This Privacy Policy explains how Megamind Management LLC (“Panko,” “we,” “us,” or “our”) collects, uses, and shares information in connection with the Panko event management platform, including our website at panko.events, our web application, and related services (collectively, the “Service”). It also explains the choices available to you.
Panko is a business-to-business software platform for event management, with a focus on venue management and catering management. Our direct customers are venues, caterers, and other event businesses and their staff (each, a “Customer” or “Account”). Through the Service, our Customers manage their own clients, event inquiries and bookings, venue and vendor partners, quotes, contracts, and communications.
Please read this together with our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service.
1. Who this policy covers, and our role
This policy applies to information we handle in two different capacities:
- As a controller — for information we collect about our Customers and their authorized users (for example, account registration, billing, and support), and for operating and securing the Service. This is the information we decide how to use.
- As a service provider / processor — for the personal information that a Customer uploads to or generates in the Service about its own clients, event contacts, venue partners, and vendors (we call these individuals “End Users”). We process this information on the Customer’s behalf and under its instructions, to provide the Service. The Customer — not Panko — decides what End-User information to collect and why.
If you are an End User (for example, someone who submitted an event or catering inquiry, is named on an event, or signs a contract through Panko), the venue, caterer, or event business you are dealing with is responsible for that information. Please direct privacy questions and requests to that business. We will refer you to them and support their handling of your request. Sections 2–4 below describe the categories of information involved either way; Sections 8–10 describe your choices.
We serve customers in the United States, and the Service is intended for use in the United States only.
2. Information we collect
2.1 Information Customers and their users provide
- Account and profile information — name, business name, email address, phone number, mailing address, job role, and login credentials for the individuals who administer or use a Customer account (owners, staff, team members).
- Business and legal-entity details — information a Customer provides about the legal entity(ies) it invoices from, such as legal name and taxpayer identification number (EIN).
- Billing information — the contact and billing details we need to invoice a Customer for the Service, and records of the plan and payments. (See Section 6 for payment processing.)
- Support and communications — information you provide when you contact us, respond to a survey, or otherwise communicate with us.
2.2 Information about End Users, provided or generated through the Service
When a Customer uses the Service, the following categories of information about its clients, event contacts, venue partners, and vendors may be stored and processed in Panko:
- Contact details — first and last name, email address(es), phone number(s), and mailing or billing addresses.
- Event, booking, and inquiry details — event type and dates, guest counts, venue names and addresses, spaces/resources booked, service preferences, budget-related notes, preferred contact method, and free-text notes.
- Dietary information — dietary restrictions and allergen information associated with an event or its guests, which a Customer may collect to plan and safely serve food.
- Messages and files — email and in-app messages exchanged through the Service, message threads, attachments, and files uploaded to an event or account (for example, floor plans, menus, or reference documents).
- Orders, quotes, and invoices — menu selections, order and quote details, pricing, and invoice records (such as invoice number, amount due, and due date).
- Payment records — for payments an End User makes to a Customer through the Service: amount, date, status, payment method type (for example, card vs. bank transfer, and whether a card is a credit or debit card, which determines whether any Customer-configured card surcharge applies), and any surcharge or discount amount. Full card numbers and bank credentials are handled by Stripe, not Panko — see Section 6.
- Contracts and e-signatures — catering, venue, and event agreements sent for signature, signer identity and contact details, signature/audit records (including a certificate of evidence), and any preferences captured during signing (such as an optional marketing opt-in choice).
- Scheduling and consultations — consultation and appointment bookings, calendar entries, and video-call links.
- Venue- and vendor-partner submissions — information a venue or vendor partner submits when referring or handing off an inquiry to a Customer.
The specific fields are determined by each Customer through the forms and features it chooses to use.
2.3 Information we collect automatically
When anyone uses the Service, we and our infrastructure providers automatically collect limited technical information needed to operate, secure, and troubleshoot it:
- Log and device data — IP address, browser and device type, pages or screens accessed, and timestamps.
- Security data — signals used to detect and prevent fraud, spam, and abuse, including data (such as your IP address) processed by our bot-protection provider (Cloudflare Turnstile) on public forms.
- Address autocomplete — when you type an address into an address field, the text you type is sent to Google Maps Platform (Places) to suggest and format U.S. addresses. Google’s privacy policy applies to its processing of that input.
- Essential cookies and similar technologies — used to keep you signed in, remember your preferences, and maintain the security and integrity of the Service. We do not use advertising cookies or sell information collected through cookies, and we do not use the Service to track you across other websites for advertising.
2.4 Information from third parties and integrations
If a Customer chooses to connect a third-party service, we receive information from that service to provide the requested feature. For example, if a Customer connects QuickBooks Online we receive accounting-related data from Intuit; if a Customer connects Stripe to accept payments we receive payment and payout status; if a Customer connects a scheduling provider we receive booking details; and if a Customer uses e-signature features we receive signer and signature records. We also receive email delivery status (such as bounces) from our email provider. See Section 5 for details on each integration.
3. How we use information
We use information to:
- Provide, maintain, and improve the Service — including managing accounts, storing and displaying Customer content, sending and receiving messages, generating quotes, invoices, and contracts, managing bookings and events, and enabling integrations the Customer turns on.
- Communicate — send transactional and service messages (for example, inquiry notifications, invoice reminders, appointment confirmations, and account or security notices). Some of these messages are sent by Customers to their End Users through the Service.
- Secure the Service — authenticate users, enforce permissions, detect and prevent fraud, abuse, and unauthorized access, and maintain backups and audit records.
- Support — respond to questions and troubleshoot problems.
- Billing — invoice Customers and keep records of payments for the Service.
- Comply with law — meet our legal, tax, and regulatory obligations, and enforce our agreements.
- Improve and develop — understand how the Service is used and develop new features. When we use information for product improvement, we use aggregated or de-identified data where practicable.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not use End-User information for our own marketing.
4. How and when we share information
We share information only as described below:
- With your organization — information in a Customer account is accessible to that Customer’s authorized users according to the permissions the Customer configures.
- At the Customer’s direction — for example, when a Customer sends a message, quote, invoice, or contract to an End User, or connects an integration.
- Service providers (subprocessors) — third parties that host and support the Service under contracts that require them to protect the information and use it only to provide services to us. See the current list in the Appendix.
- Integrations you enable — such as QuickBooks Online, scheduling, and e-signature providers, as described in Section 5. Information flows to these services only when a Customer connects them.
- Legal and safety — when we believe disclosure is reasonably necessary to comply with a law, regulation, legal process, or governmental request; to enforce our terms; or to protect the rights, property, or safety of Panko, our Customers, or others.
- Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to the surviving entity honoring this policy.
5. Integrations you connect
Customers can connect optional third-party services. Information flows to these services only when a Customer connects and configures them, and each service’s own terms and privacy policy also apply to the Customer’s use of it.
5.1 QuickBooks Online (Intuit)
- Authorization. We access QuickBooks data only after
the Customer authorizes the connection through Intuit’s standard
OAuth 2.0 flow. We request a single authorization scope —
com.intuit.quickbooks.accounting(accounting data). We do not request access to Intuit payroll, payments, or user-profile data. We never ask for or store QuickBooks (Intuit) login credentials; Intuit provides us with time-limited access tokens, which we store encrypted at rest. - What we access. Solely the accounting objects needed to keep the Customer’s books in sync with Panko: we create or update customers, items/products-and-services, accounts, invoices, and payments in the Customer’s QuickBooks company, and we read company preferences (such as tax and class-tracking settings), tax codes, classes, the company name, and invoice status. Data we send to QuickBooks is limited to what an invoice needs — for example a customer display name, invoice number, dates, line amounts and descriptions, and the invoice recipient’s email address for QuickBooks’ billing-email field.
- Change notifications. If Intuit sends us webhook notifications about invoice or payment changes in the connected company, we verify and use them only to keep already-synced records current; changes to records we did not create are ignored.
- Why we access it. We use QuickBooks data solely to provide the features the Customer requests — keeping invoices, customers, and payment status in sync between Panko and the Customer’s QuickBooks Online company. We do not use QuickBooks data for advertising, we do not sell it, and we do not share it except with the subprocessors that host our Service (Appendix) or as required by law.
- Storage and retention. We store the minimum QuickBooks data necessary to provide the integration — encrypted tokens, record-mapping identifiers, sync status, and change notifications — and retain it in line with Section 7 and Intuit’s developer requirements.
- Disconnecting. A Customer can disconnect QuickBooks at any time from within Panko, or from Intuit (Settings → Apps / Connected apps in QuickBooks Online). Disconnecting revokes and deletes our access tokens and stops all syncing. We retain the non-sensitive record-mapping identifiers so that if the Customer later reconnects the same QuickBooks company, existing records pair back up instead of being duplicated; a Customer can request full deletion.
- Intuit’s terms. Use of the QuickBooks integration is also subject to Intuit’s terms and privacy notices. Our use of Intuit APIs and data complies with the Intuit Developer terms.
5.2 Scheduling (calendar and video calls)
If a Customer connects a scheduling provider (currently cal.com), the Customer connects its own cal.com account by providing its cal.com API key, which we store encrypted at rest. Booking itself happens on the provider’s scheduling pages; the provider then notifies Panko of bookings, reschedules, and cancellations, and those notifications include attendee details (name, email address, time zone, and responses to booking questions) and any video-call link the provider generates, which we store to show appointments in the Service. Any calendar the Customer connects inside its scheduling account — such as Google Calendar or Microsoft Outlook — is connected there, under the Customer’s own account and those providers’ terms. Panko does not access the Customer’s Google or Microsoft account and does not receive Google or Microsoft credentials.
5.3 Electronic signatures
If a Customer uses e-signature features (currently via BlueInk), we send the e-signature provider each signer’s name and email address and the document to be signed, and receive back signing status, the completed document, a certificate of evidence, and the values of fields completed during signing. Signing is embedded in the Service — the e-signature provider does not email or contact signers directly. Signed documents and evidence records are stored in the Service’s file storage as part of the Customer’s records. See Section 8 of the Terms of Service for how electronic signatures work and each party’s responsibilities.
5.4 Email
We use Resend to send and receive email on behalf of Customers. Email addresses, message content and attachments, and delivery status (such as bounces) are processed to deliver and manage those messages, including inbound replies routed back into the Service.
5.5 Address autocomplete
Address fields in the Service use Google Maps Platform (Places) to suggest and standardize U.S. addresses as you type; the text entered in those fields is sent to Google for that purpose (see Section 2.3).
6. Payments (Stripe Connect)
Panko integrates with Stripe to let Customers accept payments from their own clients (for example, event deposits and invoices), using Stripe Connect with Standard connected accounts. This means:
- The Customer has its own Stripe account. To accept payments, a Customer creates or connects a Stripe account and agrees to Stripe’s terms directly; the Customer manages payments, payouts, and refunds primarily through the Stripe Dashboard.
- Stripe collects and stores payment details. Card, bank, and other payment credentials are collected and processed by Stripe on its own PCI-compliant systems and are governed by Stripe’s privacy policy. Panko does not collect or store full payment card numbers or bank account credentials.
- What Panko receives. Panko receives limited payment information from Stripe — payment status, amounts, dates, non-sensitive identifiers, account onboarding/verification status, and the payment method’s type (for example, whether a card is credit or debit, which determines whether a Customer-configured card surcharge applies) — to display payment status in the Service, apply the Customer’s payment pricing settings, and reconcile invoices. Panko also receives and retains Stripe’s event notifications (webhooks) about these payments and accounts.
- Surcharges and discounts. If a Customer enables a card surcharge or bank-payment discount, the adjusted total and a disclosure (for example, “Includes a N% card processing adjustment”) are shown to the payer before they confirm payment.
- Separate from Service fees. This is separate from any fees a Customer pays Panko for the Service, which are described in the Terms of Service. Panko does not add a platform fee to payments processed through a Customer’s Stripe account.
Stripe is listed in the Appendix.
7. Data retention
We retain information for as long as a Customer’s account is active and as needed to provide the Service. When a Customer closes its account, we delete or de-identify Customer content within a commercially reasonable period, except where we must retain it to comply with legal, tax, or accounting obligations, resolve disputes, enforce our agreements, or maintain security (for example, backups from which data is purged on a rolling basis). Customers control the retention of individual records within their account and may delete them through the Service. End Users seeking deletion should contact the relevant Customer (see Section 1).
8. Security
We use administrative, technical, and physical safeguards designed to protect information, including:
- Encryption of data in transit (TLS) and encryption of data and access tokens at rest;
- Role- and relationship-based access controls that limit who within a Customer account can see each record, and that separate one Customer’s data from another’s (multi-tenant isolation);
- Least-privilege access for our personnel and audit logging of sensitive actions;
- Reputable infrastructure providers with recognized security programs (see Appendix); and
- Ongoing monitoring for vulnerabilities and abuse.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Customers are responsible for maintaining the confidentiality of their login credentials and for configuring user permissions appropriately.
9. Where information is stored
We store and process information in the United States. Our infrastructure providers may maintain redundant facilities within the United States for reliability and backup.
10. Your choices and rights
Account users. You can access and update your account and profile information within the Service or by contacting us. You can opt out of non-essential emails using the unsubscribe link; we will still send transactional and account/security messages you need to use the Service.
U.S. state privacy rights. Depending on your state of residence, you may have rights to request access to, correction of, or deletion of personal information about you, to obtain a copy of it, and to not be discriminated against for exercising these rights. Because personal information about End Users is controlled by our Customers, we will forward your request to the relevant Customer and assist them, or act on their instructions. For information we control (Section 1), you may submit a request using the contact details below; we will verify your request before acting on it. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use it to make decisions that produce legal or similarly significant effects about you.
You may designate an authorized agent to make a request on your behalf; we may require verification of the agent’s authority.
11. Children’s privacy
The Service is intended for business use by adults. It is not directed to children, and we do not knowingly collect personal information directly from children under 18. If you believe a child has provided information to us directly, please contact us and we will take appropriate steps to delete it. Customers are responsible for any information about event guests they choose to enter.
12. Third-party links and services
The Service may link to or interoperate with third-party websites and services that we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them.
13. Changes to this policy
We may update this policy from time to time. If we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice (for example, by email or an in-app notice). Your continued use of the Service after an update means you accept the revised policy.
14. Contact us
Questions, concerns, or privacy requests:
Megamind Management LLCAttn: Privacy
Email: privacy@panko.events
If you are an End User with a question about information a venue, caterer, or event business holds about you, please contact that business directly.
Appendix — Subprocessors
We use the following service providers to operate the Service. Each processes information only to provide services to us and under confidentiality and data-protection obligations. This list may change; we will update it when it does.
| Provider | Purpose | Data involved |
|---|---|---|
| Cloudflare, Inc. | Application hosting, content delivery, file/object storage, background queues, document (PDF) rendering, and bot protection (Turnstile) | All Service data (hosting/storage); document content during PDF generation; technical and security data |
| Supabase, Inc. | Managed PostgreSQL database hosting and authentication | All Service data stored in the database; login credentials |
| Resend (Plus Five Five, Inc.) | Sending and receiving transactional and inbound email | Email addresses, message content, delivery status |
| Intuit Inc. (QuickBooks Online) | Accounting/invoicing integration a Customer connects | Customer/invoice/accounting data (Section 5.1) |
| Stripe, Inc. | Payment processing so a Customer can accept payments (Stripe Connect) | Payment/transaction data; card/bank details collected and stored by Stripe, not Panko (Section 6) |
| Cal.com, Inc. | Scheduling/appointment integration a Customer connects | Contact and booking details (Section 5.2) |
| BlueInk (BlueInk, Inc.) | Contract e-signature | Signer name and email, document content, signature/audit records (Section 5.3) |
| Google LLC (Google Maps Platform) | Address autocomplete and standardization | Text typed into address fields (Sections 2.3, 5.5) |
| Railway Corporation | Hosting for the authorization (permissions) service and its datastore | Internal permission records (opaque account/resource identifiers only — no names, contact details, or business content) |
We do not use third-party analytics, advertising, or session-recording services in the Service.
Where a Customer connects its own Google or Microsoft calendar inside a scheduling provider, that connection is between the Customer and those providers under their terms; Google and Microsoft are not Panko subprocessors for calendar data, because Panko does not access those accounts (Section 5.2). Similarly, under Stripe Connect, the Customer contracts with Stripe directly and Stripe acts as an independent payment processor for the Customer’s transactions.