ITM Studio, Inc. Privacy Policy
Last Updated: June 16, 2026
1. Introduction
This Privacy Policy explains how ITM Studio, Inc. ("ITM," "we," "us," or "our") collects, uses, shares, and otherwise processes personal data when you use our websites (itm.studio and itm.space), mobile applications (ITM ID and ITM Backstage), and services (collectively, the "Services").
2. Information We Collect
We collect data from three main sources: data you provide directly, data collected automatically when you use our Services, and data from third parties.
2.1 User Information
When you create an ITM account, we collect your phone number as a universal identifier, first name, last name, date of birth, and email address (if provided). We also collect any additional profile information you choose to provide.
2.2 Precise Geolocation Data
If you opt-in to sharing your precise location data when you use our Services, we collect your precise location data (accurate within approximately one meter) whenever you use our apps or visit our websites. If you opt-in to allowing us to collect your precise location data when our Services are not in use, we will collect such data when our apps are closed or running in the background (as permitted by your device settings).
You may select between two permission levels: "While Using App" requires you to open the app within a geofenced area to receive location-based Echoes; "Always Allow" enables automatic notifications when entering geofenced areas without opening the app, providing access to more discounts and exclusive content.
Location data is attached to your user profile and includes which Moments (events) you have attended and which location-based Echoes you have received. You can disable location sharing at any time through your device settings. Location sharing is required only for location-based Echoes and is not necessary for other Services features.
2.3 Social Media Verification Data
We use Opacity Network's zkTLS technology to verify your ownership of accounts on Spotify, Instagram, X, and TikTok. This zero-knowledge proof technology performs verification computations locally on your device. We collect only proof of account ownership and public information on your account – profile information, account activity data, and public account details. You may disconnect these integrations at any time through your account settings.
2.4 Brand/Admin Information
For brand accounts, we collect business email addresses, organizer names and phone numbers for each event, and business verification documents.
2.5 Payment Information
We collect payment card information (processed by third-party payment providers), billing addresses, transaction history, and purchase preferences. Prices are displayed and processed in the local currency of the Moment's location.
2.6 Usage Data
We automatically collect data about your interactions with our Services, including app usage data, device information (model, operating system, version), IP addresses, and error reports through analytics providers including Amplitude and Sentry.
3. How We Use Your Information
3.1 Service Provision
We use your information to provide, maintain, and improve our Services, process transactions, provide customer support, authenticate accounts, and prevent fraud.
3.2 Location-Based Features
When you opt-in to location services, we use your location data to send location-based Echoes (discounts, exclusive content, products) when you enter brand geofences, track attendance at Moments, provide recommendations based on visited locations, and display nearby events.
Geofencing is subject to the following limitations: brands may only create geofences around their own retail locations or event venues; notifications are limited to one per geofence entry per hour; geofences are address-based using Radar technology.
3.3 Social Verification
We use zkTLS-verified social media data to confirm account ownership, allow brands to identify followers, provide follower-exclusive content, and enable personalized experiences based on social connections.
3.4 Analytics and Business Operations
We use data to understand usage patterns, develop new features, conduct research, and improve Service performance.
3.5 Communications
With your consent, we send marketing communications about events and offers, push notifications for nearby experiences, and Service updates. You may opt out at any time.
3.6 Legal Compliance
We use information to comply with applicable laws, respond to legal processes, protect rights and safety, and detect and prevent fraud.
4. Information Sharing
4.1 Brand Access
Brands can export data about their own attendees and fans. Brands can see when users with location enabled enter their geofenced areas but cannot access user locations outside their designated spaces. ITM does not sell user data to third parties. No mobile information will be sold or shared with third parties for promotional or marketing purposes.
4.2 Aggregated Data
We may use aggregated, anonymized platform data to facilitate partnerships between brands and generate industry insights. Individual user data is not shared without consent.
4.3 Service Providers
We share data with service providers including Radar (geofencing), Opacity Network (zkTLS), payment processors, analytics providers, and hosting services. These providers are contractually required to protect data and use it only for specified purposes.
4.4 Business Transfers
In the event of a merger, acquisition, or asset sale, your information may be transferred. We will provide notice and options regarding your data before any transfer.
4.5 Legal Requirements
We may disclose information when required by law, legal process, or governmental request.
4.6 Consent
We share information when you provide explicit consent.
5. Data Retention
We retain personal data for as long as your account is active or as needed to provide Services. Retention periods: account data (duration of account plus 90 days), location history (2 years), transaction records (7 years for legal compliance), social verification data (until disconnection), marketing preferences (until changed).
Upon account deletion request, personal data is deleted within 30 days, except where retention is required by law. Aggregated or anonymized data may be retained. Backup systems may retain data for up to 90 days.
6. Data Security
We implement administrative, technical, and physical safeguards including encryption in transit and at rest, access controls, security audits, secure development practices, and incident response procedures. Zero-knowledge proofs are used for social verification. No internet transmission method is completely secure.
7. Your Privacy Rights
7.1 Your Choices
You may access, update, or delete your personal data, download your data in a portable format, object to or restrict processing, manage location permissions, control social media connections, and opt out of marketing communications.
7.2 Location Controls
You can enable or disable location services at any time, choose between "while using app" or "always allow" permissions, delete location history, and opt out of location-based marketing.
7.3 Regional Privacy Rights
California Residents (CCPA/CPRA): California residents have rights to know what personal information we collect, use, and share; delete personal information (subject to exceptions); opt-out of sale/sharing (we do not sell personal information); non-discrimination; correct inaccurate information; and limit use of sensitive personal information. To exercise these rights, contact privacy@itm.studio.
European Residents (GDPR): If you are in the European Economic Area, you have rights to access, rectify, or erase data; restrict or object to processing; data portability; withdraw consent; and lodge complaints with supervisory authorities. Our legal bases for processing are consent (location data, marketing, social verification), contract performance (Service provision), legitimate interests (security, analytics), and legal obligations.
Other Jurisdictions: We respect privacy rights in all jurisdictions where we operate.
8. Children's Privacy
Our Services are not directed at children under 13. We do not knowingly collect personal information from children under 13.
9. International Data Transfers
ITM is based in the United States. Data may be transferred to and processed in countries other than your residence. We ensure appropriate safeguards through standard contractual clauses and other transfer mechanisms where required.
10. Third-Party Services
Our Services may link to third-party services. We are not responsible for their privacy practices.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified via email, in-app notice, or website announcement. The Last Updated date will be revised.
12. Contact Information
For privacy-related questions or to exercise your rights:
Support: support@itm.studio