Legal
Privacy Policy
Last updated: September 8, 2026
1. Overview
Chidolabs LLC ("Chidolabs," "tryceratop," "we," "us," or "our") provides tryceratop, a web-based platform that helps nonprofit and mission-driven organizations manage funding, budgets, and event operations (the "Service"). This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, and the choices and rights available to you. This policy applies to visitors of our marketing site and to users of the Service, and is designed to address applicable privacy and data protection requirements, including the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended by the CPRA ("CCPA"), where applicable.
2. Information We Collect
Information you provide to us:
- Account information — name, email address, password (stored as a salted hash, never in plain text), and organization name/role when you register.
- Organizational content — event details, budgets, funder and sponsor records, run-of-show plans, tasks, comments, attachments, and cover images that you or your team upload to the Service.
- Contact and key-contact records — names, emails, phone numbers, and titles of speakers, sponsors, and key contacts that you choose to add to an event.
- Billing information — billing name and address, and the last four digits and card brand of a payment card. Full card numbers are collected and stored directly by our payment processor, Stripe — see Section 6.
- Communications — information you provide when you contact us for support or other inquiries.
Information collected automatically:
- Usage data — pages and features accessed, actions taken within the Service, and timestamps, collected to operate and improve the Service.
- Device and log data — IP address, browser type, operating system, and general device information, collected automatically by our hosting and infrastructure providers as part of standard request logging.
- Cookies and similar technologies — see Section 5.
Information from third parties: if you or your organization choose to connect a third-party account such as Eventbrite, we receive event and order data from that provider, which you authorize at the time of connection. For each order, this currently includes: attendee first and last name, email address, ticket type, order date, quantity, order/ticket code, and the revenue associated with that order. We use this information as described in Section 3.
AI assistant interactions: if you use tryceratop's AI assistant features ("Bodhi AI assistant"), the messages you send it are transmitted to our AI service provider (see Section 4) to generate a response. We do not separately store the free-text content of those messages or the assistant's replies in our own database. We do keep a record of each use, including which organization and user made the request, which AI feature was used, the AI model and token counts (used to operate and monitor the feature), and, when the assistant takes an action on your behalf such as creating an event, the structured details of that action, in the same way we log any other change made in the Service.
3. How We Use Your Information
We use personal information for the following purposes:
- To provide the Service (performance of our contract with you) — to create and maintain your account, operate the features you use, process billing, and provide customer support.
- To generate analytics for your organization (performance of our contract with you) — where you connect a third-party account such as Eventbrite, we use the attendee and order data described in Section 2 to build reporting for your organization, such as attendance trends, ticket sales patterns, and revenue over time. We do not use this data to contact attendees directly on our own behalf, and we do not share it outside your organization except as described in Section 4.
- To communicate with you (contract performance and legitimate interest) — service updates, security alerts, and responses to your inquiries.
- To maintain and improve the Service (legitimate interest) — monitoring performance, diagnosing technical issues, and understanding how features are used.
- To protect the Service (legitimate interest) — detecting, preventing, and investigating fraud, abuse, and security incidents.
- To comply with the law (legal obligation) — responding to lawful requests, tax and accounting obligations, and enforcing our Terms of Service.
- With your consent — for optional cookies or communications, where we rely on consent as the legal basis, which you can withdraw at any time.
We do not use Customer Content to train public, shared, or third-party artificial intelligence or machine-learning models. Where we use a third-party AI provider (Section 4) to power AI features, we rely on that provider's own commitment not to use content submitted through its API to train its models. We do not sell your personal information, as described in Section 4.
4. How We Share Your Information
We do not sell your personal information. We share information only in the following circumstances:
- Within your organization. Information you add to an event or organization account is visible to other members of that organization, according to the roles and permissions your organization's administrators configure.
- Service providers. We share information with vendors who process it on our behalf, under contractual confidentiality and data-protection obligations, including, but not limited to: Supabase (database hosting and authentication), Vercel (application hosting), Stripe (payment processing), Resend (transactional email delivery), OpenAI (AI assistant features, including generating event content, answering questions about your organization's data, and drafting funding-related materials), and Eventbrite (source of the attendee and order data described in Section 2, only if you connect that integration).
- Legal compliance and safety. We may disclose information if required by law, subpoena, or legal process, or when we believe in good faith it is necessary to protect the rights, property, or safety of Chidolabs, our users, or the public.
- Business transfers. If we are involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction, subject to this Privacy Policy or a policy at least as protective.
5. Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Strictly necessary cookies — to keep you signed in and maintain your session; the Service cannot function without these.
- Preference cookies — to remember settings such as your last-viewed organization or display preferences.
We do not currently use third-party advertising cookies or cross-site tracking. Most browsers let you block or delete cookies through their settings; doing so for strictly necessary cookies may prevent you from signing in.
6. Payment Information & Security
All subscription payments are processed by Stripe, Inc., a PCI-DSS Level 1 certified payment processor — the highest level of certification available in the payments industry. When you enter payment card details, they are transmitted directly to Stripe over an encrypted connection and are never received or stored on tryceratop's own servers or database. We retain only a non-sensitive reference to your payment method (such as the card's brand and last four digits) so we can display it to you and manage your subscription.
More broadly, we apply industry-standard technical and organizational safeguards across the Service, described in Section 7.
7. Data Security Measures
We protect personal information using measures including:
- Encryption of data in transit (TLS/HTTPS) between your browser and our servers.
- Encryption of data at rest within our database provider's infrastructure.
- Row-level access controls so that data is only accessible to authenticated members of the correct organization, enforced at the database level.
- Password hashing using industry-standard algorithms — we never store plaintext passwords.
- Role-based permissions within organizations to limit who can view or edit sensitive records.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting personal information, we will provide notice without undue delay and in accordance with applicable law.
8. Data Retention and International Transfers
Retention. We retain personal information for as long as your account is active, and for a limited period afterward to allow you to reactivate your account, comply with legal and accounting obligations, resolve disputes, and enforce our agreements. As a general rule, we delete or anonymize account and organizational data within 12 months after an account is closed or becomes permanently inactive, unless a longer period is required by law (for example, financial records related to billing). Backup copies are purged on a rolling basis and may persist for a limited additional period after deletion from active systems.
AI assistant records. The records described in Section 2 (AI assistant interactions) follow the same general retention rule above — deleted or anonymized within 12 months after an account is closed or becomes permanently inactive, unless a longer period is required by law.
Third-party integration data. If you disconnect a third-party integration such as Eventbrite, or if our access to that account is revoked or expires, we will delete the attendee and order data received through that integration within 30 days, unless a longer period applies under the general retention rule above (for example, to comply with law) or you have separately authorized us to retain it for continued analytics.
International transfers. We and our service providers (Section 4) may process personal information in the United States and other countries outside your own, which may have different data protection laws. Where we transfer personal information out of the European Economic Area, the UK, or Switzerland, we rely on appropriate safeguards, such as Standard Contractual Clauses, or transfers to providers certified under an approved data protection framework.
9. Your Privacy Rights
If you are in the European Economic Area, UK, or Switzerland (GDPR): you have the right to:
- access the personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request erasure of your personal information, subject to certain exceptions;
- request a portable copy of the information you provided to us, in a structured, machine-readable format;
- object to, or request that we restrict, certain processing;
- withdraw consent at any time, where processing is based on consent; and
- lodge a complaint with your local data protection authority.
If you are a California resident (CCPA/CPRA): you have the right to:
- know what personal information we collect, use, and disclose, and why;
- request deletion of your personal information, subject to certain exceptions;
- request correction of inaccurate personal information; and
- opt out of the "sale" or "sharing" of personal information — we do not sell or share personal information for cross-context behavioral advertising purposes.
We will not discriminate against you for exercising any of these rights.
To exercise any of these rights, contact us at legal@tryceratop.com. We may need to verify your identity before completing your request. Where information is submitted on behalf of an organization, an organization administrator may also manage or delete that data directly within account settings. If your personal information was provided to us by an organization using the Service — for example, as an event attendee whose information we received through a connected Eventbrite account — you may also contact us directly at legal@tryceratop.com, and we will coordinate with the relevant organization to address your request.
10. Children's Privacy
tryceratop is a business tool intended for use by adults acting on behalf of an organization, and is not directed at children. We do not knowingly collect personal information from anyone under the age of 13, in compliance with the Children's Online Privacy Protection Act ("COPPA"). If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete it promptly. If you believe a child has provided us with personal information, please contact us at legal@tryceratop.com.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through an in-product notice before the changes take effect. Continued use of the Service after a change takes effect constitutes your acceptance of the revised policy.