This Privacy Policy explains how we collect, use, store, and share personal data in Cursor Community software and related community operations tools (the "Service"). The Service began inside the Cursor Philippines Community. People were excited to learn Cursor together, and organizers wanted to take good care of them. That meant remembering who signed up, who attended, who should receive credits or certificates, and who needed follow-up. We built the Service to make that care dependable, while collecting only the personal data the work needs. NextDecade operates the Service and acts as the controller of personal data processed through it.
What started as event operations now covers attendee verification, credits, certificates, partner requests, and organizer access. The goal is simple: collect what the work needs, protect it, and make Cursor community operations more trustworthy. The Service may later support other developer-tool communities, tool providers, sponsors, employers, schools, and partner programs. This Policy applies to those uses unless we provide a different privacy notice for a specific program. The Cursor application itself is operated by Anysphere, Inc. and is governed by cursor.com/privacy.
1. Personal data we collect
We collect the following categories of personal data:
- Identity and contact data. Your name, email address, profile photo, plus any social or contact links (such as GitHub, LinkedIn, Telegram, a website, or portfolio) and a phone number if you provide one in event registration data.
- Event registration data. Luma event registrations, Luma user and registration identifiers, ticket status, check-in status, registration timestamps, registration question answers, referral sources, UTM fields, and similar event metadata. Registration answers may include free text that you choose to submit.
- Attendance data. Event attendance and check-in records, including check-in method and time, whether recorded by an organizer, kiosk, QR flow, self-service flow, Luma sync, or Luma webhook.
- Perk and certificate data. Credits, referral links, tool access artifacts, partner requests, certificates, issue and redemption status, certificate view and download counts, and audit history tied to those records.
- Organizer and partner access data. Admin grant email addresses, workspace membership records, one-time sign-in code flows, role and workspace scope, and user preferences for organizer tools.
- Security and audit data. Sign-in audit records, activity logs, rate-limit inputs, and anti-abuse signals. Where we persist IP address or browser information for these purposes, we store hashed values rather than raw IP addresses or full user-agent strings.
- Reliability and integration data. Luma webhook logs and import staging data. These can contain the full event or guest payload received from Luma, including registration answers and contact details.
- Organizer console analytics. Admin page views, exceptions, sanitized URLs, and masked session recordings when PostHog is enabled. Public event, claim, credit, and certificate pages do not load PostHog analytics.
2. Purposes and legal bases
We process personal data for the following purposes. For people in the European Union, European Economic Area, and United Kingdom, we also state the legal bases we rely on.
- Event operation and perk delivery. We verify registration and attendance, send sign-in codes, issue credits, certificates, partner grants, and related messages. Legal basis: contract or steps taken at your request.
- Administration and security. We manage organizer access, workspace membership, fraud checks, rate limits, audit logs, and abuse prevention. Legal basis: legitimate interests, and legal obligation where applicable.
- Service improvement and diagnostics. We use limited analytics in the organizer console to understand use, diagnose errors, and improve workflows. Legal basis: legitimate interests.
- Optional communications or uses. Where a use is optional or consent-based, we ask for consent and you may withdraw it at any time.
3. Cookies and local storage
The Service uses a small set of functional cookies and browser storage. The organizer session cookie is http-only, same-site, and lasts about 12 hours. The CSRF security cookie protects state-changing requests and lasts about 5 days. Local storage may keep theme, sidebar, table, and form preferences. Admin screens may also use IndexedDB to cache list and detail responses for faster loading. When PostHog is enabled in the organizer console, PostHog may set analytics cookies. We do not use advertising cookies.
4. Who we share it with
We do not sell personal data. We share personal data with service providers, tool providers, and partner entities only as needed to operate the Service, deliver Perks, secure the Service, or comply with law.
- Luma. Event registration, guest management, and profile photos.
- Supabase. Database, authentication, storage, and organizer sign-in code delivery. Organizer sign-in may also use OAuth identity providers configured through Supabase Auth (currently Google, GitHub, and Slack).
- Vercel.Application hosting and delivery. When city sites use custom hostnames, we may also use Vercel's Domains API to verify and attach those hostnames.
- PostHog. Analytics and diagnostics in the organizer console.
- Google. Transactional email delivery for credits, certificates, partner messages, and onboarding messages. When event memory archives are enabled, media may also be stored in Google Drive.
- Slack. Community memory and event-memory sync from approved Slack channels when that integration is configured.
- Upstash Redis. Distributed rate-limiting infrastructure when configured.
- Tool providers and partner entities. For example, Cursor (Anysphere) or another provider may receive data needed to validate, issue, or honor a Perk.
- Supporting infrastructure. This may include content delivery networks, image hosts, and certificate PDF rendering infrastructure.
We may disclose information if required by law, to protect rights and safety, or to investigate abuse of the Service.
5. International transfers
We operate from the Philippines, and some of our providers process data in other countries, including the United States. When we move personal data out of the EU, EEA, or UK to a country without an adequacy decision, we use appropriate safeguards, typically the European Commission's Standard Contractual Clauses and the UK Addendum where applicable. You may contact us for more information about those safeguards.
6. Retention
We keep personal data for as long as needed for the purposes described in this Policy. Some event records can be recreated from Luma if needed. Credit ledgers, certificate ledgers, attendance logs, webhook delivery records, workspace activity logs, and admin audit records may be kept longer because they protect the integrity of Perks, certificates, and operational decisions. Supabase backups and point-in-time recovery may retain data for a limited recovery period. We may disable workspaces and tokens rather than delete them immediately where audit records are required.
7. Security
We use technical and organizational safeguards, including:
- encrypted connections, security headers, and a content security policy;
- AES-256-GCM encryption for sensitive Luma tokens, webhook secrets, and re-exportable QR or claim link tokens;
- one-way hashes for bearer token lookup and selected security audit fields;
- anti-forgery tokens, origin checks, body size limits, and rate limits on sensitive routes;
- role-based access controls and workspace scoping for organizer and partner actions;
- session cookies that are http-only, same-site, and limited in time.
No system can be made completely secure. If we learn of a security issue that affects your data, we will assess it and take action required by applicable law.
8. Your rights
Depending on where you live, you may have the right to request access to your personal data, correction, deletion, portability, restriction of processing, objection to processing, and withdrawal of consent. To make a request, contact software@nextdecade.org. We may need to verify your identity before acting on a request. We will respond within the period required by applicable law.
If you are in the EU, EEA, or UK, you may lodge a complaint with your local data protection authority. In the Philippines, you may contact the National Privacy Commission.
9. Children
The Service is intended for users who are at least 18 years old. We do not knowingly collect personal data from children. If you believe a child provided data to the Service, contact us and we will take appropriate steps.
10. Changes to this Policy
We may update this Policy. When we make a material change, we will update the date at the top of this page. Your continued use of the Service after an update means you accept the revised Policy.
11. Contact
NextDecade is the controller for personal data processed through the Service. Privacy questions and requests should be sent to software@nextdecade.org.