

How we protect your data.
This page is maintained by FUNC to answer common security and privacy questions about the FUNC event platform. It reflects controls that are enabled today and is updated as our practices evolve. It is not an independent certification or audit report.
Last updated: July 25, 2026
Access & authentication
- Email/password accounts with hashed credentials, plus Google and Apple OAuth sign-in.
- Email verification is required before purchasing tickets or accessing organizer tools.
- Session tokens are stored in the browser and automatically refreshed; users can sign out any time.
- Role-based access control separates attendees, promoters, event staff, organization managers, owners, and FUNC platform admins.
- Row-Level Security (RLS) policies enforce data isolation at the database layer so users only see records they are authorized to see.
- Sensitive check-in QR codes rotate every 30–60 seconds to prevent screenshot fraud.
Platform & hosting
- Application traffic is served over TLS (HTTPS) end-to-end.
- Databases and object storage are encrypted at rest by our infrastructure providers.
- Backups and point-in-time recovery are handled by our managed database provider.
- Secrets (API keys, service credentials) are stored in a managed secrets vault, never in source code.
- Edge functions authenticate service-to-service calls using JWTs and validate input on every request.
Data we collect & how we use it
- Account data: name, email, phone (optional), and profile info you provide.
- Order data: tickets purchased, order totals, and payment method identifiers (never full card numbers).
- Event data: events you create, tickets tiers, attendee rosters, promoter activity.
- ID scans (optional, 18+/21+ events only): when an organizer enables ID scanning, the driver's-license barcode is decoded on-device to verify age. FUNC records only the verification result (pass/fail) — the raw ID payload is not stored on our servers.
- Usage data: basic page events and error logs to keep the product working.
See our Privacy Policy for the full details, including your rights under GDPR and CCPA.
Subprocessors & integrations
We use a small set of vetted providers to run FUNC. Each handles a specific slice of data:
| Provider | Purpose |
|---|---|
| Stripe | Payment processing, Connect payouts, subscriptions (PCI-DSS Level 1) |
| Lovable Cloud (Supabase infrastructure) | Managed Postgres, auth, storage, edge functions |
| Resend | Transactional email delivery |
| Google Maps Platform | Address autocomplete and event maps |
| GoHighLevel | Optional SMS relay for organizer messaging |
| Google Gemini (via Lovable AI Gateway) | Milo AI assistant (Pro feature) |
Payments are processed by Stripe; FUNC never sees or stores full card numbers.
Retention, deletion & privacy requests
- Order and ticket records are retained for the life of the account so buyers and organizers keep an accurate history.
- Draft events and unpublished data can be deleted from the organizer dashboard at any time.
- Account deletion, data export, and correction requests can be submitted to privacy@func-app.com. We aim to respond within 30 days.
- Financial and tax records may be retained after deletion where required by law.
Vulnerability disclosure
If you believe you've found a security issue, please email security@func-app.com with steps to reproduce. Please don't publicly disclose the issue until we've had a chance to investigate and remediate. We appreciate coordinated disclosure and will credit reporters in our release notes when appropriate.
Compliance & shared responsibility
FUNC uses SOC 2 Type II–attested infrastructure providers (Stripe, our managed database provider), but FUNC itself is not currently SOC 2, ISO 27001, or HIPAA certified. We're planning to formalize our controls with a compliance partner (e.g., Vanta) as the business scales. For now, we describe only the controls we actually operate today.
Security is a shared responsibility: FUNC secures the platform; organizers are responsible for managing their team's access, protecting their own credentials, and handling attendee data in line with the laws that apply to their events.
Questions?
Security & privacy: security@func-app.com
General support: support@func-app.com
See also our Privacy Policy, Terms of Service, and Refund Policy.