For everyone
Privacy Policy
- Version
- 2.0
- Effective
- August 15, 2026
- Last updated
- July 26, 2026
ShowRunner LLC (ShowRunner, we, us) is a Minnesota limited liability company. We operate the ShowRunner customer relationship management platform at www.showrunnercrm.com, together with the public seminar registration pages, text-message and email delivery, and related services that our customers use to run dinner seminars for regenerative-medicine practices.
This policy explains what personal information moves through ShowRunner, why, who else touches it, how long it stays, and what you can do about it. It is written for two readers at once: a guest in their sixties who filled in a registration form and wants to know what happens to their phone number, and a lawyer checking this notice against twenty state privacy statutes.
This policy sits alongside the Terms of Service, Acceptable Use Policy, Messaging Policy, Data Processing Addendum, Subprocessor List, Consumer Health Data Privacy Policy, and Guest Privacy Notice, all indexed at /legal.
1.Who this policy covers and our role for each group
Privacy law asks a threshold question first: who decides why personal information is being processed? The entity that decides is the controller (some statutes say business); an entity that processes only on the controller's instructions is a processor (some statutes say service provider). ShowRunner is one or the other depending on which group we are talking about, so we define the three groups here and keep them separate throughout.
| Group | Who this is | Our role | Who decides how the information is used |
|---|---|---|---|
| Account Users | The sales representative who subscribes, their staff, and any Authorized User invited into an organization. | Controller / business | ShowRunner, for account, billing, support, and platform-operations information. |
| Guests | People who register for or attend a customer's seminar, and people whose prospect records a customer uploads, imports, or buys from a list vendor. | Processor / service provider | The customer whose organization holds the record, acting under the Data Processing Addendum. |
| Visitors | Anyone browsing www.showrunnercrm.com without logging in or registering for a seminar. | Controller / business | ShowRunner. |
One person can be in more than one group — a representative who is also a guest at a colleague's seminar — and the two records are governed separately: the account record by ShowRunner as controller, the guest record by the organization that holds it.
What our role as a processor means in practice
For Guest information, ShowRunner does not decide who gets added to a contact list, what an invitation says, who receives a text, or how long a record is kept. Our customer decides all of that. We provide the software, store the information, deliver the messages, and keep the records our customer asks us to keep. We do not sell Guest information, use it for our own marketing, or use it to build products or train models. Our contractual commitments are in the Data Processing Addendum.
Because the customer is the controller, most rights a Guest wants to exercise are ultimately that customer's decision. What ShowRunner adds is a real place to start. Many event platforms tell guests to go find the organizer and stop there. We do not. Write to privacy@showrunnercrm.com and we will locate the organization holding your record, tell you who it is, forward your request, and follow up. The procedure and its limits are in Your privacy rights.
2.Information we collect
This section lists the actual fields ShowRunner stores, by population. It is deliberately specific rather than a generic list of categories, because a generic list would not tell you whether we store your date of birth or your income range. We do.
Account Users — information ShowRunner controls
- Login credentials. Your email address and a cryptographic hash of your password, held in our authentication provider. We never store your password in readable form and cannot recover it for you.
- Organization membership and role. Which ShowRunner organization you belong to and what permission level you hold in it. This is what determines the records you can see.
- Business details. The business name you operate under and the contact details you give us for your account.
- Billing information. The billing contact for your subscription. Payment card processing is handled by Stripe. ShowRunner does not receive or store full payment card numbers.
- Support interactions. Messages you send to support, and — if you use the in-product help assistant — a redacted transcript, the mode used, the duration, and the screen context. Raw voice audio is never stored. Help tickets and a redacted feedback ledger are also kept.
- Operational records. Records generated by using the product: audit entries for administrative actions, rate-limiting counters, and error diagnostics.
- Connected Google account information. If you choose to connect Google, we store an encrypted refresh token and the basic profile fields described in Google user data. Connecting Google is optional.
Guests — information ShowRunner processes for its customers
Everything in this subsection belongs to the ShowRunner customer that collected it. We describe it here so Guests can see plainly what is held.
From a seminar registration page. Registering for a dinner seminar on a page we host submits your seating preference, first name, last name, email address, phone number, party size, and how you heard about the event, plus two consent checkboxes described in Text messages and email — separate, unchecked by default, and not required to register or attend. The page also captures attribution details from the link or printed code you arrived through, a hidden field used to catch form-filling bots (never stored), and, where enabled, a Cloudflare Turnstile bot-check token.
In a customer's contact records. A contact record can hold a first and last name, whether the person is the primary contact for a household, their relationship to that primary contact, a phone number and an alternate, an email address and an alternate, separate opt-in flags for text, email, and phone, a global opted-out flag, birth month and birth year, age, gender, an income band, demographic attributes supplied by a list vendor, interest tags identifying the treatment topic the person responded to, lifecycle tags, attribution details recording where the record came from, a responder identifier where the record came from LeadingResponse, free-text notes, and the verification status of the email address.
Household and location. A household record carries a street address, a second address line, city, state, and postal code. To map a household and estimate travel distance to a venue, ShowRunner sends the street address — and only the street address, never a name — to the United States Census Bureau's public geocoder and stores the coordinates it returns. This is approximate location derived from a mailing address; ShowRunner does not collect precise location from any phone or browser.
Consent records. Whenever consent for text or email is granted or withdrawn, ShowRunner writes an entry to an append-only consent ledger recording the channel, whether consent was granted or revoked, the exact wording shown at the time, where it happened (a specific organization's registration page, or an inbound text containing the word stop), the timestamp, the IP address, and the user-agent. Entries can be added but never edited or removed, so an opt-out can always be proved.
Message logs. For text messages, ShowRunner stores the destination and sending phone numbers, the full message body, the provider's identifier, and delivery status. For email it stores the destination address, subject line, sending provider, message identifier, and status.
Appointments. Where a customer schedules a follow-up, ShowRunner stores the scheduled time, the appointment's status, the outcome the customer records, an amount if one is entered, and any notes the customer types.
Scanned response cards. ShowRunner includes an optional feature for reading handwritten response cards collected at a seminar, off by default for every organization. When enabled, a photograph of the card is transmitted to OpenAI for extraction and page images are retained in private storage. Health-question fields are forced blank before anything is saved, so those answers are not stored — but the transmitted photograph still contains them. See AI features.
Visitors — information ShowRunner controls
- Access requests. Our public request-access form stores the name and email address you enter, an optional note, and your browser's user-agent string. Your IP address is used momentarily as a rate-limiting key to stop automated abuse and is not stored with the request.
- Essential cookies. A small set of cookies that keep you signed in, protect against cross-site request forgery, and remember that a disclosure has been shown to you. Every one of them is listed in Cookies and tracking technologies.
- Performance measurement. The application measures basic page-performance metrics and sends them to our own servers only. No third party receives them.
- Bot protection. Where the Cloudflare Turnstile bot check is used on a public form, Cloudflare receives the visitor's IP address to perform the check. This control is not currently provisioned in production.
Information we do not collect
Stating the negatives matters too. ShowRunner does not collect full payment card numbers, Social Security numbers, government identification numbers, financial account numbers, biometric identifiers, precise device geolocation, advertising identifiers, or cross-site browsing history. We do not store raw audio from help-assistant voice sessions, and we operate no analytics, advertising, telemetry, or session-replay technology anywhere.
3.Where information comes from
Information reaches ShowRunner through a small number of well-defined paths. Knowing which one applies to you usually answers the question of who to talk to about it.
Directly from you
- Account Users provide account, business, and billing details when signing up and while using the product, and provide the content of support conversations.
- Guests provide their own details on a registration page, in a reply to a text message, on a written response card, or in conversation with the customer's staff.
- Visitors provide their details when they submit the request-access form.
From our customer
A customer may upload or type in prospect records obtained elsewhere: its own past clients, records purchased from a consumer list vendor, or records supplied by the direct-mail vendor LeadingResponse when a person mails back a reply card. Where a record arrives this way, ShowRunner had no relationship with the person beforehand. List-vendor records can arrive with demographic attributes attached, including age, gender, and an income band. The customer is responsible for having a lawful basis and for accuracy, as set out in the Terms of Service and the Data Processing Addendum.
Generated by the service
- Delivery results returned by the messaging and email providers — whether a message was delivered, rejected, or reported as undeliverable.
- Email verification results from ZeroBounce, which receives an email address and returns whether it appears deliverable. ZeroBounce receives the email address only.
- Approximate coordinates returned by the United States Census Bureau geocoder for a household's street address.
- Attribution details recorded when a Guest reaches a registration page through a printed code or a tracked link.
- Consent ledger entries written whenever consent is granted or withdrawn.
- Audit and access records written when an administrator acts across organizations or when sensitive contact information is read by a person.
4.How we use information
Account User information — our purposes
- To create and secure your account, authenticate you, and enforce the permissions attached to your role.
- To provide, maintain, and improve the ShowRunner platform, including diagnosing errors and monitoring reliability.
- To bill your subscription, collect payment through Stripe, and keep the financial records a business is required to keep.
- To respond to your support requests and to operate the in-product help assistant.
- To send you service communications — security notices, billing notices, changes to these documents, and material product changes. You cannot opt out of these while you have an account, because they are part of running the service.
- To send you product and marketing communications about ShowRunner, from which you can unsubscribe at any time without affecting your account.
- To detect, investigate, and prevent fraud, abuse, and violations of the Acceptable Use Policy, and to protect the rights and safety of ShowRunner, our customers, and the public.
- To comply with law and to establish, exercise, or defend legal claims.
Guest information — our customer's purposes
ShowRunner uses Guest information only to perform the service for the customer that controls it. In practice this means:
- Registering a Guest for a seminar and holding the seats requested.
- Sending the confirmations, reminders, and follow-up messages the customer configures, on the channels the Guest agreed to.
- Recording and honouring opt-ins and opt-outs across text, email, and phone.
- Scheduling appointments and recording their outcome for the customer.
- Showing the customer where its Guests are located relative to a venue, and reporting on how its events performed.
- Providing security, backup, troubleshooting, and support to the customer.
ShowRunner does not use Guest information for its own marketing, does not combine one customer's records with another's, and builds no cross-customer profile of a Guest. Organizations are isolated at the database level, as described in How we protect information.
Visitor information — our purposes
We use Visitor information to respond to access requests, keep the site available and secure, stop automated abuse of public forms, and measure page performance on our own servers. We do not profile Visitors, build advertising audiences, or track anyone across other websites.
Profiling and automated decisions
ShowRunner does not use automated decision-making or profiling that produces legal or similarly significant effects. No feature decides, without a person involved, whether someone is offered a service, given a price, granted credit, or excluded from an event. Contact records carry lifecycle and interest tags that customers can filter on, but the decision about what to do next is always made by a human at the customer's business. To question a decision you believe was automated, write to privacy@showrunnercrm.com. Minnesota residents have a specific right here, described in State-specific disclosures.
5.Text messages and email
ShowRunner sends text messages and email on behalf of its customers. The business that invited you is the sender; ShowRunner is the delivery system it uses. Our full rules for customers are in the Messaging Policy.
How consent is captured
On a ShowRunner registration page there are two separate consent checkboxes, one for text and one for email. They are separate on purpose: agreeing to one does not agree to the other. Both start unchecked, and neither is required to register or attend. If you leave both blank you are still registered.
When you tick a box, ShowRunner writes a consent-ledger entry recording the channel, that consent was granted, the exact wording that appeared beside the checkbox, the page, the time, your IP address, and your user-agent. The verbatim wording is stored rather than a reference to it, so if the wording later changes, what you actually agreed to is still on file.
Stopping messages
- Text messages. Reply STOP to any message to stop receiving texts from that sender. ShowRunner records the opt-out in the consent ledger and stops sending. Reply HELP for help. Message and data rates may apply and message frequency varies.
- Email. Every marketing email carries an unsubscribe link. Following it stops marketing email from that sender. Transactional email about something you asked for — such as a confirmation for a seminar you registered for — may still be sent.
- Either channel, by asking us. Email privacy@showrunnercrm.com with the phone number or email address you want stopped and we will process the opt-out and route the request to the business that holds your record.
An opt-out is recorded against the contact record and applies to future sends; messages already queued may still arrive. If messages continue after that, tell us — that is a problem we want to know about.
Mobile information and third parties
That statement is worded precisely. Delivering a text necessarily involves transmitting it to a messaging provider and then to a carrier — that is how a text arrives. What does not happen is any onward use of your number or your consent by anyone for their own marketing, lead resale, or list building. Our subprocessors are contractually limited to processing information to provide their service to us; the list is at /legal/subprocessors.
What is stored about a message
ShowRunner stores the full body of every text sent and received through the platform, with the phone numbers, provider identifier, and delivery status; for email, the recipient address, subject, provider, message identifier, and status. These records are visible to the sending customer and to ShowRunner staff who need them to operate the service. They are the evidence of what was sent and when, which is what a carrier, regulator, or court asks for when a complaint is made.
Push notifications
If an Account User installs the ShowRunner mobile application and enables notifications, alerts are delivered through Expo and the Apple and Google push services. Those payloads currently include the contact's name and the text of an inbound message, so a limited amount of Guest information passes through those services. Account Users who do not want this can turn notifications off on the device.
6.AI features and how your information is used
ShowRunner uses artificial intelligence in exactly two places. Both are described here in full, including what is sent outside our systems and what is not.
Rail one: the in-product help assistant
The help assistant answers questions about how to use ShowRunner. Typed questions are handled by OpenAI chat models; spoken questions are handled by an OpenAI realtime model. It is available to Account Users inside the product. Guests never interact with it.
The important design decision is what the assistant is allowed to know. Its context is not assembled by sending whatever is on your screen; it is rebuilt on our server from an explicit allowlist: aggregate counts, your role, your plan, and a length-limited first name. A scrubber runs over the assembled context and fails closed — if it cannot verify the content is clean, the request does not go out. As a result, no contact record, interest tag, phone number, message body, or appointment reaches the assistant. Stored transcripts are redacted, raw voice audio is never stored, the feedback ledger is stripped of personal information, and these records need service-level credentials to read.
Rail two: response card scanning
This feature is off by default for every organization. When a customer enables it, a photograph of a handwritten response card is sent to OpenAI with a short roster of expected names and the last four digits of their phone numbers, which helps match handwriting to the right person. Health-question fields are forced blank before anything is written to the database, so those answers are not stored — but the photograph as transmitted contains whatever was written on the card. Customers that do not want that transmission should leave the feature off.
What OpenAI does and does not do with this
- ShowRunner sets the flag that instructs OpenAI not to retain these requests for its own purposes.
- Zero Data Retention is not configured on our OpenAI account. OpenAI's standard abuse-monitoring retention — approximately thirty days — therefore still applies to the requests we send.
- No customer information is used to train OpenAI's models, and ShowRunner does not train generalized or public models on customer information.
- ShowRunner does not use AI to make decisions about Guests. Nothing in either rail scores, ranks, or qualifies a person.
We state the retention point plainly rather than burying it. If your business requires Zero Data Retention, tell us — we will not claim it until it is in place.
9.Health-related information
ShowRunner is not a healthcare provider, is not a health plan, and is not a business associate under the Health Insurance Portability and Accountability Act. We do not claim compliance with that law, and we have not executed a business associate agreement with anyone.
Some of what moves through ShowRunner can still reveal something about a person's health. A contact record's interest tags identify the treatment topic a person responded to — knee, shoulder, back, or systemic. Registering for a seminar about a regenerative-medicine treatment is itself a signal of interest in it. Under Washington's My Health My Data Act, Nevada Senate Bill 370, and the Connecticut Data Privacy Act as amended, information of that kind can qualify as consumer health data.
We treat those signals as sensitive: they sit behind the same access controls as the rest of a contact record, human reads of sensitive contact information are logged, and they are never used for advertising, never sold, and never sent to our AI help assistant.
10.Your privacy rights and how to exercise them
Twenty states now have comprehensive consumer privacy laws in force, and their rights lists overlap heavily. Rather than make you find your state in a table, we offer the same rights to everyone, drafted to the strictest standard among them. Rights unique to one state appear in State-specific disclosures.
The rights we offer
- Know and access. Confirm whether we hold personal information about you and get a copy, with the categories, sources, purposes, and categories of third parties that received it.
- Correct. Have inaccurate personal information about you corrected, taking into account the nature of the information and the purpose it is used for.
- Delete. Have personal information about you deleted, subject to the exceptions the law allows — for example, records we must keep to prove that you opted out of messages, or to comply with a legal obligation.
- Portability. Receive a copy in a portable and, where technically feasible, readily usable format that lets you move it elsewhere.
- Opt out of sale, sharing, and targeted advertising. ShowRunner does none of these, so there is nothing to opt out of. We will still record your request.
- Limit the use of sensitive information. Ask us to restrict the use of sensitive information, including health-related interest signals. See Health-related information.
- Opt out of profiling in furtherance of decisions producing legal or similarly significant effects. ShowRunner does not conduct such profiling.
- Withdraw consent you previously gave — including text and email consent, which you can also withdraw directly as described in Text messages and email.
- Appeal. Ask us to reconsider if we refuse your request.
- Non-discrimination. Exercise these rights without being denied service, charged a different price, or given lower quality. We offer no financial incentives for personal information.
How to make a request — Account Users
Email privacy@showrunnercrm.com from the address on your account, or tell us which account you mean. Much of your account information you can also view and correct yourself in the product. If you want your account deleted, say so and we will confirm what will be removed first, because deleting an organization removes the contact records inside it.
How to make a request — Guests
If you registered for a seminar, ShowRunner holds your record for the business that invited you, and that business decides the outcome. Here is exactly what happens when you write to us:
- Email privacy@showrunnercrm.com. Tell us the phone number or email address you used, and roughly where or when the seminar was. That is usually enough to find you.
- We acknowledge your request and search for records matching what you told us across the organizations on the platform.
- We tell you which business or businesses hold a record for you, so that you know who the controller is.
- We forward your request to that business as its processor, with a summary of what you asked for and the deadline it faces.
- Where we can act directly without a business decision — recording a text or email opt-out, for example — we do it straight away and tell you.
- We follow up if the business does not respond, and tell you the outcome. If it refuses, we tell you so and give you its contact details so you can appeal to it directly.
The honest limit: ShowRunner cannot overrule the business that controls a record, and there is no self-service deletion feature in the product today, so these requests are handled manually by our staff. What we promise is that your request reaches a human, that you learn who holds your information, and that you get an answer.
How to make a request — Visitors
Email privacy@showrunnercrm.com. The only records we are likely to hold are an access request you submitted, and we can delete it on request.
Verifying who you are
Before we release or delete information we need reasonable confidence the request comes from you, because handing your information to the wrong person is itself a privacy failure. For Account Users we verify through the email address on the account or a signed-in session. For Guests we match the phone number or email address against the record, and may ask for one additional detail you would know, such as the seminar date or venue. We will not ask for a government identification document, a Social Security number, or a payment card number, and you should be suspicious of anyone who does. Verification information is used only to verify and is not kept.
Authorized agents
You may use an authorized agent. We will ask the agent for written permission signed by you, and may contact you to confirm it. A person acting under power of attorney, conservatorship, or guardianship may submit a request under that authority with documentation. This matters here: many seminar guests are older adults whose family members help them with correspondence.
Timelines
- We acknowledge a request promptly and respond within 45 days of receiving it.
- Where a request is complex or we have received a large number of them, we may extend once by a further 45 days, and we will tell you before the first period ends, with the reason.
- There is no charge for a request. If a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or decline it — and if we do, we will tell you why and explain how to appeal.
Appeals
If we decline your request, you may appeal by replying to our decision or writing to privacy@showrunnercrm.com with the word appeal in the subject line. Someone not involved in the original decision reviews it, and we write to you with the outcome and our reasoning within 45 days.
If we deny your appeal, you may complain to your state attorney general — for example the California Attorney General, the Connecticut Attorney General, or the Minnesota Attorney General. We will give you the correct address for any other state if you ask.
11.State-specific disclosures
This section provides the additional disclosures required by state comprehensive privacy laws. The rights themselves are unified and listed in Your privacy rights; what follows is the state-specific detail that does not fit there.
States covered
We apply this policy to residents of every state with a comprehensive privacy law in force: California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Where they differ, we drafted to the strictest.
California — categories of personal information
The following table gives the disclosure required by the California Consumer Privacy Act as amended by the California Privacy Rights Act, covering information we handle as a business and, for Guest information, as a service provider. California's exemptions for business-contact and employee information expired on January 1, 2023, so our customers' staff and our own personnel are covered like anyone else.
| Category | Collected | Sources | Business purpose | Categories of recipients |
|---|---|---|---|---|
| Identifiers — name, postal address, email, phone, unique account identifier, IP address | Yes | Account Users, Guests, and Visitors directly; customer imports; list vendors and LeadingResponse | Providing the service, registering guests, delivering messages, authentication, security | Subprocessors listed above; the controlling customer |
| Customer records information under section 1798.80(e) — name with phone or address | Yes | Same as identifiers | Same as identifiers, plus billing for Account Users | Same as identifiers, plus Stripe for billing information |
| Protected classification characteristics — age or date of birth components, gender | Yes, for Guest records | List vendors and demographic appends; occasionally from the Guest | Helping a customer understand and segment its own audience | Hosting and database subprocessors; the controlling customer |
| Commercial information — seminar registrations, party size, appointments, outcomes, amounts | Yes | Registration pages, customer entry, response cards | Running the event, scheduling follow-ups, reporting to the customer | Hosting and database subprocessors; the controlling customer |
| Biometric information | No | Not applicable | Not applicable | Not applicable |
| Internet or network activity — user-agent string, attribution parameters, page-performance metrics | Yes, limited | Automatically when a page is used | Security, consent evidence, fraud prevention, performance | Hosting subprocessor only. No analytics or advertising vendor |
| Geolocation data — approximate coordinates derived from a household postal address | Yes, approximate only | Census Bureau geocoder, from the address on file | Mapping households relative to a venue and estimating travel distance | Census Bureau (address only); hosting and database subprocessors |
| Audio, electronic, visual, or similar information — photographs of handwritten response cards; help-assistant sessions | Yes, where the customer enables card scanning | Photographs taken by the customer at an event; help-assistant use | Extracting handwritten registration details; product support | OpenAI for extraction; storage subprocessor. Raw voice audio is never stored |
| Professional or employment information — business name, role within an organization | Yes, for Account Users | Directly from the Account User | Account provisioning, permissions, billing | Hosting, database, and billing subprocessors |
| Non-public education information | No | Not applicable | Not applicable | Not applicable |
| Inferences — lifecycle tags, attribution, income band supplied by a vendor | Yes, for Guest records | Customer entry; list vendor appends | Helping a customer manage its own pipeline | Hosting and database subprocessors; the controlling customer |
| Sensitive personal information — account credentials; health-related interest signals such as treatment-topic tags | Yes | Account sign-up; registration pages; response cards; list vendors | Authentication; running a seminar on the topic the person expressed interest in. Never used to infer characteristics for advertising | Hosting and database subprocessors; the controlling customer |
ShowRunner has not sold or shared personal information, including sensitive personal information, in the twelve months preceding this policy, and does not do so now. We do not use or disclose sensitive personal information for purposes beyond those permitted under section 7027(m) of the California Consumer Privacy Act regulations, so the right to limit restricts nothing we actually do — but we honour a request to limit anyway. We do not knowingly sell or share the personal information of consumers under sixteen.
Minnesota
Minnesota residents have the rights listed above under the Minnesota Consumer Data Privacy Act, Minnesota Statutes sections 325M.10 to 325M.21, together with two rights that go beyond most other states:
- A list of the specific third parties to which we have disclosed personal data. Ask us and we will provide it, or, if we do not maintain it in that form, the list of specific third parties to which we have disclosed any personal data.
- Questioning the result of profiling. If a decision were made about you through profiling, you may question the result, be told the reason, review the personal data used, and have inaccurate data corrected and the decision reconsidered. As stated in How we use information, ShowRunner does not conduct profiling with legal or similarly significant effects — but the route to ask is open.
Minnesota also requires this notice to describe our retention practices and to carry a last-updated date. Our retention description is at How long we keep information, and the last-updated date appears at the top of this document.
Washington, Nevada, and Connecticut — consumer health data
Washington's My Health My Data Act, Nevada Senate Bill 370, and the Connecticut Data Privacy Act each regulate consumer health data specifically, including the requirement of separate consent for its collection and sharing and a prohibition on geofencing around healthcare facilities. ShowRunner does not use geofencing of any kind. The full statutory notice is the standalone Consumer Health Data Privacy Policy.
Colorado, Connecticut, Oregon, Texas, Montana, and others — consent for sensitive data
Several of these statutes require opt-in consent before processing sensitive data. Where ShowRunner processes seminar-topic interest as sensitive data, it does so on the customer's instruction, and the customer is responsible under the Terms of Service and the Data Processing Addendum for obtaining the consent the statute requires. Oregon residents, like Minnesota residents, may request the list of specific third parties.
Nevada — sale of covered information
Nevada Revised Statutes chapter 603A gives consumers the right to direct an operator not to sell covered information. ShowRunner does not sell covered information and has no plans to. Submit a request to privacy@showrunnercrm.com and we will record it.
Notice of financial incentive
ShowRunner offers no financial incentive, price difference, or service-level difference in exchange for personal information, so no notice of financial incentive is required.
12.How long we keep information
We would rather give an accurate account of our retention practices than an impressive schedule we do not run. Retention is tied to the life of a customer's account, plus deletion on request, and several categories have no automated deletion today.
The general rule
- Account Data is retained while the account is open and for a reasonable period afterwards to allow reactivation, resolve billing, and meet our own legal and accounting obligations.
- Contact Data is retained for as long as the controlling customer keeps it in its organization. When a customer deletes a record, it is removed from the live system. When a customer's account is closed, its organization and the records in it are deleted after the wind-down period described in the Terms of Service.
- Consent ledger entries are retained for at least five years and are not deleted on request. This is deliberate: the ledger is the proof that someone opted out, and destroying it would remove the evidence that protects that person. Retaining a record required to honour an opt-out is an express exception to the deletion right in every state statute listed above.
- Backups persist for a limited period after deletion from the live system and are overwritten on their own cycle.
Where there is no automated deletion today
We say this because it is true, not because we think it is ideal. Message logs are genuinely useful evidence, but indefinite retention of every message body is not a defensible long-term position, and card images least of all. Retention limits and a self-service deletion path are planned work. Until they exist, this policy will keep saying so.
Deletion on request
You can ask us to delete information at any time using the process in Your privacy rights. For Guest records we route the request to the controlling customer and act on its instruction. We may keep a minimal record of the request and of any opt-out, so we can prove we honoured it and so the same record is not re-imported and contacted again.
Third-party retention
Subprocessors apply their own retention periods. In particular, OpenAI applies abuse-monitoring retention of roughly thirty days to the requests we send, as described in AI features, because Zero Data Retention is not configured on our account.
13.How we protect information
Below is what ShowRunner actually does. Every item is a control that exists in the product today.
- Encryption in transit. All traffic to and from ShowRunner is protected with Transport Layer Security.
- Encryption at rest. Stored data is encrypted at rest by our database and storage provider.
- Encrypted Google tokens. Google OAuth refresh tokens are additionally encrypted by the application using AES-256-GCM, with a random initialization vector per encryption and an authentication tag, so a token is unreadable without the application key even to someone holding the database.
- Tenant isolation. Each organization is isolated inside the database by PostgreSQL row-level security keyed to organization membership; a query issued in one organization's context cannot return another's rows.
- Restricted cross-account access. Cross-account access is limited to platform administrators and further restricted by an explicit per-user, per-organization allowlist. Being an administrator is not by itself sufficient.
- Append-only audit of cross-tenant actions. Cross-tenant actions are written to an append-only operator action log, so an entry cannot later be edited or deleted.
- Logging of sensitive reads. Human reads of sensitive contact information are logged by record identifier and count — the fact of access, not the content.
- Rate limiting on public forms. Public forms, including the registration and access-request pages, are rate limited to resist automated abuse.
- Bot protection. Cloudflare Turnstile bot protection is built into the public forms. It is not yet enabled in production.
- Password handling. Passwords are stored only as cryptographic hashes by our authentication provider and cannot be recovered or read by us.
- Least-privilege service access. Help-assistant records are reachable only with service-level credentials, not through ordinary user sessions.
No system is perfectly secure. If we become aware of a security incident affecting personal information, we will notify affected customers and, where the law requires, affected individuals and regulators within the time the applicable statute allows. To report a vulnerability, write to our support address.
14.Children's information
ShowRunner is a business tool, and the seminars our customers run are events for adults. The service is not directed to children, and we do not knowingly collect personal information from anyone under eighteen. Account holders must be adults able to enter a binding contract.
We do not knowingly sell or share the personal information of consumers under sixteen years of age, and we do not sell or share personal information at all. If you believe a child has provided information through ShowRunner, write to privacy@showrunnercrm.com and we will delete it and notify the customer whose organization holds it.
15.Google user data
Connecting your Google account is optional and applies only to Account Users. If you connect it, ShowRunner requests the following scopes and uses them only as described.
- Gmail — send only (gmail.send)
- — Used solely to send emails that you compose, initiate, or schedule inside ShowRunner — for example appointment confirmations and follow-ups to your own contacts — from your own Gmail address, so that replies arrive in your own inbox. ShowRunner cannot read, delete, or modify any email in your mailbox, and never sends a message you did not initiate.
- Google Calendar — read only (calendar.events.readonly)
- — Used solely to display your existing calendar availability inside ShowRunner so that appointments you schedule do not double-book against your personal calendar. ShowRunner cannot create, change, or delete calendar events.
- Basic profile (email, openid)
- — Used solely to display which Google account is connected.
OAuth tokens are encrypted at rest using industry-standard encryption (AES-256). Google user data is never sold, never used for advertising, never used to train machine-learning models, and never shared with third parties except as required to provide the service you requested — for example, transmitting a message you send to Google's own servers for delivery — or as required by law. Human access to Google user data is not permitted except with your explicit consent for support, for security purposes, or to comply with applicable law.
You can disconnect Google at any time in ShowRunner Settings, which deletes your stored tokens, or revoke ShowRunner's access from your Google Account permissions page. Disconnecting stops any further sending from your Gmail address and stops ShowRunner reading your calendar availability; messages already sent remain in your own Sent folder, where they belong to you.
16.Where information is processed
ShowRunner is operated from the United States, and all processing by us and by every subprocessor listed in How we share information takes place in the United States. We do not currently transfer personal information to processing locations outside the United States.
ShowRunner is offered to businesses operating in the United States and is not directed to individuals in the European Economic Area, the United Kingdom, or Switzerland. If you access the service from elsewhere, your information is transferred to and processed in the United States, where privacy laws differ. Nothing here represents that ShowRunner meets the General Data Protection Regulation or any other non-United States privacy law.
17.Changes to this policy
We update this policy when the product, our vendors, or the law changes. The version number, effective date, and last-updated date at the top tell you which text you are reading. Prior versions are available from legal@showrunnercrm.com.
For material changes affecting our customers, we give at least thirty days' notice by email to account administrators or by an in-product notice before the change takes effect, consistent with the Terms of Service. For non-material changes we update the last-updated date and post the revised policy. Continuing to use ShowRunner after a change takes effect means the updated policy applies to you.
If a change would materially reduce the protection given to Guest information, we will also make that change visible on the public registration pages, because Guests do not receive our customer emails and would otherwise never see it.
18.How to contact us
ShowRunner LLC is a Minnesota limited liability company and is responsible for the information described here where we act as a controller. For Guest information we act as a processor for the customer that collected it, as explained in Who this policy covers.
- Privacy requests and questions
- — privacy@showrunnercrm.com — for access, correction, deletion, opt-out, appeals, and anything else in this policy. This address is monitored by a person.
- Product support
- — support@showrunnercrm.com — for help using ShowRunner, including turning off notifications or disconnecting an integration.
- Legal notices
- — legal@showrunnercrm.com — for formal notices, law-enforcement requests, and requests for prior versions of this policy or our current mailing address for service.
The complete set of ShowRunner legal documents is indexed at /legal.
Related policies
- Terms of Service
The agreement between ShowRunner LLC and the businesses that subscribe to ShowRunner. Covers accounts and seats, ownership of Customer Data, messaging and consent obligations, the prohibition on protected health information, fees, warranties, liability limits, indemnities, and binding individual arbitration under Minnesota law.
- Acceptable Use Policy
What Customers may and may not send, collect, claim and do with ShowRunner: prohibited content, list-sourcing rules, data restrictions, health-claim limits, geofencing limits, and how ShowRunner investigates and enforces.
- Messaging Terms
The consent, record-keeping, opt-out, A2P 10DLC registration, carrier, email and do-not-call obligations that apply to every Customer who sends SMS, MMS or email through ShowRunner.
- Data Processing Addendum
The terms governing how ShowRunner processes contact and guest data on a customer's behalf: instructions, security, subprocessors, breach notice, deletion, and assessment rights.
- Subprocessor List
The third-party providers ShowRunner uses to deliver the Service, what each one does, the personal data each receives, and where each processes it.
- Consumer Health Data Policy
The standalone notice required by Washington's My Health My Data Act: the categories of consumer health data ShowRunner processes, where it comes from, who receives it, and how to exercise your rights to confirm, access, withdraw consent, delete, and appeal.
- Guest Privacy Notice
A plain-language explanation for people who registered for a seminar dinner: what the form asked for, how it is used, how to stop text messages and email, who can see your information, and how to have it deleted.