Privacy Policy
Effective date: August 7, 2026 (replaces the version effective July 8, 2026)
Mixtape (“Our Mixtape,” “we”) is a song-request and charitable-giving layer for live events, operated by Efficient Frontier Labs, LLC. This policy explains what we collect, what we deliberately don’t, and your choices. The short version: we never see your payment details, we never hold donated funds, and we keep as little about you as running the event requires.
What we collect from guests
We collect information at four moments: when you RSVP, when you search for a song, when you request a song, and when a donation completes. Each list below is everything we collect at that moment.
When you RSVP:
- Your name. This is required.
- One way to reach you, either an email address or a phone number. One of the two is required. You can also give us a phone number in addition to an email address, which is optional.
- A normalized copy of the contact information you gave us. We lowercase it and strip formatting so we can match your RSVP when you arrive and match your activity during the event back to it. This copy contains the same email address or phone number you typed, in a standardized form, and we index it so the matching works.
- Whether you checked in and when, how many people arrived with you, and which host or volunteer checked you in.
Your RSVP name and contact information are never shown on the event screen or on a recap page. They are used for the guest list and check-in. The RSVP name is separate from the optional dedication described below, which is the only place a guest name is displayed publicly.
When you search for a song:
- That a search happened, and whether it found anything. We record one entry noting that this session searched and how the search was answered — that it returned songs, that it returned none, or that the song list was not available. We do not keep the words you typed. The search text is never written down anywhere, so we cannot tell you, or anyone else, what any guest searched for.
- The same functional session identifier described below, so we can tell how many people searched rather than how many searches happened. Nothing here is tied to your name or your RSVP.
We collect this for one reason: to see how many guests looked for a song and did not end up requesting one. That gap is the only way we can tell whether the song list is too small or the flow is confusing, and it is not visible from anything else we keep.
When you request a song:
- The song and artist you requested, the charity you chose, and the amount you selected before checkout.
- An optional dedication, meaning your name and a short message, and only if you check the box agreeing to display it.
- A code identifying which QR you scanned, for example a table number, used for event analytics.
- A functional session identifier so the app remembers your charity choice during the event. We use no advertising cookies and no cross-site tracking of any kind, and no third parties place cookies through Mixtape. You can clear or block this identifier through your browser's standard cookie controls. Mixtape works without it, though it won't remember your charity choice between requests.
- Basic technical information, such as IP address and device type, used for security, rate-limiting, and abuse prevention.
- Event analytics collected server-side, for example that a request was started or completed. These are not tied to advertising profiles. We don't have any.
- If your request could not be accepted, an entry noting why — for example that the host had paused requests, that the event had ended, or that the song cannot be played at this event. This records the reason only. It does not record the song you were trying to request.
When your donation completes: donations are made on Every.org, not on our site. We never receive or store your payment card details. Those are handled entirely by Every.org and its payment processor.
When a donation completes, Every.org sends us a confirmation message. That message can include your name, email address, donation amount, chosen charity, and a charge identifier. Two things happen to it, and we want to be precise about both. First, we read out the fields the event needs and store those on their own: the amount, the charity, the charge identifier, the date, how the donation was confirmed, and, only if you opted in, your name for the dedication. Second, we also keep the confirmation message itself, in full and unaltered, in a delivery log. We do this so that if our processing fails we can replay the message rather than drop your donation out of the event total. That stored copy can contain your name and your email address. We do not read it for any other purpose, we never use it to contact you, and we never add you to a mailing list. We keep this delivery log as part of the event’s technical record.
An earlier version of this policy said that we do not store your email address. That was not accurate, because of the delivery log described above. This version corrects it.
If you join the waitlist
If you sign up on our landing page to hear about the beta, we collect your name, your email address, what you told us you want to use Mixtape for, and which page you came from. This one is a mailing list: we keep it so we can email you about Mixtape, and we hold it ourselves rather than handing it to an email vendor. It is separate from event data. Ask us at andrew@efficientfrontierlabs.com and we will remove you.
If you’re an event host
We store your Spotify account connection using encrypted tokens, plus playback state needed to run the queue. There is no self-serve “disconnect Spotify” button today. Signing out ends your session but does not remove the connection. To have your Spotify tokens and Spotify-derived data deleted, email andrew@efficientfrontierlabs.com and we will remove them.
How we use information
To run the event. That means: managing the guest list and check-in, managing the request queue, displaying verified donation totals, showing dedications you opted into on the event screen and the event recap page, replaying failed donation confirmations so that totals stay accurate, preventing abuse, and understanding aggregate event performance, for example how many requests an event generated. That is the whole list.
We do not use your RSVP contact information for marketing. Today Mixtape sends no email or text messages to guests at all — there is no mailing or messaging system connected to event data. If that ever changes, we will say so here first.
Who can see your information
The event host can see the guest list, including RSVP names and contact information, because the host owns the invitation. A host may also be able to grant one read-only view of their event dashboard to someone helping them run it; that view shows RSVP names, party sizes, and the invitation list the host uploaded, but not the contact information guests submitted, and it cannot export anything or change anything. Hosts do not see donor email addresses from Every.org confirmations. Nobody outside the event’s own operation sees any of it.
What we don’t do
We do not sell personal information. We do not run ads or advertising trackers. We do not process payments or hold donated funds at any time. Donations flow from you to Every.org, a 501(c)(3) public charity, which grants funds to the charity you choose. Every.org’s own privacy policy (every.org/privacy) governs the checkout experience and your donation record with them.
Public display
Dedications, meaning name, message, song, and charity, appear on the event’s big screen and may appear on the event’s recap page, and only with your opt-in. RSVP names and contact information never appear on either one. If you’d like a dedication removed from a recap page, email andrew@efficientfrontierlabs.comand we’ll remove it.
Photos and video
Events using Mixtape may be photographed or recorded. See the Event Photo Notice posted at each event. Event footage may be used by the event host and by us to document and share the event and to demonstrate Mixtape.
Service providers
We use infrastructure providers to run the service (currently Vercel for hosting, Neon for our database, Upstash for real-time infrastructure), Spotify for host-controlled playback, and Every.org for donations. Every.org acts as an independent organization with its own policies, not as our processor.
Retention and your choices
We keep RSVP records, song-request records, and donation-state records as part of the event’s record. We do not currently delete them on an automatic schedule, and we would rather say so than describe a schedule we don’t run.
To access or delete information about you, email andrew@efficientfrontierlabs.com. We honor reasonable deletion requests from anyone, regardless of whether a specific privacy law requires it, except records we need for integrity, security, or legal purposes. Records that Every.org holds about your donation are governed by Every.org’s policy, and we can’t delete those on your behalf, though Every.org can.
We don’t track you across other websites, so we don’t respond differently to “Do Not Track” signals. There’s nothing to turn off.
Children
Mixtape is not directed at children under 13, and we do not knowingly collect personal information from them. Individual events may be age-restricted by their venue.
Security
All traffic is encrypted in transit (HTTPS). Host tokens are encrypted at rest. We keep the number of things we store about you small and the number of reasons few, because the best protection for data is not having it.
Changes and contact
We’ll update this page when the policy changes and adjust the effective date. Questions: andrew@efficientfrontierlabs.com.