Privacy policy

Last updated July 24, 2026

The short version

Booster Tickets stores almost nothing about the families who buy tickets. We keep the purchaser's email address just long enough to deliver their tickets, and one week after your event ends we permanently delete it. We never sell data, we show no ads, and we use no tracking — ticket buyers never even need an account.

What we collect about ticket buyers

The purchase itself happens in your organization's Square store. Booster Tickets never sees card numbers or payment details — Square handles the checkout, under Square's own privacy policy.

From Square, with your organization's permission, we read the order (what was bought and when) and the purchaser's email address, so we can email their QR tickets. That is the whole list: no names, no phone numbers, no postal addresses. Tickets themselves are anonymous — nothing personal is printed on them, and the QR code contains only a ticket number, not who bought it.

Some free events take sign-ups through a Google Form instead of a Square store. That form belongs to your organization and lives in its Google account; responses stay there, under Google's own privacy policy. From each response we read exactly two things — the email address the registrant typed and how many tickets they asked for — so we can email their QR tickets. If the form asks for a name or anything else, those answers stay in your organization's form; they never enter Booster Tickets.

How long we keep it: one week after the event

One week after an event ends, we permanently delete everything that could identify a buyer:

  • the cached email address,
  • the link between tickets and the buyer's order,
  • email delivery records, and
  • any notes door staff typed during check-in.

What remains is anonymous: totals like tickets sold and people checked in, and operational records that say something happened (“an email bounced”) without saying to whom. Our database backups exclude the email cache entirely, so a backup can never quietly outlive this promise. Our technical logs and monitoring never contain buyer information in the first place.

What we keep about your organization's staff

The people who run your events sign in with accounts. For them we keep an email address, an optional display name, a role, and a record of sign-ins and actions taken — who checked tickets in, who changed settings. That audit trail exists so your organization can answer “who did what” about its own events; it refers to buyers only by order and ticket numbers, never by name or email, and it is kept while your organization's account is active.

Cookies

Signed-in staff get the essential cookies that keep them signed in and protect their session. Those are the only cookies we set — no analytics cookies, no advertising, no cross-site tracking. Ticket buyers never sign in, so they never get a cookie at all.

The services we rely on

A small set of carefully chosen services helps us run:

  • Square — your organization's store and payments; we read order data from your Square account with permission you can revoke at any time.
  • Google — for organizations that run free events through a Google Form, we read registration email addresses and ticket counts from that form with permission your organization grants and can revoke at any time; the form and its responses stay in your organization's own Google account.
  • Resend — delivers ticket emails.
  • Amazon Web Services — stores encrypted database backups, always excluding the buyer-email cache.
  • Akamai (Linode) — the servers the service runs on, located in the United States.
  • Cloudflare — routes and protects traffic to the site.
  • Grafana Cloud — technical monitoring; by design it never receives buyer information.

We add a service only when the product needs it, and this page changes when the list does.

Children

Tickets are bought by adults — parents, guardians, and staff — through your organization's Square store, and we do not knowingly collect personal information from children. A student holding a QR ticket shares nothing with us: the ticket carries no personal information.

Your choices and questions

Most privacy requests are handled by design: the only personal information we ever hold about a buyer — the email address used to deliver their tickets — deletes itself one week after the event, along with everything that links tickets to a person. If you would like it removed sooner, or have any question about your data, email us at hello@boostertickets.com and we will help.

When this policy changes

If this policy changes, we will update this page and its date. If a change actually matters — a new service, a different retention promise — we will tell the organizations we serve directly. You can read about the product itself on the front page and our terms of service.