Privacy Policy

Last updated: June 2026 · GDPR / PIPEDA / POPIA compliant

1. Data Controller

BoothPass (hereinafter "we") is the data controller for your personal data. DPO contact: privacy@boothpass.live

2. Data Collected

Depending on your profile, we collect the following data:
• All users : name, email address, profile photo (via Google OAuth or Magic Link).
• DJs / Live artists : stage name, discipline (DJ, saxophone, piano, vocals…), city, genres/styles, rate, availability, social links, audio/video samples.
• Event staff : first name, last name, roles, city, languages, years of experience.
• Agencies : company name, company number, province, service types, cities covered, public contact information, insurance information.
• Decoration : studio name, specialties, city, price range, portfolio photos, payout details.
• Organizers : history of events created, booking requests, agency requests.
• Payments : collected exclusively by Stripe (we do not have access to banking data).
• Device : camera access is used only to scan tickets (QR codes) and to add photos you choose; no image is captured without your action. Sign-in available via Google or Apple (identifier provided by these services).
• Notifications : push notification token (mobile app) to send you booking, payment and follow-up alerts.
• Navigation : pages visited, detected region, preferred language (anonymous analytics).

3. Purposes of Processing

Your data is used for: account creation and management, processing bookings and ticket purchases, sending QR tickets by email, connecting DJs/organizers/agencies/staff, sending quotes and mission notifications, improving the platform (anonymous analytics), verifying agencies (legal compliance), and accounting and tax obligations.

4. Legal Basis (GDPR — European users)

Processing is based on contract performance (Article 6.1.b GDPR) for essential features, and on your consent (Article 6.1.a) for marketing communications. You may withdraw your consent at any time without affecting the lawfulness of prior processing.

5. Data Retention

Your account data is retained as long as your account is active. Upon deletion, personally identifiable data is anonymized within 30 days (email is replaced with a random identifier). Accounting data (invoices, transactions) is retained for 7 years as required by law. Public profiles (DJs, agencies, staff) are removed from display immediately after account deletion.

6. Data Sharing

We never sell your data. It may be shared with: Stripe (payments — stripe.com/privacy), Resend (transactional emails), Supabase (database hosting, EU/US servers), Anthropic (Vibe Match AI — anonymized data only). For agencies, the legal information entered (company number, insurance) may be verified via public registries. All our providers comply with GDPR.

7. Your Rights

In accordance with the GDPR (EU users) and PIPEDA (Canadian users), you have the following rights: access to your data, rectification, erasure ("right to be forgotten"), portability, objection to processing. To exercise these rights: privacy@boothpass.live. Response time: maximum 30 days. Upon account deletion, your public profiles (DJ, agency, staff) are also deleted.

8. Cookies

We use only strictly necessary cookies for operation (authentication session, region and language preferences). No advertising or third-party tracking cookies are used. No consent is required for these essential cookies (ePrivacy Directive, Article 5.3).

9. International Transfers

Your data may be processed in the United States (Stripe, Anthropic, Resend) under the EU-US Data Privacy Framework. Appropriate safeguards (standard contractual clauses) are in place to ensure the protection of your data.

10. Security

Your data is hosted at Supabase (encrypted PostgreSQL, restricted access). Passwords are not used — authentication is done exclusively via Google OAuth or single-use magic links. Administrator access is protected by strong authentication and logged.

11. Contact and Complaint

BoothPass DPO: privacy@boothpass.live. If you believe your rights are not being respected, you may file a complaint with the CNIL (France), the ICO (UK), or the Office of the Privacy Commissioner (Canada).