Skip to content
DrivenEvents

DrivenEvents Privacy Policy

Effective date: July 18, 2026

1. Who we are and what this notice covers

This notice covers drivenevents.app, operated from the United States. DrivenEvents is the controller (GDPR) / business (CCPA) for platform account, analytics, and operations data.

Event organizers are independent controllers/businesses for attendee data they access through their events (registrations, ticket lists, waiver acknowledgments). Their handling of data they export or collect off-platform is governed by their own practices, not this notice.

2. Data we collect

  • Account: email, name, and profile photo, via our sign-in provider (Clerk).
  • Event participation: events you create or manage; vehicle and registration details; votes; ticket and booth purchase records (amounts and items — card numbers go to Stripe and never reach us); comp-ticket invitations (invitee email); waiver acknowledgments (name, waiver version, timestamp).
  • Content: photos you upload, stored on AWS S3. Photos in event galleries are publicly accessible.
  • Reports: report-form submissions (your signed-in identity plus the report content).
  • Technical: device and log data; error diagnostics (Sentry, §5); usage analytics and masked session replay (PostHog, §4); push-notification subscriptions if you enable them.

3. How and why we use data (legal bases)

  • Contract performance: accounts, event management, registrations, ticketing, refunds, comp-ticket invites, waiver records.
  • Legitimate interests: platform security, anti-fraud and anti-scam review of reported events, error monitoring, and analytics outside the EU.
  • Consent: analytics and session replay in the EU (§4), push notifications, and marketing where offered. You can withdraw consent at any time without affecting prior processing.
  • Legal obligation: tax and financial records, and responses to lawful requests.

We do not use your data for automated decisions that produce legal or similarly significant effects.

4. Analytics and session replay (PostHog)

We use PostHog for product analytics and session replay. Replay masks all typed input and all on-page text before capture, and analytics events exclude email, phone, and form contents by design.

  • EU visitors: analytics runs only if you accept the opt-in banner. Your choice is stored locally and honored on revisits.
  • Outside the EU: analytics is on by default; you can opt out at any time in Notification and privacy preferences.

We do not use analytics data for advertising.

5. Error monitoring (Sentry)

We use Sentry to capture application errors, which may include your IP address, device and browser information, and the account or event context in which an error occurred. This data is used solely to diagnose and fix defects and is retained per §9.

6. Cookies and local storage

We use: Clerk session cookies (strictly necessary — sign-in); PostHog cookies and identifiers (analytics, consent-gated in the EU); and localStorage keys for your analytics choice and UI preferences. We do not use third-party advertising cookies.

7. Who we share data with

Service providers acting on our instructions: Clerk (authentication), Stripe (payments — Stripe also acts as an independent controller for its own financial-services obligations), AWS (hosting, database, and S3 photo storage), Brevo (transactional email), PostHog (analytics), and Sentry (error monitoring). Organizers see attendee data for their own events. We disclose data when legally required. We never send automated direct messages to you on social platforms.

8. No sale or sharing of personal information

We do not sell your personal information and do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. Because we do not sell or share, no “Do Not Sell or Share” link is required; if this ever changes, we will update this notice and add the required controls first.

9. Retention

  • Account data: life of the account plus 90 days after a deletion request, except records we must keep: financial and transaction records (up to 7 years, tax/audit), waiver acknowledgments (for the organizer’s limitation period), and fraud-investigation records (as needed).
  • Analytics and session replay: retained per our analytics project’s configured retention window, then deleted automatically.
  • Error events: retained per our error-monitoring provider’s configured retention window, then deleted automatically.
  • Backups age out on a rolling schedule.

10. Your rights and how to exercise them

You may request access, correction, deletion, portability, or restriction of your data, object to legitimate-interest processing, and withdraw consent (for example, EU analytics) at any time without affecting prior processing.

Submit requests to support@drivenevents.app. We verify requests via your signed-in email and respond within 30 days (GDPR) / 45 days (CCPA). We do not discriminate against you for exercising your rights. EU/UK users may complain to their supervisory authority; California residents may use an authorized agent.

11. Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn we have, we delete it. Contact us if you believe a child has provided us data.

12. Security

We use TLS in transit, encrypted managed database storage, scoped access credentials, payment handling delegated to Stripe (we never store card numbers), and code-review and testing gates on changes to money and auth paths. No system is perfectly secure; we will notify you and regulators of breaches as required by applicable law.

13. International transfers

We operate from the United States and store data on US infrastructure (AWS). If you use the Services from the EU/UK, your data is transferred to the US. We rely on our processors’ safeguards (Standard Contractual Clauses and/or EU-US Data Privacy Framework participation, per each processor’s terms).

14. Changes and contact

We will post updates to this notice with a revised effective date and notify you of material changes via the Services or email before they take effect.

Contact: DrivenEvents, 370 N Dugan Rd, Urbana, OH 43078, support@drivenevents.app.