Ci legal

MobileFlow Inc. Ci Privacy Policy

Effective Date: July 13, 2026

This Privacy Policy explains how MobileFlow Inc. collects, uses, discloses, and protects personal information in connection with Ci. It also describes choices and privacy rights that may be available to you.

1. SCOPE AND WHO WE ARE

MobileFlow Inc. (“MobileFlow,” “we,” “us,” or “our”) operates Ci for fans, artists, promoters, venues, labels, and their authorized users. This Privacy Policy applies to Ci mobile applications, websites, dashboards, communications, and related services that link to it.

It does not govern a third party’s independent service or a professional user’s independent use of information outside Ci. For example, a venue or artist may independently collect ticket purchaser information under its own privacy notice. When MobileFlow processes information solely on behalf of a business customer under a written agreement, that customer may be responsible for responding to your privacy request for that information.

Ci uses shared MobileFlow service infrastructure, including modern-api and Hytch systems, for certain identity, reward, subscriber-chat, and related features. This Policy covers MobileFlow’s handling of Ci information across those systems.

2. INFORMATION WE COLLECT

We collect information you provide, information generated through your use of Ci, information from connected services, and information from other users or partners.

Account and profile information. We may collect your name or display name, handle, email address, phone number, password hash, profile photo, home city, approximate home coordinates, account role, organization, social links, biography, preferences, and account-consent records. We store authentication tokens or verification records needed to keep you signed in and secure your account. On a supported device, application tokens are stored using the device’s secure storage features.

Professional and organization information. For artists, promoters, venues, labels, and administrators, we may collect stage or business name, team membership, role, venue details, artist identifiers, show roster, authorization status, booking or campaign information, and administrative activity.

Shows, invitations, referrals, and attendance. We collect show name, venue, address, date and time, geographic coordinates, invitation and RSVP status, referral relationships, guest-list activity, QR codes or scan results, check-in attempts, attendance status, timestamps, verification evidence, distance calculations, audit events, and related notes.

Location information. With device permission, we may receive precise or approximate location while you actively use a location-dependent feature. We may also infer location from an event address, IP address, home city, or information you submit. Ci does not need continuous background location for the ordinary check-in flow described in the current application, but device and operating-system behavior may vary.

Contacts. If you choose contact matching and confirm the upload, we may process phone numbers from selected or available device contacts. We normalize them to look for matching accounts and may retain a cryptographic phone-number hash, an optional contact label, and a matched user identifier. We do not need to retain the raw address-book number in Ci’s contact-match record after hashing and matching.

User Content and communications. We collect profile content, artist pages, setlists, photos, videos, show media, reactions, messages, support requests, reports, block records, moderation decisions, and other content you submit. Media may contain metadata depending on your device and upload settings.

Subscriber chat. We collect room membership and subject information, handoff and entitlement status, plaintext message bodies, sent and read timestamps, reports, report reasons, review notes, moderation status, and block information. Subscriber chat is not end-to-end encrypted. Message content is processed through MobileFlow’s modern-api or Hytch infrastructure and may be accessible to authorized systems, personnel, and providers for the purposes described in this Policy.

Spotify information. If you connect Spotify, we may receive your Spotify user identifier, display name, email within the authorized scope, authorization scopes, access and refresh tokens, top artists, top tracks, recently played items, genres, listening timestamps, track and artist identifiers, and derived music-interest or audio-profile information. Tokens are protected using application and infrastructure controls, but no system is perfectly secure.

Transactions and rewards. We may collect subscription status, product or entitlement, payment-provider customer or transaction identifiers, Stripe account, payment-intent or charge identifiers, purchase amount, currency, spending category, transaction status, reward opportunity and redemption identifiers, sponsor or venue identifiers, credits, ledger status, payout status where enabled, and timestamps. Payment providers generally collect full payment-card details directly; MobileFlow typically receives a token or identifier and transaction details rather than the complete card number.

SafeRide information. When SafeRide is enabled, we may collect a session code, driver or rider role, MobileFlow user identifier, origin or geofence, participation status, arrival or completion time, distance or proximity evidence, reward points, and payout status where a program provides one.

Device, technical, and usage information. We may collect device and platform type, application version, IP address, push token, browser type, operating system, identifiers used for security or abuse detection, pages or screens viewed, actions taken, referring information, error and diagnostic records, login or session events, and timestamps. Our web services may use cookies, local storage, or similar technologies needed for sign-in, preferences, security, and functionality.

Analytics and inferences. We may calculate or infer fan score, experience points, streaks, verified attendance, referrals, engagement, likely music interests, draw or turnout patterns, campaign results, venue or artist insights, weekly snapshots, abuse risk, and other performance or audience metrics. These outputs may be based on incomplete information and should be treated as estimates.

Information from others. We may receive information from another Ci user, an artist or venue team, a label, a promoter, a linked MobileFlow or Hytch account, Spotify, Stripe, Apple, a payment or email provider, a storage or hosting provider, or another partner involved in a feature you use.

3. HOW WE USE INFORMATION

We use personal information to:

create, authenticate, secure, and administer accounts;

provide profiles, shows, invitations, RSVPs, referrals, contact matching, attendance verification, media, chat, rewards, subscriptions, and SafeRide features;

connect fan, artist, promoter, venue, and label workflows;

personalize content and create music, attendance, engagement, fan, artist, venue, and campaign insights;

process transactions, confirm entitlements, administer rewards, prevent duplicate benefits, and maintain records;

send authentication, service, safety, invitation, support, payment, and optional marketing communications;

diagnose errors, support users, maintain availability, and develop or improve Ci;

detect, investigate, and prevent fraud, manipulation, abuse, security incidents, and violations;

moderate content, respond to reports, enforce agreements, and protect users, MobileFlow, and the public;

comply with law, legal process, accounting, tax, audit, and regulatory obligations; and

establish, exercise, or defend legal claims and complete a corporate transaction.

We may aggregate or de-identify information so it is not reasonably linked to an individual. We may use and disclose that information for lawful purposes and will not attempt to reidentify it except to test our de-identification methods or as permitted by law.

4. LEGAL BASES FOR EEA, UK, AND SWISS USERS

Where applicable law requires a legal basis, we rely on:

performance of a contract, to provide the account and features you request;

legitimate interests, such as securing, supporting, analyzing, and improving Ci, preventing fraud, and communicating about the Service, balanced against your rights;

consent, for optional permissions, connected accounts, or marketing where required; and

compliance with legal obligations and protection of vital interests, where applicable.

You may withdraw consent at any time, but withdrawal does not affect processing that was lawful before withdrawal. Some information is required to provide Ci; if you do not provide it, the relevant feature may not work.

5. HOW WE DISCLOSE INFORMATION

Other users and the public. We disclose information you make public, such as public artist profiles, handles, show information, setlists, and selected media. Invitations, referrals, guest lists, messages, and reactions are shared with the people involved in those features.

Artists, promoters, venues, and labels. Authorized professional users may receive show responses, verified attendance, referral, fan-engagement, and campaign information. Subject to fan visibility controls, they may also receive profile and home-city information. If you restrict sharing, we may provide pseudonymous, aggregate, or count-level data, including verified attendance totals.

Service providers. We disclose information to providers that help us host data, store media, deliver email and push notifications, process payments, geocode locations, monitor performance, provide support, and secure Ci. Depending on the feature, these may include providers such as Stripe, Apple, Expo, Google, Vercel, Resend or other email providers, and S3-compatible storage services. They may process information under their own terms when acting independently.

Connected services. At your direction, we exchange information with Spotify, Hytch, or another account you connect. Ci’s shared modern-api and Hytch infrastructure may receive account identifiers, reward, chat, and related information needed to operate cross-service features.

Business customers. If you use Ci through or in connection with an organization, we may disclose account and activity information to authorized administrators of that organization, consistent with role permissions.

Legal, safety, and enforcement. We may disclose information if we reasonably believe it is necessary to comply with law or valid legal process; investigate fraud or security incidents; enforce agreements; protect rights, property, or safety; or respond to an emergency involving danger of death or serious physical injury.

Corporate transactions. We may disclose information in connection with a merger, financing, acquisition, bankruptcy, reorganization, sale of assets, or due diligence, subject to appropriate safeguards.

With consent or direction. We disclose information for another purpose when you direct us or consent.

6. SALE, SHARING, AND TARGETED ADVERTISING

As of the Effective Date, MobileFlow does not sell personal information for money and does not share personal information for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws. We do not use third-party advertising SDKs in the current Ci applications reviewed for this Policy.

If our practices change, we will update this Policy and provide legally required choices, such as a “Do Not Sell or Share My Personal Information” mechanism. Disclosures to service providers, connected services you request, or professional users within Ci are not treated as sales when an applicable legal exception applies.

7. YOUR SETTINGS AND CHOICES

Account and profile. You may review or update certain account, role, profile, avatar, handle, city, and preference information through Ci.

Visibility controls. Fan settings may allow you to control whether hosts receive profile information and whether hosts receive location or home-city information. Restricting these settings may result in anonymized or reduced host-facing data, but verified attendance counts and records needed for integrity, security, or legal compliance may remain.

Location, camera, contacts, photos, and notifications. You can manage permissions in device settings. Ci will request permission before using protected device resources. Revoking a permission may disable the related feature but does not delete information already collected.

Spotify. You may disconnect Spotify in Ci or through Spotify account settings. You may also request deletion of previously imported Spotify data.

Marketing. You may use unsubscribe instructions or settings to stop optional marketing. We may continue to send non-marketing communications needed for your account, security, transactions, or legal notices.

Chat and safety. You may use available reporting and blocking controls. Blocking affects future interactions but may not erase messages already delivered, reported, or retained for safety and legal reasons.

Account deletion. You may use available in-app deletion controls or contact us. Deletion is subject to the limitations described in Section 9.

8. DATA RETENTION

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including providing Ci, maintaining account and transaction history, resolving disputes, enforcing agreements, preventing fraud, meeting legal obligations, and protecting users.

Retention depends on the type of information and context. For example:

active account, profile, and linked-account information generally remains while the account or connection is active;

show, invitation, referral, attendance, reward, and analytics records may remain to preserve historical reporting, integrity, fraud controls, and business records;

transaction and tax-related records may be retained for legally required accounting periods;

reports, blocks, moderation, and security records may remain as needed to protect users and prevent repeat abuse;

messages and shared content may remain until deleted under applicable controls, the room or account is deleted, or the relevant retention period ends;

backups may retain deleted information for a limited period before being overwritten; and

de-identified or aggregated information may be retained without the same limits if it cannot reasonably be linked to you.

When retention is no longer reasonably necessary, we delete, de-identify, or securely isolate information, subject to technical feasibility and legal requirements.

9. ACCOUNT DELETION AND SHARED RECORDS

Deleting a Ci account is designed to remove or de-identify account-owned records in active Ci systems. It may not remove every reference immediately. Some records are maintained with the user field removed, retained because another party has an independent record, held for payment or fraud prevention, or stored temporarily in backups.

Ci information processed in shared modern-api or Hytch infrastructure may follow a separate deletion workflow or retention cycle. We will coordinate a verified request across MobileFlow-controlled systems where applicable. Information copied by another user, posted publicly and republished, or held by an independent third party may remain outside our control.

10. SECURITY

We use administrative, technical, and organizational safeguards designed to protect personal information, such as access controls, credential hashing, token protection, secure device storage where supported, transport security, logging, and provider security features. The safeguards used depend on the sensitivity and context of the information.

No system is completely secure. Subscriber chat is not end-to-end encrypted, and anyone with authorized server-side access for the purposes described in this Policy may be technically capable of accessing message content. You are responsible for using a strong, unique credential, protecting your device, and promptly reporting suspected compromise.

11. INTERNATIONAL DATA TRANSFERS

MobileFlow and its providers may process information in the United States and other countries where privacy laws may differ from those where you live. Where required, we use an approved transfer mechanism or other legally recognized safeguard. You may contact us for more information about applicable safeguards.

12. U.S. STATE PRIVACY RIGHTS

Depending on where you live and whether the applicable law covers MobileFlow or the particular processing, you may have rights to:

confirm whether we process your personal information and access it;

correct inaccuracies;

delete personal information;

obtain a portable copy of certain information;

opt out of sale, targeted advertising, or certain profiling;

limit certain uses or disclosures of sensitive personal information; and

appeal a decision on your request.

We will not discriminate against you for exercising an applicable privacy right. To submit a request, email holt@celebintel.com with the subject “Ci Privacy Request” and describe the right you wish to exercise. We will verify your identity by matching information associated with your account or requesting additional information. An authorized agent may submit a request where permitted, but we may require proof of authority and identity verification.

We may deny or limit a request when an exception applies, such as protecting security, preventing fraud, preserving another person’s rights, completing a transaction, or complying with law. If we deny an appealable request, our response will explain how to appeal.

California notice at collection. The categories we may collect are identifiers; customer-record and account information; commercial and transaction information; internet or electronic activity; approximate or precise geolocation; audio, electronic, visual, or similar content; professional or employment-related information; inferences; and sensitive personal information such as account credentials, precise geolocation, message contents not directed to MobileFlow, and payment-related data. We collect and use these categories for the purposes in Section 3, retain them under Section 8, and disclose them to the categories of recipients in Section 5. We do not use or disclose sensitive personal information to infer characteristics about you outside purposes permitted without a right to limit under California law.

13. EEA, UK, AND SWISS PRIVACY RIGHTS

Where applicable, you may request access, correction, erasure, restriction, or portability; object to processing based on legitimate interests or direct marketing; withdraw consent; and lodge a complaint with your local data-protection authority. You may also have rights concerning decisions based solely on automated processing that produce legal or similarly significant effects.

Ci’s scores, estimates, and recommendations support engagement and operational decisions. MobileFlow does not intend them to make solely automated decisions that produce legal or similarly significant effects about ordinary consumer users. Contact us if you believe a feature has significantly affected you and you want human review.

MobileFlow Inc. is the controller for processing covered by this Policy unless we state that we act as a processor for a business customer.

14. CHILDREN

Ci is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided personal information, contact us. We will investigate and delete the information where required.

Parents and guardians should not permit a child to use an adult’s account. Age restrictions imposed by a venue, event, connected service, or payment platform still apply.

15. THIRD-PARTY LINKS AND SERVICES

Ci may link to or integrate third-party services. Their privacy policies govern their independent collection and use. Review those policies before connecting an account or providing information. MobileFlow is not responsible for the privacy or security practices of an independent third party.

16. CHANGES TO THIS POLICY

We may update this Policy to reflect changes in Ci, law, or our practices. We will post the updated version and revise the Effective Date. If a change materially affects your rights, we will provide additional notice or seek consent when required.

17. CONTACT US

For questions, requests, or complaints about this Privacy Policy or MobileFlow’s Ci privacy practices, contact:

MobileFlow Inc.

Email: holt@celebintel.com

If applicable law gives you the right to complain to a regulator, you may contact the privacy or data-protection authority where you live.

See also the Ci Terms of Service.