privacy policy
TL;DR: We collect your email, optionally your phone number, and RSVP details (name, email, IG handle) via Luma. We use them to run events and send you invites you asked for. We never sell your data. The Meta ad pixel loads only if you accept advertising cookies. Email hello@hackinghours.com to see, fix, or delete your data.
Effective date: July 20, 2026. This Privacy Policy explains how Digital Chair, Inc., a New York corporation doing business as "Hacking Hours" ("we," "us," "our"), collects, uses, and shares personal information in connection with hackinghours.com (the "Site") and Hacking Hours events. It applies to attendees, applicants, subscribers, and Site visitors.
1. what we collect, and where it comes from
- From you, via the Site: your email address; optionally your phone number and your consent to receive SMS messages (a separate, unticked checkbox); and any messages you send us.
- From you, via Luma (our RSVP platform): your name, email address, and Instagram handle, plus your RSVP status and any answers to event application questions.
- Automatically: the Site is hosted on Cloudflare and does not run analytics by default. Cloudflare processes standard server/request data (such as IP address and user agent) to deliver and secure the Site. If — and only if — you accept advertising cookies, the Meta pixel collects device and browsing information as described in section 5.
- At events: photographs and video/audio recordings in which you may appear (see our Photo/Video Release), and check-in records.
We do not knowingly collect sensitive personal information (such as government ID numbers, precise geolocation, health data, or biometric identifiers), and we ask that you not include it in messages to us. Checking ID at the door for age verification is done visually; we do not scan, copy, or retain IDs.
2. why we use it (purposes)
- reviewing applications and managing invitations, RSVPs, guest lists, and check-in;
- running events safely, including capacity, age-gating, and security;
- sending event invitations, updates, and marketing by email and — only with your express consent — by SMS;
- advertising Hacking Hours, including via Meta (see section 5);
- promoting the series using event photos and video (see the media release for consent and opt-out);
- protecting our rights, preventing abuse, and complying with law.
3. legal bases
We are a U.S. business, but where a GDPR-style legal basis is relevant we rely on: consent (email/SMS marketing, advertising cookies and the Meta pixel, promotional use of your image where consent is the applicable basis); contract (processing your RSVP and running the event you registered for); legitimate interests (event safety and security, defending legal claims, basic service communications); and legal obligation (records we must keep by law). Where we rely on consent, you can withdraw it at any time without affecting prior processing.
4. no sale of personal information
We do not sell your personal information, and we have not sold it in the preceding 12 months. As described in section 5, using the Meta pixel and Meta custom audiences may constitute "sharing" for cross-context behavioral advertising under the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA"); you can opt out of that sharing as described in sections 5 and 9. We do not knowingly sell or share the personal information of anyone under 16.
5. advertising: meta pixel and custom audiences
- Pixel, gated on consent. The Site includes the Meta (Facebook/Instagram) advertising pixel, but it is loaded only after you accept advertising cookies in our consent banner. If you decline (or never respond), the pixel does not load and no data is sent to Meta from your browsing. You can change your choice at any time on our Consent & Cookie page.
- Custom and lookalike audiences. We may upload hashed email addresses (and, where applicable, phone numbers) from our RSVP and subscriber lists to Meta to show ads to those people ("custom audiences") and to people with similar characteristics ("lookalike audiences"). Meta acts under its business tools terms for this processing.
- Opting out. Email hello@hackinghours.com with the subject "Ad Opt-Out" and we will exclude your identifiers from future custom-audience uploads. You can also control ad preferences in your Meta account settings, and decline advertising cookies to keep the pixel off entirely.
6. who we share it with
We share personal information only with:
- Luma — event RSVP and registration platform (processes name, email, IG handle, RSVP data);
- Cloudflare — website hosting and security (processes request/log data); we do not run separate analytics;
- Twilio — SMS delivery for the Hacking Hours Alerts program (processes phone numbers and message content);
- Meta Platforms — advertising, as described in section 5 (pixel only after consent; hashed list uploads for custom/lookalike audiences);
- professional advisers and authorities — where required to comply with law, enforce our terms, or protect rights, safety, and property;
- a successor entity — in connection with a merger, acquisition, or sale of assets, subject to this policy.
These providers are service providers/processors acting on our documented instructions, except Meta, which acts as an independent business for some advertising processing. We do not share your information with other attendees, and we do not give sponsors attendee lists containing personal information without telling you first.
7. cookies
- Essential cookies — strictly necessary items such as the cookie that remembers your consent choice and any security cookies set by Cloudflare. These are always on.
- Advertising cookies — set by the Meta pixel, only after you accept them in the banner.
- We do not use analytics cookies. We do not currently respond to "Do Not Track" browser signals, but we do honor the Global Privacy Control (GPC) signal as an opt-out of sharing where required by law, and declining our banner keeps all non-essential cookies off. See the Consent & Cookie page to change your choice at any time.
8. retention
- Email and SMS list data: kept until you unsubscribe (or text STOP) or ask us to delete it; we retain suppression records (the minimum needed to keep you unsubscribed) as required for compliance.
- RSVP and application data: kept while the event series is active and for up to 3 years after your last interaction, then deleted or anonymized.
- Event photos and video: retained as promotional assets per the media release, subject to the opt-out and removal process described there.
- Legal, safety, and financial records: kept as long as required by applicable law or for the defense of legal claims.
9. your rights (california and similar u.s. state laws)
If you are a California resident (and, to the extent similar state laws apply, a resident of another state with a comprehensive privacy law), you have the right to:
- know/access — request the categories and specific pieces of personal information we hold about you, the sources, purposes, and third parties involved;
- delete — request deletion of your personal information, subject to legal exceptions;
- correct — request correction of inaccurate personal information;
- opt out of sale/sharing — we do not sell personal information; to opt out of "sharing" for cross-context behavioral advertising, decline advertising cookies, enable GPC, and/or email us an "Ad Opt-Out" request as described in section 5;
- non-discrimination — we will not discriminate against you for exercising any of these rights.
How to exercise: email hello@hackinghours.com with your request. We will verify your identity by matching the email (or phone number) you write from against our records, and may ask for additional confirmation. You may use an authorized agent with signed permission. We respond within 45 days (extendable by 45 more with notice). If we deny a request, we will explain why, and you may appeal by replying to our decision.
10. gdpr-style rights honored voluntarily
Our events and audience are U.S.-based, and we do not target the EU/UK. Nevertheless, if you contact us from anywhere in the world, we will voluntarily honor reasonable requests for access, rectification, erasure, restriction, objection, and withdrawal of consent, using the same process as section 9.
11. children
The Site and our events are intended for adults 18 and older (21+ where alcohol is served). We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, email hello@hackinghours.com and we will delete it.
12. illinois biometric information (BIPA)
We do not collect, capture, purchase, or otherwise obtain biometric identifiers or biometric information as defined by the Illinois Biometric Information Privacy Act. We do not use facial-recognition technology on event photos or video, and we do not permit our processors to do so on our behalf. Ordinary photographs and video are not used to extract biometric identifiers.
13. security
We use reasonable administrative, technical, and organizational safeguards appropriate to the data we hold, including access limited to people who need it, reputable processors with their own security programs, transport encryption (HTTPS), and hashing of identifiers before advertising uploads. No system is perfectly secure; if a breach affecting you occurs, we will notify you as required by applicable law, including the Illinois Personal Information Protection Act.
14. changes to this policy
We may update this policy from time to time. The effective date above will change, and for material changes we will provide reasonable advance notice (for example, email to subscribers or a Site notice). We will not use previously collected information for materially new purposes without the required notice or consent.
15. contact
Digital Chair, Inc. d/b/a Hacking Hours (New York corporation; events held in Chicago, Illinois) — hello@hackinghours.com.
This document was prepared with automated assistance and is not legal advice. Review by a licensed attorney is recommended before relying on it.