Back to shows

Privacy Policy

Effective April 21, 2026

The short version

In plain English.

  • ·We collect only what we need to run the Service: your email and password (if you register), optional profile details, and the events you save.
  • ·We don't sell your data. We don't rent it. We don't trade it. We never will.
  • ·We don't run third-party ad trackers, session replay tools, or behavioral profilers.
  • ·We store data with a few well-known providers (Supabase, Vercel, Cloudflare) that are contractually required to protect it.
  • ·You can delete your account anytime. Your data is wiped on a rolling basis after that.
  • ·Questions or requests: email us. We answer.

This summary is a convenience, not a contract. The detailed policy below is the controlling document.

Scope of this policy

This Privacy Policy (the “Policy”) describes how The Fringe (“The Fringe,” “we,” “us,” “our”) collects, uses, discloses, retains, and protects personal information in connection with the website at alleymap.com, any related mobile applications, APIs, emails, and other services (collectively, the “Service”).

Your use of the Service is also governed by our Terms of Service, which are incorporated by reference. Capitalized terms not defined here have the meanings given in the Terms.

Information we collect

We collect only what is reasonably necessary to operate and improve the Service. The categories below describe what we may collect; whether we actually collect a given category depends on how you use the Service.

Account registration

When you create an account, we collect your email address, a password, your first and last name, and your date of birth. Passwords are processed by our authentication provider, Supabase Auth, which stores them as salted hashes; The Fringe staff never see your plaintext password. You may also sign in by one-time email link (“magic link”) instead of password. Date of birth is used to verify that you meet the Service's minimum age and is not shown publicly.

Optional profile details

You may choose to add your phone number, preferred NYC neighborhoods, preferred genres, and a “show-finding style” (spontaneous / planner). These help us personalize recommendations. All fields are optional and you can remove them at any time.

Saved events and interactions

When you save an event (“interested” list), swipe through Match Mode, or set filters, we store these interactions so the Service can show them back to you across devices. Swipe-left / skip decisions are stored to prevent us from showing you the same show twice.

Authentication cookies

When you sign in (by password or magic link), our authentication provider (Supabase Auth) issues a session that we store in a secure HTTP-only cookie via the @supabase/ssr library. This cookie keeps you signed in across server and client requests, and is cleared when you sign out or when the session expires. It is a strictly necessary cookie under ePrivacy / GDPR Article 5(3).

Local browser storage

We use your browser's local storage to cache filters, saved-event IDs, and your cookie-consent decision for a faster experience. This data never leaves your device until you sign in, at which point the saved-event list is synced with your account.

Server logs

Our hosting provider (Vercel) automatically logs request data including IP address, user agent, timestamp, and the URL requested. These logs are used for security, rate limiting, abuse prevention, and troubleshooting. They are typically retained for 30 days and are not combined with your account data for analytics or advertising.

Bot / abuse protection

We use Cloudflare Turnstile on signup forms to detect automated abuse. Turnstile collects limited telemetry (e.g., timing and device-class signals) but is designed to avoid collecting personally identifying information and does not use the data for advertising.

Geolocation (browser-only)

If you enable location-based features (e.g., “closest to me”), your browser computes distances locally. Your coordinates are not transmitted to our servers.

Communications with us

When you email us or respond to a product survey, we retain the contents of those messages for as long as needed to respond to your inquiry and document our support history.

What we do not collect

No third-party advertising trackers (no Google Analytics, Meta Pixel, TikTok Pixel, AppNexus, Criteo, or similar).
No session-replay tools (no FullStory, Hotjar, LogRocket, Microsoft Clarity).
No behavioral profiling, fingerprinting, or cross-site tracking.
No sale, rental, lease, trade, or sharing of your personal information with data brokers or advertisers.
No precise geolocation on our servers. Distance calculations happen in your browser.
No scraping of third-party accounts (we never ask for social-login credentials to “import” contacts).

How we use your information

We use the categories of information described above for the following purposes:

  • To provide, operate, and maintain the Service and core features (sign-in, saving events, matching, filtering).
  • To personalize content, including recommendations based on your stated preferences.
  • To respond to support requests, feedback, copyright notices, and legal inquiries.
  • To detect, prevent, and respond to abuse, fraud, security incidents, and violations of our Terms.
  • To improve the Service through aggregate, de-identified analysis of usage patterns. We do not build individual behavioral profiles.
  • To communicate with you about the Service, including important administrative notices (e.g., security alerts, policy changes). Marketing emails are opt-in only.
  • To comply with legal obligations, enforce our Terms, and establish, exercise, or defend legal claims.

Under applicable privacy laws such as the GDPR and equivalent frameworks, our lawful bases for processing are (a) performance of a contract (providing the Service you requested), (b) your consent where required (optional profile fields, marketing emails), (c) our legitimate interests (securing the Service, preventing abuse, product improvement), and (d) compliance with legal obligations.

How we share your information

We share personal information only in the limited circumstances listed below. We do not, and will not, sell, rent, lease, or trade your personal information for advertising or marketing purposes.

Service providers

We share data with a small number of vendors that process information on our behalf under written contracts requiring them to protect it and use it only to provide their services to us:
  • Supabase — authentication and database hosting. Stores your account credentials (email, password hash), profile data, saved events, and related records.
  • Vercel — web hosting, serverless functions, and request routing. Processes server logs on a short retention window.
  • Cloudflare — bot detection (Turnstile) and edge security protections on our forms.
Each vendor maintains its own privacy policy and security program. We continually evaluate our vendor stack and may add or change vendors; we will update this list when material changes occur.

Legal and safety

We may disclose information if we believe in good faith that doing so is necessary to: (a) comply with a lawful subpoena, court order, or other legal process; (b) enforce our Terms; (c) investigate or prevent fraud, security, or technical issues; or (d) protect the rights, property, or safety of The Fringe, our users, or the public.

Business transfers

If The Fringe is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of the transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

With your direction

If you publicly post content on the Service, or explicitly authorize us to share your information with a third party, we will do so consistent with your direction.

International data transfers

We and our service providers are based in the United States. If you access the Service from outside the United States, your information will be transferred to, processed in, and stored in the United States and possibly other jurisdictions, which may have data-protection laws that differ from those in your country. Where required (e.g., under GDPR), we rely on Standard Contractual Clauses or equivalent legal mechanisms for cross-border transfers.

How long we keep your information

  • Account data: retained while your account is active. Deleted within 30 days after you delete your account, except where continued retention is required for legal, security, or fraud-prevention purposes.
  • Saved events and preferences: retained with your account; removed when the account is deleted.
  • Server logs: purged by Vercel on a rolling basis, typically within 30 days.
  • Support correspondence: retained for up to 3 years to maintain a support history and resolve disputes.
  • Backups: encrypted backups are rotated on a regular cycle and purged within 90 days.

Security

We implement commercially reasonable technical and organizational measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include: HTTPS/TLS for all data in transit, encrypted storage at rest, row-level-security policies in our database, the principle of least privilege for staff and vendor access, periodic credential rotation, and logging of administrative actions.

No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. You are responsible for safeguarding your password (if you set one) and the email account you sign in with, since anyone with access to that inbox can request a magic-link sign-in. If you believe your account or email has been compromised, contact us immediately.

Data breach notification

In the event of a breach that compromises your personal information, we will notify you and the applicable regulators as promptly as reasonably possible, and no later than required by applicable law (including, where applicable, within 72 hours of becoming aware under GDPR Article 33 and on an “expedient and without unreasonable delay” basis under the New York SHIELD Act). Notifications will be sent via the email on file and, where appropriate, posted publicly on the Service.

Your privacy rights

Depending on where you live, you may have the following rights over your personal information:

  • Access — request a copy of the personal information we hold about you.
  • Correction — ask us to correct inaccurate or incomplete information.
  • Deletion — ask us to delete your account and associated information.
  • Portability — receive your data in a structured, machine-readable format (JSON).
  • Restriction / objection — ask us to restrict or object to certain processing.
  • Opt-out of marketing — unsubscribe from marketing email at any time.
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time (without affecting the lawfulness of prior processing).
  • Complaint — lodge a complaint with your local data-protection authority.

To exercise any of these rights, email contact.alleymap@gmail.com. We will respond within 30 days and may ask you to verify your identity before acting on sensitive requests. We will not discriminate against you for exercising any right granted by law.

California residents (CCPA / CPRA)

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, California residents have the rights described above, plus the right to know the categories of personal information collected, the categories of sources, the business purposes for collecting, and the categories of third parties with whom information is shared.

We do not sell or share personal information for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA.We do not knowingly sell or share the personal information of any consumer under 16 years of age. You do not need to submit a “Do Not Sell My Personal Information” request, because there is no sale or sharing to opt out of.

California residents may designate an authorized agent to submit requests on their behalf. The agent must provide proof of authorization.

European / UK residents (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the controller of your personal information is The Fringe. Our lawful bases for processing are described above under “How we use your information.”

You have the rights described above, including the right to lodge a complaint with your local supervisory authority. For residents of the UK, the Information Commissioner's Office (ICO) is the relevant authority.

We do not rely on automated decision-making with legal or similarly significant effects (GDPR Article 22). Recommendations are advisory and based on preferences you explicitly set.

Children

The Service is not directed to children under 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe that we have collected personal information from a child, contact us at contact.alleymap@gmail.com and we will delete it promptly.

Cookies and tracking technologies

We use a small number of strictly necessary and functional cookies and storage mechanisms, described below. We do not use advertising cookies, pixels, beacons, or other cross-site trackers.

  • Session cookie (Supabase Auth): keeps you signed in. Expires on sign-out or session expiry. Strictly necessary.
  • Cookie-consent localStorage value: remembers whether you've accepted or declined our welcome message. Not a cookie, and not transmitted to our servers.
  • Local-cache entries: your saved-event IDs and recent filter selections are cached in localStorage for performance.
  • Cloudflare Turnstile: runs a short-lived challenge to detect bots on our signup form. See Cloudflare's privacy documentation for details.

Browsers that send a Do Not Track or Global Privacy Control signal are honored: since we do not sell, share, or track across sites, no additional action is required to respect those signals.

Changes to this policy

We may update this Policy from time to time. When we make material changes (for example, adding a new vendor, changing retention periods, or adding a new category of data), we will update the effective date above and notify registered users in-product or by email before the changes take effect, where reasonably practicable. Your continued use of the Service after the effective date of an updated Policy constitutes your acceptance.

Contact

Questions, requests, complaints, or anything else privacy-related go to contact.alleymap@gmail.com. We read every message and typically respond within two business days.