Privacy policy
What information the platform handles, why it is used, and what choices to consider.
On this page
1. Scope and policy status
This foundational draft describes the data flows supported by the current ConcessionKit application. The responsible legal business, public privacy contact, and effective date remain to be confirmed. It should be finalized against the production service before being relied on as an effective privacy notice.
This policy covers the website, portal, and player. An organization using ConcessionKit is responsible for the personal information it puts in its menus, artwork, or other content and for notices it must provide to its own staff, sponsors, and guests.
2. Information the platform handles
- Account and team information: names, email addresses, authentication records, roles, organization membership, and invitations.
- Workspace content: organization and location details, menus, designs, uploaded assets, schedules, screen names, and sponsor contact information.
- Device and activity information: player credentials, screen check-ins, published versions, recorded ad plays, account-session information such as IP address and user agent, and audit events.
- Transaction information: billing customer and subscription identifiers, booking amounts, payment status, credits, and refund or dispute records. Hosted payment providers collect payment details through their own forms.
- Connected-service information: authorization credentials and catalog data needed for integrations such as Square.
- Correspondence you provide when requesting help or discussing your account.
3. Why information is used
Information is used to create and authenticate accounts, manage access, deliver and synchronize boards, process bookings and billing, send service emails, provide reports, troubleshoot issues, and investigate misuse.
Where a legal basis is required, it must match the purpose and applicable law, such as providing a contracted service, meeting legal obligations, legitimate interests in operating and protecting the service, or consent where required. The final notice will confirm the responsible business and applicable regional details.
5. Cookies and device storage
The portal uses authentication cookies and browser storage for functions such as keeping you signed in and remembering the selected location. The player keeps credentials, board data, live state, and queued play reports locally and caches supported assets for offline playback.
Clearing device storage can sign you out or erase a paired player’s saved content. Local copies may remain on an offline device even after access is changed on the server.
6. Retention and security
Account, workspace, transaction, and diagnostic records can have different retention needs. Retention should be limited to what is needed for service delivery, legitimate operational needs, disputes, and legal requirements. A fixed server-side deletion schedule and backup-retention policy have not yet been established for this draft.
The application includes authentication and role-based access controls. No system or transmission method guarantees absolute security. This draft makes no claim of a security certification, independent audit, or particular data-residency arrangement.
7. Your choices and requests
You can edit information where the portal provides controls. Organization owners manage team membership. Browser settings let you inspect or clear cookies and stored site data.
Depending on your location and the law that applies, you may have rights to access, correct, delete, or obtain a copy of personal information, restrict or object to processing, withdraw consent, or complain to a privacy regulator. Requests may require identity verification and may be subject to lawful exceptions.
The public privacy-request channel is not yet designated. This is an outstanding item for the effective policy. For information managed by your organization, its owner may be able to help with account and content changes. No self-service account-deletion or data-export workflow is promised by this draft.
8. Children and public content
The management platform is intended for people authorized to operate organizations, not for children to create personal accounts. A board may be displayed at a youth venue; that does not require collecting information about its audience.
Avoid uploading personal information about children. If such information has been included in your organization’s content, ask the organization owner to remove it and republish affected screens. Local copies also need to be addressed on offline devices.
9. International processing and updates
Hosting and integration providers may process data in locations different from yours. Actual processing locations and any required transfer safeguards must be confirmed for the effective policy; this draft does not promise regional hosting.
This notice will be updated as the product and its data practices change. The page will show a review or effective date, and material changes will be communicated where required.