Privacy Policy
The short version
Vessa is operated by Vessa Technologies LLC, a Texas limited liability company. This policy covers guests, organizers, door staff and Scouts.
We collect what a ticket needs and nothing else. We do not sell your data, and we do not run ads.
What we collect
If you buy a ticket: your email and your name, and a phone number only if you choose to give one (see text messages). Checkout asks for the first two: your email is how your ticket reaches you, and your name is how the door finds your ticket if your phone dies. If a payment reaches us without a name, we use the name on the card or wallet that paid, and that name goes on your ticket and the organizer’s guest list. Your card number goes to Stripe and never touches us.
If you organize events: your email, your page details, whatever Stripe needs to pay you, and any guest list you upload from another ticketing platform so its names can be checked in at the same door. Those names are used for that night’s door and nothing else: they are never added to a mailing list. If you give us a phone number for the door’s help alert, it is never shown to guests: it exists so somebody can be woken up if the scanner stops.
If you are a Vessa Scout: your name, your city, the answer you give to “how will you find promoters?”, whatever Stripe needs to pay you, and the record of what you have earned and been paid. If somebody referred you to the program, we record who.
If you work a door: the first name you type when you open the door link, so the organizer can see who is on which phone, and a record of the scans that phone made. The name is remembered on that phone so you are not asked again; it is not used for anything else. The guest list the scanner downloads stays on the phone for that night, and the phone clears it after the event.
Automatically: basic request logs; the IP address and browser of a checkout, and of an organizer or Scout accepting their agreement, kept with the order or the acceptance as a fraud and evidence record; a record of when a ticket was scanned at a door; and, in the app, a device token so the phone can receive alerts. To tell people from bots, the site also runs Vercel BotID, which reads signals from your browser for fraud prevention only.
What we never see
Card numbers. Payments go straight to Stripe and we only ever get back a token, the last four digits and, for a ticket bought without a name, the name on the card. Same for organizer bank details and ID documents: those are collected by Stripe, for Stripe.
Why we have it
- To send you your ticket and let you back into it later.
- To let door staff check you in.
- To pay organizers and handle refunds.
- To fight fraud and chargebacks.
- To keep the records tax law requires.
- To send you an organizer’s announcements through Vessa, only if you ticked the box at checkout, and only from that organizer. Every one of those emails has a way to stop them that needs no sign-in. The organizer also receives your name and email directly; see who is responsible for what.
Who else gets it
The organizer of the event you bought a ticket to sees your name, email and which ticket you bought. They need it to run the door. They are responsible for what they do with it after that.
Our service providers: Stripe for payments, Supabase for the database, Vercel for hosting, Resend for email, Twilio for text messages, Sentry for error reporting when it is switched on, and Apple, if you use the organizer app, to deliver a push alert to your phone. Each only gets what it needs to do its job; Sentry in particular is configured not to receive your IP address or request headers, and every error report is stripped of email addresses, phone numbers, ticket codes, sign-in links and any field holding a name before it is sent.
Nobody else. We do not sell or rent personal information, and we do not share it for anyone else’s advertising.
Text messages
If you give us a phone number at checkout, Vessa texts your ticket to it, and updates about that event on the day, like a change of time or place. That is all. We never send marketing texts.
Message and data rates may apply. Reply STOP to any text to opt out, or HELP for help. You can also email hello@vessatickets.com.
We send texts through Twilio. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
How long we keep it
Order and ticket records for seven years, because tax and chargeback rules require it. Scan records for two years. Marketing emails stop the moment you unsubscribe.
Your choices
Delete your account yourself, in Settings. It removes your name, email and phone, takes you off every promoter page, and stops you being able to sign in. It tells you before you confirm whether anything is kept: orders and tickets from nights you ran, and the name you typed when you accepted the organizer agreement, because an acceptance with nobody behind it is not evidence of anything, or the commissions you earned as a Scout, because tax rules require the same seven years of them. Your Scout name and city are replaced with "Deleted Scout" either way.
Bought a ticket and have no account? Go to Delete my data, from Find my tickets, and put in the email you bought with. We send a link to that address, so only its owner can use it, and the link shows exactly what will happen before anything does. It removes your name, email and phone from every order and ticket, the browser and network details recorded at checkout, and your name on any guest list an organizer uploaded, and takes you off every organizer’s mailing list. The orders themselves stay, without your name, for the seven years above: which event, what was paid, any refund, and whether the ticket was scanned. Stripe keeps its own record of the card payment. We keep a one-way fingerprint of the address and the date, as the record that you asked and we did it.
Email hello@vessatickets.com to get a copy of your data or correct it. We will do it within thirty days, except where we are legally required to keep financial records.
If you are in California, the CCPA gives you these rights explicitly, including the right to know what we collect and the right not to be discriminated against for exercising them. We do not sell personal information, so there is nothing to opt out of.
If you are in Texas, the Texas Data Privacy and Security Act gives you rights to know, correct and delete personal data and to opt out of its sale. We do not sell personal data. Email hello@vessatickets.com to exercise any of these rights and we will respond within 45 days.
Children
You must be 18 or over to buy a ticket. Vessa is not for anyone under 13, and we do not knowingly collect anything from them. Individual events set their own age limits.
Cookies
None of these is for advertising, and none of them follows you to another website. Here is every one, who sets it and what it is for.
- sb-bgmxbpighmsicahxyfsk-auth-token, set by us. This is the session cookie that keeps organizers signed in. It may be split across a few numbered cookies of the same name when it is too large for one, which is a detail of how it is stored and not a separate thing. Buyers never get one: you do not need an account to buy a ticket.
- vessa_ref, set by us, and only if you open a Vessa Scout’s referral link. It stores that Scout’s six-character code and nothing else. No identifier for you, and nothing about what you look at. It lasts 90 days and is read once: if you later create an organizer page, we ask you whether that person sent you. It is functional rather than analytical, and declining the question is enough to remove the connection entirely.
- vessa_src, set by us, and only if you arrive on a link that says where it was posted, such as a link shared on social media. It stores that one word, and nothing else: which link you came from. No identifier for you, nothing about what you look at, and it is never read unless you go on to create an organizer page, where it tells us that link brought somebody. It lasts 90 days and the first one wins, so coming back later through a different link does not change it.
- __stripe_mid and __stripe_sid, set by Stripe on our domain when a checkout page loads. Stripe uses them to tell a real buyer from a card tester, which is fraud prevention on the payment itself. Stripe sets its own cookie on its own domain at the same time. We do not read any of them and they are not used to advertise to you. Stripe’s privacy policy covers what it does with them.
- vessa_shell, set by us, and only inside the Vessa Organizer iPhone app. It says “this is the app” so the app opens on your dashboard instead of the home page. It holds no identifier for you and lasts a year.
On a phone that works a door, the scanner also keeps the guest list and the door person’s first name in that phone’s own storage, so the door keeps working without signal. Nothing there is sent anywhere except back to us.
Page counts
We count page views through Vercel Web Analytics, which is run by the company that hosts this site. It records that a page was opened, from roughly where in the world and on what kind of device. It sets no cookie, stores no identifier for you, and cannot follow you to any other website. We use it to see which pages people actually open.
There is no advertising network here, no pixel, and nothing that builds a profile of you. There is no consent banner because there is nothing here that a consent banner would be asked about.
Do Not Track. Nothing here tracks you across other websites, so there is nothing for a Do Not Track signal to switch off, and we do not change behaviour when one is sent.
What a Scout can see about a promoter they referred
Your page name, your city, when you were referred, how many events of yours have finished and settled, the date their earning window on you ends, and what they earned. That is the whole list, and it is the whole of what my_scout_referrals() returns.
There is deliberately no way for a Scout to contact you through Vessa. They are not given your email, your phone number or your handle, and there is no export, no list and no download anywhere in the Scout dashboard. A Scout can see that you exist and cannot see how to reach you.
They do not see your ticket sales, your revenue, your payouts, your guests, your email address or anything about individual events beyond the count. A referral does not entitle anybody to your takings, and the function that answers a Scout’s dashboard returns nothing else. You are asked to confirm a referral before it earns anybody anything, and saying no removes it.
Who is responsible for what
Organizers are independent controllers of their guests’ information. When you buy a ticket, the organizer receives your name, email and ticket type so they can run the door and contact you about their own events. They decide how they use it and are responsible for their own compliance with privacy and marketing law. Their agreement with us requires them to honour an opt-out and forbids them from texting you without your agreement. If you want an organizer to stop contacting you, tell them; their contact details are on your ticket.
Scouts are independent contractors, not Vessa staff. A Scout is a person who introduced an organizer to Vessa and earns a share of our fee for doing so. They do not work for us, they cannot speak for us, and they have no access to guest information of any kind.
Security
Everything is encrypted in transit. Access to the database is limited by row-level rules so an organizer can only reach their own events. No system is perfect. If we ever have a breach that affects your personal information we will tell you without unreasonable delay and within 60 days, as Texas law requires, and we will tell the Texas Attorney General where the law requires that too.
Changes to this policy
When we change this policy we post the new version here and change the date at the top. If a change affects how we use information we already hold, we will tell you by email before it applies.