This Privacy Policy describes how CHILL ACT EXPO, operated by The XYZ World Inc. ("we", "us", or "our"), collects, uses, and protects information when you use chillactexpo.com, register for one of our expos, book a pre-screening appointment, or sign up as an exhibitor.
1. Information We Collect
Information you provide directly
- Family registration: parent/guardian name, email, mobile number, number of visitors, activities of interest.
- Screening appointment: parent contact details, child's first name, date of birth, age, gender, type of screening requested, optional notes about previous diagnoses or concerns.
- Exhibitor signup: company name, contact details, locations, team members, social media handles, logo, business address, payment information (processed by Stripe โ we don't store full card numbers).
- Communication: any message you send us by email, SMS reply, or contact form.
Information collected automatically
- Approximate location (IP-based): when you visit our registration pages we use ipapi.co to read the general state/city suggested by your IP address โ only to pre-fill the nearest CHILL ACT expo in the form. Your precise location is not stored or shared.
- Basic usage data: browser type, device type, pages visited, timestamps, referring site. Used only for security and debugging.
Information about children
When you book a pre-screening appointment, we collect limited information about your child (first name, date of birth, age, gender, previous diagnoses if you choose to share them). This information is provided by the parent/guardian and used solely to prepare for the screening and match your child with an appropriate provider at the expo. We comply with COPPA (the U.S. Children's Online Privacy Protection Act). We do not knowingly collect information directly from children under 13 โ only from a parent or guardian on their behalf. Child information is never sold, shared with marketers, or used for advertising purposes. You can request deletion of your child's information at any time.
2. How We Use Your Information
- Send booking confirmations, reminders (14 / 7 / 3 / 1 days before the event), and essential logistics (venue, parking, check-in time, assigned provider).
- Match screening appointments with an appropriate licensed provider at the expo.
- Send optional updates about future CHILL ACT events and opportunities in your area (only if you've opted in; you can unsubscribe anytime).
- Process payment for exhibitor bookings (via Stripe).
- Run the expo safely โ including incident response, lost-and-found, and emergency contact if needed on the day of the event.
- Improve the website and our services.
- Comply with applicable law and respond to lawful requests.
3. How We Share Your Information
We share information only with the trusted service providers that power this site and with the specific screening provider you've been matched with for your appointment. We never sell your information.
- Supabase โ our database and backend infrastructure. Stores registration records, bookings, and exhibitor info securely.
- Stripe โ processes all exhibitor payments. Card details are handled directly by Stripe and never stored on our servers. See Stripe's Privacy Policy.
- Resend โ sends confirmation and reminder emails. See Resend's Privacy Policy.
- Twilio โ sends confirmation and reminder SMS. See Twilio's Privacy Policy.
- Assigned screening provider โ once you book a pre-screening, we share your contact details and your child's information with the licensed provider assigned to your appointment at the expo. You will be notified who that provider is by email and SMS 1โ2 days before the event. The provider uses this information only to conduct your screening.
- Legal obligations โ we may disclose information if required by law, court order, or to protect the safety of our attendees.
4. SMS Messaging
If you opt in by checking the SMS consent box on a registration form, we may send text messages for:
- Booking and payment confirmations
- Reminders about your upcoming event (14, 7, 3, and 1 days before)
- Same-day logistics (check-in time, provider assignment, venue updates)
Message frequency: up to 6 messages per registered event. Message and data rates may apply depending on your carrier and plan. Reply HELP for help, STOP to cancel. Opting out of SMS does not affect your registration; you'll still receive confirmation by email.
5. Your Rights & Choices
- Unsubscribe from email: click the "Unsubscribe" link at the bottom of any email, or email us at [email protected].
- Unsubscribe from SMS: reply STOP to any message.
- Access or correct your data: email [email protected] and we'll respond within 30 days.
- Delete your data: email [email protected] with your request. We'll delete your record (and your child's, if applicable) within 30 days, unless we're required to retain it for legal, tax, or accounting reasons.
- California residents (CCPA): you have the right to know what personal information we collect, request deletion, and opt out of any sale โ which we never do.
- EU/UK residents (GDPR): you have the right to access, rectify, erase, restrict, and port your data. Contact us at [email protected] to exercise these rights.
6. Data Security
All data in transit is encrypted via HTTPS/TLS. Data at rest is stored in Supabase's encrypted databases. Access to personal data is restricted to CHILL ACT EXPO staff who need it to run the expo. Payment data is handled entirely by Stripe (PCI-DSS Level 1 compliant) and never touches our servers.
7. Data Retention
- Registration records: kept for 2 years after your most recent event, then archived or anonymized.
- Screening records: kept for 3 years after the appointment, to comply with typical healthcare recordkeeping expectations. Medical screenings themselves are conducted by licensed providers who retain their own records per their professional obligations.
- Exhibitor / payment records: kept for 7 years for tax and legal compliance.
- Unsubscribe list: kept indefinitely so we don't accidentally contact you again.
8. Cookies & Tracking
We use essential cookies to keep the site working (for example, remembering your form progress). We don't currently use third-party advertising cookies or run retargeting pixels. If we add any in the future, we'll update this policy and show a consent banner.
9. Third-Party Links
Our site may link to third-party sites (sponsors, providers, press articles). We're not responsible for the privacy practices of those sites. Please review their privacy policies separately.
10. Changes to This Policy
We'll update this page when our practices change. The "Last updated" date at the top reflects the most recent revision. For substantive changes we'll email registered users in advance.
๐ฌ Contact Us
Questions about this Privacy Policy or your data? Reach us at:
The XYZ World Inc.
Email: [email protected]
Website: chillactexpo.com