Who this applies to
MyEventScape is used by four kinds of people, and the policy treats them differently because their relationship to us differs. Customers — event organizers, cities, and vendor businesses — hold accounts and decide what goes into their workspace. Invited collaborators hold accounts scoped to a particular event. Recipients open a shared proposal, invitation, or site-map link without an account. Visitors read our public pages.
For most event data we act as a processor on a customer’s instructions: the organizer or the city controls the record, and we handle it for them. For our own account, billing, security, and marketing records we act as a controller. Where we are a processor, a request to see or delete data should usually go to the organization that holds the event — we will help you reach them.
Information we collect
- Account and profile. Name, email address, password credentials held by our authentication provider, role, organization, phone number if you add one, and multi-factor enrolment.
- Event and permit records. Event details, dates, locations and map geometry, site plans, permit applications and their status, conditions, tasks, and approval history.
- Documents you upload. Certificates of insurance, business licenses, health permits, drawings, and other files — including any personal information they happen to contain.
- Collaboration activity. Messages, comments, change requests, signatures on proposals, and the record of who did what and when.
- Vendor and commercial records. Business details, quotes, proposals, bookings, and budget line items.
- Billing. Subscription plan, billing contact, and payment history. Card details are collected directly by Stripe and never reach our systems.
- Security and diagnostics. Sign-in events, IP address, truncated user-agent information, opaque rate-limit identifiers, audit entries, and application errors.
- Communications with us. Support requests, city inquiry forms, and anything you send to our published addresses.
We do not ask for government identifiers, health information, or payment card numbers, and we ask that you do not upload them. A document you attach to an event may contain more than the event requires — please upload the narrowest version that satisfies the requirement.
How we use information
- Provide event planning, permitting, communication, and document services.
- Authenticate users and enforce organization, event, and role permissions.
- Deliver invitations, reminders, security notices, and service communications.
- Process subscriptions and payments.
- Protect the platform, investigate abuse, and maintain reliability.
- Provide support and respond to what you ask us.
- Improve the product using aggregate, non-identifying usage patterns.
- Comply with legal obligations and documented municipal records schedules.
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use customer content to train AI models — see the AI and automation disclosure. There is no advertising or analytics tracking on this site; the cookie notice lists the few cookies we set.
Legal bases
Where the GDPR or UK GDPR applies, we rely on: contract, to provide the service you or your organization signed up for; legitimate interests, to secure the platform, prevent abuse, and communicate about the service, balanced against your rights; legal obligation, for tax, records, and law enforcement requirements; and consent, for optional marketing email, which you can withdraw at any time.
Who can access information
Inside the platform, access is determined by the organization, event membership, city-review jurisdiction, vendor assignment, and document visibility selected in the product. Event work is collaborative by design: material you add to an event is visible to that event’s team, to the reviewing jurisdiction where one is involved, and to vendors assigned to the parts of it that concern them.
Outside the platform, we use service providers for hosting, email, payments, and maps. Each is listed on our subprocessor page and processes information only to provide contracted services. We may also disclose information when required by valid legal process, to protect rights and safety, or in connection with a merger or acquisition — in which case this policy continues to apply until it is replaced with notice.
One consequence deserves its own mention: when a city or other public body uses MyEventScape, records in its workspace may be subject to public records or freedom of information law. Whether a given record must be disclosed is determined by that body and the applicable statute, not by us.
Secret links
Proposal, invitation, calendar, and site-map links act as credentials: anyone who receives a valid link may be able to open the limited content it grants. Do not forward these links unless the recipient should have access, and revoke them when they are no longer needed. See Security for how to manage them.
Retention and deletion
Retention depends on the record type, customer instructions, municipal records law, financial requirements, and legal holds. As a general matter: account records are kept while the account is active; event and permit records are kept for the customer’s retention period and then deleted or archived on their instruction; billing records are kept as long as tax and accounting rules require; and security logs are kept for a limited period proportionate to their purpose. Deleted material is removed from backups as those backups expire on their normal cycle.
Authorized users may request correction, export, or deletion by contacting us. Some records may need to be retained where law, a legal hold, or a municipal records schedule requires it, and we will say so if that is the case.
Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, receive a portable copy, object to or restrict certain processing, withdraw consent, and appeal a decision we make on your request. California residents additionally have the right to know what is collected and disclosed, to delete, to correct, to opt out of sale or sharing — neither of which we do — and not to be discriminated against for exercising these rights.
Write to privacy@myeventscape.com to exercise a right. We will verify your identity through your account or by other reasonable means before acting, and we will respond within the period the applicable law allows. Requests may be made by an authorized agent with proof of authority. Where we act as a processor for a customer, we will pass your request to them and support their response. If you are in the EEA or UK, you may also complain to your local supervisory authority.
Security and international processing
We use encryption in transit and at rest, row-level tenant isolation in the database, private document storage, restricted service credentials, audit records, and multi-factor authentication for privileged access. No system is completely secure. Our security page describes the controls in detail and explains how to report a vulnerability. Service providers may process data in the United States and other locations where they operate; transfers rely on Standard Contractual Clauses or equivalent mechanisms where required.
Children
MyEventScape is a business and government coordination service, is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us information, write to privacy@myeventscape.com and we will delete it. Note that an event record may name minors — a youth performer, a participant contact — and that information is the customer’s to manage under their own obligations.
Changes and contact
We may update this policy as the product or legal requirements change; material changes will be communicated through the service or by email where appropriate, and the revision date at the top of this page will change. Questions, requests, and complaints go to privacy@myeventscape.com, or by mail to MyEventScape, Minneapolis, Minnesota, United States.