Privacy Policy

Last updated 2026-08-25

Introduction

Conzora is an event companion platform — a mobile app for attendees and a web dashboard for event organizers — operated by Stone General LLC, 1514 Turning Leaf Lane, Garland, TX 75040, United States ("we", "us"). This policy explains what information we collect, how we use it, and the choices you have. Our services are intended for users in the United States.

Browsing as a guest

You can browse events, schedules, guests, vendors, and venue maps in the Conzora app without creating an account, and most attendees use it that way. When you browse as a guest we do not collect your name, email address, or phone number, and we do not build an advertising or device profile of you. Like virtually every online service, our hosting providers — Vercel for our website and Supabase for app data — process standard technical data such as your IP address, device type, app version, and request logs to deliver content, keep the service secure, and diagnose problems. We also use IP addresses briefly for rate limiting to prevent abuse; those records are kept for no more than one hour. When the app launches it checks Expo’s update service for a newer version of the app, which sends Expo your IP address and basic app version details. If the app crashes or runs into problems, we receive diagnostic reports through Sentry, our error-monitoring provider — these include technical details such as your device model, operating system version, device state (for example memory and battery level), and the screens visited leading up to the problem, but they are not linked to your name, email, or any account. Preferences such as recent searches are stored only on your device.

If you create an account

Attendee features that require an account (such as saved favorites and synced schedules) are currently disabled, so today accounts are used by event organizers and their staff. If you create an account we collect your email address, your authentication credentials (a password, or one-time sign-in links sent to your email), and an optional display name. Organizer roles with elevated access also enroll an authenticator app for multi-factor authentication. If attendee accounts become available, the same account information will apply and this policy will be updated as needed.

Tickets and payments

When ticket purchases are available for an event (they require an account and are not currently enabled), we collect the information needed to issue and honor your ticket: the ticket holder's name and email address, plus order records such as the amount paid, order status, and a payment reference. Payments are processed by Stripe, our payment processor — your card number goes directly to Stripe and is never received or stored by us.

Device permissions and push notifications

The mobile app asks for camera access only when event staff use check-in mode to scan ticket QR codes; the camera feed is processed on the device and never uploaded. If you opt in to push notifications — while signed in, or as a guest by following an event and granting the notification permission — we store a push token for your device so we can deliver the notifications you asked for. Guest devices are identified only by a random per-install identifier that is not linked to your name, email, or any account, and a device that follows no events registers nothing. We do not request or collect your device location, contacts, photos, or calendar, and we do not use advertising identifiers.

How we use your information

We use the information described above to provide and operate the services — signing you in, issuing and validating tickets, sending notifications you have requested, and delivering app updates — and to offer support, keep the services secure, prevent fraud and abuse, and comply with legal obligations. We do not sell your personal information, we do not use it for targeted advertising, and we do not use it for profiling that produces legal or similarly significant effects.

Sharing

We share personal information only in a few situations. Service providers process it on our behalf under contract: Supabase (hosting, database, and authentication), Vercel (web hosting), Stripe (payment processing, when ticketing is enabled), Expo (push notification delivery and app updates), and Sentry (crash and performance diagnostics). These providers are contractually required to protect your information to at least the same standard as this policy and may not use it for their own purposes. Event organizers can see attendee information related to their own event — for example, ticket holder lists and check-in records — and are responsible for using it only to run their event. We may disclose information when required by law, and if we are involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. We do not share personal information with ad networks or data brokers.

Cookies and tracking

The web dashboard uses only the cookies required to keep you signed in (authentication and session cookies). We do not use analytics, advertising, or social-media cookies, and no third-party trackers run on our services. Because there is no cross-site tracking to opt out of, we do not respond to browser Do Not Track signals.

Data retention

We keep account information for as long as your account is active, and delete or anonymize it within 30 days after your account is deleted, except where we need to keep records for legal, tax, accounting, security, or fraud-prevention purposes — for example, order and ticket records tied to a completed purchase. Rate-limiting records that contain IP addresses are deleted within one hour. Diagnostic reports are retained by our error-monitoring provider for a limited period and then deleted. Server logs containing technical data are kept for a short operational window and then deleted.

Your privacy rights

Depending on your state of residence, you may have the right to know what personal information we hold about you, to access it or obtain a copy, to correct inaccuracies, and to request deletion. We do not sell personal information or share it for targeted advertising, so no sale or sharing opt-out is needed. You can withdraw consent for push notifications at any time by unfollowing an event or turning off notifications in your device settings, and deleting the app discards the device identifier. If you have an account, you can request account deletion by emailing support@conzora.app or privacy@conzora.app, and we will complete it within 30 days as described in the retention section above. To exercise any of these rights, email us at the address below; we will verify your identity before acting on a request and respond within the time required by applicable law. If we decline a request you may appeal by replying to our decision, and if your appeal is denied you may contact your state attorney general.

Children's privacy

Conzora is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us and we will delete it.

Security

We use reasonable technical and organizational measures to protect personal information, including encryption in transit, access controls, and multi-factor authentication for administrative access. No online service can guarantee absolute security, but we work to protect the information we hold and to minimize what we collect in the first place.

Changes to this policy

We may update this policy as the product evolves. We will update the date at the top of this page, and if changes are material we will surface a notice in the app or on our website before they take effect.

Contact

Questions about this policy? Email privacy@conzora.app and we’ll get back to you.