Privacy Policy.
How we handle organizer accounts, the attendee data organizers collect through us, and the terms we process it on.
Last updated August 22, 2026 · Version 1.1
1. Who we are and what this policy covers
Event Shepherd is operated by Group Hug Software, LLC, a limited liability company organised under the laws of the State of Delaware, United States, with operations in the Republic of the Philippines. In this policy, "we", "us" and "our" mean Group Hug Software, LLC.
Event Shepherd is an event management platform. Organisers use it to run registration, sell tickets, manage guest lists and check people in at the door.
This policy covers two different audiences, and it is written for both:
- Organisers, meaning the people and organisations who hold accounts with us and run events on the platform.
- Attendees, meaning the people who register for those events. If you registered for an event and are reading this, section 6 is written for you.
If you do not want to be bound by this policy, please do not use Event Shepherd.
2. Our two roles
We handle personal information in two distinct capacities, and which one applies changes what we can do with your information and who you should ask about it.
We are the controller of information about organiser accounts: the people who sign up, their profile details, their team memberships, how they use the platform, and the information we collect to keep the service running and secure. We decide how that information is used.
We are a processor of attendee personal data. When an organiser collects names, email addresses, phone numbers and answers to their own registration questions, they decide what to collect and why. We hold and process it on their instructions in order to provide the service to them. The organiser is the controller of that data.
This distinction matters in practice. If you registered for someone's event and you want your details corrected or deleted, the organiser makes that decision. We will help them act on it, and we will not act unilaterally on their data unless the law requires it.
The terms on which we process attendee data for an organiser, which an organiser's compliance team will be looking for, are set out in section 14.
3. Information we collect
From organisers
- Account information. Name, email address, password (stored only as a cryptographic hash, never in readable form), profile photo, postal address and timezone.
- Team information. The teams you belong to, your role in them, and invitations sent and received.
- Event content. Everything you create: events, descriptions, schedules, venues, ticket tiers, registration questions, terminals and event pages.
- Two-factor authentication data. Where you enable it, the secret that generates your codes and your recovery codes.
- Connected accounts. Where you sign in with Google or Microsoft, the identifier and email address that provider returns to us.
About attendees, on an organiser's behalf
- Attendee details. Name, email address, and any other contact details the organiser asks for.
- Registration answers. The responses to whatever custom questions the organiser has set. We do not control what those questions ask.
- Ticket data. The ticket tier held, the QR identifier issued, and payment status.
- Attendance data. Each check-in: the time, the terminal, the schedule, and the outcome, including refused scans.
Automatically, from everyone
- Technical data. IP address, browser and device information, and pages visited.
- Approximate location. Derived from IP address at country and region level. We do not collect precise device location.
- Cookies and local storage. See section 12.
- Security signals. Data generated by our bot protection when forms are submitted.
Payments
Card details are entered on our payment provider's own hosted checkout page and are never sent to or stored by us. We receive the outcome of a payment and metadata about the transaction, not the instrument used to make it.
4. How we use information
We use personal information to:
- provide the service: create accounts, run events, issue tickets, record check-ins
- send transactional messages: registration acknowledgments, QR tickets, check-in confirmations where the organiser has enabled them, team invitations, password resets
- prevent duplicate and fraudulent check-ins
- protect the platform against abuse, spam and unauthorised access
- respond to support requests
- understand how the platform is used in aggregate, so we can improve it
- comply with legal obligations
We do not sell personal information. We do not use attendee data collected on an organiser's behalf to market anything to those attendees.
5. Legal bases for processing
Where the law requires us to identify a legal basis, we rely on the following:
| Purpose | Basis |
|---|---|
| Providing the service to an account holder | Performance of a contract |
| Sending transactional email | Performance of a contract |
| Security, fraud prevention and abuse handling | Legitimate interests |
| Aggregate product measurement | Legitimate interests |
| Analytics and marketing cookies on our public pages | Consent, where required |
| Retaining records we are legally required to keep | Legal obligation |
| Processing attendee data for an event | The organiser's legal basis, on their instructions |
Under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), the corresponding criteria are contractual necessity, our legitimate interests, your consent, and compliance with legal obligations.
6. If you registered for an event
This section is for attendees.
The organiser decides. The organiser who ran the event chose what to ask you, why, and how long to keep it. They are the controller of your information. We hold it for them.
Ask the organiser first. To see, correct or delete your registration, contact the organiser directly. They can edit your record and your answers, archive you, or delete you outright, and they can do it immediately.
What we will do. If you cannot reach the organiser, or they do not respond, contact us and we will make reasonable efforts to put you in touch and to assist them in acting on your request. Where the law gives you a right we must honour directly, we will honour it.
What we will not do. We will not change or delete an organiser's records simply because someone asks us to. Guest lists and attendance records are the organiser's business records, and altering them on request from a third party would be a serious breach of our obligations to them.
We do not market to you. Registering for an event does not put you on any list of ours.
7. Sharing and sub-processors
We share personal information only as set out here.
With the organiser. If you registered for an event, the organiser and everyone on their team can see your registration.
With service providers who process data on our behalf, under contract and only for the purposes we specify:
| Category | Purpose |
|---|---|
| Cloud hosting and infrastructure | Running the application and its database |
| Object storage | Storing uploaded images and generated export files |
| Email delivery | Sending transactional email |
| Payment processing | Processing ticket payments |
| Realtime messaging | Delivering the live door feed |
| Bot protection | Preventing automated abuse of public forms |
| IP geolocation | Deriving approximate region from IP address |
| Application monitoring | Diagnosing errors and performance problems |
| Identity providers | Google and Microsoft sign-in, where you use it |
| Website analytics | Measuring use of our public marketing pages |
[[CONFIRM SUB-PROCESSOR LIST, NAMED VENDORS AND PROCESSING REGIONS BEFORE PUBLICATION]]
Where the law requires it, or to establish or defend legal claims, or to protect the rights and safety of any person.
In a business transfer. If we are acquired or merged, information may transfer as part of that transaction. This policy continues to apply to it until it is replaced by one that is not materially less protective, and we will give notice before that happens.
8. International transfers
We operate between the United States and the Philippines, and our service providers may process data in other countries. Where personal information is transferred out of the jurisdiction it was collected in, we take reasonable steps to ensure it remains protected to the standard described in this policy and required by applicable law.
9. How long we keep information
Organiser accounts are kept while the account is open. If you delete your account, we delete or anonymise your account information within a reasonable period, subject to any records we are legally required to retain.
Event and attendee data is kept while the organiser's team exists and the organiser chooses to keep it. Organisers can delete individual guests at any time before an event closes, and can delete an entire event that has never had a guest registered on it.
Once an event is marked completed or cancelled, its guest records are frozen and can no longer be edited or deleted through the interface. This preserves the accuracy of what happened. Deleting the team removes the events it owns.
Attendance records are kept for as long as the event that produced them.
Export files stay in the organiser's exports list until they delete them. Because they contain personal data outside the application, we recommend deleting them once they have served their purpose.
Technical logs are kept for a limited period for security and diagnostic purposes and are then deleted or aggregated.
Backups persist for a limited period after deletion, in line with our backup rotation, and are then overwritten.
10. Security
We take reasonable and appropriate technical and organisational measures to protect personal information, including:
- encryption in transit over TLS
- passwords stored only as cryptographic hashes
- optional two-factor authentication on accounts
- role-based access control within teams
- opaque, non-guessable ticket identifiers
- administrative access limited to the small number of people who need it, with account impersonation logged
No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal information and the law requires us to notify you, we will do so without undue delay, and we will notify the relevant supervisory authority within the period the law prescribes.
Organisers share responsibility here. Use a strong, unique password, turn on two-factor authentication, give team members the minimum role they need, and handle exported guest lists carefully.
11. Your rights
Everyone
Subject to the conditions in your local law, you may ask us to:
- confirm whether we hold personal information about you, and give you a copy
- correct information that is inaccurate or incomplete
- delete information we no longer have a lawful reason to keep
- restrict or object to certain processing
- provide your information in a portable format
- withdraw consent, where processing is based on consent
Where we hold your information on an organiser's behalf, we will refer your request to them and assist them in responding. See section 6.
Philippines
Under the Data Privacy Act of 2012 (Republic Act No. 10173), data subjects in the Philippines have the rights to be informed, to object, to access, to rectification, to erasure or blocking, to damages, and to data portability, and the right to lodge a complaint with the National Privacy Commission.
[[CONFIRM PHILIPPINE REPRESENTATIVE AND NPC REGISTRATION POSITION, IF APPLICABLE]]
European Economic Area and United Kingdom
Where the General Data Protection Regulation applies, you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your local supervisory authority.
California
Where the California Consumer Privacy Act applies, you have the rights to know what personal information is collected and how it is used, to request deletion, to correct inaccurate information, and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising.
How to exercise a right
Contact us with enough detail to identify what you are asking about. We may need to verify your identity before acting, particularly for deletion requests. We will respond within the period required by applicable law.
12. Cookies and local storage
We use cookies and browser storage for the following purposes:
- Session cookies, to keep you signed in. Strictly necessary.
- Security tokens, to protect forms against cross-site request forgery. Strictly necessary.
- Appearance preference, remembering your light or dark theme choice.
- Bot protection, set by our security provider when you submit a public form. Strictly necessary.
- Scanner storage, holding the guest manifest and any queued scans on a device that is running the door scanner. This is what lets check-in work without a connection. It stays on the device and is cleared when the queue syncs.
- Analytics, on our public marketing pages, to measure how those pages are used.
You can clear or block cookies in your browser. Blocking the strictly necessary ones will stop you signing in and stop the scanner working offline.
[[CONFIRM POSITION ON ANALYTICS AND MARKETING PIXELS, AND WHETHER A CONSENT BANNER IS REQUIRED FOR YOUR AUDIENCE]]
13. Children
Event Shepherd is not directed at children and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
Organisers running events for children are responsible for obtaining any parental consent their own law requires before collecting a child's details through our platform.
14. Data processing terms for organisers
This section is the data processing agreement between an organiser, as controller of Attendee Data, and us, as processor of it. It forms part of the Terms of Use and applies wherever we process personal data about your attendees on your instructions.
It is written to be readable. If your own compliance team needs a signed agreement on their paper, contact us.
[[HAVE COUNSEL REVIEW THESE PROCESSING TERMS AGAINST THE JURISDICTIONS YOU OPERATE IN BEFORE PUBLICATION]]
Roles and instructions
For personal data about your attendees ("Attendee Data"):
- You are the controller. You decide what data to collect, why, and how long to keep it.
- We are the processor. We process Attendee Data on your documented instructions in order to provide Event Shepherd to you.
Your use of the service, and your configuration of it, constitute your documented instructions. We will not process Attendee Data for our own purposes, and we will not sell it or use it to market to your attendees.
For personal data about you and your team members, we are the controller. That processing is described in the rest of this policy.
Subject matter, duration, nature and purpose
Subject matter. Provision of the Event Shepherd event management platform.
Duration. For as long as your team holds the data in the service, and thereafter as described under Return and deletion below.
Nature and purpose. Collecting registrations, issuing tickets, maintaining guest lists, recording check-ins, sending transactional email at your direction, and generating exports you request.
Data subjects and categories of data
The data subjects are attendees who register for your events, billing contacts responsible for registrations, people you add to a guest list by import or by hand, and your own team members who use the service to run the event.
The categories of personal data are those listed in section 3: identity and contact data, registration answers, ticket data, attendance data and technical data.
Special category data. The service is not designed for special category or sensitive personal data. If your registration questions collect it, for example health or accessibility information, you are responsible for having an appropriate lawful basis and appropriate safeguards, and you must tell us if the volume or sensitivity is material.
Our obligations as processor
We will:
- process Attendee Data only on your documented instructions, unless required otherwise by law, in which case we will tell you before processing unless the law forbids it
- ensure that people authorised to process Attendee Data are bound by confidentiality
- implement appropriate technical and organisational security measures, as described in section 10 and below
- respect the conditions below for engaging sub-processors
- assist you, taking into account the nature of the processing, in responding to data subject requests
- assist you with security, breach notification and data protection impact assessments, taking into account the information available to us
- delete or return Attendee Data as described below
- make available the information reasonably necessary to demonstrate compliance with these terms
Sub-processors
You give us general authorisation to engage sub-processors to provide the service. The categories we use are listed in section 7.
We will impose data protection obligations on each sub-processor that are no less protective than those set out here, and we remain responsible to you for their performance.
We will give reasonable notice before adding or replacing a sub-processor in a way that materially affects the processing of Attendee Data. If you have a reasonable objection on data protection grounds, tell us, and if we cannot resolve it you may terminate the affected part of the service.
Security measures
The measures described in section 10 apply to Attendee Data. In addition, guest manifests held on scanning devices are deliberately limited to the fields the door needs, excluding contact details, payment data and registration answers.
We may update these measures over time, provided the level of protection is not reduced.
Data subject requests
Attendees can exercise their rights through you directly, using the tools in the service: you can view, edit, archive and delete guest records, and correct their registration answers, at any time before an event is closed.
If an attendee comes to us instead, we will refer them to you and will not act on their data unilaterally unless the law requires it, as described in section 6. We will provide reasonable assistance for requests you cannot fulfil through the interface.
Return and deletion
You control deletion through the service, on the terms described in section 9. On termination of your account, we will delete or anonymise Attendee Data within a reasonable period, except where we are required by law to keep it. Backups persist for a limited period in line with our backup rotation and are then overwritten.
Export your data before you terminate. Guest sheets, QR archives and attendance CSVs are available through the exports tool.
Personal data breach
If we become aware of a personal data breach affecting Attendee Data, we will notify you without undue delay, with the information reasonably available to us about the nature of the breach, its likely consequences, and the measures taken or proposed.
Notifying your supervisory authority and your attendees, where required, is your responsibility as the controller. We will provide reasonable assistance.
International transfers
Transfers are as described in section 8. Where a transfer of Attendee Data requires a safeguard under applicable law, we will put an appropriate one in place.
Audits
On reasonable written request, and no more than once a year unless required by a supervisory authority, we will provide information reasonably necessary to demonstrate compliance with these processing terms. Where an on-site audit is legally required, the parties will agree a reasonable scope, timing and confidentiality arrangement in advance.
Order of precedence
If these processing terms conflict with the rest of the Terms of Use in respect of the processing of Attendee Data, these terms prevail.
15. Changes to this policy
We may update this policy. The version and the date it was last updated appear at the top of this page.
Where a change materially affects your rights, we will give notice by email or through the platform before it takes effect. Continuing to use Event Shepherd after a change takes effect means you accept the updated policy.
16. Contact us
Questions, requests and complaints about this policy or about how we handle personal information can be sent through our contact page.
Group Hug Software, LLC
[[REGISTERED ADDRESS]]
Privacy contact: [[PRIVACY CONTACT EMAIL]]