Privacy Policy

Lounge Technologies, Inc.
Effective Date: January 1, 2026

Last Updated: 10 August 2026

Lounge Technologies, Inc. (“Lounge,” “we,” “us,” or “our”) provides a digital platform for student engagement, event management, communications, and related services (the “Services”), including mobile and web-based applications. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with the Services.

This Privacy Policy applies to individuals who interact with Lounge through an institution, organization, or directly, including students, faculty, staff, administrators, and other authorized users (“Users”).

1. Our Role and Relationship to Institutions

When Lounge provides Services to a college, university, or other organization (each, an “Institution”), we process personal information on behalf of that Institution and under its documented instructions, as a service provider and data processor. In these cases:

  • The Institution determines what data is shared with Lounge and how it is used.

  • Lounge acts as a service provider or data processor for Institutional data.

  • Questions regarding an Institution’s internal data practices should be directed to the Institution.

When acting as a service provider or processor, Lounge processes personal information solely for the purpose of providing the Services in accordance with applicable agreements and does not retain, use, or disclose such information for any purpose other than as permitted by those agreements or applicable law. Lounge acts under the direct control of the Institution, including as a "school official" with a legitimate educational interest under FERPA where applicable. Lounge does not sell personal information, does not use it for targeted advertising, and does not use student or institutional data to train third-party artificial intelligence or machine learning models.

Where Users interact directly with Lounge outside of an Institutional context, Lounge may act as an independent data controller.

2. Information We Collect

We collect information in several ways depending on how the Services are used.

A. Information Provided by Institutions

Institutions may provide information such as:

  • Name, institutional email address, and affiliation

  • Role or status (e.g., student, staff, advisor, administrator)

  • Organization or group membership

  • Event, attendance, or participation records

  • Other information submitted through administrative tools

B. Information Provided by Users

Users may provide information directly, including:

  • Profile details (e.g., name, photo, pronouns, preferences)

  • Contact information

  • Messages, posts, or submissions made through the Services

  • Content uploaded in connection with events, organizations, or activities

  • Support requests and communications

C. Automatically Collected Information

When Users access the Services, we may collect:

  • Device and browser information

  • IP address and general location data

  • Log files and usage activity

  • Interaction data (pages viewed, features used, timestamps)

This information is collected through cookies, local storage, mobile SDKs, and similar technologies. Lounge uses strictly necessary cookies for authentication and session management, and limited analytics tooling (including Google Analytics) to understand feature usage and diagnose errors. Lounge does not use advertising cookies or third-party advertising trackers, and does not permit analytics providers to use Institutional data for their own purposes. Users may control non-essential cookies through browser settings or any cookie preference tool provided within the Services.

D. Information from Integrations

If an Institution enables integrations with third-party systems (e.g., single sign-on, learning systems, payment processors), Lounge may receive information from those systems consistent with the Institution’s configuration and permissions.

Depending on Institutional configuration, the Services may process information Users or Institutions choose to submit that could be considered sensitive, such as dietary or accessibility requirements for events, or conduct and compliance records maintained by an Institution. Lounge processes such information only as configured by the Institution and does not use it for any purpose beyond providing the Services. Lounge does not require or request government identification numbers, financial account numbers, or health records.

3. How We Use Information

We use information for purposes that include:

  • Providing, operating, and maintaining the Services

  • Enabling institutional engagement, events, communications, and reporting

  • Authenticating Users and managing access controls

  • Customizing the user experience and improving the reliability, security, and functionality of the Services

  • Communicating service-related information and updates

  • Providing customer support and technical assistance

  • Monitoring performance, security, and system integrity

  • Complying with legal obligations

4. Artificial Intelligence and Machine Learning

Lounge does not use Institutional data, student records, or User Content to train or fine-tune Lounge or third-party artificial intelligence or machine learning models unless expressly authorized in writing by the Institution. Lounge may use aggregated or de-identified information to improve the Services only as permitted by the applicable agreement and will not attempt to re-identify that information. AI-assisted features involving Institutional data may be enabled or disabled by the Institution.

5. Legal Bases for Processing (Where Applicable)

Depending on jurisdiction, Lounge processes personal information based on:

  • Performance of a contract (e.g., providing Services to an Institution)

  • Legitimate interests (e.g., security, service improvement)

  • Consent (where required or obtained)

  • Compliance with legal obligations

6. Disclosure of Information

A. With Institutions

Information is shared with the Institution that sponsors or administers a User’s access, consistent with the Institution’s configuration and policies.

B. With Service Providers

Lounge may share information with vendors that provide services such as hosting, analytics, customer support, and payment processing. These providers are authorized to use information only as necessary to perform services for Lounge.

Lounge maintains agreements with service providers requiring appropriate confidentiality and security protections. A current list of material subprocessors is available upon request.

C. Legal and Safety Reasons

Lounge may disclose information if required by law, regulation, legal process, or to protect the rights, safety, or security of Lounge, Users, Institutions, or others.

D. Aggregated or De-Identified Data

Lounge may use aggregated or de-identified information that does not reasonably identify an individual only as permitted by the applicable agreement. Lounge will not attempt to re-identify such information or permit a recipient to do so.

7. Data Retention

We retain personal information for as long as necessary to:

  • Provide the Services

  • Fulfill contractual obligations with Institutions

  • Comply with legal requirements

  • Resolve disputes and enforce agreements

Retention periods may vary depending on the nature of the data and the Institution’s instructions.

Upon termination or expiration of an agreement with an Institution, Lounge will delete or return Institutional personal information in accordance with the applicable agreement, subject to limited retention in backup systems or as required by law. Backup copies are retained only for disaster recovery purposes and are securely overwritten in accordance with Lounge’s data retention schedule.

8. Data Security

Lounge implements administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, or alteration.

These safeguards include encryption of data in transit using industry-standard protocols, such as TLS, encryption of Institutional data at rest, role-based access controls, audit logging, and ongoing monitoring designed to protect system integrity.

Lounge's security program is aligned to recognized industry frameworks, and current security documentation, including any available third-party audit reports, is provided to Institutions on request under confidentiality. Additional controls include enforced multi-factor authentication for administrative access, support for Institution-managed single sign-on, least-privilege access provisioning with periodic review, encrypted backups, vulnerability scanning, and periodic penetration testing.

Lounge maintains a documented security incident response process. In the event of a security incident affecting Institutional personal information, Lounge will notify the affected Institution without undue delay and in accordance with the applicable agreement and applicable law, and will provide information reasonably necessary for the Institution to meet its own notification obligations.

9. User Rights and Choices

Depending on location and applicable law, Users may have rights to:

  • Access personal information

  • Request correction or deletion

  • Object to or restrict certain processing

  • Request data portability

Requests related to Institutional data may need to be handled by the Institution. Users may contact Lounge using the information below, and we will coordinate as appropriate.

Where applicable under U.S. state privacy laws, Users may have additional rights, including the right to know what personal information is collected and the right to request deletion. Lounge does not sell or share personal information for targeted advertising purposes.

10. Children and Minors

The Services are intended for use by individuals aged 13 and over. Where an Institution enables access for individuals under 18 — for example in dual enrollment, pre-college, or summer programs — the Institution is responsible for obtaining any parental or guardian consent required under applicable law, including the Children's Online Privacy Protection Act (COPPA), and Lounge processes such information solely under the Institution's direction. Lounge does not knowingly collect personal information from children under 13 and will delete such information promptly on becoming aware of it.

11. Student and Educational Records

When Lounge processes student information on behalf of an Institution, such information may be considered part of the Institution’s educational records. Lounge processes such information solely to provide the Services and in accordance with applicable education privacy laws, including the Family Educational Rights and Privacy Act (FERPA), the Protection of Pupil Rights Amendment (PPRA), and applicable state student privacy laws, where applicable. Lounge does not use student information to create a profile for any purpose other than supporting the Institution's authorized educational purposes, does not engage in targeted advertising to students, and does not sell student information. Lounge asserts no ownership over student records, which remain under the control of the Institution. Institutions may access and export their Institutional data in commonly used formats during the term of the applicable agreement and for any applicable post-termination retrieval period.

12. International Data Transfers

Lounge is based in the United States. Primary hosting and data storage are located in the United States. Certain service providers may process limited operational data, such as support communications and system telemetry, in other locations. Institutions with data residency requirements outside of the USA can be accommodated, subject to confirmation of available hosting regions before deployment.

Where required by applicable law, Lounge implements appropriate safeguards for international data transfers, which may include Standard Contractual Clauses or other legally recognized transfer mechanisms.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When changes are made, we will update the effective date and, where appropriate, provide notice through the Services or other reasonable means. Where changes materially affect the processing of Institutional data, Lounge will provide advance notice to affected Institutions. Changes to this Privacy Policy do not amend any separate agreement between Lounge and an Institution.

14. Contact Us

If you have questions about this Privacy Policy or Lounge’s data practices, please contact:

Lounge Technologies, Inc.
Email: admin@lounge.live
Website: https://about.lounge.live

Privacy inquiries and data subject requests: partnerships@lounge.live

Security and incident reporting: support@lounge.live