Legal · Privacy
Privacy, plainly.
Last updated: August 30, 2026
RollCall — operated by RollCall - NightLife, Inc., a Delaware corporation — helps you
see where the night's at, coordinate with your crew, and buy cover at venues. This policy explains
what we collect, why, and the choices you have.
Information we collect
You give us
- Profile: the display name and emoji you choose. If you sign in with Apple,
we receive a private identifier (and your name once, if you share it).
- Your crew & activity: the friends you add by referral code, the rallies you
start or join, the crews you make or join, and the venues you save for later. If you join a crew
through a crew invite link someone shares, you and the crew's members become connected — before you
confirm, you'll see the crew, how many people are in it, and who you'll be connected to, and nothing
happens until you tap to confirm. You can mute a person or a crew any time to stop their
notifications (a private choice — the muted person is never told), and you can block anyone.
- Your nights: your check-in history, the friends you tag as "with you" on a
night, and your one-tap morning ratings — used as a venue-quality signal and to understand
whether the nights we helped you find were actually good ones. Venues only ever see aggregate
scores, never an individual rating.
- Night gallery photos: photos you choose to share to a night's gallery
are uploaded and shown only to the people you were with that night — you control per-photo
visibility and can delete your photos anytime. Matching your camera roll to a night happens
on-device; nothing is uploaded unless you share it.
- Support messages: if you message support (from the app or this site), we
keep your message and the reply address you give us, just to help you.
- Safety actions: if you block or report someone, we keep that record to keep
the community safe.
- Venue partners: if you list a venue, the contact details you provide (name,
role, phone, email) so we can verify the venue and reach you about payouts and support. These are
kept private to you and the RollCall team and are never shown in the app.
- Venue room scans: when a venue posts a room scan (a photo or short clip of how
busy it is), we process it to read the crowd level and headcount and show that live in the app.
That reading is performed by our AI vision provider, Anthropic, which processes scan images on our
behalf as a service provider; under its API terms, Anthropic does not use this data to train its
models. We also use these scans, and the crowd counts derived from them, to build, train, and improve
RollCall's own crowd-detection models so the read gets more accurate over time. Scans expire from
the live page automatically, a venue can delete a scan, and we take reasonable steps to avoid
singling out identifiable individuals when scans are used to improve our models. Our vision
pipeline counts, never identifies: no facial recognition, no tracking of any
individual — ever. Raw scan clips are deleted from our storage after 90 days; only the aggregate
counts and charts derived from them are kept.
- Venue walkthroughs: a venue owner records a one-time walkthrough video of
their space so we can build their room map. Walkthroughs are captured without audio,
are never visible to other users, and are analyzed the same counting-only way as scans.
- Venue staff & texts: if a venue owner adds you to their scan roster, they
give us your name and mobile number so we can text you shift links. Before anything else, we text
you once to ask — nothing more arrives unless you reply YES, and STOP always works, immediately
and permanently, even if the venue re-adds your number. We keep a record of your yes or no (that
record is how we make sure a no sticks). Messages are delivered by Twilio. We never use staff
numbers for marketing.
- Venue sales data (point of sale): a venue owner can connect their own
point-of-sale account — such as Square or Clover — so RollCall can show them how their sales track
against how full the room was. The connection is read-only: we can read transaction
records, and we can never charge, refund, or change anything in their POS. When an owner
disconnects, we delete our stored access tokens and end all access — asking the provider to
revoke them where the provider supports it, and otherwise the owner removes the app on the
provider's side.
What we read is money and timing: order, payment and refund totals, discounts,
tax, tips, the quantity of items on an order, when it was placed, and whether it was an in-room
or off-premise sale. We also store the reference numbers the provider assigns to each
order, payment and refund — we need them to avoid double-counting and to match a refund to the
sale it corrects. Those references mean this data is pseudonymous rather than anonymous:
we cannot connect them to a person, but the venue and its POS provider can, through their own systems.
What we deliberately do not read or store: item or product names, guest counts,
card numbers or cardholder details, and any customer or employee name or identity. If
you buy something at a venue that uses RollCall, we never learn who you are from their POS. This
is a venue's own business data, it is never shown to other venues, and it is never combined with
your RollCall account.
- Purchases: when you buy cover, our payment processor (Stripe) handles your
card details — we never see or store your full card number. We keep a record of the
purchase (venue, amount, time, status).
- ID verification (optional): you can choose to verify your ID once to skip the
in-app age check. If you do, your ID photo and selfie go directly to our verification
provider, Stripe — they never reach RollCall. RollCall never receives, stores, or
has access to your ID image, your selfie, your face-geometry data, or your document number.
To complete the check, our server briefly receives your name and date of birth from Stripe, uses them
only to confirm you're 21+, to record a broad age range, and to stop one ID from verifying many
accounts, and then discards them — they are never stored, never logged, and never shown to anyone.
What we keep is the yes/no result plus a short coarse summary: a broad age range
(21–24, 25–34, 35–44, or 45+), the sex marker printed on your document, the kind of document
(licence, ID card or passport), and its country and state. Never your date of birth, name,
street address, or document number. We use that summary only in aggregate
— to understand which nights and venues suit which crowds, and where to open next. It is never shown
on your profile, never shown to a venue in any form that could identify you, and never used to decide
who gets into anywhere. The sex marker is the one printed on the document; it is not a statement
about anyone's gender identity, and we never display it.
Verifying is entirely optional. Because the selfie-to-ID check involves biometric data, we handle it
under a dedicated Biometric Data Policy, and we ask for your explicit
consent before anything is captured.
Collected automatically
- Precise location: while you're using the app, to show venues near you,
measure distance, and confirm you're actually at a venue when you check in. We use it only while
the app is in use (never in the background) and never sell it. You can turn it off in iOS Settings.
- Check-ins: the venue you check into (visible only to your friends — or no
one, in Ghost mode). Checking in is always a choice you make, night by night — we ask before your
first one, and check-ins expire on their own within hours. Your own check-in history stays in
your Nights tab (and our records) until you delete your account — that history is yours, and
venues only ever see anonymous aggregate counts, never who was there.
- Usage analytics: how you use RollCall, tied to your account — the venues
you're shown and open, when you check in and head out, and purchases you make — to understand
and improve the product, fix what's broken, and measure whether features like deals actually
work. This stays first-party: it is never sold, never shared with advertisers, and never used
to track you across other apps. Raw records are deleted on a fixed schedule, and when you
delete your account they are removed from our live systems right away and from our analytics
reporting within days. Ghost-mode check-ins never enter these records with a venue attached —
we keep only the fact that a ghost check-in happened, never where.
- Notifications token: a device token so we can send you crew/deal alerts.
- Waitlist email: if you join the launch waitlist on our website, we keep the
email you enter solely to tell you when RollCall opens in your city. We don't sell it or use it for
anything else, and you can ask us to delete it any time.
- Story submissions: if you send RollCall Stories an idea, we collect the name,
email, role, city, selected Story channels, story details, and attribution preference you provide,
plus an optional company and website. We use that information only to review the idea and contact
you about it. It may be seen by the RollCall team and processed by our email delivery provider only
to alert our team and reply to you. We keep it for as long as needed to review and follow up on the
submission or maintain necessary business records; you can ask us to delete it at any time. Sending
an idea does not authorize us to publish it or subscribe you to any newsletter.
How we use it
- To run the core experience: nearby venues, live crowd, your crew, rallies, your nights, and
cover passes.
- To read how busy a venue is from its room scans, and to build, train, and improve RollCall's
own crowd-detection models from those scans and the headcounts derived from them.
- To process cover purchases and issue your pass.
- To send notifications you've opted into.
- To keep the service safe, prevent abuse, and improve features.
Venue cameras
Some venues connect cameras they already own so their room can count itself. Here is exactly
what that means for anyone standing in the room:
- What RollCall produces: an anonymous estimate of how many people are in the
room, plus camera health. Depending on the connection, the count runs on a small computer at the
venue or in RollCall's controlled cloud infrastructure. That estimate joins the venue's live
crowd level the same way a room scan does: always aggregate, never about any one person.
- What never happens: RollCall does not store camera footage or frames, does
not recognize faces, does not identify anyone, does not listen to audio, and does not read
license plates. A frame is read for a count and discarded in the same moment, and no RollCall
screen — the venue's own dashboard included — can display camera video.
- Accuracy checks: connected-camera frames are not sent to Anthropic or another
outside AI model provider. RollCall checks the estimate using the cameras' agreement, health,
directional flow where available, and other permitted aggregate measurements. When the evidence
is not strong enough, RollCall shows that it is still learning or needs attention instead of
presenting a precise count.
- No training on camera footage: our counting model is not trained on venue
camera frames. If a venue separately agrees to an accuracy study, imagery for that study is
collected under that explicit written agreement — never silently through this integration.
- The venue is in control: the owner chooses which cameras are connected and
can disconnect any of them, or all of them, at any time — counting stops immediately. Any notice
to guests or staff that local law requires for camera use on the premises is the venue's
responsibility, and we put that obligation in front of the owner at connection time.
- What we keep about the connection: to read a connected camera we hold the
access credentials the camera provider issues to us, and the provider's identifiers for the
account and the chosen cameras. They are kept on our servers only, are never shown on any
screen, and are never shared or sold. Motion notices a provider sends us are deleted within 24
hours. Disconnecting a provider deletes its credentials, and deleting the venue or your account
deletes everything about the connection. To ask for deletion, or to check what we hold, write
to [email protected].
- Reporting misuse: if you believe RollCall or a connected camera is being
misused, write to [email protected] and we will
look into it.
What we share
- With your friends: your name, emoji, and current check-in (unless you're in
Ghost mode). Strangers never see your location.
- With your night circle: photos you share to a night's gallery are visible only
to the people tagged on that night — and only the ones you've allowed per photo.
- With venues: only aggregate signals (how many people are there now)
— never your identity. When you redeem a pass, the venue confirms that pass is valid.
- Service providers: Google Firebase and Google Analytics (hosting, database,
notifications, and first-party analytics), Stripe (payments, and — only if you choose to verify — ID
verification), Anthropic (AI reading of venue scans, but not connected-camera frames), and Twilio
(staff shift texts). They process data on our behalf under their own terms.
- We do not sell or share your personal information for advertising, and we never
sell or share sensitive information — including anything related to ID verification — for any purpose.
Your choices
- Ghost mode: count toward a venue's crowd anonymously without sharing where
you are.
- Per-photo visibility: choose exactly who can see each photo you share — or
delete it.
- Location & notifications: control both in iOS Settings at any time.
- Mute: silence a person's or a crew's notifications without unfriending or
leaving — a private choice the other person is never told about.
- ID verification: it's optional. If you verified and change your mind, remove it
any time in Profile → ID verification → Delete my verification; that clears your verified status and
asks Stripe to destroy anything it still holds.
- Delete your account: Profile → Delete account removes your profile, crew,
check-ins, nights, shared photos, passes, and verification from our systems.
Sensitive information & ID verification
The only sensitive information involved in RollCall is what's needed for optional ID verification —
and by design, we don't hold the biometric part of it. Your ID image, selfie, and the
face-geometry scan used to match them are collected by our provider (Stripe) and never reach RollCall.
To complete the check our server briefly receives your name and date of birth to confirm you're 21+
and prevent duplicate accounts, then discards them; we keep only the verified/not-verified and
21-or-older result. We ask for your explicit, informed consent before any capture, verifying is always
optional, and you can withdraw consent and delete your verification any time. Because the check
involves biometric data, its handling — including our retention schedule and destruction guidelines —
is set out in full in our Biometric Data Policy. We do not use
verification, or anything derived from it, for advertising or profiling, and we never sell or share
it.
Your state privacy rights
Depending on where you live (for example, California, and other states with comprehensive privacy
laws), you may have the right to know what personal information we hold about you, to access or correct
it, to delete it, and to opt out of any "sale" or "sharing" of it. We honor deletion for
everyone, regardless of state. In the RollCall app, delete your account under Profile →
Delete account and it goes. If you run a venue and use the operator dashboard, email
[email protected] and we will delete your account, your
venues and their history; we may need to confirm who you are first.
- We do not sell or share your personal information for cross-context behavioral
advertising, and we never sell or share sensitive personal information — including anything related
to ID verification — for any purpose. So there is nothing to opt out of, but the choice is yours by
default.
- Sensitive personal information: two categories. First, precise
location — we use it while the app is open to show nearby venues and to confirm you're
actually at a venue when you check in. We never store your coordinates on our servers; only the venue
you chose to check into. Second, optional ID verification, which our provider handles
and whose images we never receive (see above). We use both only to provide and secure the service you
asked for — never to build a profile of you, never for advertising, and never sold or shared — which
are permitted purposes, so there's nothing here you need to separately limit. You can still turn
location off in iOS Settings at any time, and you can delete your verification in the app.
- No discrimination: we won't deny you service or charge you differently for
exercising these rights.
- How to exercise them: use the in-app controls, or email
[email protected]. We may need to confirm your identity
to act on a request. You can also authorize an agent to make a request on your behalf.
Data retention
We keep your information while your account is active. When you delete your account, we remove
your personal data; we may retain limited purchase records as required for tax, accounting, or
dispute resolution. Where the law requires proof that we obtained your consent (for example, a record
that you agreed to ID verification), we keep only a minimized record of that consent — an internal
account identifier, the consent version, and a timestamp — never the underlying sensitive data. If you
verified your ID, we keep only the verification result and
it expires after 365 days; the biometric data itself is held by our provider and destroyed on the
short schedule set out in the Biometric Data Policy.
Age
RollCall is intended for adults of legal nightlife age (21+). It is not directed to children.
Security
Data is encrypted in transit, access is locked down server-side, and we keep only what the
product needs. If we ever have a security incident that affects your data, we'll tell you what
happened, what it means, and what we did — promptly and plainly. Security researchers: see
/.well-known/security.txt.
Changes
We'll update this page and the "last updated" date when this policy changes.