Privacy policy
Techweek GR Planner by Moonshine Labs · Last updated September 3, 2026
Techweek GR Planner ("the service", techweek.moonshinelabs.io) is operated by Moonshine Labs ("we", "us"). It helps attendees of Tech Week Grand Rapids build a personal schedule. This policy explains what we collect, why, how long we keep it, and the choices you have. We designed the service to be private by default: browsing and building a plan require no account, and nothing about your plan is visible to anyone else unless you choose to share it.
1. What we collect
Without an account
- Your plan on this device. Interests, availability, saved events, and registration-confirmation answers are stored in your browser's local storage. They stay on your device until you clear them or sign in and choose to merge them.
- Server logs. Standard web-server and Cloudflare logs (IP address, user agent, requested URL, timestamp) used for security and reliability. Retained for up to 30 days.
- Aggregate usage. We count outbound registration-link clicks per event to help organizers. These counts contain no identifier, profile, schedule, or interest data.
With an account
- Sign-in identity. When you sign in with Google or LinkedIn we receive your provider user ID, name, email address, whether the provider verified that email, and profile picture. We use the provider ID as your account identifier. We request only the basic
openid,email, andprofilescopes. We never receive your password, contacts, connections, posts, or calendar. - Your plan. Saved events, attendance status you set (interested, going, registered), the fact that you clicked a registration link, travel-mode preferences, interests, and privacy settings.
- Profile. Optional display name, title, company, and bio you enter.
- Connected accounts. If you connect an X account we store your X user ID, handle, display name, and avatar URL to show a verified handle on your profile. The one-time access token is used to read your handle and immediately discarded; we never post on your behalf or read your timeline.
- Host and speaker claims. If you claim an event you host or speak at, we record the claim, its outcome, and edits you make, in an audit log.
- Notifications. In-app notices about changes to events you saved.
Public event data
Event titles, descriptions, times, venues, hosts, and named speakers are imported from techweekgr.com and public registration pages. Organizer contact details found on those pages are stored privately and shown only to administrators and the verified host of that event; they are never displayed publicly.
2. How we use it
- To build and store your schedule, detect time conflicts, and estimate travel between venues.
- To sync your plan across devices when you sign in.
- To notify you when an event you saved changes time, venue, or status.
- To let hosts and speakers correct their own event information after a verified claim.
- To secure the service, prevent abuse, and keep an audit trail of administrative actions.
We do not sell personal data, show advertising, or build advertising profiles. Interests are used only to rank recommendations and are never displayed to other users.
3. What other people can see
By default your profile is visible only to other signed-in attendees and your itinerary is private. You control both in Profile & privacy. Sharing your itinerary creates an unlisted link; anyone with that link can see the events you saved. You can turn sharing off at any time. Attendee counts on event pages are shown only when at least five people saved the event.
4. Third parties we rely on
- Google (sign-in via OAuth 2.0 / OpenID Connect; Routes API for walking and driving times between venues, which receives only venue coordinates, never your identity or location).
- LinkedIn (sign-in via OpenID Connect).
- X (optional account connection).
- Cloudflare (network security and caching).
- OpenStreetMap tile servers (map images; your browser requests map tiles directly).
- Luma, Eventbrite, and other host registration platforms. When you register for an event you leave this site; their privacy policies apply. We add no tracking parameters or personal data to those links.
Our servers are hosted in the United States. We never request or store your precise device location.
5. Cookies and local storage
We use one strictly necessary session cookie when you sign in, a short-lived cookie during the X connection flow, and browser local storage for your on-device plan and preferences. We do not use advertising or cross-site tracking cookies.
6. Retention and deletion
Account data is kept while your account exists. You can export everything we hold about you (Profile & privacy → Export my data) and delete your account at any time; deletion removes your profile, plan, connected accounts, claims, and notifications immediately. Audit-log entries created by administrative or host actions are retained for one year with your user ID replaced by a pseudonymous reference. Conference data and logs are deleted or anonymized within 90 days after the conference ends unless needed for a future edition.
7. Your rights
Wherever you live, you can access, correct, export, or delete your data using the controls in the app or by emailing us. If you are in the EU/UK or California you also have the rights provided by GDPR/UK GDPR and CCPA respectively, including the right to complain to a supervisory authority. We honour Global Privacy Control signals. The service is not directed to children under 13 and we do not knowingly collect their data.
8. Google API Services
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google sign-in data solely to create and secure your account.
9. Changes and contact
We will post changes here and update the date above. Material changes are announced in the app. Questions or requests: [email protected]. See also our Terms of service.