Skip to main content
Gather HQs
  • Help
  • Sign in
  • Start free trial
← Legal center

Pre-launch policy draft — legal review required before public launch

Privacy Notice

How information is collected, used, shared, retained, and protected across the Gather HQs platform and the independent subscriber sites it powers.

Effective date
July 30, 2026
Applies to
Gather HQs and subscriber sites

Policies

Terms Privacy Cookies Payments & refunds Acceptable use Retention Security Reviews

Questions?

For an event, ticket, membership, or subscriber-held record, contact the group that operates the subscriber site first.

support@gatherhqs.com

On this page

  1. Our privacy roles
  2. Information collected
  3. How information is used
  4. How information is shared
  5. Communications
  6. Children and minors
  7. Choices and rights
  8. Retention and security

1. Who this notice covers and our privacy roles

This notice applies to Gather HQs accounts, the Gather HQs platform, and subscriber sites hosted on the Service.

Gather HQs-controlled information

Gather HQs decides how account, platform-subscription, security, support, operations, and platform-usage information is processed. Questions about that information may be sent to support@gatherhqs.com.

Subscriber-controlled information

Each subscriber group decides what event, contact, attendee, member, form, volunteer, sponsor, communication, and site-content information it collects and why. Gather HQs generally processes that information to provide the tools the subscriber selected. If your question concerns a particular event, RSVP, membership, guest, waiver, newsletter, or subscriber record, contact that group first using its site contact information.

Depending on the law and the activity, the subscriber may be an independent controller or business and Gather HQs may act as its processor or service provider. This notice does not replace a subscriber’s own privacy notice or legal duties.

2. Information we process

The information involved depends on which features are used.

Account and subscriber-site information

  • name, email address, password hash, email-verification status, account roles, and authentication activity;
  • group name, subdomain, site settings, branding, pages, blog posts, images, and administrator or manager relationships;
  • platform plan, trial, billing interval, Stripe customer and subscription references, invoice status, and billing events; and
  • support requests, administrative actions, exports, moderation decisions, and audit history.

Contacts, events, and participation

  • contact names, email addresses, phone numbers, tags, notes, membership status, and communication-consent history;
  • event invitations, responses, named guests, participant contact details, attendance and check-in history, capacity, event and album images, captions, accessibility descriptions, and related timestamps;
  • event reviews, ratings, subscriber responses, reports, and moderation history; and
  • if enabled, tasks, comments, documents, forms, waiver or agreement records, volunteer activity, sponsor information, workflow history, and AI drafting prompts and outputs.

Payments and commerce

We process ticket and membership order details, purchaser identity, prices, currency, transaction status, limited Stripe identifiers, refunds, disputes, fees, and financial history. Full payment-card numbers are collected on Stripe-hosted pages and are not stored by Gather HQs.

Communications

We process campaign drafts, audience criteria, recipient and consent status, unsubscribe capabilities, delivery status, provider identifiers, and engagement events such as delivery, bounce, complaint, open, or click when the provider supplies them. Message bodies may exist while awaiting delivery and are redacted after successful delivery or final failure under the platform’s operating rules.

Technical and usage information

We may collect IP address, browser and device information, requested pages, referring page, timestamps, request or correlation IDs, security events, error details, cookie or session identifiers, and service-health information. Public forms may record IP address and user agent for security, consent, and agreement evidence.

Sources

Information comes from account holders, subscriber administrators and managers, attendees and form submitters, people who register guests or minors, payment and communications providers, and automatic platform logs.

3. How information is used

We use information to:

  • create and secure accounts, subscriber sites, and role-based access;
  • publish sites and events; manage invitations, RSVPs, guests, attendance, memberships, forms, reviews, and reports;
  • process platform billing and support subscriber-connected ticket and membership payments;
  • deliver transactional messages and consent-based marketing communications;
  • provide support, investigate errors, recover failed work, prevent fraud and abuse, and maintain service reliability;
  • moderate reported content, enforce policies, preserve audit trails, and protect users and third parties;
  • analyze and improve the Service using aggregated or de-identified information where practical; and
  • comply with law, valid legal process, tax and accounting requirements, and enforceable agreements.

Where a law requires a legal basis, processing may rely on performing a contract, taking requested pre-contract steps, consent, legitimate interests in operating and securing the Service, or compliance with legal obligations. A subscriber is responsible for identifying its own legal basis for subscriber-controlled processing.

4. How information is disclosed

We may disclose information:

  • to the relevant subscriber group, including its authorized administrators and site managers, so it can operate its site, events, memberships, communications, and records;
  • to service providers that supply hosting, storage, content delivery, security, email, optional AI drafting, customer support, analytics if later enabled, and other infrastructure under appropriate restrictions; organization documents are currently sent to Cloudmersive for malware and content-security scanning before storage;
  • to Stripe and payment participants for platform subscriptions, connected-account onboarding, checkout, recurring dues, refunds, disputes, reconciliation, fraud prevention, and legal compliance;
  • to other people or the public when you or a subscriber intentionally publishes content, such as a public site, event, blog post, review, rating aggregate, or subscriber response;
  • for legal and safety reasons when reasonably necessary to comply with law or valid process, enforce agreements, investigate fraud or abuse, or protect rights, safety, property, and service integrity; and
  • in a business transaction involving financing, merger, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice obligations.

Gather HQs does not sell personal information for money and does not share personal information for cross-context behavioral advertising. The Service currently does not use third-party advertising cookies. If those practices change, this notice and any required choices will be updated before the change applies.

5. Email, text messages, and communication choices

Account verification, password reset, security, billing, event confirmation, receipt, cancellation, reminder, and other operational messages may be sent when needed to provide the Service or a requested event or membership.

Marketing email and text campaigns are limited to contacts with the recorded permission required for that channel. Marketing emails include an unsubscribe method. Text recipients may withdraw consent through the method in the message or another reasonable method. Withdrawing marketing consent does not prevent essential transactional messages about an existing account, order, event response, or membership.

A subscriber is responsible for the contacts it imports or enters, its consent records, the accuracy and legality of its content, and honoring direct opt-out requests. Gather HQs also maintains suppression and unsubscribe controls to help enforce those choices.

6. Cookies and hosted third-party pages

Gather HQs currently uses browser storage needed for sign-in, sessions, security, form protection, preferences, and reliable site operation. We do not currently use advertising cookies. Details are in the Cookie Notice.

Stripe-hosted checkout, billing, and onboarding pages may use Stripe’s own cookies and collect information under Stripe’s privacy notice. Links to other independent sites are governed by those sites’ practices.

7. Children and information about minors

The Service is designed for adult-led groups and is not directed to children under 13. Children under 13 may not create accounts or submit personal information directly. We do not knowingly collect personal information directly from a child under 13 without legally valid authorization.

An adult may register or list a minor as a participant or guest for a youth or family event only when the adult and subscriber have the authority and notices or consents required by law. Subscribers that offer youth programs are responsible for age-appropriate forms, parental or guardian authorization, limited collection, supervision, access controls, and any child-privacy obligations that apply to them.

If you believe a child submitted information without appropriate authorization, contact the subscriber group and support@gatherhqs.com so the record can be reviewed.

8. Your choices and privacy rights

Depending on your location and relationship to the Service, you may have rights to request access, correction, deletion, a portable copy, restriction, objection, withdrawal of consent, or information about processing and disclosures. You may also have a right to appeal a denied request or complain to a regulator.

For subscriber-controlled information, send the request to that subscriber first. For a Gather HQs account or platform-controlled information, contact support@gatherhqs.com. We may verify identity and authority before acting. Legal exceptions may allow or require us or a subscriber to retain certain records, such as transaction, security, fraud-prevention, consent, dispute, or legal-compliance information.

You can update certain account or subscriber information in the Service, download a subscriber-site export where available, unsubscribe from marketing through the message link, and control necessary browser storage through browser settings subject to loss of functionality.

9. Retention, security, and international processing

Information is retained for as long as reasonably needed for the purposes above, including while an account or subscriber site is active. Deletion requests, protected records, and backups follow the Data Retention & Deletion Policy. Different records have different periods based on operational, contractual, tax, accounting, safety, fraud-prevention, dispute, and legal needs.

We use administrative, technical, and organizational safeguards designed for the nature of the Service. No internet service can promise absolute security. Security practices and reporting instructions are described on the Security & Responsible Disclosure page.

Gather HQs is operated from the United States. Service providers may process information in the United States and other places where they operate. Those locations may have different privacy laws. Where required, we use recognized transfer and contractual safeguards.

10. Changes to this notice

We may update this notice as the Service, providers, or legal requirements change. Material changes will be communicated through the Service, email, or another appropriate method when required. The effective date above identifies the current version.

Contact

Gather HQs
support@gatherhqs.com

The approved public mailing address must be configured before launch.

© 2026 Gather HQs
Legal center Privacy Terms Payments & refunds Acceptable use Review guidelines Support