Data Policy
Last updated: August 24, 2026
1. Purpose
This Data Policy explains — in plain terms — what data NITEPASS stores, how long we keep it, who can see it, and how money-attached scan data is protected. It complements our Privacy Policy with the operational details.
2. The data we store
Accounts: name, email, hashed password, role (guest/promoter/venue/admin), handle, city, visibility setting, notification preference, subscription plan and status.
NITEPASS activity: check-ins (guest, venue, event, promoter attribution, scanner account, entry point, timestamp, amount paid, reward unlocked), guest-list passes, favorites, "going" marks, NITE POINTS, and status tier.
Business listings: venue profiles, events, cover charges, hours, dress codes, rewards programs, entry points, NITE DROPS, and promoter team rosters.
Analytics: NITE PULSE inputs (verified check-ins, going counts, arrivals), night reports (attendance, door revenue, rewards redeemed, new vs. returning customers), and promoter leaderboards (guests, paid entries, revenue, payout owed).
Payments: Stripe session/transaction IDs, plan, amount, and status. Card data never touches our servers.
3. The scan record
Because promoter payouts and venue analytics depend on scans, every check-in is an immutable audit record containing: guest ID, venue, event, promoter attribution, scanner account, entry point, timestamp, entry amount, reward granted, and payout attribution. Scan records cannot be edited after creation — only appended to — so venues and promoters always see the same numbers.
NITEPASS QR codes are dynamic: each code is an HMAC-signed token that rotates every 30 seconds, is validated server-side, and can be checked in only once per event (unless re-entry is authorized). Static screenshots fail verification.
4. Data visibility matrix
Guests see: their own passes, points, status, check-in history, and public venue/event/promoter data.
Promoters see: their own events, their guest lists (name, handle, check-in status), and their own performance/earnings — never other promoters' data.
Venues see: scans at their venue, their events, their promoter team's performance, and their own analytics — never other venues' data.
Other guests see: only what your visibility setting allows (Public / Friends Only / Close Friends / Hidden).
5. Location data
Venue coordinates power the NITE MAP. Guest location is used only to compute approximate distances and city-level feeds, is not stored as a history, and is never sold. Map tiles are served by OpenStreetMap/CARTO under their respective terms.
6. Retention schedule
Account data: kept while the account is active. Scan/audit records: kept for the life of the venue's subscription plus 24 months for dispute resolution and fraud prevention. Payment transaction records: kept as required by financial regulations. Notifications: kept 90 days. Failed-login lockout records: purged after lockout expiry.
7. Deletion
Email Imjovetech@gmail.com to delete your account. Deletion removes your profile, passes, favorites, and notifications within 30 days. Anonymized scan records (stripped of identity) may be retained where a venue has a legitimate accounting need, and financial records are retained as legally required.
8. Security measures
Bcrypt password hashing; signed httpOnly session cookies; role-based access control enforced server-side on every endpoint; single-use rotating QR tokens; brute-force login lockouts; immutable scan audit trail; encrypted transport (HTTPS) everywhere.
9. Processors
We use: Stripe (payments), MongoDB (database), and cloud hosting provided by our deployment platform. Each processes data only as needed to deliver the Service.
10. Contact
Data requests, corrections, exports, or deletion: Imjovetech@gmail.com. We respond within 30 days.
