Legal

Privacy Policy

What we collect, why, and what you can do about it. The short version: we do not sell anyone's data, we run no advertising trackers, and if you registered for somebody's event, your information belongs to that organizer, not to us.

Version 1.0 · Effective September 18, 2026 · We Do Your Events LLC

1. Who This Covers, and Which Part Applies to You

We Do Your Events LLC ("we", "us") runs WDYE Studio and this website. Three different kinds of people reach us, and the rules are genuinely different for each:

Visitors to wedoyourevents.com. See sections 2 and 7.

Customers: people with a WDYE Studio account who build and publish events. See sections 3 and 5 to 9.

Registrants: people who signed up for an event that somebody else runs on our software. Read section 4 first. The short answer is that the organizer of that event, not us, decides what is collected and answers your requests.

2. If You Are Just Visiting This Website

We set no cookies on this website. Not for advertising, not for analytics, not for anything.

We run no third-party trackers. There is no Google Analytics, no Google Tag Manager, no Meta pixel, no Segment, no Hotjar, no advertising network. We use Cloudflare Web Analytics, which counts page views without cookies and without building a profile of you.

Our host, Cloudflare, processes your IP address in order to serve the page and to block attacks. That is ordinary infrastructure logging, kept briefly and not used to identify you.

If you fill in the contact form we get what you typed: your name, email, phone, company, website and whatever you tell us about your event. We use it to answer you and to talk about working together. Nothing else.

3. If You Have a WDYE Studio Account

We hold what you gave us and what running the service requires: your name, email, organization, the events you build, the people you invite and what you granted them, your support conversations, and a record of your purchases.

We never store your access code. We store a salted hash of it, which cannot be reversed, so nobody, including us, can read your code out of the database.

Payment card details never reach us. Stripe handles payment and holds the card. We see the outcome, the amount and the last four digits, never the number.

We use this to operate your account, take payment, provide support, and send you transactional email about your own events. We do not sell it and we do not rent it.

4. If You Registered for an Event

The organizer of that event decides what is asked of you and why. We only hold it for them. In data protection terms the organizer is the controller and we are their processor. We act on their instructions; we do not decide what their form asks, what they do with the answers, or what they email you.

So please take requests to the organizer. If you want your registration data corrected or deleted, contact the event organizer. If you cannot reach them, contact us and we will pass it on and support them in answering it, but the decision is theirs to make, not ours.

We do not market to you. Registering for somebody's event does not put you on any list of ours. We do not use organizers' registrant lists to sell anything, to ourselves or to anyone else.

What the organizer collects through us typically includes your name and contact details, the sessions or items you chose, your answers to their questions, any files you uploaded, and your order and check-in record.

5. Cookies

This website sets none. The studio at wdyestudio.com sets only what signing in requires:

  • A session cookie that keeps you signed in. It is marked HttpOnly and Secure so scripts cannot read it and it never travels unencrypted.
  • A short-lived preview cookie (one hour) so a private preview link opens the unpublished site you were sent.
  • A review cookie when you enter the password for a site that is still behind its review gate.

All three are strictly necessary to provide the service you asked for. None is used for advertising and none tracks you across other websites.

6. Who Else Processes Data, Including AI

We use a small number of providers, each of which processes data only to deliver the service and is bound to confidentiality and security obligations:

  • Cloudflare - hosting, database, file storage, bot protection and the web application firewall.
  • Stripe - payments. Money your registrants pay goes directly to the organizer's own Stripe account; we never hold it.
  • Resend - transactional email.
  • Anthropic - the optional AI setup review described below.

About the AI. WDYE Studio has a setup review that runs only when a customer asks for it. It sends the event's CONFIGURATION to Anthropic: settings, sections, schedule structure and the findings our own rule engine computed. It does not send registrant records - no attendee names, emails, phone numbers, payment details or answers to registration questions. What comes back is advice. The AI changes nothing and cannot act on an account, and no data is used to train any model. A customer who would rather no data reached an AI provider can ask us to switch it off.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have never done either.

7. How Long We Keep Things

Account and event data lives as long as the account does. If a plan ends we keep the data available for at least 30 days so it can be exported, then we may delete it.

Records of purchases and refunds are kept longer, because tax and accounting law requires it and because they are the proof a payment happened.

Registrant data is kept for as long as the organizer's account holds it. Deletion is the organizer's decision, subject to the same legal exceptions.

Contact form messages are kept while we are talking and for a reasonable period afterwards.

8. Your Rights

Wherever you live, you can ask us what we hold about you, ask us to correct it, ask us to delete it, or ask for a copy. Email us and we will answer. We will not charge you and we will not treat you differently for asking.

Under the GDPR and UK GDPR you also have the right to object to or restrict processing, the right to data portability, and the right to complain to your supervisory authority. Where we process your data as a customer of ours, our legal bases are performing our contract with you, our legitimate interest in running and securing the service, and, where the law requires it, your consent.

Under the Colorado Privacy Act and similar US state laws you have rights of access, correction, deletion, portability, and the right to opt out of sale or targeted advertising. There is nothing to opt out of: we do neither.

If your data reached us through an event you registered for, send the request to the organizer. See section 4. We will help them answer it.

9. Security, Transfers and Children

Everything is encrypted in transit and at rest, access codes are stored as salted hashes, sign-in is rate limited, and a managed web application firewall sits in front of every surface. Section 10 of our Software and Services Agreement describes this in more detail. No system is perfectly secure, and we will tell affected customers without undue delay, and in any event within 72 hours, if a breach affects their data.

We are based in the United States and data is processed there. Where personal data moves out of the EEA or the UK, that transfer is made under the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum.

Our software is built for event organizers and is not directed at children. We do not knowingly collect personal information from a child under 13. If an organizer's event involves minors, that is the organizer's responsibility to handle lawfully, including any parental consent their jurisdiction requires.

10. Changes, and How to Reach Us

If we change this policy we will update the version and date at the top. A material change to how we handle customer data will also be told to customers directly.

Questions, or a request about your data: contact us.