SODA

Privacy Policy

Last updated July 30, 2026

1. Who we are

SODA is a room operating system for live events, built and operated by Equalpoint, Inc., a Delaware corporation headquartered in Cleveland, Ohio. When you use SODA at an event, Equalpoint is the data controller for the information you provide through the SODA platform. The host organization that runs the event is a data processor acting on Equalpoint’s behalf for event operations.

Equalpoint, Inc., Cleveland, Ohio

2. What we collect and why

SODA collects the minimum information needed to connect you with the people in the room and to remember those connections afterward. Here is every category, what it is, and why we collect it.

Your sign-in information. When you sign in, we collect the email address or phone number you use to sign in, so we can create and authenticate your account. If you choose a social sign-in (such as Google or LinkedIn), we also receive the basic profile that provider shares, typically your name and email. Some events use an anonymous door (see the section on children and classroom rooms below) where no email or phone is collected at all.

Your profile. You may choose to add a display name, a role (what you do), an offer (what you bring to a room), and a need (what you are looking for). Offers and needs can include a short detail you type to make them specific (for example, “Mentorship in design”). All are optional except the email or phone used to sign in. Your profile is visible to other guests at the same event.

Your photo. You may add a profile photo. It is optional. If you add one, we store it and show it on your card to other guests in the same room. To keep rooms safe, a photo may be checked by an automated image-safety provider (see section 5) before it appears. You can remove your photo at any time.

Your contact card (key card). You may build a key card — your fuller contact details, which can include a phone number, email, work phone, website, and social handles. This is optional. It is stored encrypted and is not visible to anyone until you choose to hand it to a specific person; you can take it back at any time.

Your attendance at an event. When you check in by scanning the QR code, we record that you attended and link your profile to that event. This is how the room knows you are present.

Your connections. When SODA connects you with another guest, a shared connection record is created, co-owned by both guests, and it can persist across events so you can find each other again. It includes a warmth score calculated from how recently you have been in contact. The warmth score is derived mathematically and never stored as a permanent rating; it is recalculated each time it is needed.

Your messages. When you and another guest connect, SODA opens a conversation. We store the messages so we can deliver the conversation to both of you. Message content is between you and the person you are talking to. Hosts and Equalpoint can see whether conversations happened and how active they were — counts and timing only — never the words.

Survey answers. After an event, a host may invite you to answer a short survey. If you choose to answer, your responses are shared with that event’s host, together with your name, so they can improve the next room.

Follow-up drafts. If you use SODA to generate a suggested follow-up message, the draft is created by an AI system and shown to you for review. It is only sent if you explicitly approve it. If you discard a draft, we log that you discarded it (but not the contents) so the AI can improve over time.

Private nudges. A host may send a private nudge to a specific guest. Nudge contents are visible only to the recipient and are not shared with other guests or accessible to other hosts.

Event metadata. We record the events you attend, the dates, and aggregate activity within each event. We do not sell this data.

Platform network view. To operate and improve SODA, Equalpoint can see the overall picture of activity across events: who attended which rooms and the network of connections between people, along with counts and timing of interactions. This view uses names, but never the content of your messages. It is available only to Equalpoint operators, not to hosts, and it is not built for advertising or sold.

Technical information. We collect standard technical data to operate the service: device type, browser type, error reports, and usage patterns. Error reports are stripped of personal information before being logged.

3. How we use your information

We use the information above for the following purposes only:

  • To authenticate you and maintain your session across events
  • To show your profile, and photo if you added one, to other guests at the same event
  • To track your connections and display your warmth with each connection
  • To store and deliver the conversations you have with people you connect with
  • To generate and send follow-up draft suggestions, with your approval
  • To keep rooms safe, including an automated safety check on profile photos
  • To deliver event recaps to your email after an event closes
  • To help hosts run events and manage access to their rooms
  • To improve AI-generated draft suggestions, using anonymized discard signals
  • To operate, understand, maintain, and improve the SODA platform

We do not use your information for advertising, we do not sell it to third parties, and we do not use it for any purpose not listed here.

4. How long we keep your information

We retain your profile and connection records for as long as you have an account. If you request deletion, we delete your profile, your attendance records, and your side of any shared connection records within 30 days. Because connections are co-owned, the other guest’s record of the connection may remain visible to them after you delete your account, but your identifying information is removed from it.

Messages you send are kept for as long as the conversation exists, so both people can read it; deleting your account removes the messages you sent. If a host emails you a recap after an event, a record that the recap was sent (including the address it went to) is kept with that event and is visible to that event’s host.

Draft contents are never stored after a draft is sent or discarded. Discard signals (that a draft was declined, not what it said) are retained for model improvement. Error logs are retained for 90 days and are stripped of personal information.

5. Who we share your information with

We use the following third-party services to operate SODA. Each receives only the data it needs to perform its function.

Clerk (clerk.com). Our sign-in provider for guests. Clerk handles account creation and authentication and processes the email address or phone number you sign in with, and your name if a social sign-in provides it.

Supabase (supabase.com). Our database, storage, and real-time infrastructure provider. Your profile, photo, connections, attendance, messages, encrypted key card, and event data are stored in Supabase under a data processing agreement. Supabase stores data in the United States.

Vercel (vercel.com). Our hosting provider. Vercel serves the SODA application and processes standard web request data to deliver the service.

Sentry (sentry.io). Our error-monitoring provider, which helps us find and fix problems. It receives technical error and performance data, and records a small sample of sessions to reproduce bugs; text, form inputs, and images are masked in those recordings.

Resend (resend.com). Our transactional email provider. We send your sign-in codes, post-event recaps, and walk-in verification emails through Resend, which processes your email address on our behalf.

Anthropic (anthropic.com). The provider of the AI models we use for two things: generating follow-up draft suggestions, and the optional image-safety check on profile photos. For a draft, we send only the connection context needed, not your full profile. For the safety check, the profile photo is sent for an automated, one-word suitable/not-suitable verdict.

We do not share your information with any other third parties, and we do not sell it. Event hosts can see aggregate event data, the profiles of guests who attended their event, whether recaps were delivered, and (if you answered) survey responses; they cannot read your messages or the contents of your connections.

6. Your rights

You have the right to access the personal information we hold about you, to correct inaccurate information, to request deletion of your account and data, and to ask us what data we hold and how we use it. To exercise any of these rights, contact us at datagov@equalpoint.com. We will respond within 30 days.

If you are a California resident, you have additional rights under CCPA/CPRA, including the right to know the categories of personal information we collect, the right to opt out of the sale of personal information (we do not sell personal information), and the right to non-discrimination for exercising your rights.

If you are in the European Union or United Kingdom, the GDPR applies to our processing of your personal data. Our legal basis for processing is consent and legitimate interests. You have the right to lodge a complaint with a data protection authority.

7. Children, and classroom rooms

Regular SODA accounts are meant for adult and professional events. You must be old enough to form a binding contract in your jurisdiction to create one, and we do not knowingly collect personal information from children under 13 through a regular account.

Some events — such as school showcases and classroom rooms — run on an anonymous door instead. In these rooms no account is created and no email or phone number is collected; a guest simply types the card they want to show, and everything is automatically deleted a short time after the event ends. These rooms are set up and run by the host organization (for example, a school), which is responsible for obtaining any parental permission its own rules require before students take part.

If you believe a child’s personal information has reached us in a way it should not have, contact us at datagov@equalpoint.com and we will delete it promptly.

8. Security

All data is stored with row-level security, meaning each record is accessible only to authorized users. All data in transit is encrypted using TLS. API keys and secrets are stored server-side only and are never exposed to client devices.

If you discover a security vulnerability in SODA, please contact us at datagov@equalpoint.com rather than disclosing it publicly.

9. Changes to this policy

If we make material changes to this policy, we will notify you by email at least 14 days before the changes take effect. Continued use of SODA after that date constitutes acceptance of the updated policy.

10. Contact

Equalpoint, Inc. Cleveland, Ohio — datagov@equalpoint.com