Legal

Privacy Policy

Last updated: July 31, 2026.

FestAxis provides software for planning, selling, staffing, operating, and reporting on events. This Privacy Policy explains how FestAxis collects, uses, discloses, stores, and otherwise processes personal information in connection with festaxis.com, organizer workspaces, event microsites, ticketing and registration pages, partner and vendor portals, credential and access-control tools, field applications, support channels, and related products and services (collectively, the “Service”).

In this policy, “FestAxis,” “we,” “us,” and “our” refer to the operator of the Service and any successor that provides it. “Organizer” means the event owner, producer, association, nonprofit, government body, venue, promoter, or other organization that configures an event or workspace. “User” means any person who accesses the Service, including organizers, staff, volunteers, partners, vendors, sponsors, contractors, applicants, attendees, ticket purchasers, and public visitors.

1. Scope and privacy roles

FestAxis may act in more than one privacy role. The role depends on who decides why and how personal information is processed.

FestAxis as an independent business or controller

FestAxis generally determines the purposes and means of processing for account administration, subscription and billing records, platform security, fraud prevention, support, product operations, legal compliance, marketing-site analytics after consent, and communications about the Service.

FestAxis as a service provider or processor for an Organizer

When an Organizer configures forms, ticketing, applications, credentialing, partner workflows, staff assignments, site plans, communications, reports, or other event operations, the Organizer generally determines why the event data is collected and how it is used. FestAxis processes that information on the Organizer’s behalf and according to the Organizer’s instructions, the applicable agreement, and law.

Organizers are responsible for their event-specific privacy notices, lawful collection instructions, consent language, waivers, refund rules, eligibility requirements, accessibility processes, minor-participation processes, marketing choices, retention settings, and authorized-user access. An Organizer must not use FestAxis to collect information it does not reasonably need for a legitimate event purpose.

Third-party services

This policy does not govern the independent privacy practices of an Organizer, payment processor, event supplier, embedded map or media provider, social network, external website, or other third party. Their own terms and privacy notices apply when they independently control personal information.

2. Personal information we collect

The information collected depends on the features used, the role of the person, and the choices made by the Organizer.

Account, identity, and organization information

This may include name, email address, phone number, username, password hash, multi-factor authentication settings, profile image, job title, organization name, organization role, saved preferences, time zone, account status, invitation records, and acceptance of legal or security terms. We do not store plaintext account passwords.

Event and workspace information

This may include event names, dates, locations, contact details, public descriptions, schedules, maps, site plans, venue details, operational notes, capacity settings, staff assignments, branding choices, logos, images, custom domains, workflows, forms, messages, and records created by authorized users.

Ticketing, registration, and transaction information

This may include purchaser and attendee names, contact details, ticket type, order number, price, discounts, add-ons, parking or camping selections, refund status, transaction timestamps, delivery status, check-in or redemption records, and information entered into Organizer-configured registration questions. Payment processors may return transaction identifiers, payment status, card brand, last four digits, billing country, dispute information, or fraud signals.

Payments are processed by Stripe or another approved payment processor. FestAxis does not intentionally receive or store full payment-card numbers, CVV/CVC values, magnetic-stripe data, or equivalent sensitive authentication data.

Partner, vendor, exhibitor, sponsor, applicant, and contractor information

This may include business and contact information, applications, products or services offered, booth or campsite preferences, permits, licenses, tax or payment records, certificates of insurance, contracts, signatures, invoices, messages, documents, team members, vehicle information, location assignments, compliance status, and Organizer review notes.

Staff, volunteer, credential, and access-control information

This may include names, photos, contact information, roles, departments, shifts, assignments, credential types, credential identifiers, access zones, scan and check-in history, station identifiers, denial reasons, manual overrides, incident associations, and audit records showing who issued, edited, revoked, or scanned a credential.

Camera, barcode, QR code, and image-upload information

Scanner pages may request camera permission so a device can read a barcode or QR code. Live camera frames are ordinarily processed in the browser for code detection and are not intentionally uploaded or retained by FestAxis merely because the camera is open. A decoded ticket or credential value, scan result, device/station context, and audit information may be sent to the Service to validate and record the scan.

If a user deliberately uploads an image for code recognition, profile use, event content, incident evidence, documentation, or another workflow, the uploaded file is processed and retained according to that workflow and the Organizer’s instructions. Device and browser permission settings control camera access.

Site Planner, maps, and location information

This may include event addresses, map centers, drawn shapes, object placements, routes, zones, parking layouts, coordinates, measurements, imported map data, and equipment estimates. FestAxis does not need continuous personal-device location tracking to provide ordinary Site Planner functionality. When a feature requests device location, the purpose and browser permission will be presented at that time.

Communications and content

This may include emails, in-platform messages, announcements, form responses, survey responses, feedback, support requests, attachments, notification preferences, delivery events, and records showing when communications were created, queued, sent, opened, failed, or responded to where supported.

Support, security, diagnostics, and device information

This may include IP address, approximate network location, browser and operating-system details, device type, referring page, session identifiers, authentication events, failed sign-ins, multi-factor events, request paths, timestamps, error codes, trace identifiers, rate-limit events, administrative actions, audit logs, service-health data, and records provided during support or security investigations.

Cookies, preferences, and analytics

We use essential cookies and similar technologies for authentication, checkout, fraud prevention, security, workflow state, load balancing, and saved preferences. On public marketing pages, optional analytics may be activated only after the visitor accepts analytics cookies where the consent mechanism is presented.

Inferences, aggregated information, and de-identified information

We may derive operational indicators such as account risk signals, probable duplicate records, usage counts, delivery reliability, capacity trends, or feature-performance statistics. We may aggregate or de-identify information so it no longer reasonably identifies a person. We do not attempt to re-identify information maintained as de-identified except to test the effectiveness of de-identification controls or as required by law.

3. Sources of information

We collect information from:

4. How we use personal information

We may use personal information to:

Where applicable law requires a legal basis, processing may rely on performance of a contract, steps requested before entering a contract, legitimate interests in operating and securing the Service, compliance with legal obligations, consent, protection of vital interests, or another lawful basis. Consent may be withdrawn where processing depends on consent, but withdrawal does not affect processing already lawfully completed.

FestAxis does not use event-submitted personal information to train general-purpose artificial intelligence models. Product features that use automated assistance must remain scoped to the requested function and the permissions of the requesting user.

5. How information is used for different roles

Event owners and Organizers

We use Organizer information to establish the workspace, verify administrative authority, provide billing and support, enforce plan usage allowances, secure the account, communicate service changes, and maintain business and legal records. Organizer users can see data for the organizations and events to which they have been granted access. FestAxis applies organization and event scoping, but each Organizer remains responsible for assigning the minimum permissions reasonably needed.

Partners, vendors, exhibitors, sponsors, and contractors

Information submitted through an application or portal is generally made available to the Organizer that requested it and to authorized members of that Organizer’s team. An Organizer may use it to evaluate participation, issue assignments, coordinate logistics, request documents, process payments, communicate requirements, manage contracts, and operate the event. A partner organization may separately control information about its own team members.

Staff, volunteers, scanners, and field operators

Information is used to assign work, manage schedules and permissions, operate gates or checkpoints, record actions, coordinate incidents, maintain accountability, and protect event operations. Administrative and scan actions may be attributable to the signed-in user, station, event, device session, date, and time. Users must not share credentials or use another person’s account.

Attendees, ticket purchasers, registrants, and public visitors

Information is used to complete requested purchases or registrations, deliver tickets and confirmations, answer support questions, validate admission, communicate event information, process refunds or disputes, and support safety and accessibility workflows configured by the Organizer. The Organizer may use contact information for event communications according to the notices and choices it provides.

6. How we disclose information

We may disclose personal information in the following circumstances:

To the applicable Organizer and authorized participants

Information submitted to an event may be disclosed to the Organizer, its authorized staff, its contracted operators, and relevant partners when needed to administer the event. For example, a campsite assignment may be available to camping staff, an access credential to gate staff, a production requirement to the assigned supplier, or an incident record to authorized safety personnel. Access is intended to follow role and event boundaries rather than making every record visible to every participant.

To service providers and subprocessors

We may use service providers for cloud hosting, storage, content delivery, database services, email and messaging, payment processing, customer support, security, logging, analytics, mapping, document delivery, and other operational functions. They may process information only for contracted services, their legal obligations, and permitted security or abuse-prevention purposes.

For transactions and financial administration

Payment processors, banks, card networks, tax providers, accounting providers, and fraud-prevention partners may receive information necessary to authorize, settle, refund, reconcile, or dispute a transaction.

For legal, safety, and security reasons

We may disclose information when we reasonably believe disclosure is required by law or valid legal process; necessary to protect rights, safety, property, users, events, or the public; necessary to investigate fraud, abuse, security incidents, or prohibited activity; or appropriate to establish, exercise, or defend legal claims. We may notify the affected customer when legally permitted and reasonably practicable.

Business transfers

Information may be disclosed in connection with a merger, financing, acquisition, reorganization, bankruptcy, due-diligence review, sale of assets, or transition of the Service. Any successor will be required to handle personal information consistently with applicable law and the commitments that continue to apply.

At the user’s or Organizer’s direction

We may disclose information when a user or Organizer deliberately exports it, embeds a public directory, sends a message, assigns a partner, enables an integration, publishes a page, or otherwise instructs the Service to share it.

7. No sale of personal information and no behavioral advertising

FestAxis does not sell personal information for monetary consideration. FestAxis does not disclose personal information to advertisers for cross-context behavioral advertising and does not use event-submitted personal information to build third-party advertising profiles.

Nevada consumers may submit a verified do-not-sell request through the privacy request form with the subject line Nevada Do Not Sell Request. Because FestAxis does not sell covered information, a verified request will be recorded and honored if our practices change.

8. Consumer health, accessibility, and sensitive event information

The Service is not a healthcare service and is not intended to maintain medical records. An Organizer may nevertheless configure a form or incident workflow that requests accessibility needs, disability accommodations, allergies, dietary restrictions, emergency contacts, injury details, safety notes, or similar event-participation information. Depending on the jurisdiction and context, some of this information may be considered sensitive or consumer health data.

Such information should be collected only when reasonably necessary for the event purpose, limited to authorized users, and retained no longer than needed. FestAxis processes it to provide the configured workflow, support safety and accommodations, secure the Service, respond to rights requests, comply with law, and protect users. We do not sell consumer health data and do not use geofencing to identify or target people based on visits to healthcare facilities.

Requests concerning this information may be submitted through the privacy request form. When the Organizer controls the record, FestAxis may refer the request to the Organizer or coordinate the response with it.

9. Cookies, consent, and analytics

Essential cookies and local-storage values support authentication, security, checkout, workflow state, interface preferences, and other functions that cannot reasonably operate without them. Blocking essential technologies may prevent sign-in, checkout, saved preferences, or other features from working.

A first-party preference record may remember whether optional analytics was accepted or declined. Google Analytics or another approved analytics service loads on public marketing pages only after acceptance where consent is presented. If analytics is declined, the analytics tag is not loaded and identifiable analytics cookies are removed where technically accessible. FestAxis disables advertising storage, ad-personalization features, and Google Signals for this use.

Cookie choices can be revisited through Cookie settings in the public footer. Browser controls may also delete or block cookies, but browser controls do not always communicate a legally recognized opt-out signal for every purpose or jurisdiction.

10. Data retention and deletion

We retain information only for as long as reasonably necessary for the purpose collected, the Organizer’s instructions, contractual requirements, security needs, dispute periods, and legal obligations. Retention may vary by record type and event configuration.

Deletion from active systems may not immediately remove information from encrypted backups, disaster-recovery copies, legal holds, or immutable security records. Those copies are isolated from ordinary use and removed through normal rotation or when the retention reason ends. We may retain de-identified information that no longer reasonably identifies a person.

11. Security, tenant boundaries, and access controls

FestAxis maintains administrative, technical, and organizational safeguards designed for the nature of the Service. These include HTTPS/TLS in transit, password hashing, multi-factor authentication options, role-based access control, organization and event scoping, session protections, audit logging, encrypted or access-controlled infrastructure, backups, monitoring, rate limiting, vulnerability management, and incident-response procedures.

Tenant and role controls are intended to prevent one organization or event from accessing another organization’s private records. Authorized Organizer administrators can nevertheless grant broad permissions within their own organization. Organizers must promptly remove access for departed or reassigned users, review privileged roles, and report suspected account compromise.

No transmission, storage, or authentication system is perfectly secure. Users should use unique passwords, protect authentication devices, avoid shared accounts, verify the event context before performing sensitive actions, and report suspicious activity through the security report form.

12. Automated signals and consequential decisions

FestAxis may evaluate account, payment, delivery, authentication, error, and scanner metadata for fraud, abuse, reliability, duplicate detection, and security signals. Temporary protective controls may delay a message, challenge a sign-in, rate-limit activity, or contain a suspected incident.

FestAxis does not use a general-purpose automated system to make final decisions about a person’s admission, employment, vendor selection, volunteer eligibility, legal rights, or access to essential services. Organizers are responsible for their own event decisions and should provide a meaningful review process where a decision has a significant effect.

13. Children and minors

Organizer-side accounts are not directed to children under 13. Organizers may not intentionally create a workflow directed to children under 13 or collect personal information directly from children under 13 through the Service unless FestAxis has expressly approved the workflow in writing and the Organizer has implemented legally sufficient parental notice and consent.

Events may involve minors, and an adult may purchase tickets, register a household, or provide information for a minor. The Organizer is responsible for age-appropriate notices, parent or guardian permissions, waivers, supervision requirements, photo or publicity choices, and any additional protections required for youth activities. A parent or guardian may contact the Organizer or FestAxis regarding information submitted about a minor.

14. Privacy rights and choices

Depending on location and context, a person may have rights to request access, correction, deletion, portability, restriction, objection, appeal, withdrawal of consent, or information about categories of data and recipients. Rights are not absolute and may be limited by identity-verification needs, another person’s rights, security, fraud prevention, legal privilege, transaction records, legal holds, or other lawful exceptions.

Requests may be submitted through the privacy request form. Please identify the event, Organizer, email address, order or application reference, and nature of the request where possible. We may ask for information reasonably necessary to verify identity, authority, and the record involved.

When FestAxis processes information solely for an Organizer, the Organizer generally must decide the request. We may forward the request, direct the person to the Organizer, or assist the Organizer with export, correction, or deletion. Authorized agents must provide evidence of authority, and we may verify the request directly with the person where permitted.

A person may unsubscribe from optional FestAxis marketing email through the message link or contact form. Transactional, security, legal, and requested event communications may still be sent when necessary. Event-marketing preferences controlled by an Organizer should generally be directed to that Organizer.

15. International processing

FestAxis and its service providers may process information in the United States and other locations where they operate. Privacy laws may differ from those in the person’s home jurisdiction. Where required, FestAxis uses contractual, organizational, or other lawful mechanisms intended to protect international transfers.

16. Security incidents

If we confirm a security incident affecting personal information, we will investigate, contain, remediate, preserve appropriate evidence, and provide notifications required by applicable law and contract. Notification timing and content depend on the nature of the incident, the information involved, law-enforcement restrictions, and whether FestAxis or the Organizer has the direct notification obligation.

17. Changes to this policy

We may update this policy to reflect changes in the Service, law, vendors, or privacy practices. The “Last updated” date identifies the current version. For material changes, we may provide notice by posting the updated policy, displaying an in-product notice, emailing account holders, or using another reasonable method. Continued use after the effective date is subject to the updated policy, except where additional consent is required.

18. Contact

Privacy questions and rights requests: privacy request form
Security reports: security report form
General support: support form
Legal questions: legal contact form