Legal · Privacy

Privacy Policy

Last updated 2026-05-20

Draft. This document is a working draft and has not been reviewed by counsel or a privacy specialist. Final language will replace this page before public launch.

What we collect

Operator accounts. Email, name, role, the organization you're affiliated with, timezone, and the hashed password you set on signup.

Buyer accounts. Email, name, hashed password (if you create a customer account), and the orders associated with your email — including events purchased, ticket types, and amounts.

Guest checkout. If you buy tickets without creating an account, we still store your email, name, and optionally your phone — they're needed to deliver the tickets and respond to support requests.

Payment data. Card details are entered into Stripe's hosted Payment Element and never touch riser.fm servers. We store a Stripe customer reference, a payment intent id, and the amounts charged.

How we use it

  • Deliver tickets and order receipts.
  • Authenticate you when you sign in.
  • Show operators the analytics and settlement views for their own events only.
  • Send transactional email (purchase confirmation, refund notices, password resets).
  • Detect and prevent fraud or abuse.

Who we share it with

Stripe — for card processing and Connect payouts to operators.

AWS — for hosting (EC2, S3, Cognito, SES). Data resides in the region noted at the bottom of this page.

Operators you buy from — when you purchase a ticket, the operator running that event gets your email, name, ticket type, and order total. They need this to run the door and answer support questions about your purchase.

We don't sell personal data. We don't share it with advertisers.

Cookies and analytics

We use a session cookie to keep you signed in. We don't run third-party analytics or advertising trackers. Stripe sets cookies on its own checkout iframe per their privacy policy.

Retention

Order records are kept for at least seven years to satisfy tax and accounting obligations. Account data is kept for as long as the account is active; closed accounts are anonymized within 90 days, retaining only what we're required to keep for financial records.

Your rights

You can request a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it (subject to the retention requirements above). Email hello@riser.fm with "Privacy request" in the subject.

Security

Passwords are stored as bcrypt hashes. Card data is tokenized by Stripe and never stored by riser.fm. Traffic is served over TLS. Access to production data is limited to staff who need it to operate the platform.

Contact

Questions about this policy or a specific request about your data? hello@riser.fm