Privacy policy
How Information Session Manager handles personal information
Effective August 19, 2026
This policy describes how Information Session Manager collects, uses, discloses, retains, and protects personal information when people use the service, including its Zoom integration.
1. Who controls the information
Information Session Manager provides a multi-organization event-management service. For information submitted to an organization’s events, that organization decides why the information is collected and how its authorized Leaders use it. Information Session Manager processes that information to provide the service and also controls information used for platform administration, security, billing, and support.
2. Information we collect
- Identity and access information: name, email address, authentication identifiers, organization memberships, permissions, sign-in history, and security events.
- Organization and event information: organization name, event schedules, venues, capacities, ticket settings, team or upline information, instructions, and staff assignments.
- Registration and attendance information: attendee and guest names, email addresses, delivery choice, ticket type, order status, admission codes, door check-ins, and attendance estimates.
- Zoom information: the connected Zoom account’s profile and capability information; Meeting or Webinar identifiers and settings; registrant identifiers and join links; and participant join, leave, duration, display-name, and matching information. The service does not access Meeting audio, video, chat, or recordings.
- Payment information: ticket amounts, currency, Stripe account, payment, refund, dispute, transfer, and payout identifiers, statuses, and balance impacts. Payment-card details and dispute evidence are handled by Stripe and are not stored by Information Session Manager.
- Communications and technical information: support messages, email-delivery status, IP-derived security data, browser and request metadata, logs, and error information.
3. How we use information
- Provide registration, ticketing, guest invitations, door check-in, Zoom access, live attendance, event closeout, staff permissions, alerts, and support.
- Create and update an organization’s Zoom Meetings or Webinars, register attendees, and reconcile Zoom participation.
- Process payments and refunds, reconcile disputes and payouts, and send authorized financial alerts through an organization’s connected Stripe account.
- Authenticate users, prevent abuse, diagnose failures, keep audit records, and protect the service.
- Send operational messages such as registration confirmations, access links, invitations, receipts, and support replies.
- Comply with legal obligations and enforce the Terms of Use.
We do not sell personal information or use Zoom data for advertising.
4. When information is disclosed
Information may be disclosed to:
- The relevant organization: authorized staff can access registration, attendance, event, and financial information according to their individual permissions.
- Service providers: Zoom for Meetings and Webinars; Stripe for payments; WorkOS for managed authentication; Resend for email delivery; Render for application and database hosting; and other vendors needed to operate and secure the service.
- Legal and safety recipients: when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or respond to lawful process.
- A successor: as part of a merger, financing, acquisition, reorganization, or sale, subject to appropriate confidentiality protections.
Providers receive only the information needed for their services and handle it under their own terms and privacy commitments.
5. Zoom authorization, storage, and removal
A Leader with permission connects the organization’s Zoom account using Zoom OAuth. Access and refresh tokens are encrypted by the application before database storage. Meeting and Webinar identifiers, registrant details, join links, and attendance records are stored so the organization can operate and document its events. HTTPS is used for browser and Zoom API traffic.
A Zoom account owner can revoke the app in the Zoom App Marketplace under Manage → Added Apps. Revocation stops future Zoom API access. Removing Zoom does not automatically erase historical registration, financial, or attendance records that the organization may need. A user or organization can request deletion as described below.
6. Retention
We retain information only as long as reasonably necessary to provide the service, maintain event and financial history, resolve disputes, meet legal obligations, and protect security. Retention depends on the information and the organization’s continued use. Authentication and integration credentials are removed or made unusable when access is revoked or the related connection is deleted. Backup copies may remain for a limited recovery period before being overwritten.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transport, application encryption for Zoom OAuth tokens, secret separation, tenant-scoped authorization, least-privilege staff permissions, signed admission and access links, audit records, input validation, dependency checks, and monitoring. No system can guarantee absolute security.
8. Your privacy rights
Depending on where you live, you may have the right to request access to, correction of, deletion of, or a portable copy of your personal information; to object to or restrict certain processing; to withdraw consent; and to appeal a denied request. You may also use an authorized agent where applicable.
To exercise a right, use the contact form and choose General question or Technical support. State the right you want to exercise and the organization or event involved. We may verify your identity and authority before acting. If an organization controls the relevant event information, we may forward the request to that organization or help you contact it. We will not discriminate against you for exercising a privacy right.
9. Cookies and local storage
The service uses cookies and browser storage that are necessary for authentication, security, recovery, organization routing, and remembering registration details on a device. The service does not use third-party advertising cookies.
10. Children
The service is intended for adults operating or attending business information sessions and is not directed to children under 18. Do not knowingly submit a child’s information.
11. International processing
Information may be processed in the United States and other places where service providers operate. Where required, appropriate contractual or legal safeguards are used for cross-border processing.
12. Changes and contact
We may update this policy as the service or law changes. The effective date above will be revised, and material changes will be communicated when required.
Questions, complaints, and privacy requests can be sent through the Information Session Manager contact form.