Your data, on your terms.
We collect data to run live music well and, where you allow it, to build insights the industry will pay for. This page is the plain-language version of exactly what we hold, why, who sees it, and the controls you have. Last updated August 6, 2026.
What We Collect
Account & contact. Your name, email, phone (if you add it), and role (fan, artist, venue, crew). Created when you sign up or buy a ticket.
Purchases & tickets. Orders, amounts, fees, discounts, the shows you bought, check-in records, and resale activity. We need this to deliver and support your tickets.
Coarse location. On requests we record for analytics — page views as well as checkout and demand votes — we may record the city/region/country the request came from (derived at our edge — never your IP address). It powers demand and tour-routing insights, nothing more.
Product usage. Signals about how the product is used (page views, feature usage), so we can improve it. These are tied to a random id stored in your browser that rotates every 90 days — not to your name — and never to your account identity. Turning on Do Not Track stops them entirely.
Why We're Allowed to Hold It
Every meaningful event we record carries a stated basis: transaction (needed to deliver your purchase), legitimate interest (running and securing the platform), marketing (only when you've opted in), or data-sharing (on by default — you can turn it off anytime, and we stop using your data for it going forward). We keep these apart, and we record whether you actually chose: a default is not a decision, and we never present one as if it were.
How We Use It
To sell, deliver, and support tickets; to pay venues, artists, and crew; to prevent fraud and abuse; to send you the alerts and reminders you ask for; and to produce analytics that help venues and artists book smarter shows.
We do not sell ad space against your identity, and we don't let third parties target you inside BandPass.
Your Controls
Export. Download everything tied to your account — profile, orders, tickets, activity, and your data preferences — as JSON or CSV from your data & privacy page.
Delete. Request deletion of your account and associated data; we complete it within 30 days. Upcoming tickets stay valid and refundable.
Opt out. Marketing email is off unless you opt in; the data-sharing program is on by default. Turn either off at any time on your data & privacy page and we stop using your data for that purpose going forward. If your browser sends a Global Privacy Control or Do Not Track signal, we stop recording your on-site browsing — page and event analytics, and the calendar-download signal. That signal does not by itself remove purchases from the data-sharing program — use the toggle above for that.
Depending on where you live (including under GDPR, CCPA, and Colorado's privacy law), you may have additional rights to access, correct, or restrict processing. Email us and we'll honor them.
How Long We Keep It
As long as your account is active, plus the period we're legally required to retain financial records. De-identified analytics may persist after deletion because they no longer identify you.
How We Protect It
Encryption in transit, row-level access controls on our database, scoped access for staff, signed ticket tokens, and audited check-in. Payment details are handled by Stripe and never touch our servers.
Contact
Questions or requests: privacy@thebandpass.com. We reply within 30 days.
This policy describes our current practices and may change as the product evolves; we'll update the date above and, for material changes, notify you. It is provided for transparency and is not legal advice.