message content, and delivery status (delivered, opened, bounced)
AnthropicAI-assisted event setupText and links pasted into setup (section 5) — not attendee data

Organizers can also embed or link to third-party content in a hub (videos, maps, photo galleries). Opening those sends your browser to that third party under its own privacy policy.

These providers may process information in Canada, the United States and other countries, where it may be accessible to courts and authorities under local law. We may also disclose information when the law requires it, to protect people’s safety or our legal rights, or to a successor if the business is sold or reorganized — in which case this policy continues to apply to information already collected.

8.Cookies and similar technologies

Event Hub uses signed session cookies only: one that keeps an organizer signed in to the dashboard, one that keeps an attendee signed in to a particular event’s hub, one for door-staff access, and one that remembers an unsaved setup draft. They are strictly necessary, are not readable by scripts, and are not used to track you across sites.

We store a few preferences (such as light or dark mode) in your browser’s local storage. We use Vercel Analytics, which measures page views in aggregate without cookies and without building a profile of you. We do not use advertising or social-media trackers. Stripe sets its own cookies on its checkout pages for fraud prevention.

9.How long we keep information

  • Events and their attendee data are kept for as long as the organizer keeps the event. Archiving an event closes its hub but does not delete anything; when an organizer deletes an event, its registrations, profiles for that event, and activity are deleted with it.
  • Your account and persistent profile are kept until you ask us to delete them.
  • Sign-in links expire after 20 minutes and work once.
  • Email logs (who was sent what, and delivery status) are kept with the event.
  • Billing records are kept for as long as tax and accounting law requires, typically seven years.
  • Unclaimed setup drafts — we aim to delete within 30 days.
  • Backups and server logs are kept by our providers for limited periods and then overwritten.

10.Your choices and rights

Whatever privacy law applies to you — Canada’s PIPEDA and British Columbia’s PIPA, the GDPR in Europe and the UK, or another — we aim to honour the same things for everyone:

  • See it. Ask for a copy of the personal information we hold about you.
  • Fix it. Edit your profile yourself at any time, or ask us to correct something you can’t reach.
  • Delete it. Ask us to delete your account and persistent profile. For your registration in a specific event, the organizer controls that record; ask them, or ask us and we will pass it on and help.
  • Hide it. Opt out of any event’s directory from your profile in that hub.
  • Take it with you. Ask for your information in a portable format.
  • Object or withdraw consent to a use of your information, where the law gives you that right. Some information is needed for the service to work (we can’t issue a pass without an email address).
  • Stop event email. Reply to the organizer or write to us, and you will be removed from that event’s messages.

Write to josh@thedigitalthird.com from the email address on your account. We may need to confirm it is really you, and we will respond within 30 days. If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada, the Office of the Information and Privacy Commissioner for British Columbia, or your local data protection authority.

Where the GDPR applies, our legal bases are: performing our contract with you (running your account and events), our legitimate interests (security, fraud prevention, improving the service), your consent (optional profile fields, the directory, publishing a testimonial), and legal obligation (financial records).

11.Security

Access to the database is closed by default and goes only through our server. Session cookies are cryptographically signed and cannot be read by scripts; sign-in links are single-use and short-lived; door-staff access is limited to one event and a small set of actions; uploads and connections are encrypted in transit. No system is perfectly secure. If a breach creates a real risk of significant harm to you, we will notify you and the relevant regulator as the law requires.

12.Children

Event Hub is not directed at children, and we do not knowingly collect personal information from children under 13. Organizers who run events that minors attend are responsible for obtaining a parent’s or guardian’s consent. If you believe a child has given us information without that consent, tell us and we will delete it.

13.Changes to this policy

We will update this policy as the service changes, and change the date at the top when we do. If a change materially affects how we use information we already hold, we will tell account holders by email or in the dashboard before it takes effect.

14.Contact

The Digital Third — Event Hub, Vancouver, British Columbia, Canada. Privacy questions and requests: josh@thedigitalthird.com.