Editorial event companions // Conferences, seminars, conventions, retreats // Built for rooms where the trip has to be worth itEvent companions
/Simpli-FIEvents
Privacy · plain English

What we collect. Why we collect it. What we do with it.

We handle data the way we would want our own data handled. Last updated August 2026.

01

Who we are

Simpli-FI Events is a sub-brand of Simpli-FI OS LLC, a Texas limited liability company. Reach us at events@simpli-fi-os.com.

02

What we collect from prospective customers

When you submit the lead-intake form at /get-started, we collect the fields you fill in: name, email, organization, role, event size, events per year, next event date, current event app vendor, pain points, decision-maker status, decision factors, and any referral organization or referrer contact email you choose to provide. We store that record in a Supabase database owned by Simpli-FI OS LLC, use it to respond to your request, scope a possible event project, manage any referral credit, and notify our team by email so we can usually reply by the next business day.

When you submit the Beautiful Histories Travel Desk form at /travel, we collect the fields you choose to provide about your role, business-travel rhythm, rough monthly spend band, point programs, point-balance range, destination, travel window, trip purpose, cultural interests, and consent preferences. We use that record to create an internal handoff packet for Beautiful Histories. Do not submit card numbers, bank logins, passport files, dates of birth, account screenshots, or other sensitive financial or travel documents through this form.

03

What we collect from site visitors

We log standard request metadata at the edge (IP, user agent, referrer, path) for security and rate-limiting. If Vercel Web Analytics is enabled, we use it in privacy-first mode; it does not set cookies or track individual visitors across sites. We do not run third-party advertising trackers.

Lead-intake rate-limit keys are kept only to slow abusive or accidental repeated submissions. They reset after about ten minutes, and stale keys are deleted by the rate-limit service as new intake requests are processed.

When you interact with the feedback survey at /feedback, the page records a per-tab session identifier, the user agent string, the page referrer, and the in-page event you triggered (such as “step viewed” or “submission attempted”) into a Supabase analytics table owned by Simpli-FI OS LLC. The session identifier is created in your browser, lives only in your tab, and resets when you close the tab. We use this signal to make the survey work and to learn which steps lose people. We do not link it to your account or to third-party advertising profiles.

04

What we collect from event attendees

When a customer runs an event on our platform, the attendee data we handle is the data their organization has chosen to provide or that you choose to provide in the event app. This typically includes name, registration or account email, organization, role or member type, title, check-in status, and (when you choose) a profile photo for your badge and the event attendee directory. Sponsor lead retrieval is opt-in per attendee scan. We do not share attendee data across tenants (different customer organizations). We do not sell attendee data to anyone, ever.

05

Live engagement, profiles, networking, and sponsor exports

Live polling, Q and A, QR networking, attendee profiles, in-app peer messaging between attendees, connection or contact requests, the event directory of checked-in people, sponsor lead retrieval, room feedback, and message preferences may collect the choices, scans, comments, profile fields, message text you send, device installation IDs, timestamps, and event context needed to provide the feature. Messages you send to another attendee are delivered to that person for that event and stored so both of you can re-read the thread. Sponsor lead data is shared only when an attendee affirmatively scans, opts in, or otherwise consents through the event flow.

06

Voice, recordings, and local drafts

Voice memos or recording-related features are enabled only when an event contract and on-screen consent flow allow them. If enabled, we store the recording, transcript, related metadata, and retention status needed for the customer workflow. Some review and feedback tools also save local browser drafts in localStorage so a user can resume their own unsent notes.

07

Images, venue media, and references

Venue and city images are used as editorial references, not as endorsements unless a venue expressly agrees otherwise. We track source, permission status, credit requirements, approval notes, media-kit links, and audit dates for public venue imagery.

08

Where the data lives

Lead-form data, Beautiful Histories partner referral data, and customer event data are stored in Supabase Postgres instances under Simpli-FI OS LLC, with production regions selected for the customer use case when we provision the project. Hosting, transactional email, security logs, backups, and other subprocessors may process the limited data needed to provide those services under their own security, subprocessor, and data-processing terms. We use database and application access controls to limit customer event data to authorized workflows.

09

Who we share data with

We share lead-form data only with the subprocessors required to operate the site: Vercel for hosting, Supabase for storage, Resend for transactional email. A signed Data Processing Addendum with Resend is on file as of 2026-05-21 and covers EU SCCs and the UK Addendum. If you submit the Beautiful Histories Travel Desk form and consent to handoff, we share the request with Beautiful Histories so Shelli or the team can review and follow up. We use subprocessors under their published or signed security, subprocessor, and data-processing terms. We do not sell data. We do not share data with advertisers.

For internal venue intelligence and provider research used in customer engagements, we may use Firecrawl as a research subprocessor to fetch publicly available pages from venue and association websites. Lead-form data, attendee data, and customer event data are never sent to Firecrawl. Each Firecrawl call is recorded in an internal audit log with the requested URL, the allowlist decision, and the credits consumed.

10

How long we keep it

Lead-form and Beautiful Histories partner-referral records are kept for 36 months from last contact, then deleted or archived with limited internal access for ordinary business recordkeeping for up to 7 years. Closed-lost leads are kept 12 months for win-back outreach, then deleted or archived under the same limit. Referral contact data follows the same schedule unless a credit is issued, in which case the credit record is retained while the credit is active and for ordinary business recordkeeping after it expires. Deleted records may remain in provider backups until those backups expire under the provider’s normal backup schedule. Customer event data is retained for the term of the contract plus 90 days, then exported to the customer and deleted or archived according to the signed order form.

11

Your rights

Depending on where you live (including under Texas and other U.S. state privacy laws that may apply), you can ask us what personal data we have about you, ask us to correct it, ask us to delete it, ask for a portable copy, or appeal a denied request. We do not sell personal data and we do not share it for cross-context targeted advertising. Email events@simpli-fi-os.com with the subject line “Privacy request” and we will usually confirm within 5 business days. If we cannot honor a request in full (for example because the data is controlled by the event organizer under their contract), we will say so and tell you who can help.

12

The event mobile app

When a customer’s event runs on our mobile app (for example the TEXPERS Events app), you can create a free account with an email address and a password, or continue as a guest. Guests can browse core event surfaces (such as home, agenda, and sponsors) according to that event’s settings. If you create an account we collect your email address and a password, both handled by our authentication provider (Supabase), and we never see your password. We assign your account an identifier, and you complete a profile: first and last name, title, member type (or guest status), and organization are typically required for a full profile; other fields are optional.

Check-in and the attendee directory. If you check in for an event, we record that you arrived (a timestamp and your event profile identifiers) so the organizer can see attendance and so you can appear in the in-app directory of people who have checked in. Directory cards show the profile fields you have chosen to share for that event (for example name, title, organization, and role label). They do not publish your phone number or password.

Networking, connections, and peer messages. You may bookmark other attendees, send or accept a connection request, and send short in-app messages to other attendees for that event. We store the connection state, the message text, who sent and received it, and related timestamps so both parties can re-read the conversation and so unread indicators can work. Messages are for the event networking feature, not for bulk marketing from us. Do not use peer messaging for unlawful content, harassment, or anything the event organizer forbids. Organizers and safety tools may review reports when a user blocks or reports another person.

Profile photo. A photo is optional. You may keep a photo only on your device for your own badge preview. If you choose a feature that shows your photo to other attendees (for example on the event directory or badge surfaces that sync to the event), that photo is uploaded and stored for that event so others can recognize you. You can remove or replace it from profile or settings when the app offers that control. We do not use event profile photos for third-party advertising. Camera access is used to read QR codes and, if you choose, to capture a photo; we do not keep continuous camera video from those flows.

You can delete your account at any time from Settings inside the app, or by using our account deletion page. Deleting removes your account credentials and clears personal fields on your event profile according to that process. Message copies already delivered to another attendee may remain visible to them in their thread until that event data is deleted under section 10, the same way email works after you send it.

The app also creates a random installation identifier on your device so the event can count opens, keep check-in and networking state reliable across sessions, and remember your message and notification preferences. If you turn on alerts, we collect a push notification token through Apple’s or Google’s notification service to deliver them. If the app crashes, it may send us the error message and technical details so we can fix it.

If you create an account or complete a profile for an event, the organizer of that event can see and export a roster of registered or checked-in attendees that may include your name, organization, title, member type, email address (when collected), and registration or check-in dates. That export is delivered to the organizer (for example by email or admin tools) for running the event.

Anonymous session feedback is built to stay anonymous. When you rate a session, the app sends a random one-time token instead of your installation identifier, the stored rating carries no installation identity, and reports are produced as session-level totals. Other in-app activity (such as poll answers and screen opens) is recorded against the installation identifier and follows the customer event data retention schedule in section 10. The optional “claim your free Simpli-FI ID” link opens a separate product with its own privacy policy; nothing is shared with it unless you sign up there. The app is built with Expo and delivered through Apple and Google; their build and store services process the app binary, not attendee records.

13

Children

This is a B2B platform. We do not knowingly collect data from anyone under 18. If you believe a child has submitted information to us, contact events@simpli-fi-os.com and we will remove it.

14

Changes

When we update this notice, we change the “last updated” date at the top. Material changes are emailed to active customers and posted to the home page for 30 days.