Privacy Policy
Effective date: May 11, 2025
McBride Family Productions ("MFP", "we", "us", or "our") operates the platform at mcbridefamily.net and related subdomains, including the guest song request interface and the Backstage portal. This Privacy Policy explains what information we collect, how we use it, and how we protect it.
By using our platform you agree to the practices described in this policy.
1. Information We Collect
Account Data
- Name and display name
- Email address
- Phone number (optional, provided voluntarily)
- Organization affiliations and role within the platform
- Login session identifiers and authentication records
Event Data
- Event title, venue, date, and timeline information
- Song requests submitted by guests (song title, artist, requester name, message)
- Guest IP addresses associated with song requests and votes (used for rate-limiting)
- Uploaded files associated with events
- Operational notes entered by platform users
Communications
- Messages sent through platform communication features
- Push-to-talk metadata (duration, timestamp, sender identity)
- Talkback audio submissions (stored temporarily; see Section 7)
Technical Data
- IP address and browser/device information for security and rate-limiting purposes
- Session tokens and cookies (see Section 5)
- Audit log entries for security-relevant actions
2. How We Use Your Information
- To operate and deliver the song request and event management platform
- To authenticate users and maintain secure sessions
- To send transactional emails (e.g., magic login links, event notifications)
- To enforce rate limits and prevent abuse
- To improve the platform and troubleshoot issues
- To comply with legal obligations
3. Marketing and Media Consent
If you voluntarily submit a voice recording, audio talkback, photo, or other media through the platform, you grant McBride Family Productions a non-exclusive, limited license to use that content for promotional purposes (such as social media highlights or event recaps), unless you request otherwise.
You may withdraw this consent at any time by contacting us at privacy@mcbridefamily.net.
4. Payment Processing
Payment processing is handled exclusively by third-party providers (currently Stripe). We do not store full credit card numbers, CVV codes, or raw payment credentials on our servers. We store only:
- Transaction reference identifiers
- Invoice metadata and status
- Reconciliation notes
Please review Stripe's privacy policy at stripe.com/privacy for details on how your payment data is handled.
5. Cookies and Session Technologies
We use cookies and browser local storage for the following purposes:
- Session cookie (
mfp_session): Maintains your authenticated session in the Backstage portal. This cookie is HTTP-only and set with the Secure flag on HTTPS connections. - Cookie consent acknowledgement: Remembers that you have acknowledged this notice.
- Private event passcode: Stores temporary passcode access for private events in session storage.
We do not use advertising cookies or cross-site tracking technologies.
6. Third-Party Providers
- Brevo (Sendinblue): Transactional email delivery. Email addresses and event-related content may be transmitted to Brevo to deliver emails on our behalf.
- Stripe: Payment processing. See Section 4.
- Apple Music / Spotify: Music metadata search. Search queries are sent to these providers to retrieve song information. No personally identifiable information is transmitted.
7. Data Retention
- Contracts and audit logs: Retained long-term for legal and compliance purposes.
- Talkback audio submissions: Retained for a limited period; may be removed upon request.
- Event chat and temporary uploads: Retained for a limited period after the event concludes.
- Login tokens and session data: Expire automatically per the configured session lifetime.
8. Data Security
We implement security best practices including:
- HTTPS encryption for all data in transit
- Secure, HTTP-only session cookies
- CSRF protection on all state-changing requests
- Rate limiting on authentication endpoints
- Role-based access controls throughout the platform
- Encryption of sensitive stored values (e.g., TOTP secrets)
- Security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options)
9. Your Rights
Depending on your jurisdiction, you may have rights regarding your personal data including the right to access, correct, or delete information we hold about you. To exercise any of these rights, contact us at privacy@mcbridefamily.net.
10. Children's Privacy
The platform is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has submitted personal information through the platform, please contact us and we will remove it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be noted with a revised effective date. Continued use of the platform after changes constitutes acceptance of the revised policy.
12. Contact Us
For privacy-related inquiries, data requests, or to report a concern:
- Email: privacy@mcbridefamily.net
- General contact: events@mcbridefamily.net