Privacy Policy
Last updated: 5 August 2026
This policy explains what personal information Momentum uses, why we use it, who helps us provide the service, and the choices you have.
1. Who we are
Momentum is provided by Rostrum Studio.
Rostrum Studio is the trading name used for this service.
Privacy enquiries and data-rights requests: [email protected]
Product support: [email protected]
General enquiries: [email protected]
[BEFORE LAUNCH: add the legal name and postal address of the business operating as Rostrum Studio.]
2. When Rostrum Studio is the controller
Rostrum Studio decides how personal information is used when it relates to:
- Momentum user accounts
- authentication and account security
- enquiries and product support
- service administration
- technical logs used to run and protect the service
For this information, Rostrum Studio normally acts as the data controller.
Momentum does not currently take payments, run subscriptions or send promotional marketing email, and no third-party website analytics service is connected. If that changes, we will update this policy first.
3. When Rostrum Studio is a processor
Conference organisers may upload participant information and use Momentum to create personal participant pages, links, campaign activity and reports.
The organiser normally decides:
- whose information is uploaded
- why it is used
- what campaign messages are created
- when participant links or messages are sent
- how long the event data is needed
For that participant and event-campaign information, the organiser is normally the controller and Rostrum Studio processes the information on the organiser's instructions.
If you have questions about why an organiser holds your information or contacted you, please contact that organiser first. Rostrum Studio will still help the organiser respond to valid data-rights requests where required.
4. Information we collect
Account and organiser information
- full name
- email address
- encrypted authentication credentials managed by Supabase
- organisation membership
- role and permissions
- profile and workspace settings, including a support email address you choose to show participants
- invitation and acceptance records, including terms and privacy acceptance
- account creation and sign-in information
Passwords are stored and checked by Supabase authentication. Momentum cannot read or recover your password.
Event and campaign information
- event names, dates, venue, city, country and website links
- event descriptions and images supplied as URLs
- Blueprint selections
- Marketing Moment content
- email copy prepared by organisers
- campaign status and publication history
Participant information supplied by organisers
- first name
- last name
- email address
- organisation
- job title
- participant identifiers, including a public ID and personal link tokens
- import and review status
This information usually comes from the organiser rather than directly from the participant. Momentum does not ask participants to create an account.
Participant activity
Momentum records a limited set of activity connected with the links it creates:
- visits to a personal Momentum page
- views of a Marketing Moment
- opening an available action
- starting a sharing action, such as copying a message or opening email, WhatsApp or LinkedIn
- clicks on a tracked share link
- clicks on an external booking or survey link
- campaign, Moment and link identifiers
- date and time of the activity
- limited technical information needed to operate the service: a broad device category (mobile, tablet or desktop), the referring website domain, an opaque session identifier and an opaque visitor identifier
Momentum records that an action was started, not that it was completed. Starting a share or clicking a link does not tell us whether anyone posted a message, registered or booked on another platform. Momentum does not store full IP addresses or the content of messages people send.
Communications
- Momentum sends transactional emails for account confirmation, sign-in and password recovery, invitations to join an organisation, and service or support messages.
- Momentum prepares campaign email content and a participant distribution file for organisers to download.
- Momentum does not send an organiser's campaign emails to participants. Organisers send those through their own email or CRM systems.
Organisers are responsible for deciding when and why they send campaign communications through their own systems.
5. Why we use information and our lawful bases
| What we use information for | Information involved | Our reason under data-protection law | Plain-English explanation |
|---|---|---|---|
| Providing organiser accounts and the contracted service | Account, organisation, profile and event data | Contract | We need this information to create your account and provide the service you or your organisation asked for. |
| Processing participant and campaign data for an organiser | Participant records, links and participant activity | The organiser chooses the lawful basis. Rostrum Studio processes the data under its contract with the organiser. | We use this information to provide Momentum on the organiser's instructions. |
| Account security, fraud prevention and service reliability | Sign-in records, roles, application and error logs | Legitimate interests | We have a legitimate interest in protecting accounts, investigating misuse and keeping the service reliable. |
| Product support for an existing service | Account details and the content of your enquiry | Contract | We use your details to answer support requests about the service you use. |
| Responding to general enquiries | Your contact details and the content of your enquiry | Legitimate interests | We have a legitimate interest in replying to people who contact us. |
Momentum does not currently take payments, so we do not hold billing records for the service. We do not run non-essential analytics or promotional marketing, so we do not currently rely on consent for those purposes. If we introduce them, we will update this policy and provide any consent or opt-out controls the law requires before starting.
6. Who receives information
| Provider | What it does | Information it may receive | Storage or processing region |
|---|---|---|---|
| Lovable | Application development platform, hosting and deployment of the Momentum web application | Application traffic and request data needed to serve the site, plus application logs | Needs owner confirmation |
| Supabase | Authentication, PostgreSQL database and backend services | All account, organisation, event, campaign, participant and activity records described above | Amazon Web Services, Ireland (eu-west-1) |
| Resend | Transactional email delivery | Recipient email address, sender details, subject and message content of the email being sent | Needs owner confirmation |
| n8n | Workflow automation, triggered when an organiser publishes a Marketing Moment | Event ID and name, Moment ID and internal name, opportunity ID and publication timestamp. No participant names, email addresses or participant activity are sent. | Needs owner confirmation |
Momentum does not currently send data to Stripe or to any third-party analytics provider. We may also share information with professional advisers or authorities where the law requires it.
7. International transfers
Some suppliers may process information outside the UK. Our database and authentication records are stored in Ireland.
Where personal information is transferred outside the UK, we use a lawful transfer method such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
8. How long we keep information
We keep account and service information while the account is active. When an account or customer contract ends, we delete or anonymise information under our documented retention process, except where we must keep limited records for legal, security or dispute purposes.
| Information | How long we keep it | What happens at the end |
|---|---|---|
| User account and profile data | While the account exists | Deleted when the account is deleted |
| Legal acceptance records | While the account exists | Deleted with the account. Retention beyond account deletion is under review. |
| Organisation invitations | While the organisation exists | Deleted when the organisation is deleted. Expired invitations can no longer be used. |
| Event and campaign data | Until the organiser deletes the event | Deleted with the event |
| Participant data | Until the organiser deletes the participant or the event | Deleted with the participant or event, together with their personal links |
| Participant activity records | Until the related event is deleted | Deleted with the event |
| Transactional email delivery records | A time-limited period set by our email systems | Removed automatically. The exact period is under review. |
| Support enquiries | Kept in our email systems while needed to answer and evidence the request | Deleted under our documented retention process |
| Security and application logs | A limited period set by our hosting and database providers | Removed automatically. The exact period is under review. |
| Backup copies | Managed by our database provider | Overwritten or removed on the provider's backup cycle. The exact period is under review. |
Momentum does not currently hold billing or tax records for the service, run analytics, or keep marketing suppression records, because those activities are not active.
9. Security
- access to organiser areas requires authentication
- database access rules restrict records by organisation, event ownership and account role
- public participant pages and share links use long, unguessable tokens rather than exposing internal records
- service secrets are stored outside the public frontend and are only used by server-side code
- HTTPS is provided by the deployed service
- access is limited according to account permissions
- errors are logged without intentionally exposing tokens or passwords
No online service can promise perfect security. We use reasonable technical and organisational measures designed to reduce the risk of unauthorised access, loss or misuse.
10. Your rights
Depending on the situation, you may ask to:
- receive a copy of your personal information
- correct inaccurate information
- receive certain information in a portable format
- delete information
- limit how information is used
- object to certain uses
- withdraw consent where consent is the basis
- complain about how information is handled
To make a request, email [email protected].
We normally respond without undue delay and within one month. We may ask for information needed to confirm your identity. In limited cases, the law allows more time or allows us to refuse part of a request, and we will explain this if it applies.
If your request concerns information uploaded by a conference organiser, we may pass the request to that organiser or help them respond because they normally decide how that information is used.
11. Complaints
Please contact [email protected] first so we can investigate your concern.
You may also complain to the Information Commissioner's Office, the UK data-protection regulator.
12. Cookies and similar technology
Momentum uses essential cookies and browser storage to keep accounts signed in, protect the service and remember necessary settings. These cannot be switched off through our cookie settings because the service would not work correctly without them.
| Name or key | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| sb-…-auth-token (browser local storage) | Supabase | Keeps an organiser signed in and refreshes the session | Strictly necessary | Until sign-out or expiry |
| pending_invite_token, pending_terms_acceptance (local storage) | Momentum | Carries an invitation and terms acceptance through email confirmation | Strictly necessary | Removed as soon as sign-up completes |
| momentum:selected-event-id (local storage) | Momentum | Remembers the event you were last working on | Preferences | Until you change events, switch workspace or clear your browser |
| sidebar_state (cookie) | Momentum | Remembers whether the app sidebar is open or collapsed | Preferences | 7 days |
| Participant page session key (session storage) | Momentum | An opaque identifier that stops one page visit being counted several times in the same browsing session | Strictly necessary | Cleared when the browser tab is closed |
| mm_rv (cookie) | Momentum | An opaque, randomly generated identifier used only to stop the same share-link click being counted twice. It is not used for advertising or profiling. | Strictly necessary | 2 years |
We do not use advertising cookies, and no third-party analytics or marketing tracking is loaded on this site.
13. Automated decisions
Momentum does not currently make automated decisions about people that have legal or similarly significant effects.
14. Children
Momentum is a business service for conference organisers and is not designed for children. Organisers should not upload information about children unless they have considered the extra legal and safeguarding requirements that apply. Contact us before using Momentum for an event aimed at under-18s.
15. Marketing
Momentum currently sends service messages needed to operate accounts, invitations, security and support. Organisers may also use content and distribution files created by Momentum in their own communication systems. Those organiser communications are controlled by the organiser.
We do not currently use Momentum account details for routine promotional email campaigns. If this changes, we will update this policy and provide any consent or opt-out controls required by law before starting.
16. Changes to this policy
We may update this policy when the service, our suppliers or the law changes. We will update the date at the top. If a change materially affects existing users, we will give reasonable notice in the service or by email.
Our Terms of Use also apply when you use Momentum.