Privacy Policy
AfterShow helps creators, shops, and live hosts keep the audiences they build between shows, drops, and sales. To do that, we collect and process certain information. This policy explains what we collect, why, who we share it with, and what rights you have.
- Who we are
- Information we collect
- How we use information
- Data imported from seller platforms
- Connected platforms and authorized access
- Sign-in with Google and Meta
- Third-party processors
- AI features and analysis
- Email and SMS broadcasts
- Cookies and similar technologies
- Your rights
- Data retention
- Security
- Children
- International users
- Changes to this policy
- Contact us
Who we are
AfterShow is a product of AfterShow, Inc., a Georgia corporation. When this policy says "we", "us", or "AfterShow", it means AfterShow, Inc.
We are the controller of personal information you provide directly to us as a creator using the platform. For information about your customers and audiences that you import into AfterShow, you are the controller and we act as a processor on your behalf, as described below.
Information we collect
Information you give us as a creator
When you create an AfterShow account, we collect your name, email address, and either a password or an identifier from your chosen sign-in provider (Google or Meta). If you connect a business profile, we also collect business name, business slug, and optional category and biographical details.
If you subscribe to a paid plan, our payment processor (Stripe) collects and processes your billing information directly. We receive a customer identifier and subscription status from Stripe, not your full card details.
Information you import about your customers and audience
AfterShow lets you import order history, customer lists, and engagement data from third-party seller platforms by uploading files you export from those platforms. The kinds of information these files commonly contain include:
- Customer names, usernames, and handles
- Email addresses, and phone numbers where you upload a contact or marketing list that includes them
- Shipping addresses, including city, state, ZIP/postal code, and country
- Order details: dates, items purchased, quantities, prices, and order identifiers
- Engagement data such as live-chat comments, viewer counts, and conversion metrics
You are responsible for ensuring you have the legal right to export this data from the source platform and to import it into AfterShow. See the Terms of Service for details.
AfterShow also offers an optional email-forward import feature. If you choose to use it, you forward platform recap or settlement emails to a dedicated AfterShow import address. When you do, we receive and store the forwarded email content (including the metrics and order details it contains) and the email address you forward from, so we can match the import to your account and process it. This feature is off unless you actively use it, and you control which emails you forward.
Information collected automatically
When you use AfterShow we automatically collect technical and usage information, such as your IP address, device and browser details, and how you interact with the service. We use this to operate, secure, and improve the service.
Information from third parties
If you sign in with Google or Meta, we receive basic profile information from those providers, as described in the Sign-in with Google and Meta section. If you connect a payment method, Stripe shares subscription and billing status with us. If you authorize a connection to a seller platform, we receive your own order and customer data from that platform on a read-only basis, as described in Connected platforms and authorized access.
How we use information
We use the information described above to:
- Operate, maintain, and improve the AfterShow service
- Authenticate your account and protect it from abuse
- Process subscription payments and manage your subscription
- Generate analytics, reports, and insights for you from data you import
- Send email and SMS broadcasts on your behalf when you initiate them
- Send transactional communications about your account, billing, and the service
- Respond to your support questions and feedback
- Comply with legal obligations and enforce our agreements
We do not sell your personal information. We do not sell, lend, or rent your imported customer or audience data to anyone. We do not use your imported data to train any general-purpose AI model.
Data imported from seller platforms
AfterShow supports importing exported order and customer data from a range of third-party seller platforms, including but not limited to live-selling platforms, online marketplaces, and direct-to-consumer storefronts (for example, platforms used for live auctions, vintage and resale, handmade goods, sneakers, livestream shopping, and direct sales).
These third-party platforms are owned by their respective companies and are not affiliated with, endorsed by, or sponsored by AfterShow. All platform names and marks remain the property of their respective owners.
Important points:
- AfterShow does not directly access these platforms' APIs unless a specific integration is enabled by you and clearly described to you. The default import flow works by you uploading files that you exported from the source platform, or by you forwarding platform recap emails to your AfterShow import address.
- You represent that you have the legal right to export the data from the source platform and import it into AfterShow.
- You are responsible for ensuring your export and use of the data complies with the source platform's terms of service.
- Imported data is stored on your behalf, scoped to your account, and is not accessible to other AfterShow creators.
Connected platforms and authorized access
In addition to file-based and email-forward imports, AfterShow offers optional connections that let you authorize AfterShow to read your own order and customer data directly from a seller platform you use (for example, through that platform's official authorization flow). These connections are off unless you choose to enable one, and you can disconnect at any time.
When you connect a platform:
- You authorize the access. AfterShow reads your data only after you grant permission through the platform's own authorization (OAuth) process, and only within the scope that process grants.
- Access is read-only and limited to your own data. AfterShow uses the connection only to read your order records and the associated customer information (such as customer name, email, and shipping address) needed to provide your analytics and customer list. AfterShow does not modify data on the source platform.
- We use it only to serve you. Data obtained through a connection is processed solely to provide the service to you, the authorizing seller. It is scoped to your account, is never shared with other creators, is never aggregated across sellers, and is never sold.
- We protect the keys to that access. The access and refresh tokens that authorize a connection are encrypted before we store them, using a key kept separately from the database that holds the encrypted tokens. You can revoke a connection at any time from the platform's settings or by disconnecting in AfterShow; on disconnection or account closure, the associated tokens are revoked or deleted.
Each platform's own terms and privacy policy continue to govern your relationship with that platform. We honor the data-handling and security requirements of the platforms we connect to, and we use authorized data only for the purposes described in this policy.
Sign-in with Google and Meta
If you choose to sign in to AfterShow with a Google or Meta account, we receive limited profile information from those providers. Specifically:
- Google: we request access only to your basic profile (name, email address, profile picture) for the purpose of authenticating you. AfterShow's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not transfer it except as necessary to provide the service, and do not allow humans to read it except with your consent or as required by law.
- Meta (Facebook and Instagram): we request access only to basic profile information for authentication. We do not post on your behalf or access content beyond what is necessary to sign you in. If you opt into future integrations (for example, automatic broadcasts triggered by Instagram posts), we will request additional permissions at that time and describe what we access before you grant them.
You may revoke AfterShow's access to your Google or Meta account at any time through your provider's security settings. Doing so will end your ability to sign in using that provider but will not delete your AfterShow account; contact us if you also want your account data deleted.
Third-party processors
We rely on a small set of trusted service providers to operate AfterShow. Each processes information only as needed to deliver their service to us, and each is bound by their own terms and privacy commitments.
- Supabase - database hosting (United States); stores your account, order, and customer data, encrypted at rest, with per-account isolation
- Cloudflare - hosting, edge compute, content delivery, security, and abuse protection (United States); processes data in transit and runs the service
- Resend - transactional and broadcast email delivery, including inbound email forwarding for the email-forward import feature
- Twilio - SMS and MMS message delivery for text-message broadcasts
- Stripe - payment processing and subscription billing
- Google - sign-in and authentication
- Meta - sign-in and authentication (and, in future opt-in features, integration with Instagram and Facebook surfaces you control)
- Anthropic - AI-powered analysis and screening, including order-data insights, image moderation, screenshot stat verification, and data-file screening (see AI features)
We may share information with these providers only to the extent needed to provide the service to you. We do not sell information to any of them, and we do not allow them to use information for their own marketing.
AI features and analysis
AfterShow uses our AI provider (Anthropic) in several ways, described below. In all cases, the AI provider processes data on our behalf under contractual terms and does not use it to train general-purpose AI models.
Insights. Optional AI-powered insights analyze your imported order data and surface patterns such as top customers, geographic trends, and notable changes over time. When you use these features, summarized order data (primarily numeric and categorical values) is sent to the AI provider and the resulting insight text is returned to you and displayed in your account. We do not send raw customer contact fields (full email addresses, phone numbers, or physical addresses) to the insights feature.
Image moderation. To keep uploaded images appropriate for a professional setting, images you upload (such as a profile photo or card image) are sent to the AI provider's vision model for automated screening before they are stored or displayed. Because an image can contain whatever you chose to include, any content visible in the image is part of what is screened.
Stat verification (screenshots). If you use the feature that verifies your platform statistics, the screenshot you upload of your own platform profile is sent to the AI provider's vision model so it can read the numeric stats and the visible account handle or display name. Screenshots of a platform profile typically contain identifying text such as your handle and display name, and that visible text is processed as part of reading the image. We use the handle the model reads only to confirm the screenshot belongs to your account.
Data-file screening. When you import a data file (such as a CSV or spreadsheet), a sample of representative rows is sent to the AI provider as text for automated screening for malicious content and accidental sensitive-data spills before the file is processed. Depending on the file you upload, this sample may include data from your file, which can include customer details that appear in those rows.
AI-generated insights are provided for informational purposes and may be incomplete or inaccurate. They are not a substitute for your own judgment, professional advice, or your records of truth.
Email and SMS broadcasts
AfterShow lets you send broadcasts (email and SMS or MMS) to people on your contact list. When you initiate a broadcast, AfterShow acts as a processor on your behalf to deliver it. You are the sender of those communications and you are responsible for ensuring that your broadcasts comply with applicable laws (such as the CAN-SPAM Act in the United States, the TCPA for SMS, the GDPR in the European Union and United Kingdom, and PIPEDA and CASL in Canada), and with the terms of any platform you obtained contacts from.
AfterShow includes unsubscribe and opt-out handling in all broadcast messages. Email unsubscribe requests are honored within ten (10) business days, as required by the CAN-SPAM Act. SMS STOP requests are honored immediately. You may not disable, alter, or attempt to bypass these mechanisms.
SMS messaging program (information for recipients)
If you provide your mobile phone number on a creator's AfterShow signup page and check the SMS consent box, you agree to receive recurring text messages from that creator, sent through AfterShow on the creator's behalf. The number of messages you receive varies depending on the creator's activity (for example, notifications about upcoming or live shows). Consent to receive text messages is not a condition of any purchase.
Message and data rates may apply. Message frequency varies. You can opt out at any time by replying STOP to any text message; you will receive a single confirmation that you have been unsubscribed, and no further messages will be sent unless you opt in again. For help, reply HELP or contact us at support@aftershow.net. Carriers are not liable for delayed or undelivered messages.
We do not share or sell mobile phone numbers, or any consent or opt-in information, with third parties for their own marketing purposes. Mobile numbers and SMS consent records are used only to deliver the messages you opted into and to operate the service, as described in this policy. Mobile information is not shared with third parties or affiliates for marketing or promotional purposes; service providers that help us deliver messages (such as our SMS delivery provider) receive only what is necessary to send them and may not use the information for any other purpose.
AfterShow will not access, use, or share your customer or audience data for any purpose other than operating the service for you, as described in this policy. We do not read the content of broadcasts you compose, except where required to deliver them or to investigate abuse reports. We do not contact people on your list except through broadcasts you initiate.
Cookies and similar technologies
AfterShow uses only essential cookies needed to operate the service - principally a session cookie that keeps you signed in, and infrastructure cookies set by our hosting provider for security and abuse prevention. We do not use third-party advertising or analytics cookies on the AfterShow product.
You can clear or block cookies in your browser settings. If you block essential cookies, AfterShow will not function correctly.
Your rights
Depending on where you live, you may have rights regarding personal information we hold about you, including the rights to:
- Access the information we hold about you
- Receive a copy of your data in a portable format
- Correct inaccurate information
- Delete your information
- Object to certain processing
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority in your jurisdiction
Many of these are available directly inside the product: you can edit your profile, delete imported data, export your audience and order history, and close your account. For requests we cannot service in-app, contact us using the details in Contact us.
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you specific rights, including the rights to know, delete, correct, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioral advertising.
If you are in the European Economic Area, United Kingdom, or Switzerland, you have rights under the GDPR. Our legal bases for processing are contractual necessity (to provide the service), legitimate interests (to secure and improve it), legal obligation (where required by law), and consent (for features like marketing communications).
Data retention
We retain your account information and imported data for as long as your account is active. If you delete specific imports or audience records inside the product, we remove them from active systems promptly. If you close your account, we delete your account information and imported data within thirty (30) days, except where we are required to retain specific records for legal, tax, billing, fraud-prevention, or security purposes.
Backups are retained on a rolling schedule and are overwritten automatically. Deletion from backups occurs as part of the regular rotation; this typically completes within ninety (90) days.
Security
We use reasonable technical and organizational measures to protect information against unauthorized access, alteration, disclosure, and destruction. These include encryption in transit (TLS), encryption at rest for stored data, row-level security that isolates each account's data in our database, scoped service credentials, fail-closed authorization on data-handling endpoints, and limited access on a least-privilege basis. Access and refresh tokens for any connected platform are additionally encrypted at the application layer before storage, using a key held separately from the database that stores them.
Your account, order, and customer data is stored in the United States. We maintain written internal security and data-protection policies (including information security, incident response, access control, data classification, and vulnerability management) appropriate to our size.
No system can be completely secure. If we become aware of a security incident that affects your information, we will notify you and any required authorities or platforms consistent with applicable law and our agreements.
Children
AfterShow is not directed at children, and we do not knowingly collect personal information from children under sixteen (16) years of age. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
International users
AfterShow is operated from the United States. If you access the service from outside the United States, your information may be transferred to, stored in, and processed in the United States and in the countries where our service providers operate. By using AfterShow, you consent to those transfers.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where required by law, notify you through the service or by email. Continued use of AfterShow after changes take effect means you accept the updated policy.
Contact us
Questions, requests, or concerns about this Privacy Policy or your information can be sent to:
AfterShow, Inc.
1639 Bradley Park Drive, Box #374, Columbus, GA 31904
General inquiries: hello@aftershow.net
Privacy and data requests: privacy@aftershow.net
State of incorporation: Georgia, United States