Legal

Privacy Policy

Effective: May 4, 2026  ·  Operated by CyberAdX / CISO Marketplace

CISO.POKER is operated by CyberAdX Network, part of CISO Marketplace ("we", "us", "our"). This policy explains what data we collect when you use this site, how we use it, and your rights regarding that data. We collect only what we need to run our events. We do not sell your data.

1. Data We Collect

Event applications (waitlist form)

When you apply for a seat at The Stack or another CISO.POKER event, we collect:

  • Name, title, company, work email
  • Role context (in-house CISO, vendor CISO, vCISO, security leader, or other — captured for room-composition curation, not for filtering)
  • LinkedIn profile URL (optional)
  • Company size and industry (optional)
  • Poker skill level and t-shirt size (optional)
  • Events you plan to attend that week (optional)
  • Cash game interest preference (optional)
  • Partner or referral code (optional)
  • IP address (for fraud/abuse prevention)

This information is used solely to evaluate and process your seat application and to communicate with you about the event.

Sponsor inquiries

When you submit a sponsorship inquiry, we collect name, title, company, email, phone, website, sponsorship category, contribution range, and any message you include. This is used only to respond to your inquiry and, if applicable, to execute a sponsorship agreement.

NFC chip system (tag.ciso.poker)

CISO.POKER events use NFC-embedded poker chips that log anonymous tap data when scanned. Each chip contains a locked URL that routes through tag.ciso.poker — a Cloudflare Worker that records the tap and redirects your phone. No app, no account, and no permission is required to tap a chip.

What is captured on every tap (server-side):

  • Timestamp (authoritative server time)
  • Cloudflare network data: country, region, city, data center, HTTP protocol version, timezone, EU country flag
  • IP address — immediately hashed using SHA-256 with a daily salt key. Raw IP addresses are never stored.
  • Browser User Agent string (device and browser type, capped at 512 characters)
  • Referrer URL (where the tap came from, capped at 512 characters)
  • Chip class and chip ID
  • Destination URL the tap was redirected to

What is captured from the browser after redirect (profile page beacon):

  • NFC capability — whether the device supports NFC (distinguishes physical taps from URL shares)
  • Connection type — network type (4G, 3G, WiFi) at the moment of tap
  • Screen width — device category (mobile vs tablet vs desktop)

What is never captured from taps: raw IP addresses, GPS or device location, phone identifiers, names, emails, or any data requiring explicit browser permission.

Post-event: Chips remain active after the event. Taps are logged under the same data model indefinitely. Chip destinations are updated server-side — no chip is ever physically modified.

FeltIQ — Event intelligence platform and participation modes

Select CISO.POKER events feature FeltIQ, our real-time anonymous intelligence capture platform. FeltIQ operates on a zero-PII model. There are two participation modes, with different privacy characteristics:

  • Anonymous FeltIQ token (distributed at check-in to all attendees): A physical NFC token with a unique random code. Participation is fully anonymous — no name, no email, no seat number is ever attached. Survey responses are keyed only to the token code. This mode is anonymous at every layer.
  • Player chip on FeltIQ (opt-in): Attendees with a registered player chip may use it to fast-track FeltIQ check-in. In this mode, the chip token is used as a session anchor — responses are associated with the chip token, which is in turn associated with your registered seat. This is entirely opt-in. Anonymous token participation is always available as an alternative.

In both cases: no names, emails, or device identifiers are stored in FeltIQ. The NFC chip system (tag.ciso.poker) and FeltIQ maintain separate databases. The chip token is the only shared identifier — neither system exposes the other's data. Aggregate response data is published post-event under CC BY 4.0. FeltIQ participation is voluntary. See the FeltIQ Terms & Data Use Agreement for full details.

The registration form for FeltIQ-enabled events records that you acknowledged the FeltIQ Terms at the time of application. This acknowledgment is stored alongside your application data and subject to the same retention policies.

Analytics

We use Google Analytics 4 to understand how visitors use this site. Google Analytics collects anonymized usage data including pages visited, time on site, and general geographic region. We do not use this data to identify individuals. You can opt out via Google's opt-out browser add-on.

Cloudflare Turnstile

Our forms use Cloudflare Turnstile for bot protection. Turnstile processes minimal browser signals to verify human interaction. No personal data is stored by Turnstile beyond what is necessary for this verification. See Cloudflare's privacy policy.

2. How We Store Your Data

Form submissions are stored in a Cloudflare D1 database (serverless SQLite) hosted in Cloudflare's infrastructure. Transactional emails are sent via Resend. Both services operate under their own data processing agreements. We retain application data for the duration of the event cycle (typically 12 months post-event), after which it is purged.

3. How We Use Your Data

  • Event operations: reviewing applications, communicating decisions, coordinating logistics
  • Event communications: confirmation emails, schedule updates, day-of logistics
  • Sponsor coordination: responding to inquiries and executing agreements
  • Site improvement: anonymized analytics to understand what content is useful
  • Security: IP addresses are retained temporarily for abuse prevention

We do not use your data for advertising, lead generation, or any purpose unrelated to CISO.POKER events. We do not share your data with sponsors or third parties except as required to operate the event (e.g., venue logistics).

4. Email Communications

By submitting an application or inquiry, you consent to receive transactional emails related to your submission — confirmations, decisions, and event logistics. We do not send unsolicited marketing email. Every email includes a way to reach us at [email protected] to opt out of further communications.

5. Event Photography and Videography

CISO.POKER events are professionally filmed for recap and promotional use. No names, titles, or company affiliations are used in footage without explicit consent. Face blurring is available on request at check-in. Final table live streaming, where applicable, is opt-in only — participants choose how they are identified on stream.

6. Your Rights

You have the right to:

  • Request a copy of the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (subject to legitimate retention requirements)
  • Withdraw consent for communications at any time

To exercise any of these rights, email [email protected] with the subject line "Privacy Request." We will respond within 30 days.

7. Cookies

This site does not use first-party cookies for tracking or advertising. Google Analytics may set cookies per its standard implementation. Cloudflare may set security-related cookies as part of its infrastructure. No persistent tracking cookies are set by CISO.POKER directly.

8. Third-Party Services

ServicePurposePrivacy Policy
Cloudflare Pages / D1Hosting and databasecloudflare.com
tag.ciso.poker (Cloudflare Worker + D1)NFC chip tap logging and routing — anonymous tap data only, no PIIcloudflare.com
feltiq.ciso.poker (Cloudflare Pages + D1)Anonymous event intelligence — zero PII, token-keyed responses onlyfeltiq terms
ResendTransactional emailresend.com
Google Analytics 4Anonymized usage analyticsgoogle.com
Cloudflare TurnstileBot protection on formscloudflare.com

9. Changes to This Policy

We may update this policy as our practices evolve. Material changes will be noted by updating the effective date above. Continued use of the site after changes constitutes acceptance of the updated policy.

10. Contact

Questions about this policy: [email protected]
CyberAdX Network, part of CISO Marketplace  ·  Houston, TX