Legal
Privacy Policy
Effective September 11, 2026 · Version 3.6
This policy explains what Tangents (“we,” “us,” or “our”) collects, why we collect it, how it is shared and retained, and the choices available to you when you use tangentsevents.com and related services.
- We do not sell personal information or share it for cross-context behavioral advertising.
- We do not currently use advertising cookies or third-party behavioral advertising trackers.
- You may optionally let your browser use precise location for the Near Me feature. Tangents does not receive or store those coordinates.
- Our payment processor, Stripe, collects and validates payment information directly: card details, bank-account details, identity verification, and payout information.
- Public profiles, event listings, reviews, host responses, and event media can be seen and reshared by others.
1. Scope and responsibility
Tangents is responsible for the personal information described here. This policy applies to visitors, account holders, ticket purchasers, hosts and promoters, and people who communicate with us. It does not govern a host’s independent handling of information outside Tangents, venue practices, or third-party sites linked from the Platform.
If applicable law gives you stronger rights, that law controls. Regional disclosures describe rights that may apply; they do not mean every listed law applies to Tangents or every user.
2. Information we collect
| Category | What it includes |
|---|---|
| Account and authentication | Email, username, account type, authentication status, password-reset and verification events, and session information. Passwords are processed by our authentication provider; Tangents does not receive plaintext passwords. |
| Optional profile information | Display name, biography, profile photo, notification preferences, and registered passkey label and public-key credential data. Public profile fields may be visible to others. |
| Host and promoter information | Business name and, if provided, business address and EIN; host tier, payout preferences, account standing, Stripe references, onboarding status, and payout records. Stripe separately collects payment, bank, tax, identity, and verification information. |
| Event and community content | Event details, addresses and map coordinates, prices, capacities, photos, videos, captions, reviews, responses, follows, reports, appeals, and host notices. |
| Orders, tickets, and refunds | Account ID or guest email, ticket selections and quantities, totals and fees, refund-protection selection, transaction status, ticket and QR identifiers, scan time, Stripe references, and related communications. |
| Device, log, and security information | IP address, browser or user-agent information, timestamps, requested actions, rate-limit records, login failures, audit events, device patterns, a hashed fingerprint used to recognize new sign-ins, and the result of the bot-detection challenge shown on sign-in and registration. |
| Notifications and support | Email and communication preferences; optional browser push endpoint and encryption keys; and messages or attachments sent to our support addresses. |
| Diagnostics | Production application errors, performance traces, route transitions, browser context, and related technical details sent to our error-monitoring provider. |
| Catering and dietary choices | Only on events the host marks as catered. You tell the host whether you have dietary needs, either by picking from a short list (vegetarian, vegan, gluten-free, halal, kosher) or by writing a short note. The host sees how many guests picked each option and the text of any notes, never who they came from. We use this only for that event’s catering. It is not public, not in analytics or exports, and it is deleted 30 days after the event. |
What we do not currently collect
- No phone number or exact date of birth is requested during current registration.
- We do not receive or store full card numbers, CVV codes, or full bank-account numbers.
- We do not receive biometric templates from Face ID, fingerprint, or other device authentication.
- The Near Me feature does not send precise GPS coordinates to Tangents servers.
- We do not store precondition or waiver documents a Host uploads while creating an event. They are emailed directly to the Host’s own account and not retained by Tangents.
3. Sources and purposes
We collect information from you, your browser, device, network, and Platform activity. We also receive authentication results, payment and payout status from Stripe, media-processing status, email-delivery information, optional browser diagnostic reports, reports from other users, and information from authorities or other parties when legally permitted.
We use information to operate accounts, events, purchases, tickets, refunds, subscriptions, and payouts; communicate transactional, security, event, and support messages; prevent fraud and abuse; moderate content; diagnose and improve reliability; and meet legal, tax, accounting, dispute, and regulatory obligations.
For EEA and UK users, the relevant legal bases may include contract performance, legitimate interests, legal obligations, and consent. We do not use personal information for solely automated decisions producing legal or similarly significant effects. Automated controls may temporarily block sign-ins, prevent overselling, or prioritize potential fraud for review.
We use automated and artificial-intelligence systems to audit Platform activity for fraud, payment abuse, account takeover, prohibited listings, and other security and integrity risks. These systems review activity such as account, event, listing, purchase, refund, and device or network signals, and may flag activity for human review, restrict a feature, or hold a transaction pending review. Decisions with legal or similarly significant effects are not made by these systems alone; a person reviews them. You may contact us at the address in the Contact section to ask about a restriction applied to your account.
4. Public information and host access
Usernames, display names, biographies, profile photos, public host information, event listings, media, reviews, and responses are public by design. Removing content does not remove copies other people may have saved or shared.
Hosts receive operational information needed to manage events, sales, and ticket validation. They do not receive full payment-card or bank details. Information collected independently by a host or venue is governed by that party’s own practices.
A host may give door staff a time-limited link that lets them check tickets in for one specific event without a Tangents account. That link shows whether a scanned ticket is valid, already used, or not for that event, plus a running count of check-ins. It does not expose sales, payouts, attendee lists, or event settings, and the host can revoke it.
5. How we disclose information
We disclose information as needed to providers that support authentication, hosting, databases, storage, security, bot detection on sign-in and registration, map tiles, address geocoding, video processing, email delivery, and optional browser diagnostics. Stripe processes payments, subscriptions, connected accounts, verification, and payouts. Providers receive only information reasonably needed for their functions and process it under their own terms and, where applicable, our service agreements.
We may also disclose public content to other users, information in a business transfer, information required by valid legal process or necessary to protect rights and safety, and information you direct or consent to disclose. Tangents does not sell personal information for money or share it for cross-context behavioral advertising.
6. Payments and financial information
Card entry and host payout onboarding occur in Stripe-controlled interfaces. Stripe may independently process payment, verification, fraud-prevention, and regulatory information. Tangents stores transaction references, status, fees, payout records, and account-readiness information, not full card or bank details.
Refund-protection elections are recorded with the order. For events located in Arizona, applicable state, county, and city transaction privilege tax is calculated and collected at checkout. Tax calculation is not yet automated for events located outside Arizona.
7. Location, cookies, and device storage
Host-supplied event addresses are sent to a third-party geocoding provider when an event is published, to place it on the map and to determine the state, county, and city used for the tax calculation described in Section 6. Tangents does not collect your device’s precise GPS coordinates through the Near Me feature. If you use the Near Me feature, your browser asks permission and uses the coordinates locally to sort events without transmitting or storing them on Tangents servers.
The map draws its background tiles from a third-party map-tile provider. Those tiles are requested by your browser, so that provider receives your IP address and browser information when you view a map, in the same way any image loaded from another site would. The bot-detection challenge on the sign-in and registration pages is likewise served by a third-party provider, which receives your IP address and browser and interaction signals in order to tell a person from an automated script, and may use its own storage in your browser for that purpose.
Essential cookies support authentication, account recovery, and security flows. The cart and your privacy choice are stored locally in the browser. Optional browser error and performance diagnostics run only after you select “Allow optional diagnostics.” You can change that choice using the persistent Privacy choices button. Tangents does not deploy advertising cookies or a separate behavioral advertising product.
8. Data retention
| Information | Typical approach |
|---|---|
| Account and profile | For the life of the account, then deleted or de-identified after a valid request, subject to transaction, safety, legal, and backup exceptions. |
| Public content and media | Until removed, the related event or account is deleted where permitted, or removal is required. Provider deletion may take additional processing time. |
| Orders, tickets, payouts, refunds, and accounting records | Generally up to seven years after the transaction, or longer when law, a dispute, chargeback, investigation, or claim requires. |
| Security, fraud, moderation, device, and audit records | As reasonably necessary to protect the Platform and document enforcement, with longer retention for investigations, disputes, abuse patterns, or legal obligations. |
| Push subscriptions | Until disabled, unsubscribed, deleted with the account, or identified as expired. |
| Support and rights correspondence | As needed to respond and maintain an appropriate record of the request, complaint, or resolution. |
| Dietary notes | Deleted 30 days after the event they were given for. This is shorter than the retention for the rest of the order record, deliberately — the note has done its job once the event is over. |
When a user deletes an account, historical orders may be anonymized rather than erased. Hosts with order, payout, or violation history may need to contact us because immediate deletion can conflict with financial, safety, and legal records.
9. Security and international transfers
We use safeguards appropriate to the information and risks, including access controls, encrypted network transport, provider-managed encryption at rest where available, server-side authorization, database row-level controls, secure sessions, rate limits, audit logging, webhook verification, and Stripe-hosted payment components. No service can guarantee absolute security.
Tangents is based in the United States and our providers are engaged to process information in the United States. Two exceptions, and the circumstances in which a request may be served from outside the United States, are set out below.
| Provider | Established in | What it receives, and when |
|---|---|---|
| HERE Global B.V. | Netherlands | The event address a host enters, sent once when that event is published, so it can be placed on the map and the correct state, county and city tax determined. No attendee information is sent. |
| Unsplash Inc. | Canada | Your IP address and browser information, when your browser loads a stock image on one of our marketing pages. Only the request itself; we send nothing to them about you. |
Separately, our hosting, network and map-tile providers operate global content-delivery networks. A request from you may therefore be served by, or pass through, equipment located outside the United States, most often whichever location is nearest to you. Those providers are United States companies engaged under United States agreements; what varies is the location of the machine that answers a request, not who is responsible for the data.
Where a transfer requires them, recognized safeguards may include data-processing agreements, Standard Contractual Clauses, the UK Addendum, equivalent contractual protections, or an applicable transfer framework.
This section is current as of the effective date above and covers processing outside the United States only. Providers processing solely within the United States are described in Section 7.
10. Your choices and rights
Depending on applicable law, you may request access, portability, correction, deletion, restriction, or objection; withdraw consent; manage communications and push permissions; appeal certain decisions; and complain to a privacy regulator. California and other US state residents may also have rights to know, correct, delete, port, limit certain sensitive-data uses, and opt out of sale, sharing, or targeted advertising. Tangents does not currently conduct those advertising activities.
Email [email protected] to make a request. We may verify your identity or account authority. We will not discriminate against you for exercising applicable rights.
11. Children and Eligible Users
Tangents is not directed to children under 16. The Terms require every user to be an Eligible User, at least 16, or the higher minimum age applicable where they live, and a specific event may add a Host-set precondition such as a further age restriction. Registration does not currently collect a birthdate, and Tangents does not independently verify age or any other precondition; that responsibility sits with the Host. Contact us if you believe a child below the applicable age provided personal information.
12. Changes and contact
We may update this policy as the Platform, providers, or legal requirements change. Material changes will receive additional notice appropriate to the change, and consent where required.
- Privacy and rights requests: [email protected]
- Security issues: [email protected]
- General help: [email protected]
You may also complain to the privacy or data-protection authority where you live.
Controller
Von Valkenburg Systems LLC, d/b/a Tangents™
Phoenix, Arizona, United States
[email protected]
Tangents is a trading name of Von Valkenburg Systems LLC, not a separate legal entity. Tangents™ and the Tangents logo are trademarks of Von Valkenburg Systems LLC.

