Privacy Policy

Effective May 27, 2026

In plain English.

  • ·We collect only what we need to run the Service: your email and password (if you register), optional profile details, and the events you save.
  • ·We don’t sell your data. We don’t rent it. We don’t trade it. We never will.
  • ·We don’t run advertising trackers, ad pixels, session-replay tools, or cross-site behavioral profiling.
  • ·We use basic, privacy-respecting analytics to understand how the Service is used, and we keep that data to ourselves.
  • ·We store data with a small set of trusted infrastructure providers that are contractually required to protect it.
  • ·You can delete your account anytime, in the website or the app. Your data is wiped on a rolling basis after that.
  • ·Questions or requests: email us. We answer.

This summary is a convenience, not a contract. The detailed policy below is the controlling document.

Scope of this policy

This Privacy Policy (the “Policy”) describes how The Fringe (“The Fringe,” “we,” “us,” “our”) collects, uses, discloses, retains, and protects personal information in connection with the website at thefringe.app, our mobile applications, our application programming interfaces, our emails, and other related services (collectively, the “Service”).

Your use of the Service is also governed by our Terms of Service, which are incorporated by reference. Capitalized terms not defined here have the meanings given in the Terms.

Information we collect

We collect only what is reasonably necessary to operate and improve the Service. The categories below describe what we may collect; whether we actually collect a given category depends on how you use the Service.

Account registration

When you create an account, we collect your email address, a password, your first and last name, and your date of birth. Passwords are processed by our authentication provider, which stores them as salted hashes; The Fringe staff never see your plaintext password. You may also sign in by one-time email link (“magic link”) instead of a password. Date of birth is used to verify that you meet the Service's minimum age and is not shown publicly.

Optional profile details

You may choose to add your phone number, preferred NYC neighborhoods, preferred genres, and a “show-finding style” (spontaneous / planner). These help us personalize recommendations. All fields are optional and you can remove them at any time.

Saved events and interactions

When you save an event (“interested” list), swipe through Match Mode, or set filters, we store these interactions so the Service can show them back to you across devices. Swipe-left / skip decisions are stored so we don't keep showing you the same show.

Usage and page analytics

To understand how the Service is used and to improve it, we record basic usage events such as the pages or screens you view, the page you arrived from, and a randomly generated session identifier. If you are signed in, this may be associated with your account. We also use a privacy-respecting analytics provider that measures aggregate traffic and performance without advertising cookies or cross-site tracking. We use this information for product and reliability purposes only, never to build advertising profiles or to sell or share your data.

Authentication session

When you sign in (by password or magic link), our authentication provider issues a session that keeps you signed in across requests. On the website this is stored in a secure, HTTP-only cookie that is cleared when you sign out or when the session expires. In our mobile app it is stored in the device's secure storage. This is a strictly necessary mechanism under ePrivacy / GDPR Article 5(3).

Local device storage

We use your browser's local storage (or the equivalent on mobile) to cache filters, saved-event IDs, and your consent choice for a faster experience. This data stays on your device until you sign in, at which point the saved-event list is synced with your account.

Server logs

Our hosting provider automatically logs request data including IP address, user agent, timestamp, and the URL requested. These logs are used for security, rate limiting, abuse prevention, and troubleshooting. They are typically retained for about 30 days and are not used for advertising.

Bot / abuse protection

We use a bot-detection service on signup and other sensitive forms to detect automated abuse. It collects limited technical signals (such as timing and device-class signals) and is designed to avoid collecting personally identifying information and not to use the data for advertising.

Location (on-device only)

If you enable location-based features (for example, “closest to me”), your device uses your approximate location to sort or label nearby shows. These calculations happen on your device. We do not transmit or store your precise coordinates on our servers.

Communications with us

When you email us or respond to a product survey, we retain the contents of those messages for as long as needed to respond to your inquiry and document our support history.

Information specific to our mobile apps

Our mobile apps collect and use information as described throughout this Policy, with a few mobile-specific points:

  • Location permission. If you grant location access, your device computes distances to nearby shows locally. We do not collect or store your precise location on our servers. You can change or revoke this permission at any time in your device settings.
  • Audio playback. The app plays short artist preview clips. This uses audio playback only; it does not access or record from your microphone.
  • Secure storage. Your sign-in session is kept in the device's secure storage so you stay signed in.
  • No cross-app tracking. We do not track you across other companies' apps or websites, and we do not use Apple's App Tracking Transparency identifier for advertising.
  • Account deletion. You can delete your account and associated data directly inside the app, as well as on the website.

When you download an app from an app store (such as the Apple App Store or Google Play), that store may collect information under its own privacy policy, which we do not control.

What we do not do

No advertising or ad-targeting trackers (no Meta Pixel, TikTok Pixel, ad-network tags, or DSP pixels).
No session-replay tools that record your screen or keystrokes.
No cross-site or cross-app behavioral profiling or fingerprinting for advertising.
No sale, rental, lease, trade, or sharing of your personal information with data brokers or advertisers.
No precise geolocation stored on our servers. Distance calculations happen on your device.
No harvesting of your other accounts (we never ask for social-login credentials to “import” contacts).

How we use your information

We use the categories of information described above for the following purposes:

  • To provide, operate, and maintain the Service and core features (sign-in, saving events, matching, filtering).
  • To personalize content, including recommendations based on your stated preferences.
  • To respond to support requests, feedback, copyright notices, and legal inquiries.
  • To detect, prevent, and respond to abuse, fraud, security incidents, and violations of our Terms.
  • To understand how the Service is used and to improve features, performance, and reliability. We do not use this information to build advertising profiles.
  • To communicate with you about the Service, including important administrative notices (for example, security alerts and policy changes). Marketing emails are opt-in only.
  • To comply with legal obligations, enforce our Terms, and establish, exercise, or defend legal claims.

Under applicable privacy laws such as the GDPR and equivalent frameworks, our lawful bases for processing are (a) performance of a contract (providing the Service you requested), (b) your consent where required (optional profile fields, marketing emails), (c) our legitimate interests (securing the Service, preventing abuse, understanding usage, and product improvement), and (d) compliance with legal obligations.

How we share your information

We share personal information only in the limited circumstances listed below. We do not, and will not, sell, rent, lease, or trade your personal information for advertising or marketing purposes.

Service providers

We rely on a small number of trusted infrastructure and technology providers that process information on our behalf under written contracts requiring them to protect it and to use it only to provide their services to us. These include providers of cloud hosting and serverless computing, authentication and database hosting, security and bot mitigation, email delivery, and privacy-respecting product analytics. Each provider maintains its own privacy and security program. We evaluate our providers on an ongoing basis and may add or change them; we will update this Policy when a material change occurs. We will identify specific providers on request, to the extent we can do so without compromising security.

Legal and safety

We may disclose information if we believe in good faith that doing so is necessary to: (a) comply with a lawful subpoena, court order, or other legal process; (b) enforce our Terms; (c) investigate or prevent fraud, security, or technical issues; or (d) protect the rights, property, or safety of The Fringe, our users, or the public.

Business transfers

If The Fringe is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of the transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

With your direction

If you publicly post content on the Service, or explicitly authorize us to share your information with a third party, we will do so consistent with your direction.

International data transfers

We and our service providers are based in the United States. If you access the Service from outside the United States, your information will be transferred to, processed in, and stored in the United States and possibly other jurisdictions, which may have data-protection laws that differ from those in your country. Where required (for example, under the GDPR), we rely on Standard Contractual Clauses or equivalent legal mechanisms for cross-border transfers.

How long we keep your information

  • Account data: retained while your account is active. Deleted within 30 days after you delete your account, except where continued retention is required for legal, security, or fraud-prevention purposes.
  • Saved events and preferences: retained with your account; removed when the account is deleted.
  • Usage analytics: retained in aggregate or pseudonymous form for a limited period to understand trends, then aged out.
  • Server logs: purged by our hosting provider on a rolling basis, typically within 30 days.
  • Support correspondence: retained for up to 3 years to maintain a support history and resolve disputes.
  • Backups: encrypted backups are rotated on a regular cycle and purged within 90 days.

Security

We implement commercially reasonable technical and organizational measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include HTTPS/TLS for data in transit, encrypted storage at rest, database access controls and isolation between accounts, the principle of least privilege for staff and vendor access, periodic credential rotation, and logging of administrative actions.

No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for safeguarding your password (if you set one) and the email account you sign in with, since anyone with access to that inbox can request a magic-link sign-in. If you believe your account or email has been compromised, contact us immediately.

Data breach notification

In the event of a breach that compromises your personal information, we will notify you and the applicable regulators as promptly as reasonably possible, and no later than required by applicable law (including, where applicable, within 72 hours of becoming aware under GDPR Article 33, and on an “expedient and without unreasonable delay” basis under the New York SHIELD Act). Notifications will be sent via the email on file and, where appropriate, posted publicly on the Service.

Your privacy rights

Depending on where you live, you may have the following rights over your personal information:

  • Access: request a copy of the personal information we hold about you.
  • Correction: ask us to correct inaccurate or incomplete information.
  • Deletion: ask us to delete your account and associated information.
  • Portability: receive your data in a structured, machine-readable format (JSON).
  • Restriction / objection: ask us to restrict or object to certain processing.
  • Opt-out of marketing: unsubscribe from marketing email at any time.
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time (without affecting the lawfulness of prior processing).
  • Complaint: lodge a complaint with your local data-protection authority.

To exercise any of these rights, email hello@thefringe.app. We will respond within the time required by applicable law (generally within 30 to 45 days) and may ask you to verify your identity before acting on sensitive requests. We will not discriminate against you for exercising any right granted by law.

California residents (CCPA / CPRA)

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, California residents have the rights described above, plus the right to know the categories of personal information we collect, the categories of sources, the business and commercial purposes for collecting it, the length of time we retain it, and the categories of third parties with whom it is shared. This Policy serves as our notice at collection. In the past 12 months we have collected the categories of personal information described in “Information we collect” (identifiers such as email and name, account and profile information, your saved-event activity, approximate location used on-device, and internet/usage activity), from you and your device, for the business purposes described in “How we use your information,” and have disclosed it only to the categories of service providers described in “How we share your information.” We retain each category for the periods described in “How long we keep your information.”

We do not sell or share personal information for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months.We do not knowingly sell or share the personal information of any consumer under 16 years of age. Because there is no sale or sharing to opt out of, you do not need to submit a “Do Not Sell or Share My Personal Information” request.

Sensitive personal information.We do not collect sensitive personal information in order to infer characteristics about you, and we do not use or disclose it for purposes that trigger the CPRA right to limit. We therefore do not offer a separate “Limit the Use of My Sensitive Personal Information” control.

No financial incentives. We do not offer financial incentives, and we do not charge different prices or provide a different level of service, in exchange for the collection, sale, or retention of your personal information. You will never be penalized for exercising a privacy right.

Shine the Light.California's “Shine the Light” law (Cal. Civ. Code § 1798.83) lets California residents request information about personal information disclosed to third parties for those third parties' own direct marketing. We do not disclose personal information to third parties for their direct marketing, so there is nothing to report.

CalOPPA and Do Not Track.Consistent with the California Online Privacy Protection Act, we post this Policy conspicuously, describe the categories of information we collect, and explain how we respond to browser privacy signals in “Cookies and similar technologies.” We do not authorize third parties to collect personally identifiable information about your activity across different websites when you use the Service.

California residents may designate an authorized agent to submit requests on their behalf. The agent must provide proof of authorization, and we may still ask you to verify your identity directly.

Other U.S. state privacy rights

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive consumer-privacy laws have rights comparable to those above, which may include the rights to confirm whether we process your personal data, to access it, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, the “sale” of personal data, and certain profiling.

We do not engage in targeted advertising, we do not sell personal data, and we do not profile you in furtherance of decisions that produce legal or similarly significant effects, so those particular opt-outs do not apply to us. We honor the access, correction, deletion, and portability rights through the request process described in “Your privacy rights.” Where your state grants a right to appeal a declined request, you may appeal by replying to our written decision.

European / UK residents (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the controller of your personal information is The Fringe. Our lawful bases for processing are described above under “How we use your information.”

You have the rights described above, including the right to lodge a complaint with your local supervisory authority. For residents of the UK, the Information Commissioner's Office (ICO) is the relevant authority.

We do not rely on automated decision-making with legal or similarly significant effects (GDPR Article 22). Recommendations are advisory and based on preferences you explicitly set.

Children

The Service is intended for adults and is not directed to children. You must be at least 18 years old to create an account, and we do not knowingly collect personal information from children under 13 (or under 16 in the European Economic Area). If you believe that we have collected personal information from a child, contact us at hello@thefringe.app and we will delete it promptly.

Cookies and similar technologies

We use a small number of strictly necessary and functional cookies and storage mechanisms, plus privacy-respecting analytics. We do not use advertising cookies, ad pixels, or cross-site tracking technologies.

  • Session cookie: keeps you signed in. Expires on sign-out or session expiry. Strictly necessary.
  • Consent and preference storage: remembers your consent choice and recent filter selections, stored locally on your device.
  • Local-cache entries: your saved-event IDs are cached locally for performance.
  • Bot-detection challenge: a short-lived check that detects automated abuse on our forms.
  • Privacy-respecting analytics: measures aggregate traffic and performance without advertising cookies or cross-site tracking.

Browsers that send a Do Not Track or Global Privacy Control signal are honored: since we do not sell or share your information or track you across sites for advertising, no additional action is required to respect those signals.

Changes to this policy

We may update this Policy from time to time. When we make material changes (for example, adding a new category of data, changing retention periods, or introducing a new use), we will update the effective date above and notify registered users in-product or by email before the changes take effect, where reasonably practicable. Your continued use of the Service after the effective date of an updated Policy constitutes your acceptance.

Copyright complaints (DMCA)

To report material on the Service that infringes your copyright, email our designated agent at dmca@thefringe.app. The full notice-and-takedown process, and the information your notice must include, is set out in our Terms of Service.

Contact

Questions, requests, complaints, or anything else privacy-related go to hello@thefringe.app. We read every message and typically respond within two business days.