Privacy Policy
Effective 26 September 2026
In plain English
We hold three kinds of information: the accounts of organizers who use Captain Expo, the details vendors give when they book a table, and the details ticket buyers give when they buy admission to a show. Vendor and ticket buyer details belong to the organizer running that show - we hold them on their behalf.
We never see a card number. We run no advertising scripts, we put no tracking pixels in email, and we never store a raw IP address. We do not sell personal information.
This summary is here to orient you. The numbered clauses below are the agreement.
1.Who this covers
Three groups of people appear in Captain Expo, and our role differs between them.
- Organizers - our customers. They have accounts. For their account information we are the controller, and this policy describes what we do with it.
- Vendors - the organizer’s customers, who buy tables at their shows. Vendors have no account with us. We hold their details on behalf of the organizer, on that organizer’s instructions. For vendor data the organizer is the controller and we are their processor.
- Ticket buyers - also the organizer’s customers, who buy admission to their shows. Ticket buyers have no account with us either. As with vendors, the organizer is the controller of a buyer’s details and we are their processor.
The practical consequence: if you are a vendor or a ticket buyer and want your details corrected or removed, the organizer of that show is who can do it. We will help them, and we will pass on a request you send us, but the decision is theirs.
2.What we collect from organizers
- Account details - name, email address, and organization membership, handled by our authentication provider. We never see or store a password.
- Your Stripe connection - the identifier of your connected account and whether it can currently accept charges. We deliberately discard the access token Stripe issues, so there is no credential of yours in our database to leak.
- Event and floor plan content - what you build in the product, including any venue plan you upload.
- An activity log - a record of consequential actions taken in your organization, such as price changes, booking state changes and ticket refunds, so a multi-person team can answer “who changed this”.
3.What we hold about vendors
When a vendor applies for or buys a table, the organizer’s form collects: name, email address, Instagram handle, phone number, city, state, and the selling categories they choose. We also record which tables they took, what they paid, and the date they accepted the organizer’s rules - together with the text of those rules as it stood at that moment.
There is no vendor account, no password, and no login. A vendor returns to their booking through an unguessable link sent to them by email. That link is the credential: anyone holding it can see that booking, so it is never written to a log or included in a web address we hand to anyone else. Treat it like a password.
4.What we hold about ticket buyers
When someone buys admission tickets, the organizer’s ticket page collects their name and email address, and whether they ticked “Email me about [the organizer]’s next show”. We also record which tickets they bought, what they paid - the ticket price, our service fee and any processing fee - and whether the order was paid, refunded or never completed. Only the buyer is named. Tickets carry no name, so we hold nothing about the people a buyer brings with them.
There is no ticket buyer account either. The confirmation email carries one QR code per ticket and a link to a private page for the order. Like a vendor’s link, that link is the credential, and each QR code holds a random code that admits one person. Anyone holding either can use it - which is also what makes a ticket transferable - so treat them like a password.
At the door, we record when each ticket was checked in and whether it was admitted by a member of the organizer’s team or by one of the organizer’s check-in links for volunteers, each of which carries the name the organizer gave it. When somebody admits a ticket past a warning - scanned a second time, or before its entry time - that is also written to the organizer’s activity log. The scanner reads QR codes with the phone’s camera on the phone itself: camera images are never sent to us or stored.
Door lists. The organizer can download a list of paid orders to work from if check-in cannot run. The organizer’s copy includes buyer emails. The copy a volunteer’s check-in link can download has names and ticket counts and no emails.
The email opt-in is recorded on the order, and it is a request to hear about that organizer’s next show and nothing else. We do not email opted-in buyers ourselves, and they are not added to the organizer’s vendor contacts. The organizer can download the buyers who opted in and email them with their own tools. If a buyer pays for more than one order with an organizer, the most recent order’s answer is the one that counts.
The only emails we send a ticket buyer are about their order: the confirmation with their tickets, and a notice if the order is refunded or the show is cancelled.
5.Payment information
Card numbers never reach us. Checkout is hosted by Stripe and the payment is made directly to the organizer’s own Stripe account, for tables and tickets alike. We pass Stripe the email address entered on our form, so the payment page does not ask for it again. What comes back to us is the outcome - paid or not, an amount, and a reference - never the card details. On a ticket order, Stripe separates our service fee from that same payment.
Because the organizer is the merchant of record, Stripe’s handling of that payment is between Stripe and the organizer.
6.Cookies, analytics and tracking
This section is mostly a list of things we do not do.
- No advertising scripts, and no analytics beyond a page-view count. We count page views with Vercel Web Analytics, which is served from our own domain and sets no cookie, and the private link in any web address is removed before a view is counted. We will not put a third-party script on a page where somebody is entering payment details - which is also why you have never seen a cookie banner here.
- No tracking pixels or rewritten links in email. We do not record whether a vendor or a ticket buyer opened a message or clicked it. The honest cost of that is that an organizer cannot be told who read their announcement.
- No advertising, no data brokers, no sale of personal information - in any sense, including the broader definitions used by US state privacy laws.
Signed-in organizers do get a session cookie, set by our authentication provider, which is what keeps you logged in. That is strictly necessary and there is no way to use an account without it. The public marketing pages set no cookies at all.
The table and ticket pages remember an unfinished checkout in your browser’s own storage, so that coming back from the payment page can offer to resume it or release what you were holding. It is not a cookie and is not sent with your requests. The page reads it only to ask us about that one checkout, and discards it when it finds the hold has run out.
7.IP addresses
Table and ticket checkout are open to the public, and so is a volunteer’s check-in link. Taking tables or tickets off sale, and trying codes at a door, are things an automated script could abuse, so we rate limit them. That requires distinguishing one visitor from another.
We do not store raw IP addresses to do it. The address is hashed with a secret salt before anything is written down, and only the hash is kept. It is used for rate limiting, including a cap on how many tables or tickets one visitor can hold at once, and nothing else - not for analytics, not for location, not for building a profile.
8.Who else processes this data
We use a small number of infrastructure providers. Each one processes data only to provide its service to us.
- Stripe - payments for tables and tickets, and the connected account onboarding flow.
- Clerk - organizer sign-in and organization membership.
- Resend - sending transactional email, such as booking confirmations and tickets.
- Vercel - hosting, storage for uploaded floor plan images, the automated-traffic check on checkout and vendor applications, and the page-view count described in clause 6.
- Neon - the managed Postgres database, hosted in the United States.
- Sentry - error reports, so we can find and fix what breaks. It is set not to collect IP addresses or cookies, and query strings and private links are removed from every report before it is sent.
- Anthropic - automatic floor plan detection. Only the venue plan image an organizer uploads is sent, and only when they ask for a detection run. No vendor or ticket buyer personal information is ever sent.
We may also disclose information if the law requires it, or to protect the rights and safety of users. A current list of providers is maintained in the Data Processing Addendum, and we will give notice there before adding a new one that processes vendor or ticket buyer personal data.
9.How long we keep it
Event, booking and ticket order records are kept for as long as the organizer’s account is open, because they are the organizer’s business records - a booking from a show three years ago is what settles a dispute about a show three years ago.
When an organizer closes their account we delete their data within 90 days, except where we are required to keep something longer. Floor plan images that are no longer referenced are swept automatically.
10.Security
Traffic is encrypted in transit. Every tenant’s data carries an organization identifier and queries are constrained to a single organization by a database access layer that the build fails without.
Any third-party API key an organizer stores in the product is encrypted before it is written, using authenticated encryption with a key held in our environment rather than in the database, so a copy of the database alone is not enough to use it.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please write to legal@captainexpo.com before disclosing it publicly.
11.Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to certain processing. We honour these requests and do not discriminate against anyone for making one.
- Organizers - write to us and we will action it directly.
- Vendors - contact the organizer of the show you booked, since the data is theirs. If you cannot reach them, write to us and we will pass it on and help them respond.
- Ticket buyers - contact the organizer of the show you bought tickets for, for the same reason. If you cannot reach them, write to us and we will pass it on and help them respond.
Every announcement email an organizer sends through the product carries a working unsubscribe link. Unsubscribing is honoured permanently, and it applies to that organizer rather than to every organizer on the platform - a vendor who wants nothing more from one card show has said nothing about a different market.
A ticket buyer who opted in to hear about an organizer’s next show is emailed by that organizer with their own tools, not through Captain Expo, so unsubscribing from those emails is done with the organizer.
12.Children
Captain Expo is a tool for running shows and is not directed at children. Buying tickets asks only for the buyer’s own name and email, and nothing about the people they bring. We do not knowingly collect personal information from anyone under 16. If you believe we have, write to us and we will delete it.
13.Changes, and how to reach us
If we change this policy in a way that materially affects how we handle personal information, we will update the effective date at the top and notify organizers by email before it takes effect.
Write to legal@captainexpo.com with any privacy question, including a request to exercise the rights in clause 11.