Who we are
Our website is operated by Greybar Simulations LLC (“we,” “us,” or “our”).
- Website: https://prisonlockdown.com
- Privacy contact: [email protected]
This site runs on WordPress and includes membership, event registration, and (when enabled) invoicing features described below.
What personal data we collect
Account and membership profile
When you register or maintain a member account, we may collect:
- Email address and password (password stored by WordPress in hashed form)
- Username and display name / nickname
- Legal first and last name (used for membership, agreements, and billing identity; not shown publicly as a public profile field)
- Postal address (street, city, state/province, postal code, country)
- Cell phone number
- Instant-messaging handle and type
- Time zone
- Optional interests and social-media handles
- Optional clothing sizes (e.g. shirt, pants, shoe) for event logistics
- Profile photo you upload
Health-related and accommodation information (optional)
You may optionally provide:
- Dietary restrictions
- Allergies
- Medical accommodations
We use this information only to support event safety and accommodations. Access is limited to site administrators and staff roles that manage members and events.
Emergency contacts
We collect emergency-contact name, phone number, and relationship. This is information about a third party that you provide so we can reach someone if needed in connection with events or membership. Please only share contacts who expect you may list them for this purpose.
Event applications and attendance
When you apply to or participate in events, we may process:
- Event and role selections
- Add-on / merchandise selections and quantities
- Application status (e.g. pending, accepted, declined, waitlisted, cancelled)
- Typed legal-name acknowledgements of event agreements or policies (versioned agreement text shown at apply time)
- Admission / ticket records associated with your application
Vetting and membership review
New members may go through a review (vetting) process. Administrators and designated reviewers may see your profile and application-related information as part of that review.
Communications we send you
We may email you about your account and events, including application decisions, ticket readiness, payment-due reminders, and similar transactional messages. Those emails are sent to the address on your WordPress user account.
Media you upload
If you upload images (including a profile photo), avoid including embedded location data (EXIF GPS). Other people who can access the image may be able to extract location data from it.
WordPress core (standard platform data)
Independent of membership features, WordPress itself may process:
- Comments (if comments are enabled on any content): the data shown in the comment form, plus your IP address and browser user-agent string to help with spam detection. An anonymized hash of your email may be sent to the Gravatar service to check for a profile image; see Automattic’s privacy policy. Approved comments and your avatar (if any) are visible publicly with the comment.
- Password reset: if you request a password reset, your IP address may be included in the reset email.
- Spam checks: visitor comments or similar submissions may be checked through an automated spam-detection service (for example Akismet, if enabled).
- Embedded content: pages or posts may include embeds (videos, images, etc.) from other sites. Those third parties may set their own cookies and collect data as if you visited them directly.
If a feature above is not used on this site (for example, public comments are disabled), that subsection does not apply in practice—but WordPress may still retain the capability until disabled by administrators.
Payment information
We do not store credit card numbers, bank account / ACH details, or similar payment credentials on this website. When you pay an invoice, card or bank payment details are entered with and processed by Stripe (often via a payment flow linked from our invoicing provider). Stripe’s handling of that data is governed by Stripe’s privacy policy.
Cookies
WordPress uses cookies for core site operation:
- If you leave a comment and opt in, cookies may store your name, email, and website for about one year so you do not have to re-enter them.
- Visiting the login page sets a temporary cookie to test whether your browser accepts cookies; it contains no personal data and is discarded when you close the browser.
- When you log in, cookies store login state and screen-display choices. Login cookies typically last two days; screen-option cookies about a year. If you select “Remember Me,” login may persist for two weeks. Logging out removes login cookies.
- If you edit or publish content in the admin area, a cookie may store the ID of the post you edited (no personal data); it expires after about one day.
Stripe and our invoicing providers may set their own cookies or similar technologies on payment pages they host. We do not use membership features to set additional tracking cookies beyond what WordPress and any third-party embeds or analytics you enable may set. If we add analytics or marketing cookies later, we will update this policy.
How we use your data
We use personal data to:
- Create and administer your account
- Operate membership, vetting, events, applications, and tickets
- Communicate with you about those activities
- Improve safety and accommodations at events (including optional dietary, allergy, and medical information)
- Reach your emergency contact when needed
- Generate and collect payment for event-related charges when invoicing is enabled
- Maintain security, prevent abuse, and meet legal or administrative obligations
Who can see your data
Site staff
Website administrators and other authorized staff can view and edit member profiles and related records as needed to run the community.
Other members (opt-in sharing)
For event attendee directories, contact details are shown to other accepted attendees only if you opt in. You can control sharing of:
- Phone
- Approximate location (city / region / country from your profile)
- Instant-messaging handle
- Interests
- Profile photo
If you do not opt in, others will not see those fields via the directory. Your display name / nickname may still appear as a participant where the directory lists attendees.
Legal name and full street address are not treated as public directory fields.
Billing and payment providers (when invoicing is enabled)
If we enable online invoicing, we sync the minimum customer and invoice data needed to bill you through QuickBooks Online (Intuit) and/or Xero (one active accounting provider at a time). Stripe processes card and ACH (and similar) payments so invoices can be paid. These services act as processors for accounting and payment collection.
Customer / contact record we send so an invoice can be issued and paid typically includes:
- Legal (or account) first and last name, and a display/contact name
- Email address (invoice delivery and customer matching)
- Phone number
- Billing address (street, city, state/province, postal code, country)
Invoice / payment record typically includes:
- Line items and amounts for event fees and selected add-ons
- Invoice status and payment status (e.g. unpaid, paid, voided)
- Dates and identifiers linking the invoice to your customer/contact in that system
- Emailing of the invoice to your address on file (via the billing provider’s send features, when used)
We do not send dietary, allergy, medical, emergency-contact, social-media, interests, photo, or event-vetting notes to QuickBooks, Xero, or Stripe as part of customer/invoice sync from this site.
We do not store credit card or ACH information on this website. Payment credentials you enter are handled by Stripe (and, where applicable, the invoicing provider’s payment pages) under their own terms.
See also:
Other service providers
We may use hosting, email delivery, spam filtering, and similar infrastructure providers who process data only to operate the site. Embedded third-party content is governed by those third parties’ policies.
How long we retain your data
- Member profiles and accounts: retained while your membership is active and afterward as needed for community records, safety, and legal/administrative purposes, unless you successfully request erasure (see below).
- Event applications, tickets, and agreement acknowledgements: retained as part of event and membership history; duration may extend beyond a single event for operational and legal reasons.
- Billing and invoice records: retained as required for accounting, tax, and dispute purposes (often several years), including copies held in QuickBooks Online or Xero and payment records held by Stripe.
- WordPress comments (if any): retained indefinitely by default so follow-up comments can be recognized.
- Logs and security data: retained for a limited period for troubleshooting and abuse prevention.
Exact periods may vary; contact us if you need specifics for your account.
What rights you have over your data
Depending on where you live, you may have rights to access, correct, export, or delete personal data we hold about you, and to object to or restrict certain processing.
On this site:
- If you have an account, you can view and update much of your profile information while logged in. Usernames generally cannot be changed.
- You may request an export of personal data we hold about you, or request erasure of personal data we hold about you, by contacting [email protected].
Erasure requests may be limited where we must keep data for administrative, legal, security, accounting, or contractual reasons (for example invoice history or signed agreement records). Data already held by QuickBooks Online, Xero, or Stripe may also need to be addressed in those systems.
WordPress also provides tools for administrators to export or erase personal data associated with an email address (Settings → Privacy / Tools), which we may use when handling requests.
Where your data is stored and sent
Your data is stored on our website’s hosting environment and in WordPress’s database. It may be transferred to:
- QuickBooks Online and/or Xero (and their subprocessors), when billing is enabled
- Stripe (and its subprocessors), when you pay by card, ACH, or similar methods
- Email and spam-filtering providers
- Gravatar / Automattic, if comment avatars are used
- Other embedded third-party sites you interact with through embeds
Those providers may process data in the United States or other countries. Where required, we rely on appropriate safeguards for international transfers.
Age requirement
Membership and events on this site are for adults only. You must be at least 18 years old to participate. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected personal data from someone under 18, we will take steps to delete it.
Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the site after changes means you accept the revised policy where permitted by law.
Contact
Questions or privacy requests: [email protected]
