Privacy Policy
Effective 24 August 2026
In plain English
We hold two kinds of information: the accounts of organizers who use Captain Expo, and the details vendors give when they book a booth. Vendor details belong to the organizer running that show - we hold them on their behalf.
We never see a card number. We run no analytics or advertising scripts, we put no tracking pixels in email, and we never store a raw IP address. We do not sell personal information.
This summary is here to orient you. The numbered clauses below are the agreement.
1.Who this covers
Two groups of people appear in Captain Expo, and our role differs for each.
- Organizers - our customers. They have accounts. For their account information we are the controller, and this policy describes what we do with it.
- Vendors - the organizer’s customers, who buy booths at their shows. Vendors have no account with us. We hold their details on behalf of the organizer, on that organizer’s instructions. For vendor data the organizer is the controller and we are their processor.
The practical consequence: if you are a vendor and want your details corrected or removed, the organizer of that show is who can do it. We will help them, and we will pass on a request you send us, but the decision is theirs.
2.What we collect from organizers
- Account details - name, email address, and organization membership, handled by our authentication provider. We never see or store a password.
- Your Stripe connection - the identifier of your connected account and whether it can currently accept charges. We deliberately discard the access token Stripe issues, so there is no credential of yours in our database to leak.
- Event and floor plan content - what you build in the product, including any venue plan you upload.
- An activity log - a record of consequential actions taken in your organization, such as price changes and booking state changes, so a multi-person team can answer “who changed this”.
3.What we hold about vendors
When a vendor applies for or buys a booth, the organizer’s form collects: name, email address, Instagram handle, phone number, city, state, and the selling categories they choose. We also record which booths they took, what they paid, and the date they accepted the organizer’s rules - together with the text of those rules as it stood at that moment.
There is no vendor account, no password, and no login. A vendor returns to their booking through an unguessable link sent to them by email. That link is the credential: anyone holding it can see that booking, so it is never written to a log or included in a web address we hand to anyone else. Treat it like a password.
4.Payment information
Card numbers never reach us. Checkout is hosted by Stripe and the payment is made directly to the organizer’s own Stripe account. What comes back to us is the outcome - paid or not, an amount, and a reference - never the card details.
Because the organizer is the merchant of record, Stripe’s handling of that payment is between Stripe and the organizer.
5.Cookies, analytics and tracking
This section is mostly a list of things we do not do.
- No analytics or advertising scripts on the public site, the booth map, or the checkout flow. We will not put a third-party script on a page where somebody is entering payment details - which is also why you have never seen a cookie banner here.
- No tracking pixels or rewritten links in email. We do not record whether a vendor opened a message or clicked it. The honest cost of that is that an organizer cannot be told who read their announcement.
- No advertising, no data brokers, no sale of personal information - in any sense, including the broader definitions used by US state privacy laws.
Signed-in organizers do get a session cookie, set by our authentication provider, which is what keeps you logged in. That is strictly necessary and there is no way to use an account without it. The public marketing pages set no cookies at all.
6.IP addresses
Booth checkout is open to the public, and taking booths off sale is something an automated script could abuse, so we rate limit it. That requires distinguishing one visitor from another.
We do not store raw IP addresses to do it. The address is hashed with a secret salt before anything is written down, and only the hash is kept. It is used for rate limiting and nothing else - not for analytics, not for location, not for building a profile.
7.Who else processes this data
We use a small number of infrastructure providers. Each one processes data only to provide its service to us.
- Stripe - payments, and the connected account onboarding flow.
- Clerk - organizer sign-in and organization membership.
- Resend - sending transactional email, such as booking confirmations.
- Vercel - hosting, and storage for uploaded floor plan images.
- Neon - the managed Postgres database, hosted in the United States.
- Anthropic - automatic floor plan detection. Only the venue plan image an organizer uploads is sent, and only when they ask for a detection run. No vendor personal information is ever sent.
We may also disclose information if the law requires it, or to protect the rights and safety of users. A current list of providers is maintained in the Data Processing Addendum, and we will give notice there before adding a new one that processes vendor data.
8.How long we keep it
Event and booking records are kept for as long as the organizer’s account is open, because they are the organizer’s business records - a booking from a show three years ago is what settles a dispute about a show three years ago.
When an organizer closes their account we delete their data within 90 days, except where we are required to keep something longer. Floor plan images that are no longer referenced are swept automatically.
9.Security
Traffic is encrypted in transit. Every tenant’s data carries an organization identifier and queries are constrained to a single organization by a database access layer that the build fails without.
Any third-party API key an organizer stores in the product is encrypted before it is written, using authenticated encryption with a key held in our environment rather than in the database, so a copy of the database alone is not enough to use it.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please write to legal@captainexpo.com before disclosing it publicly.
10.Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to certain processing. We honour these requests and do not discriminate against anyone for making one.
- Organizers - write to us and we will action it directly.
- Vendors - contact the organizer of the show you booked, since the data is theirs. If you cannot reach them, write to us and we will pass it on and help them respond.
Every announcement email an organizer sends through the product carries a working unsubscribe link. Unsubscribing is honoured permanently, and it applies to that organizer rather than to every organizer on the platform - a vendor who wants nothing more from one card show has said nothing about a different market.
11.Children
Captain Expo is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, write to us and we will delete it.
12.Changes, and how to reach us
If we change this policy in a way that materially affects how we handle personal information, we will update the effective date at the top and notify organizers by email before it takes effect.
Write to legal@captainexpo.com with any privacy question, including a request to exercise the rights in clause 10.