1. Security approach
Gather HQs uses administrative, technical, and organizational safeguards designed for a multi-tenant event-management service. Safeguards are selected based on the sensitivity of the information, likely risks, service architecture, and available resources and are reviewed as the Service changes.
2. Platform safeguards
Current application controls include:
- tenant-scoped data access and role checks for subscriber administrators, site managers, and platform administrators;
- password hashing, email verification, secure production cookies, cross-site request forgery protection, HTTPS enforcement, HSTS, content-security and browser-capability headers, clickjacking protection, and login throttling;
- signed provider webhooks, idempotent event handling, hashed invitation and unsubscribe capabilities where the workflow permits, bounded retries, and post-delivery message-body redaction;
- private object storage in production, input and image validation, restricted file access, and file-type and size controls;
- auditing of sensitive actions such as manager changes, refunds, moderation, support access, exports, suspension, and deletion;
- read-only, reasoned, expiring platform support access and a two-administrator delayed site-deletion process;
- dependency, health, worker, backup-restore, and operational monitoring procedures; and
- Stripe-hosted card collection so Gather HQs does not store full card numbers.
No control eliminates all risk. Security descriptions may change as the Service and providers evolve.
3. Subscriber and user responsibilities
Account holders and subscribers must use unique strong passwords, protect email accounts and private links, remove access that is no longer needed, review manager permissions, keep devices and browsers current, and report suspicious activity promptly. Subscribers must limit uploaded and collected information to what the Service is designed to handle and must not upload prohibited highly sensitive information.
Subscribers are also responsible for their own event operations, staff practices, downloaded exports, external mailing lists, connected Stripe accounts, independent devices, and any data copied outside Gather HQs.
4. Security incidents
We investigate suspected unauthorized access, loss, alteration, disclosure, or service disruption and take reasonable containment, recovery, evidence-preservation, and corrective steps. When an incident triggers a legal or contractual notification duty, affected parties and authorities will be notified in the required manner and timeframe.
If you believe your account is compromised, change the password for the associated email account and Gather HQs account where safe to do so, remove unknown managers, preserve relevant evidence, and contact support immediately.
5. Responsible vulnerability disclosure
Send a suspected vulnerability to support@gatherhqs.com with a clear description, affected URL or feature, safe reproduction steps, potential impact, and a way to contact you.
Good-faith research must:
- use only accounts and subscriber sites you own or have written permission to test;
- avoid privacy violations, tenant access, data extraction, persistence, social engineering, credential attacks, malware, denial of service, automated high-volume traffic, and payment interference;
- stop immediately if another person’s data becomes visible;
- give us reasonable time to investigate and remediate before public disclosure; and
- comply with law and the Acceptable Use Policy.
Do not include secrets or unnecessary personal information in the report. This process does not promise payment, create employment, authorize unlawful activity, or waive rights. We will not pursue a claim solely for research that clearly follows these rules, to the extent within our control.