We do not sell your information. A few trusted companies process it on our behalf so we can run things, and we only share what each one needs to do its job:
Supabase stores the waitlist (and the members table once memberships open) in a Postgres database.
Vercel hosts the site and serves it, so it handles requests and basic server logs. Vercel Analytics also measures page traffic, and only after you accept analytics cookies.
Resend sends our email. It receives the address we are writing to, your name, and the contents of the message, so that membership, reservation and news emails can reach you.
GitHub holds our encrypted database backups, so that we can restore the service if something is lost. The backup is encrypted before it leaves our machine.
Stripe processes payments when memberships open, including your card details, which it handles directly.
PostHog runs our product analytics and receives your email, name, and city tied to your activity on the site.
Meta Platforms (Facebook and Instagram) receives advertising events through the Meta pixel in your browser, to measure our ads. It does not receive your email address. For this advertising, Meta may act with us as a joint controller rather than only as a processor.
Google runs our support inbox (Gmail), so emails you send to support are processed by Google.
Apple and Google provide the optional Wallet services. If you ask us to add your pass, the chosen provider processes the pass data needed to store and display it in your Wallet account or device.
When you go to a night through your membership, we share your name and your membership status with the partner venue or promoter running that event, so their door can check you in. They may only use it to validate your entry, cannot use it for their own marketing, and delete it after the event.
We ask each of these companies to protect your data and to use it only for what we ask. If a court or the law requires it, we may also have to share data, and we would only do so where we are legally obliged.