For producers, brand legal, and procurement

Data, Privacy + AI Statement

The questions financial brands, automotive clients, and agency legal teams ask before every program, answered in plain language. The formal version for your vendor packet is available on request.

Who owns the data

Guest data captured at an activation belongs to the brand (or the agency acting for the brand). PivotXP processes it on your behalf, in your client’s name, and never markets to guests, sells lists, or reuses guest content without written permission.

For agencies, this is white-label by default: guest-facing screens, share pages, texts, and emails carry your client’s brand. PivotXP pricing and invoicing are never shared with your client.

What we capture

Only what the program is designed to capture. Typically: name and contact details entered at registration, opt-in choices, the photos or videos a guest creates, QR scans or RFID taps that link a guest to a station, timestamps, and delivery events (sent, opened, downloaded).

We do not run facial recognition or build profiles across programs. Each activation is its own dataset.

Where it lives

Data is stored in PivotXP’s AWS environment in the United States, transmitted over HTTPS/TLS, with access limited to the PivotXP team members working the program and to the client contacts you authorize. Admin actions are logged.

How long we keep it

Personal information is purged after the program closes and the final export is delivered, unless you ask us to hold it for a set period (for example, a season lease or a sweepstakes with a fulfillment window).

Aggregate counts (sessions, outputs, shares, opt-in totals) stay in the reporting dashboard so year-over-year comparisons still work. That is why a dashboard’s guest-level totals can drop after a program closes while the summary numbers stay put.

How you get it

During the program: a live dashboard with sessions, unique guests, outputs created, shares by channel, QR scans, and opt-ins, plus a lead export link.

After the program: a CSV export of registrations and opt-ins, a media archive of guest outputs when included in scope, and structured exports or API delivery to your CRM or your client’s vendor when requested.

Sessions count interactions; unique guests count people. We label both so nobody has to guess.

Consent and opt-ins

Consent language, privacy links, and opt-in checkboxes are configurable per program and are usually supplied by your client’s legal team. Text and email delivery goes only to guests who requested it, from a sender identified with the brand, with the guest’s opt-in recorded and exportable.

Waivers and age gates can be added to registration when the activation needs them.

Where AI is used

Some activations transform a guest’s photo into an AI output (trading cards, themed portraits, background replacement). When a program uses AI, we say so in the proposal, name the processing provider on request, and document the data flow: what is sent, what comes back, and what is retained.

Guest photos are used to generate that guest’s output and are not used by PivotXP to train models. Outputs are reviewed with your creative team before launch for brand safety.

Programs that do not use AI simply do not: capture, delivery, and printing run entirely on PivotXP systems.

Content rights

Photos and videos guests create at your activation are your client’s content. PivotXP does not use them in case studies, social posts, or sales materials without written approval from you and, where required, the brand.

Security basics

HTTPS everywhere, scoped admin access with logging, kiosk lockdown so guests cannot leave the experience, secure endpoints for vendor integrations, and a written retention and deletion policy available for procurement reviews.

Need the formal version?

We can provide a program-specific data-flow statement, retention and deletion policy, W-9, and certificate of insurance for vendor onboarding. Email hello@pivotxp.com or send the request through the contact form.