Legal
Privacy Policy
How PassTru handles account, event, attendee, visitor, and operational data.
This Privacy Policy explains how PassTru handles account, event, attendee, visitor, and operational data when you use the platform.
Operated by
PassTru
Website
Legal contact
Privacy contact
1. Who We Are
This Privacy Policy applies to the website and application operated by PassTru at https://www.passtru.com.
2. Roles and Relationship
For attendee and Client-uploaded event data, the Client organization is generally the controller or equivalent role. PassTru acts as processor or service provider on the Client's instructions. For account, billing, security, and service-administration data, we may act as controller where required to operate the platform.
3. Information We Collect
- Account data such as name, organization name, slug, email address, and verification state.
- Event and attendee data uploaded by Clients, including custom fields and check-in status.
- Visitor registration, booth-visit, reward, and gamification data where those features are enabled.
- Billing and transaction data related to token purchases.
- Technical, security, analytics, and support data such as logs, device information, request metadata, and diagnostic events.
4. Sources of Personal Data
- Directly from Clients, users, attendees, and visitors who interact with the platform.
- From event organizers who upload attendee or event information.
- From payment, hosting, infrastructure, and email service providers that support the platform.
- Automatically from devices and browsers when the website or app is used.
5. How We Use Personal Data
- To provide and operate the Services.
- To authenticate users and secure accounts.
- To support registration, check-in, portals, visitor flows, and reporting.
- To send transactional emails and manage token balances.
- To measure usage, monitor reliability, investigate incidents, and improve platform performance.
- To maintain logs, detect abuse, improve reliability, and comply with legal obligations.
6. Sharing and Disclosure
We may disclose personal data to service providers and subprocessors that support the platform, including those listed on the Subprocessors page. This may include hosting, payments, transactional email, analytics, and observability providers. We do not sell personal data.
7. Public Content and Event Organizer Responsibility
Some features intentionally make content publicly accessible by URL, such as public check-in pages, attendee-facing pages, visitor registration flows, and public branding assets. Clients are responsible for what data and content they choose to publish. Individuals with questions about attendee or visitor data controlled by a Client may also need to contact the relevant event organizer directly.
8. Legal Bases
Depending on jurisdiction, we may process personal data based on contract performance, legitimate interests, compliance with legal obligations, and consent where required. Clients are responsible for obtaining attendee or visitor consents required for their own processing activities.
9. Retention and Deletion
We retain personal data for the period reasonably necessary to provide the Services, maintain security and audit records, comply with legal and accounting obligations, resolve disputes, and enforce agreements. Operational records such as payment history, legal acceptance logs, email delivery events, and security or audit trails may be retained longer where needed for compliance, fraud prevention, or incident investigation. Backup and archival copies may persist for a limited period after deletion.
10. International Transfers
Your data may be processed in countries other than where you are located. Where required, appropriate safeguards should be used for cross-border transfers.
11. Security
We use reasonable technical and organizational measures to protect personal data, but no transmission or storage system can be guaranteed to be fully secure.
12. Rights and Requests
Where applicable law provides rights such as access, correction, deletion, restriction, objection, portability, or withdrawal of consent, requests may be submitted to https://www.passtru.com. We may need to verify identity before responding. For attendee or visitor data controlled by a Client, requests may need to be directed to the relevant event organizer.
13. Cookies and Browser Storage
For information about cookies, local storage, cache storage, and service worker behavior used by the platform, see the Cookie Policy.
14. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes should be communicated through an appropriate notice mechanism before or when the new version takes effect.
15. Contact
For privacy questions or requests, contact us at https://www.passtru.com.