Privacy Policy

Effective date: April 18, 2026 · Last updated: September 25, 2026

1. Who We Are

OBOX ("we," "us," "our") is a networking platform centered on real-world events, organizations, and human connections. This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use the OBOX iOS app and related services (collectively, "the Service").

Data Controller: OBOX
Contact email: privacy@confexio.com
Support email: support@confexio.com

2. Data We Collect

a) Account & Profile Information

When you create an account, we collect: your name, email address, and Apple user identifier (via Sign in with Apple). You may optionally provide a username, date of birth, phone number, bio, profile photo, location (city), website URL, and social media handles (Instagram, X/Twitter, LinkedIn, TikTok, YouTube).

b) Event & Social Data

We store your event RSVPs, ticket purchases, attendance records, connections with other users, direct messages, group chat messages, event album photos you upload, and organization memberships.

c) Payment Information

Some events sell tickets, and some are free. Where an event charges, the payment is taken by Stripe on behalf of the organiser running that event. The organiser is the merchant of record — the payment is between you and them, and OBOX is not a party to it.

We never see your card details. Card numbers, expiry dates and security codes are entered directly into Stripe's payment form and never reach OBOX systems. We do not collect or store them, and there is nowhere in our database they could go.

What we do store about a purchase:

  • what you bought, the amount, the currency, and the date
  • an order reference, and whether it is paid or refunded
  • the identifiers Stripe gives us for the payment, so an order can be matched to a refund or a dispute later
  • the email address you gave at checkout, if you bought as a guest without an account
  • if you chose to save a card for next time, the reference Stripe gives that saved card — a token, not the card itself

If you are an organiser taking payment, you connect your own Stripe account and complete Stripe's identity checks with Stripe directly. We store the account's identifier, its status, what Stripe still needs from you, and the last four digits of the bank account you are paid into so you can tell your accounts apart. Payouts go from Stripe to you; OBOX never holds your money.

d) Device & Technical Data

With your permission, we collect your device push notification token (APNs) to send event reminders, messages, and connection requests. We do not collect device advertising identifiers (IDFA), GPS location, or browsing history.

e) Content Reports

If you report a user or message, we store the report reason, optional description, and your user ID for moderation purposes.

3. How and Why We Use Your Data

Under the EU General Data Protection Regulation (GDPR), we process your data on the following legal bases:

PurposeLegal Basis
Account creation and authenticationPerformance of contract (Art. 6(1)(b))
Event ticketing, RSVPs, and attendancePerformance of contract (Art. 6(1)(b))
Messaging between connected usersPerformance of contract (Art. 6(1)(b))
Displaying your profile to other usersPerformance of contract (Art. 6(1)(b))
Push notificationsConsent (Art. 6(1)(a))
Transactional emails (confirmations, invites)Performance of contract (Art. 6(1)(b))
Content moderation (report/block)Legitimate interest (Art. 6(1)(f))
Fraud prevention and securityLegitimate interest (Art. 6(1)(f))

4. Who We Share Your Data With

We share your data only with the service providers listed below, each of which provides protection of your data equal to or greater than this policy. We do not sell your personal data.

  • Supabase (data processor) — Authentication, database hosting, and file storage. Data is stored in Supabase-managed infrastructure with AES-256 encryption at rest and TLS in transit. See Supabase Privacy Policy.
  • Apple (identity provider) — Receives your Apple user ID during Sign in with Apple. Apple does not track which apps you sign into. See Apple Privacy Policy.
  • Resend (data processor) — Sends transactional emails (ticket confirmations, event invitations). Receives email addresses and email content. See Resend Privacy Policy.
  • Apple Push Notification service (APNs) — Delivers push notifications to your device. Receives your device token and notification content.
  • Stripe (payment processor) — Takes payment for paid tickets on behalf of the organiser, and runs identity checks on organisers who take payment. Receives your card details directly from you, and the email address on the order. See Stripe Privacy Policy.
  • Vercel (hosting) — Runs the OBOX website and API. Every request you make passes through it, including your IP address. See Vercel Privacy Policy.
  • Cloudflare (file storage) — Stores the images you upload: your profile photo, event cover images and event album photos. See Cloudflare Privacy Policy.
  • Sentry (error monitoring) — Receives a report when something goes wrong in the app or on the website, which can include your account identifier and the page you were on. It is how we find and fix faults. See Sentry Privacy Policy.
  • Upstash (rate limiting) — Briefly holds your account identifier to stop any one account overloading the service. Nothing is kept beyond the length of the limit itself.
  • Anthropic, via the Vercel AI Gateway (organiser assistant) — If an organiser uses the OBOX assistant to run their event, the event's own data is sent to a Claude model to answer their question. That can include the names and email addresses of people attending that organiser's event. It is not used to train models. See Anthropic Privacy Policy.
  • Google (wallet passes) — If you add a ticket to Google Wallet, the pass and the details printed on it go to Google. Only used if you choose to add the pass.
  • Twilio (SMS) — Configured to send verification codes and event messages by text where an event uses them. Receives your phone number and the message.
  • Neon (database hosting) — Hosts the database behind event web pages built on OBOX, which holds organiser accounts and the content of those pages.
  • Slack (Slack Technologies, LLC; internal alerts and team messages) — Where our team receives error alerts from our monitoring and exchanges internal messages. See Slack Privacy Policy.
  • GitHub (GitHub, Inc.; source code and engineering records) — Holds the OBOX source code and our written records of technical incidents. We now write those records without names or contact details, referring to people by an internal reference. Earlier versions, kept in the repository's history, may still contain them. See GitHub Privacy Statement.
  • Linear (Linear Orbit, Inc.; engineering issue tracking) — Where we track bugs and engineering work. We now write new issues without names or contact details; some older issues may still contain them. See Linear Privacy Policy.
  • Hetzner (Hetzner Online GmbH; hosting for the team's incident-investigation server in the EU) — Runs the server on which we investigate technical faults. The data behind a fault, which can include account details, may be read and kept there. See Hetzner Privacy Policy.

5. International Data Transfers

Your data may be processed in the United States and the European Union. Where data is transferred outside the EU/EEA, we rely on EU Standard Contractual Clauses (SCCs) or adequacy decisions to ensure your data receives an equivalent level of protection. Supabase maintains its own SCCs for transatlantic transfers.

6. Data Retention & Deletion

While your account is active: we keep your data for as long as you keep the account.

When you delete your account

Deleting your account (Settings > Delete Account) happens in two steps.

  • Immediately: your profile is anonymised — name, username, bio, photo and social links are removed — and sign-in is disabled. Your survey answers are deleted, and your email address is scrubbed from our record of the emails we have sent you.
  • Within 30 days: everything else we hold about you is destroyed, including your login, your profile record, your tickets and RSVPs, your connections, your messages, the photos you uploaded, your interests and your device notification tokens. Where deleting your account would also destroy something that is not yours — an event you created, an organisation you founded, a venue an organisation still uses — one of our team resolves that first, inside the same 30 days.
  • In the meantime: messages you sent stay visible to the people you sent them to under the sender name "Deleted User" until your account is purged. The purge removes them from those conversations too.

What we keep afterwards, and why

This is the complete schedule. Unlinked means the record survives without your name, your account, or any pointer to you.

  • Payment and order records — orders, payments and refunds are kept for up to 7 years, as tax and accounting law requires. They are kept unlinked. Where you bought as a guest, the email address you gave at checkout stays on the order, because it is part of the transaction record itself.
  • Event audit log — every change made to an event is written to a log that cannot be edited or deleted, and organisers rely on it as their record of who changed what. Changes you made stay in it, unlinked; the entry keeps the change it recorded.
  • Email and message delivery records — the record that a message was sent, delivered or bounced is kept, unlinked. Your email address is removed from it when you delete your account, so what survives is a delivery trail with nobody attached. Your place in an organiser's automated email sequence is kept the same way, so a message already sent to you is not sent again.
  • Unsubscribe lists — if you unsubscribed from an organiser's emails, or an email to you bounced, your email address stays on that organiser's suppression list. This is the one record we keep that still holds your address, and we keep it on purpose: removing it would quietly put you back on the list you left.
  • Access and approval records — if you exported or revealed another attendee's contact details, decided whether attendees were told about a change, or approved someone's access to OBOX, that is kept unlinked. A record of who reached someone else's data is not a record if the person it names can erase it.
  • Survey answers — answers you gave to organisers' surveys are deleted, not merely unlinked, at the moment you delete your account. If a response record survives that step — one you filled in under a different email address, say — the deletion keeps the empty record unlinked, so an organiser's response counts stay right.
  • Work you did as an organiser — attendee notes and tags, email templates, automations, surveys, event content, event pages, the settings you changed on an event and the decisions you made on other people's requests to join or to speak. All of it was made for an organisation and stays with that organisation. Your name comes off it.
  • Frozen event-report snapshots — when an organiser generates a post-event report, the figures are frozen into a snapshot: counts, totals, rates and whether sponsor deliverables were met. No attendee names, email addresses or free text are in it. If you created one, your link to it is removed when your account is purged; the figures stay with the organisation.
  • Your participation in events — a request to join an event, an application to speak, a co-host invitation you accepted or declined, and a speaker slot on a published programme are the organiser's record that it happened. They are kept unlinked.
  • Content reports — a report you filed, or one filed about you, is kept, unlinked. It is a safety record about another person as much as about you, and we are required to hold it. When your account is purged, your identifier comes off the report on both sides — as its author and as its subject — and what survives is the reason, the description and the outcome, attached to nobody. Deleting your account does not delete the report, and it does not tell us who filed it either.
  • Waitlist sign-ups — if you gave us your email address on a waitlist, or were approved for early access, before you had an account, that sign-up is a separate record held against your email address rather than your account. It is deleted with everything else when your account is purged, along with any early-access approval attached to it. If you never had an account and want a waitlist sign-up removed, email privacy@confexio.com.

7. Your Rights

Depending on your location, you have the following rights regarding your personal data:

Under the GDPR (EU/EEA users)

  • Access (Art. 15) — Request a copy of all personal data we hold about you.
  • Rectification (Art. 16) — Correct inaccurate or incomplete data.
  • Erasure (Art. 17) — Request deletion of your data ("right to be forgotten"). You can do this directly via Settings > Delete Account.
  • Restriction of Processing (Art. 18) — Request that we limit how your data is used.
  • Data Portability (Art. 20) — Receive your data in a structured, machine-readable format.
  • Object (Art. 21) — Object to processing based on legitimate interests.
  • Withdraw Consent (Art. 7(3)) — Withdraw consent at any time (e.g., for push notifications via iOS Settings). Withdrawal does not affect the lawfulness of processing before withdrawal.
  • Lodge a Complaint — File a complaint with a supervisory authority. For Sweden: Integritetsskyddsmyndigheten (IMY).
  • Automated Decision-Making (Art. 22) — We do not use automated profiling or decision-making that produces legal or similarly significant effects.

Under the CCPA (California users)

  • Right to Know — What personal data we collect and how we use it.
  • Right to Delete — Request deletion of your personal data.
  • Right to Correct — Correct inaccurate personal data.
  • Right to Opt-Out — We do not sell personal data. No opt-out is necessary.
  • Right to Non-Discrimination — We will not discriminate against you for exercising your rights.

To exercise any of these rights, email privacy@confexio.com or use the in-app account deletion feature. We will respond within 30 days.

8. Data Security

We protect your data using industry-standard measures including:

  • TLS/HTTPS encryption for all data in transit
  • AES-256 encryption at rest (Supabase-managed infrastructure)
  • Row-level security (RLS) policies ensuring users can only access their own data
  • Secure token-based authentication (Sign in with Apple, JWT tokens)
  • Passwords are never stored in plain text (hashed by Supabase Auth)

9. Cookies and Tracking

The OBOX iOS app does not use cookies, advertising identifiers (IDFA), or tracking pixels. We do not track you across other apps or websites. No third-party analytics or advertising SDKs are integrated into the app.

Our website (confexio.com) uses only essential cookies required for the site to function. No analytics or marketing cookies are used.

10. Children's Privacy

OBOX is not intended for anyone under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, contact us at privacy@confexio.com and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you via push notification or email before the changes take effect. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after notification constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy, your data, or wish to exercise your rights, contact us at:

Privacy inquiries: privacy@confexio.com
General support: support@confexio.com

EU Supervisory Authority: Integritetsskyddsmyndigheten (IMY), Sweden — imy.se