Legal — How data flows through the night

Data Policy

Last updated: August 24, 2026

1. Purpose

This Data Policy explains — in plain terms — what data NITEPASS stores, how long we keep it, who can see it, and how money-attached scan data is protected. It complements our Privacy Policy with the operational details.

2. The data we store

Accounts: name, email, hashed password, role (guest/promoter/venue/admin), handle, city, visibility setting, notification preference, subscription plan and status.

NITEPASS activity: check-ins (guest, venue, event, promoter attribution, scanner account, entry point, timestamp, amount paid, reward unlocked), guest-list passes, favorites, "going" marks, NITE POINTS, and status tier.

Business listings: venue profiles, events, cover charges, hours, dress codes, rewards programs, entry points, NITE DROPS, and promoter team rosters.

Analytics: NITE PULSE inputs (verified check-ins, going counts, arrivals), night reports (attendance, door revenue, rewards redeemed, new vs. returning customers), and promoter leaderboards (guests, paid entries, revenue, payout owed).

Payments: Stripe session/transaction IDs, plan, amount, and status. Card data never touches our servers.

3. The scan record

Because promoter payouts and venue analytics depend on scans, every check-in is an immutable audit record containing: guest ID, venue, event, promoter attribution, scanner account, entry point, timestamp, entry amount, reward granted, and payout attribution. Scan records cannot be edited after creation — only appended to — so venues and promoters always see the same numbers.

NITEPASS QR codes are dynamic: each code is an HMAC-signed token that rotates every 30 seconds, is validated server-side, and can be checked in only once per event (unless re-entry is authorized). Static screenshots fail verification.

4. Data visibility matrix

Guests see: their own passes, points, status, check-in history, and public venue/event/promoter data.

Promoters see: their own events, their guest lists (name, handle, check-in status), and their own performance/earnings — never other promoters' data.

Venues see: scans at their venue, their events, their promoter team's performance, and their own analytics — never other venues' data.

Other guests see: only what your visibility setting allows (Public / Friends Only / Close Friends / Hidden).

5. Location data

Venue coordinates power the NITE MAP. Guest location is used only to compute approximate distances and city-level feeds, is not stored as a history, and is never sold. Map tiles are served by OpenStreetMap/CARTO under their respective terms.

6. Retention schedule

Account data: kept while the account is active. Scan/audit records: kept for the life of the venue's subscription plus 24 months for dispute resolution and fraud prevention. Payment transaction records: kept as required by financial regulations. Notifications: kept 90 days. Failed-login lockout records: purged after lockout expiry.

7. Deletion

Email Imjovetech@gmail.com to delete your account. Deletion removes your profile, passes, favorites, and notifications within 30 days. Anonymized scan records (stripped of identity) may be retained where a venue has a legitimate accounting need, and financial records are retained as legally required.

8. Security measures

Bcrypt password hashing; signed httpOnly session cookies; role-based access control enforced server-side on every endpoint; single-use rotating QR tokens; brute-force login lockouts; immutable scan audit trail; encrypted transport (HTTPS) everywhere.

9. Processors

We use: Stripe (payments), MongoDB (database), and cloud hosting provided by our deployment platform. Each processes data only as needed to deliver the Service.

10. Contact

Data requests, corrections, exports, or deletion: Imjovetech@gmail.com. We respond within 30 days.

Questions about this policy? Contact us at Imjovetech@gmail.com.