Privacy Policy
Gültig ab: 28. August 2026Zuletzt aktualisiert: 7. September 2026
Dieses Dokument ist derzeit nur auf Englisch verfügbar.
1. Who we are and what this policy covers
TheGather, Inc., a Delaware corporation with its registered address at 2810 North Church Street, Wilmington, DE 19802, United States (“we”, “us”), operates orriven. This policy applies to:
- the website at orriven.com, including the “Contact the team” form;
- the organizer console at app.orriven.com, together with the
orrivencommand-line tool, the console shell and the MCP service; - the hosted attendee pages at pages.orriven.com (checkout, order result, entry pass, certificate, surveys and the exhibitor lead desk);
- the developer API and the Storefront API.
It applies to website visitors, organizer console users (employees of our customers), attendees and ticket buyers, exhibitor staff, and developers integrating with the APIs.
Two roles. For website visitors, console users and API developers, we decide why and how personal information is processed and are the controller of that information. For attendees, ticket buyers and exhibitor contacts (“Event Data”), the organizer of the event decides what is collected and what it is used for; we process Event Data on the organizer’s instructions under our contract with them and act as their processor. If you want to exercise rights over Event Data, contact the organizer first — we help organizers respond, and we forward any request we receive directly.
2. Summary
- Website: edge access logs, a one-year language-preference cookie, and — only after you accept the cookie banner — product analytics through PostHog. The contact form collects your work email, name, company, country, event plans and notes, and stores them in our CRM (Attio).
- Console: account email, password (stored only as a hash), name, sign-in sessions (IP address, browser), organization membership and roles, and an audit log of every change.
- Event Data (controlled by the organizer): registration details and form answers, order and payment status (card numbers go to Stripe directly and never reach us), check-in records, and technical observations captured when a registration is submitted (IP address, browser, time zone, device fingerprint and, where the organizer enables it, risk signals from Fingerprint).
- Not involved: we do not ask for sensitive personal information (an organizer’s own form may), we do not direct the service at minors, we do not use personal information to train AI models, and we make no automated decisions with legal or similarly significant effects.
- Third parties: cloud infrastructure (Cloudflare, Fly.io, PlanetScale, MongoDB Atlas), Stripe for payments, PostHog for website analytics, Attio and Kickbox for the contact form, Fingerprint for optional registration risk signals, Apple Wallet and Google Wallet when you save a pass; plus the Salesforce connection and webhook endpoints an organizer configures.
- Where: our servers are in the United States. If you are outside the United States, your information is transferred there.
- Your rights: change account details in the console; for everything else, email privacy@orriven.com and we answer within 30 days.
3. What we collect and why
| Channel | Function | Personal information | Required? | Purpose | When | Retention | If you decline |
|---|---|---|---|---|---|---|---|
| Website | Page visits | IP address, browser and device information, pages viewed, referrer, JavaScript errors (PostHog); Cloudflare edge access logs | No (analytics) | Understand how the site is used and fix errors | PostHog loads only after you choose “Accept” in the cookie banner; your choice is kept for one year in the cookie_consent cookie. Cloudflare’s edge logs are written on every request |
PostHog’s default project retention; Cloudflare’s log retention | Choose “Decline” in the banner, or change your choice later under “Cookie settings” in the footer; the site works without analytics |
| Website | Language preference | Language code in the lang cookie and local storage |
Yes | Remember the language you chose | When you pick a language | Cookie: 1 year | You choose the language again on each visit |
| Website | Contact the team | Work email, family and given name, company, country, event plans and scale, notes, page language | Yes, to submit | Reply to your sales enquiry | On submit; the email domain (never the address) is checked against Cloudflare DNS and Kickbox to reject disposable domains | Until you ask us to delete it or the enquiry is no longer active | The form cannot be submitted |
| Website | Country prefill | Country code inferred from Cloudflare’s request headers | No | Prefill the country field of the form | When the form opens | Not stored | Pick the country yourself |
| Console | Account | Email, password (hash only), name, optional avatar; session records (IP address, user agent, timestamps) | Yes | Create the account, verify identity, protect the account | At sign-up and every sign-in | While the account exists; a session expires after 7 days without activity | You cannot use the console |
| Console | Enterprise SSO | Email and name returned by your organization’s identity provider | Yes when your organization enables SSO | Sign in with your corporate identity | At sign-in | As the account | Decided by your organization |
| Console | Organizations and business units | Organization name, member roles, invitations, the organization licence’s customer contact | Yes | Tenant management and permissions | On creation and invitation | While the organization exists | You cannot join the organization |
| Console | Audit log | Acting account, time, endpoint, request contents of every change | Yes | Security and compliance audit | On every write | While the organization exists; erasure requests do not remove audit entries | — |
| Console and APIs | API keys and request logs | Key identifier, request path, IP address, user agent, truncated request and response bodies | Yes when you use the APIs | Troubleshooting, rate limiting, security | On every API call | While the organization exists | You cannot use the APIs |
| Console | Shell, CLI, MCP | Session token, client identifier, activity timestamps | Yes when you use them | Provide command-line and agent access | While in use | Until the session ends; shell sessions last at most 12 hours, CLI sessions 7 days | Other features are unaffected |
| Hosted pages (Event Data) | Registration and checkout | Name, email, answers to the organizer’s registration form, ticket type, redemption code, promotion source | Set by the organizer | Complete the registration | On submit | Set by the organizer, who can export or anonymise it | You cannot register |
| Hosted pages (Event Data) | Payment | Order amount, currency, payment status, Stripe transaction identifiers; card details are collected by Stripe directly | Yes for paid tickets | Collect payment and issue refunds | On payment | Financial records are kept for the statutory period; anonymisation removes the person, not the amounts | You cannot buy a paid ticket |
| Hosted pages (Event Data) | Submission observations | IP address, user agent, time zone, language, screen, platform, device fingerprint; when the organizer enables Fingerprint, also bot, VPN, proxy, Tor and incognito signals and the IP’s country and city | Set by the organizer (advisory for approval) | Help the organizer spot abnormal registrations | On submit | As the registration; deleted first on erasure | — |
| Hosted pages (Event Data) | Entry pass, check-in, certificate, wallet pass | Check-in code, check-in time and door, session credits; when you save a pass, the pass data goes through Apple or Google | Yes for onsite events | Admission and proof of attendance | On scan or when you tap “save” | As the registration | You cannot enter with a code |
| Hosted pages (Event Data) | Surveys and lead capture | Survey answers; when an exhibitor scans your pass, your registration and the exhibitor’s note | Set by the organizer or exhibitor | Post-event feedback, exhibitor follow-up | On submit or scan | As the registration | Skipping a survey does not affect attendance |
| Hosted pages (Event Data) | Housing | Guest and roommate names, stay dates | Set by the organizer | Room allocation | Entered by the organizer | As the registration | — |
| Sent on the organizer’s behalf | Recipient email, name, send and delivery records | Yes | Deliver tickets and event notices | On confirmation or when the organizer sends | As the registration | You do not receive ticket emails |
4. Third-party services
| Channel | Service | Provider | Purpose | Personal information involved | When | Privacy policy |
|---|---|---|---|---|---|---|
| All | Cloudflare | Cloudflare, Inc. | Hosting for the website and hosted pages, CDN, object storage for uploads, outgoing email, DNS | Access logs, uploaded files, email recipients | Every visit | cloudflare.com/privacypolicy |
| All | Fly.io | Fly.io, Inc. | API server hosting (United States) | All platform data passes through it | Every API request | fly.io/legal/privacy-policy |
| All | PlanetScale | PlanetScale, Inc. | Primary database (PostgreSQL, US East) | Accounts, organizations, registrations, orders and other structured records | Continuous | planetscale.com/legal/privacy |
| All | MongoDB Atlas | MongoDB, Inc. | Document database | Form answers, submission observations, templates, survey answers | Continuous | mongodb.com/legal/privacy-policy |
| Hosted pages | Stripe | Stripe, Inc. | Payments, refunds, organizer payout accounts (Stripe Connect) | Buyer email and name, amounts, payment method (card details are collected only by Stripe) | Paid orders | stripe.com/privacy |
| Website | PostHog | PostHog, Inc. | Website analytics and error capture | Device and browser information, page events, IP address | Website visits | posthog.com/privacy |
| Website | Attio | Attio Ltd. | Sales lead management | Every field of the contact form | Contact form submission | attio.com |
| Website | Kickbox | Kickbox, Inc. | Detect disposable email domains | The email domain only | Contact form submission | kickbox.com |
| Hosted pages | Fingerprint | FingerprintJS, Inc. | Device identification and risk signals for registrations, when the organizer enables it | Device fingerprint, IP address, browser signals | Registration submission | fingerprint.com |
| Hosted pages | Apple Wallet, Google Wallet | Apple Inc., Google LLC | Save an entry pass to a phone wallet | Name, event and check-in code on the pass | When you tap “save” | apple.com/legal/privacy, policies.google.com/privacy |
Organizers may additionally connect their own systems — a Salesforce CRM, outbound webhook endpoints, an enterprise identity provider. Those are chosen and controlled by the organizer, and what happens to the data there is governed by the organizer’s own policies.
5. Processors, disclosure, publication and international transfers
- Processors. The infrastructure and service providers in section 4 process personal information only on our instructions, under contracts that bind them to confidentiality and security.
- Disclosure. We do not sell personal information and do not give it to third parties for their own purposes. Personal information leaves us only when: the organizer accesses its own Event Data (it is the controller); the organizer has configured a webhook or CRM connection; you save a pass to Apple or Google Wallet; or the law requires it.
- Publication. We do not publish personal information. An organizer may choose to publish speaker, exhibitor or sponsor details through its own event site; that is the organizer’s decision.
- International transfers. Our servers are in the United States. If you are in the European Economic Area, the United Kingdom, mainland China or another jurisdiction, your personal information is transferred to and stored in the United States. Transfers of Event Data rest on our contract with the organizer, including its data-processing terms. Where your jurisdiction requires a specific transfer mechanism (for example EU standard contractual clauses, or a security assessment or standard contract under Chinese law), the organizer must complete it before using orriven for that event; we provide the assistance needed.
6. How we protect personal information
- All traffic is encrypted in transit (TLS). Passwords and API secrets are stored only as hashes.
- Hosted-page links work only with the matching email address, and every link can be revoked by the organizer.
- Sessions expire; access inside the console is controlled by organization and business-unit roles; every change is written to an audit log.
- Access to production infrastructure is limited to the people who need it.
- If a personal-information security incident occurs, we assess it promptly, notify the affected organizers, and notify regulators and individuals where the law requires.
7. Your rights
| Right | How | Response time | Verification | Notes |
|---|---|---|---|---|
| Access and copy | Console account: account settings. Event Data: ask the organizer, who can export a complete JSON record from the console. Or email privacy@orriven.com | 30 days | A signed-in session, or confirmation from the email address on record | — |
| Correction | Console account: account settings. Event Data: ask the organizer | 30 days | As above | — |
| Deletion | Console account: email privacy@orriven.com (there is no self-service deletion yet). Event Data: ask the organizer, who can erase you from the console | 30 days | As above | Erasure anonymises the person and keeps headcounts, financial records and the audit log, which are retained under legal obligations |
| Withdraw consent | Analytics: “Cookie settings” in the footer of orriven.com. Marketing email from us: email privacy@orriven.com. Event emails: ask the organizer | Immediately, or 30 days | — | Withdrawal does not affect processing that already happened |
| Close an account | Email privacy@orriven.com | 30 days | As above | — |
| Complain | Email privacy@orriven.com; you may also complain to the supervisory authority in your jurisdiction | 30 days | — | — |
We may refuse a request that is manifestly unfounded, repetitive, or that would require disclosing someone else’s information; we tell you why.
8. Where and how long
- Location. Application servers and databases are in the United States (Fly.io, PlanetScale US East, MongoDB Atlas). Cloudflare serves the website, hosted pages, uploads and email from its global network.
- Retention. Account information is kept while the account exists. Organization data is kept for the term of the customer’s contract and deleted afterwards on the schedule in that contract. Event Data is kept for as long as the organizer keeps it. Financial records and audit logs are kept for the statutory period. There is no automatic purge today; deletion happens on request or at contract end.
9. Minors
orriven is a business service. Console accounts are not open to anyone under 18. Organizers who run events for minors are responsible for obtaining guardian consent and for handling minors’ information lawfully. If we learn that we hold a minor’s information without the required consent, we delete it.
10. Changes to this policy
We post changes on this page and update the “last updated” date. For material changes we notify organizer accounts by email or a notice in the console before the change takes effect. Earlier versions are available on request.
11. Contact and disputes
- Email: privacy@orriven.com
- Mail: TheGather, Inc., 2810 North Church Street, Wilmington, DE 19802, United States
- Web: the “Contact the team” form on orriven.com
We reply within 30 days. If you are not satisfied, you may complain to the data-protection authority in your jurisdiction, or resolve the dispute as set out in your contract with us.