1. Introduction
ProofTix Inc. (“ProofTix,” “we,” “us,” or “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our website, applications, and services (collectively, the “Service”).
By accessing or using our Service, you consent to the collection and use of your information as described in this policy. If you do not agree with any part of this policy, please do not use our Service.
2. Information We Collect
We collect several types of information to provide and improve our Service:
2.1 Information You Provide
- Account Information: When you register for an account, we collect your first name, last name, email address, and password.
- Profile Information: Phone number, country code, preferred currency, and avatar image.
- Booking Information: Passenger names, travel dates, flight routes, and contact details provided during the reservation process.
- Agency Information: For Agency accounts, we additionally collect business name, business email, business phone, and website URL.
- Support Communications: Messages, attachments, and other content you send through our customer support chat.
2.2 Information Collected Automatically
- Device and Browser Data: IP address, browser type, operating system, device identifiers, and screen resolution.
- Usage Data: Pages visited, features used, click patterns, session duration, and referral sources.
- Cookies and Similar Technologies: We use session cookies to maintain your authentication state and analytics tools to understand how users interact with our Service. See Section 8 for more details.
2.3 Payment Information
Payment transactions are processed by our PCI-compliant payment processor. We do not store your full credit card numbers, CVV codes, or other sensitive payment details on our servers. Our payment processor handles all payment data in accordance with PCI DSS (Payment Card Industry Data Security Standard) requirements. We may receive and store limited transaction details such as the payment amount, currency, transaction ID, and payment status.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To create and manage your flight reservations, generate PNR codes, and deliver booking confirmations.
- Account Management: To create, maintain, and secure your user account.
- Payment Processing: To process your payments and issue refunds when applicable.
- Customer Support: To respond to your inquiries, resolve issues, and provide assistance through our support chat.
- Referral Program: To track referrals, attribute discounts, and manage the referral program.
- Communication: To send you order confirmations, service updates, and important notices about your account or reservations.
- Analytics and Improvement: To understand usage patterns, diagnose technical issues, and improve the performance and user experience of our Service.
- Security: To detect and prevent fraud, unauthorized access, and other harmful activities.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
4. How We Share Your Information
We do not sell your personal information to third parties. We may share your information in the following limited circumstances:
- Payment Processors: We share necessary transaction data with our payment processor to process your payments securely.
- Airline Systems: Passenger names, travel dates, and route information are submitted to airline booking systems (GDS) to create your flight reservation and generate a PNR code.
- Analytics Providers: We use PostHog to collect anonymized usage analytics. PostHog receives device and usage data but does not receive your personally identifiable booking information.
- Authentication Providers: If you sign in using Google OAuth, we receive basic profile information (name, email, profile picture) from Google in accordance with their privacy policy.
- Legal Obligations: We may disclose your information if required to do so by law, regulation, or legal process, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of ProofTix, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity. We will notify you of any such change and any choices you may have regarding your information.
5. Data Storage and Security
Your data is stored securely using Supabase, a cloud infrastructure platform with enterprise-grade security measures. Our security practices include:
- Encryption of data in transit using TLS/SSL (256-bit encryption).
- Encryption of sensitive data at rest.
- Row-level security policies that ensure users can only access their own data.
- Regular security audits and monitoring for unauthorized access.
- Secure session management with session cookies that are cleared when you close your browser.
While we implement commercially reasonable security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our Service. Specifically:
- Account Data: Retained for as long as your account exists. You may request account deletion at any time.
- Booking Records: Retained for a minimum of 2 years after the booking date for legal and business record purposes.
- Transaction Records: Retained for a minimum of 5 years to comply with financial reporting and tax obligations.
- Support Conversations: Retained for 1 year after the conversation is closed.
- Analytics Data: Usage analytics are retained in session storage and cleared when you close your browser tab. Aggregated, anonymized analytics may be retained indefinitely.
When data is no longer needed for the purposes outlined above, we will securely delete or anonymize it.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data. You can also update most of your information directly through your Account Settings page.
- Deletion: Request deletion of your personal data, subject to our legal retention obligations.
- Data Portability: Request a machine-readable copy of your personal data.
- Objection: Object to the processing of your personal data for certain purposes, including direct marketing.
- Withdrawal of Consent: Where processing is based on your consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at support@prooftix.com. We will respond to your request within 30 days.
8. Cookies and Tracking Technologies
We use the following types of cookies:
- Essential Cookies: Required for the Service to function. These include authentication session cookies that maintain your logged-in state. These cookies are session-based and are deleted when you close your browser.
- Analytics Cookies:We use PostHog for product analytics. PostHog data is stored in your browser’s session storage (not persistent cookies) and is cleared when you close your browser tab.
We do not use advertising cookies or third-party tracking cookies. We do not participate in cross-site tracking or behavioral advertising networks.
9. Third-Party Services
Our Service integrates with the following third-party services, each governed by their own privacy policies:
- Supabase: Database and authentication infrastructure.
- Payment Processor: PCI-compliant payment processing.
- PostHog: Product analytics.
- Google: OAuth authentication (when you choose to sign in with Google).
- Resend: Transactional email delivery.
We encourage you to review the privacy policies of these third-party services. ProofTix is not responsible for the privacy practices of third-party providers.
10. International Data Transfers
ProofTix operates globally, and your data may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your jurisdiction. By using our Service, you consent to the transfer of your information to countries outside your country of residence. We take appropriate measures to ensure that your personal data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.
11. Children’s Privacy
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18 without parental consent, we will take steps to delete that information promptly. If you believe we have inadvertently collected information from a child, please contact us at support@prooftix.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify registered users by email or through an in-app notification. The “Last updated” date at the top of this page indicates when the policy was most recently revised. Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact our Data Protection Officer: