Privacy Policy
Last updated: 4 October 2026
Template. Have this reviewed before launch, especially for EU/UK users (GDPR), and list your real subprocessors.
Who is responsible
For Organizer accounts and our website, Passfinch (operated by [YOUR US LLC NAME]) is the controller. For Buyer data collected on an Organizer's booking page, the Organizer is the controller and we process it on their behalf.
What we collect
- Organizers: name, email, password (stored only as a salted hash), event details, Stripe account id.
- Buyers: name, email, optional note, order and ticket details, check-in time. Card details are entered on Stripe and never reach our servers.
- Waitlist: email address and the page you signed up from.
- Technical: IP address and request data for security and rate limiting.
Why
- To provide the service: bookings, tickets, emails, check-in (contract).
- To keep it secure and prevent fraud (legitimate interest).
- To send product updates to waitlist subscribers (consent; unsubscribe any time).
Subprocessors
- Cloudflare (hosting, database, storage, bot protection)
- Stripe (payments, identity verification of Organizers)
- Resend (transactional email)
Cookies
We use one essential cookie to keep Organizers logged in. We do not use advertising cookies. If analytics is added later, it will only run after consent where required.
Retention
Organizer data is kept while the account is open. Order records are kept as long as needed for accounting and legal duties. You can ask us to delete your data.
Your rights
You can ask for access, correction, export or deletion of your data, and object to processing. Email hello@passfinch.com. You can also complain to your data protection authority.
International transfers
Our providers may process data outside your country. We rely on their standard contractual clauses or equivalent safeguards.