Privacy Policy
This Privacy Policy explains how Reeguez Rocks and its event organizer ("we," "us," or "our") collect, use, disclose, and retain information when you visit our website, buy or transfer a ticket, use a prior crew-program status link, participate as an affiliate, attend the event, or appear in event photography or recordings.
Information We Collect
We collect information you provide directly to us, including:
- Purchases and attendance: Email address; any optional name you choose to provide; order and Stripe session identifiers; ticket and add-on selections; the versioned advance-presale acknowledgment attached to an order; admission codes; transfers; and check-in status. An optional name is not newsletter enrollment.
- Payments: Stripe processes ticket, refund, affiliate payout-account information, and any retained prior crew-deposit record. Organizer-issued order refunds return through Stripe to the original payment method. We receive transaction status and identifiers but do not store full card or bank-account numbers.
- Newsletter: Email address and any optional name you submit. Buying a ticket does not automatically enroll you in marketing email.
- Affiliates: Name, email, referral identifier, completed referrals, commission balance, login credentials in protected form, public-display preference, and Stripe Connect status.
- Prior crew-program records: For people who previously applied, name, email, phone, application statement, skills, emergency-contact name and phone, application and shift status, deposit status, and internal coordinator notes. The former program is permanently closed; no new applications or deposits are accepted.
- Ticket transfers: Current holder email, recipient name and email, one-time verification records, and transfer history needed to invalidate the prior admission code and support the new holder. A transfer record changes only the admission credential holder; it does not reassign the purchase order, add-ons, payment method, or refund rights.
- Event media: Photographs and video or audio recordings made in event spaces may include your likeness, voice, and participation. We do not use those recordings to create facial-recognition or other biometric identifiers.
- Technical and security information: IP address, browser or device information, request time, route, response status, and similar server-log data used to operate and protect the service.
How We Use Your Information
- Process ticket purchases and send confirmation emails
- Deliver admission credentials, process transfers and check-in, prevent duplicate use, and provide customer support
- Send operational event messages; send promotional email only when you separately subscribe
- Reconcile prior crew-program records, deposits, status requests, and refunds
- Operate affiliate accounts, attribute eligible referrals, calculate commissions, and support payout onboarding
- Document the event and create recaps, social posts, and materials promoting Reeguez Rocks
- Secure, troubleshoot, audit, and improve our website and services
- Respond to your questions and requests
Information Sharing
We do not sell your personal information. We may share your information with:
- Service providers: Stripe for payments and Connect onboarding, and Amazon Web Services for hosting, storage, logging, and transactional email. Other vendors are used only as needed to operate the event.
- Event operations: Authorized gate, safety, crew-record reconciliation, venue, and customer-support personnel receive only the information needed for their duties.
- Transfers you request: A ticket recipient receives the new admission credential and transfer details; the sender receives confirmation. The recipient does not receive the original purchaser's payment details, add-on rights, or order-refund rights.
- Published event media: Selected event photographs and recordings may appear on our website, social channels, recaps, press materials, or future event promotions. Public media can be viewed, downloaded, or reshared by others. We review media selected for publication and remove embedded precise-location metadata.
- Legal Requirements: When required by law or to protect our rights
Browser Storage and Operational Data
The public site does not load behavioral analytics, advertising pixels, session replay, or third-party web fonts. Referral codes from shared ticket links are used only on the current ticket page and are not stored between visits or counted as page views. Paid orders remain the source of truth for referral credit and completed sales.
Private admin and affiliate sessions use session storage and end when that browser tab or session is closed.
Authorized gate-scanner devices use local storage for a pseudonymous device identifier, an offline admission manifest containing hashed admission-code fingerprints, an encrypted offline password verifier, unsynced check-in timestamps, and conflict records. The recent-scan screen may display a submitted admission code in memory during the current scanner session; that display history is cleared when the operator signs out or the page reloads. Scanner storage is used only for admission operations and is not used for marketing.
Retention and Security
We keep information only as long as reasonably needed for event operations, safety, customer service, accounting, dispute resolution, and legal obligations. Our current retention schedule is:
- Security, API-access, and application logs are generally retained for 90 days.
- Newsletter signup records and their current encrypted export are eligible for automatic deletion after two years, or earlier when you unsubscribe or request deletion. Signing up again starts a new period.
- Active affiliate records remain while the relationship is active. Deactivated affiliate records are eligible for automatic deletion after seven years.
- One-time ticket-transfer verification records expire after 10 minutes. Completed transfer and current-holder records are eligible for automatic deletion after two years; the underlying financial order remains subject to the accounting period.
- Administrative mutation-audit records are eligible for automatic deletion after seven years.
- On an authorized scanner device, an offline admission manifest expires after 12 hours, its encrypted login verifier expires within 24 hours, and synchronized conflict records are removed after 30 days. Unsynced check-in fingerprints remain until the server acknowledges them so an offline admission is not lost. The pseudonymous scanner-device identifier remains until scanner site data is cleared.
- Expired or payment-failed checkout records are eligible for automatic deletion after 90 days. Active or reconcilable reservations are not deleted while their payment state is unresolved.
- Completed transaction, refund, dispute, and related payment-lookup records are eligible for automatic deletion after seven years from their latest relevant lifecycle event, unless a longer legal hold or recordkeeping duty applies.
- We no longer request or accept ZIP codes. Older order or newsletter records may retain a ZIP code provided before August 25, 2026 until that record reaches its normal deletion date.
- Prior crew-program records are retained only as needed to finish deposit, accounting, safety, or dispute obligations.
- Event media selected for publication or the historical event archive may remain available without a fixed end date. Unpublished working media is retained only while useful for event documentation and production.
Automatic deletion systems may take additional time to finish removing an eligible record from active storage and protected backups. We use access controls, encryption, versioned backups, and limited administrative access, but no online system can be guaranteed completely secure.
Your Choices and Requests
You may unsubscribe from promotional email at any time and may ask to access, correct, or delete information associated with you. You may also ask us to review published event media in which you are identifiable. Some records or media may need to be retained for transactions, safety, fraud prevention, legal compliance, or overriding public-interest reasons. Affiliate public display is opt-in and can be turned off from the affiliate dashboard.
Your Rights
To make a privacy request, email reeguezrocks@gmail.com. We may need to verify your identity before acting on a request. We do not sell personal information.
Age Restriction
The event and its application programs are for adults age 21 and older. We do not knowingly collect information through these services from anyone under 21.
Contact Us
For questions about this Privacy Policy, contact us at: reeguezrocks@gmail.com
Last updated: August 25, 2026