VapiCon 2026 Privacy Policy
This Privacy Policy explains how Vapi Inc. collects, uses, discloses, and protects personal information in connection with VapiCon 2026, and describes the rights and choices available to you. It applies to the VapiCon 2026 website at vapicon.ai, the registration and ticketing process, the Event app and other online platforms we make available for the Event, and your attendance at and participation in the Event itself, held on November 11 and 12, 2026 at the Festival Pavilion at Fort Mason Center in San Francisco, California.
This Privacy Policy is specific to VapiCon 2026 and is separate from the Vapi platform privacy policy at vapi.ai/privacy, which governs the Vapi voice AI product and applies if you create or use a Vapi account. This Privacy Policy is incorporated into the VapiCon 2026 Terms and Conditions.
Who We Are and Who Is Responsible for Your Information
1.1.Vapi Inc. ("Vapi," "we," "us," or "our") is the controller of, and the business responsible for, personal information collected in connection with the Event, except as stated in Section 1.2 and Section 8.
1.2.Montgomery Entertainment, LLC produces the Event on our behalf and processes personal information as our service provider and processor under contract. Our ticketing platform, payment processor, Event app provider, badge and registration vendor, caterers, and the Venue Operator likewise act as our service providers or as independent parties, as described below.
1.3.Sponsors, exhibitors, media, and other third parties that collect information directly from you at the Event are independent controllers and businesses with respect to that information. Their practices are governed by their own privacy policies, not by this one. See Section 8.
Personal Information We Collect
We collect the categories of personal information described in the table below. The categories correspond to those used in the California Consumer Privacy Act, as amended, and this table also serves as our notice at collection under that law.
We collect this information from you directly, automatically through your use of our website, Event app, badge, and Event Wi-Fi, and from our service providers, the Venue Operator, and, where you have authorized it, from a person or organization that registered you or transferred a pass to you.
3. How We Use Personal Information
We use personal information to:
Administer registration, ticketing, payment, transfers, badging, check in, and session enrollment.
Operate and deliver the Event, including sessions, workshops, demonstrations, catering, and networking features.
Communicate with you about the Event, including confirmations, logistics, schedule and program changes, health and safety notices, and post-event materials such as session recordings and surveys.
Provide accommodations you request and address dietary and accessibility needs.
Document, produce, promote, and share the Event through photography, video, livestream, and recordings.
Operate, troubleshoot, and demonstrate voice AI systems at the Event, as further described in Section 5.
Provide the sponsor lead retrieval service where you choose to have your badge scanned, and provide aggregate, non-identifying attendance reporting to sponsors.
Send you marketing about Vapi products, services, and future events, where permitted and subject to your choices. Every marketing email includes an unsubscribe link.
Analyze attendance and engagement, improve our programming, and plan future events.
Maintain the safety and security of the Event, investigate and respond to incidents and Code of Conduct reports, prevent fraud and abuse, and enforce our terms.
Comply with legal obligations, including tax, accounting, and records obligations, and to establish, exercise, or defend legal claims.
We do not use personal information collected in connection with the Event to train general purpose artificial intelligence or machine learning models.
4. Legal Bases for Processing
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:
Performance of a contract, to register you, issue your badge, administer your pass and enrollments, and deliver the Event.
Legitimate interests, to secure and improve the Event, prevent fraud and abuse, produce and promote the Event, communicate about our own similar products and events, and establish, exercise, or defend legal claims. We balance these interests against your rights and expectations.
Consent, for optional marketing where consent is required, for non-essential cookies and analytics, for sharing your information with sponsors, and for capture of your voice at a voice AI demonstration. You may withdraw consent at any time, without affecting processing carried out before withdrawal.
Legal obligation, to meet tax, accounting, health and safety, and other legal requirements.
Vital interests, in a medical or safety emergency.
Where we process health-related information such as an allergy or accessibility need, we do so with your explicit consent, which you give by submitting the request to us.
5. Voice, Audio, and Transcript Information
This Section is specific to VapiCon. Because VapiCon is a voice AI conference, your speech may be captured in ways that are unusual for a technology conference, and we want to be clear about it.
5.1. What is captured. The Event includes demonstration areas, sponsor booths, stage demonstrations, workshops, and interactive installations in which you may speak with voice AI systems. If you interact with one, the system may capture and process the audio of your speech, generate a text transcript, and record associated technical metadata such as timestamps, latency, model and provider identifiers, and session identifiers. Audio and transcripts may be displayed on screens visible to other attendees and may be included in livestreams and recordings of the Event.
5.2. Notice and choice. Areas where audio is captured are marked with signage. Capture in these areas is triggered by your choice to interact. If you do not want your voice captured, do not interact with a voice demonstration and do not remain in a marked capture area. You may also ask staff at any demonstration to delete a recording of your interaction, and we will honor the request where the recording is within our control and can be identified.
5.3. How we use it. We use voice audio and transcripts to operate the demonstration you are interacting with, to display results to you, to troubleshoot and monitor system performance during the Event, and to produce and promote the Event where the audio forms part of a recording of a session or demonstration.
5.4. What we do not do. We do not create voiceprints or other biometric templates from Event audio, and we do not use Event audio to uniquely identify you. We do not use facial recognition at the Event. We do not sell Event audio or transcripts. We do not use Event audio or transcripts to train general purpose speech or language models. Where we use Event audio to improve a specific demonstration configuration, we do so only in aggregated or de-identified form.
5.5. California recording law. Audio capture areas are marked and your interaction with a demonstration is voluntary, so conversations in those areas are not confidential communications and you consent to their recording. This consent is given for purposes of California Penal Code sections 630 through 638 and comparable laws of other jurisdictions. This is also addressed in Section 9.2 of the VapiCon 2026 Terms and Conditions.
5.6. Do not disclose sensitive information. Voice demonstrations are demonstration environments. Do not speak or provide to them any confidential, proprietary, personal, regulated, or otherwise sensitive information, including customer data, health information, financial account information, government identifiers, or credentials.
5.7. Third party demonstrations. Sponsors and other third parties operate their own demonstrations and are independent controllers and businesses with respect to any audio, transcripts, or other information they collect. Their practices are their own, and you should review their notices before interacting. See Section 8.
5.8. Retention. Audio recordings from demonstration areas are deleted within thirty (30) days after the Event, except where the audio forms part of a session recording we publish, is needed to investigate a safety or Code of Conduct incident, or must be retained to establish, exercise, or defend a legal claim. Transcripts retained for troubleshooting are de-identified within thirty (30) days after the Event.
6. Photography, Video, and Recordings
6.1. We and our vendors photograph, film, livestream, and record the Event. Your image, likeness, and voice may be captured, including in sessions, in the expo and demonstration areas, at receptions, and in crowd and background footage. We use these recordings to document, produce, promote, and share the Event and our business, as described in Section 12 of the VapiCon 2026 Terms and Conditions, where you also grant us the associated license and release.
6.2. If you would prefer not to appear in recordings we produce, visit the registration desk on arrival to request an opt-out lanyard. We will use reasonable efforts to respect the request in recordings we produce. We cannot guarantee exclusion from incidental crowd or background capture, and we do not control capture by other attendees, sponsors, exhibitors, or media.
6.3. If you are in the European Economic Area or the United Kingdom, we process crowd and general Event imagery on the basis of our legitimate interest in documenting and promoting the Event, and we rely on your consent where you are individually featured.
6.4. Once a recording is made public, third parties may retain, use, and distribute it, and we have no control over that use.
7. Badge Scanning and Sponsor Lead Retrieval
7.1. Your badge contains a code that, when scanned, transmits your registration information, which may include your name, employer, job title, and email address, to the party performing the scan.
7.2. Badge scanning by sponsors and exhibitors is entirely voluntary and is controlled by you. Information is transmitted only if you allow your badge to be scanned or you scan your badge yourself. If you do not want a sponsor to receive your information, decline the scan. This is the primary way your information reaches sponsors.
7.3. When you allow a scan, the sponsor or exhibitor becomes an independent controller and business with respect to your information and may contact you under its own privacy policy. We are not responsible for a sponsor's privacy practices. Direct questions and deletion requests about information a sponsor collected to that sponsor.
7.4. We do not sell or license attendee lists. We provide sponsors with aggregate, non-identifying reporting about Event attendance and booth traffic. We share identifiable attendee information with a sponsor only where you have allowed a badge scan or have otherwise opted in during registration.
7.5. California disclosure. Transmitting your registration information to a sponsor when you allow a badge scan, and any use of advertising cookies described in Section 12, may constitute a "sale" or a "sharing for cross context behavioral advertising" under the California Consumer Privacy Act, and may constitute targeted advertising or a sale under other state privacy laws, even though we receive no money for it. In the twelve months preceding the date of this Privacy Policy, the categories of personal information we may sell or share in this sense are identifiers, contact information, professional information, and internet and device information, and the categories of recipients are Event sponsors and exhibitors and advertising and analytics providers. You can control this by declining badge scans, by managing your cookie preferences, and by submitting an opt-out request as described in Section 13. We do not knowingly sell or share the personal information of consumers under 16 years of age.
8. How We Disclose Personal Information
We disclose personal information to:
Service providers and processors, including the Producer, our ticketing and registration platform, payment processor, badge and check in vendor, Event app provider, email and marketing platform, analytics providers, photographers and video production vendors, caterers, security contractors, and cloud hosting providers, in each case under contract and only to provide services to us.
The Venue Operator, for access, safety, security, and emergency response. The Venue Operator may also operate its own closed circuit television and security systems under its own policies.
Sponsors and exhibitors, where you allow a badge scan or otherwise opt in, as described in Section 7.
Other participants, where you choose to publish a profile, connect, or message through an Event app or networking platform, and to the extent your name and employer appear on your badge and are visible to others at the Event.
Emergency and medical responders, where necessary for your safety or the safety of others.
Legal and safety recipients, including law enforcement, regulators, courts, and our legal and professional advisers, where we believe disclosure is required by law or legal process, or is necessary to investigate an incident, enforce our terms, or protect the rights, property, or safety of any person.
Acquirers, in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality protections.
We do not disclose personal information to any other third party for that party's own marketing purposes without your consent.
9. Retention
We retain personal information only for as long as necessary for the purposes described in this Privacy Policy, and then delete or de-identify it. In general:
Registration, attendance, and Event app records are retained for twenty-four (24) months after the Event to administer future events and to respond to inquiries.
Transaction and payment records are retained for seven (7) years to meet tax and accounting obligations.
Demonstration audio and transcripts are retained as described in Section 5.8.
Accessibility and dietary information is deleted within thirty (30) days after the Event.
Marketing contact information is retained until you unsubscribe or ask us to delete it.
Photographs, video, and published session recordings may be retained indefinitely as part of our archive and marketing library, consistent with the license granted in the Terms and Conditions.
Safety, security, and Code of Conduct incident records are retained for the period necessary to resolve the matter and for the applicable limitations period.
10.Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, and destruction, including access controls, encryption in transit, vendor diligence, and contractual security commitments from our service providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Do not transmit sensitive information over Event Wi-Fi, which is an open, unsecured network.
11. International Transfers
The Event takes place in the United States and we and our service providers are located in or process information in the United States. If you are located outside the United States, your personal information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate. You may request a copy of the relevant safeguards by contacting us at privacy@vapi.ai.
12. Cookies and Similar Technologies
12.1. The Event website and Event app use cookies, pixels, tags, software development kits, and similar technologies. Strictly necessary technologies are used to operate the site, keep you signed in, secure the checkout, and remember your preferences. Analytics technologies help us understand how the site and app are used. Advertising technologies may be used to measure and target promotion of the Event and of Vapi products.
12.2. Where required by law, we obtain consent for non-essential cookies through a consent banner, and you can change your choices at any time through the cookie preferences link on the Event website. You can also configure your browser to refuse cookies, though parts of the site may not function properly if you do.
12.3. We honor the Global Privacy Control and other recognized opt-out preference signals as a valid request to opt out of sale and sharing for the browser that transmits the signal.
12.4. If the Event app is provided by a third party platform, that platform collects information under its own privacy policy, which we will identify on the app and on the Event website. Such platforms typically collect your profile information, general location inferred from IP address, device information, and usage information.
12.5. Bluetooth, RFID, and similar proximity technologies may be used for badge scanning and session check in. We do not use these technologies to track your location outside the Venue, and we do not track your location after the Event ends.
13. Your Privacy Rights and Choices
13.1. Everyone
You can unsubscribe from marketing email at any time using the link in any marketing message, decline badge scans, request an opt-out lanyard for photography, decline to interact with voice demonstrations, and manage cookie preferences on the Event website. You may also contact us at privacy@vapi.ai with any request or question.
13.2. California residents
Subject to verification and to exceptions under the California Consumer Privacy Act, you have the right to know the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of recipients; the right to delete personal information we have collected from you; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of your personal information; the right to limit the use and disclosure of sensitive personal information; and the right not to receive discriminatory treatment for exercising these rights. We do not use or disclose sensitive personal information for purposes that require us to offer a right to limit, but you may still contact us to discuss your preferences.
You may exercise these rights by emailing privacy@vapi.ai with the subject line "California Privacy Request," or by using the "Do Not Sell or Share My Personal Information" link on the Event website. You may designate an authorized agent to submit a request on your behalf, in which case we will require proof of the agent's authority and may require you to verify your identity directly.
13.3. Residents of other United States states
If you reside in a state with a comprehensive privacy law, including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others, you may have rights to access, correct, delete, and obtain a portable copy of your personal data, to opt out of targeted advertising, sale, and certain profiling, and to appeal a decision we make on your request. To appeal, reply to our response or write to privacy@vapi.ai with the subject line "Privacy Appeal." If your appeal is denied, you may contact your state attorney general.
13.4. European Economic Area, United Kingdom, and Switzerland
You have the right to access your personal data, to rectification, to erasure, to restriction of processing, to data portability, to object to processing carried out on the basis of legitimate interests or for direct marketing, and to withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority, and in the United Kingdom with the Information Commissioner's Office.
13.5. How we handle requests
We will acknowledge your request promptly and respond within the period required by applicable law, generally forty-five (45) days for United States state privacy requests and one (1) month for requests under European and United Kingdom law, in each case subject to permitted extensions. We will take reasonable steps to verify your identity before acting on a request, and we may decline a request where an exception applies, in which case we will explain why. Exercising your rights is free unless a request is manifestly unfounded or excessive.
14. Children
The Event is intended for professional audiences and is restricted to persons who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18, and we do not knowingly sell or share the personal information of consumers under 16. If you believe a person under 18 has provided us with personal information, contact us at privacy@vapi.ai and we will delete it.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version at vapicon.ai/privacy and update the "Last updated" date above. If a change is material, we will provide additional notice, such as by email to registered attendees or a prominent notice on the Event website. Please review this Privacy Policy periodically.
16. Contact Us
Questions, requests, and complaints about this Privacy Policy or our handling of personal information: privacy@vapi.ai
General Event questions: vapicon@vapi.ai
If you are in the European Economic Area or the United Kingdom and wish to contact us about this Privacy Policy, please write to privacy@vapi.ai and mark your message for the attention of our data protection contact