Privacy Policy
Last updated: September 23, 2026
About Plausor
This Privacy Policy is published by Crowd Pass, LLC, doing business as Plausor. Crowd Pass, LLC owns and operates the Plausor event ticketing platform at plausor.com. References to "Plausor", "we", "us" and "our" in this document mean Crowd Pass, LLC.
Legal business name: Crowd Pass, LLC
Trading name: Plausor
Business address: 79 Wood Manor Place, The Woodlands, TX 77381, US
Website: https://plausor.com
Contact: support@plausor.com
1. Introduction
Plausor ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our event ticketing platform and related services. It applies to the Plausor website, the Plausor iOS and Android apps, and the emails and text messages we send you.
2. Information We Collect
2.1 Personal Information
We may collect the following personal information:
- Name and contact information (email address, phone number)
- Billing address and payment information
- Account credentials
- Date of birth (when required for age-restricted events)
- Government-issued ID (when required for identity verification)
2.2 Transaction Information
We collect information about your transactions, including:
- Ticket purchases and sales
- Payment history
- Event attendance records
- Ticket transfers
2.3 Automatically Collected Information
When you use our Service, we automatically collect:
- Device information (device type, operating system, app version)
- IP address, which is recorded with your consent timestamps, with sign-in and security events, and with advertising events described in Section 4.2
- Browser type and version
- Pages viewed, events browsed, and purchases made, including the approximate time of each
- Cookies and similar identifiers, including the Meta advertising cookies described in Section 8
2.4 Location Information
The Service can show you events near you. How your location is obtained depends on what you allow:
- Precise location (GPS): only if you grant your browser or phone the location permission. Your device sends the coordinates to us with the search request.
- Approximate location from your IP address: if you do not grant the location permission, the website may ask an IP-geolocation provider (ipapi.co, falling back to ip-api.com) to estimate your city-level location. Your IP address is visible to that provider; your GPS coordinates are not sent to it.
- No location at all: if both are unavailable we fall back to a default city, and you can search by city or ZIP code instead.
We do not keep your coordinates. They are used in memory to rank events by distance for the request that carried them, and are not written to your account, to a search history, to our analytics, or to our server logs. Revoking the location permission stops the collection entirely. The latitude and longitude we do store belong to venues and events, not to you.
3. How We Use Your Information
We use collected information to:
- Process ticket purchases and transactions
- Provide and maintain our Service
- Send transaction confirmations and event updates via email or SMS
- Verify your identity and prevent fraud
- Improve our Service and user experience
- Send marketing communications (with your consent)
- Comply with legal obligations
- Enforce our Terms of Service
3.1 SMS and Text Message Communications
If you provide your phone number and opt in to SMS notifications, we will use your phone number to send you:
- Account verification codes for security purposes
- Ticket purchase confirmations and digital tickets
- Event reminders and important updates
- Ticket transfer notifications when someone sends you tickets
- Password reset codes when requested
- Security alerts about your account
Your phone number will be stored securely and will not be sold or shared with third parties for marketing purposes. We use Twilio, a trusted third-party service provider, to send SMS messages on our behalf. Twilio processes your phone number solely for the purpose of delivering our messages and is bound by strict data protection agreements.
Mobile Information Sharing: No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party, except with Twilio, our messaging delivery provider, solely to deliver the messages you requested.
Message Frequency: Message frequency varies based on your account activity and the events you follow. You may receive multiple messages per transaction or event. Standard message and data rates may apply.
Your Choices: You can opt out of SMS notifications at any time by replying STOP to any message, updating your preferences in your account settings, or contacting us at support@plausor.com. Standard message and data rates may apply depending on your mobile carrier plan.
4. Information Sharing
We may share your information with:
- Event Organizers: Name and contact information for event entry and communication
- Payment Processors: Payment information to process transactions
- Service Providers: Third parties who assist in operating our Service
- Advertising and measurement partners: Meta, as described in Section 4.2
- Legal Authorities: When required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
4.1 The Providers We Actually Use
- Stripe — payment processing. Card details are entered directly with Stripe and are never stored by Plausor.
- Twilio — delivery of the text messages you opted in to.
- SendGrid (Twilio) — delivery of account, ticket and event email.
- Meta Platforms — advertising measurement, described in Section 4.2.
- ipapi.co / ip-api.com — approximate location from your IP address, only when you have not granted the location permission (Section 2.4).
- Apple and Google — delivery of push notifications and wallet passes to your device, and app distribution.
- Our hosting and database provider — operates the servers and encrypted backups that run the Service.
4.2 Advertising and Measurement (Meta)
We advertise events on Facebook and Instagram, and we measure which of those ads led to a purchase. To do that we share purchase and identity data with Meta Platforms, Inc. through the Meta Pixel in the website and through Meta's Conversions API on our servers. This happens for purchases made on the website and for purchases made in the mobile apps, because both complete through the same checkout.
What we send to Meta:
- Identity, hashed: your email address, phone number, first and last name, and your Plausor account ID are converted to SHA-256 hashes before they are sent. Hashing is not anonymisation — Meta can match those hashes to an existing Meta account, and we treat them as personal data.
- Device and network data, not hashed: your IP address, your browser's user-agent string, and Meta's own advertising cookies (`_fbp`, and `_fbc` when you arrive from an ad).
- Purchase data: order total, currency, order and checkout identifiers, the number of tickets, and the event name, ID and ticket prices.
- Browsing events on the website: page views, and the equivalent steps of the checkout funnel.
Why: to measure the performance of our event advertising and to attribute ticket sales to the ads that produced them. Meta also uses this data for its own purposes as described in Meta's own terms, which can include improving ad delivery and audience targeting. Under US state privacy laws, sharing data for cross-context behavioural advertising in this way may be treated as a "sale" or "sharing" of personal information even though we receive no money for it.
Your choices: you can limit this by blocking third-party cookies or using a browser content blocker, by using Meta's own ad-preference and off-Facebook-activity controls in your Facebook or Instagram account, and on mobile by denying app tracking permission. To have us stop sharing your data with Meta entirely, email privacy@plausor.com and we will suppress it for your account. Deleting your Plausor account (Section 7.1) ends the sharing as well. Blocking the pixel does not affect your ability to buy, receive or use tickets.
We do not sell your personal information for money, and we do not share it with advertising partners other than Meta.
5. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit and at rest
- Secure payment processing through certified providers
- Regular security assessments and updates
- Access controls and authentication measures
- Employee training on data protection
6. Data Retention
We keep your account and the personal data attached to it for as long as your account is open. When you delete your account, or when a retention period below ends, the data is erased or stripped of everything that identifies you. These are the periods that actually apply:
- Account profile, saved preferences and wallet — until you delete your account.
- Ticket, order, refund, payout and sales-tax records — 7 years, kept in anonymized form after account deletion, because tax, accounting and audit law requires them and because chargebacks and disputes are settled from them.
- Ticket validation and door-scan records — until the event has taken place, then retained inside the financial record above.
- Fraud, abuse and security logs — up to 24 months, with the link to your account removed on deletion.
- Your account-deletion request itself — up to 24 months. We keep the timestamps, the outcome and a one-way keyed digest of the email address as proof the request was made and honoured; the plain address, IP address, device string and any reason you gave are discarded when the erasure completes.
- Server access logs — retained by our hosting provider on a rolling basis for operational debugging. They record the request path, status and timing; they do not record passwords, authentication tokens, payment secrets or location coordinates.
- Encrypted backups — up to 90 days, after which deleted data ages out of rotation. Backups are never used to restore a deleted account.
- Aggregated and anonymized statistics — indefinitely; these cannot be traced back to you.
7. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Request transfer of your data to another service
- Objection: Object to certain processing of your information
- Withdrawal: Withdraw consent for marketing communications
To exercise these rights, please contact us at support@plausor.com.
7.1 Deleting Your Account
You can delete your Plausor account and the personal data attached to it in any of these ways, without contacting support:
- In the mobile app: Account, then Delete my account.
- On the website: Account, then Delete my account.
- Without signing in: use the form at plausor.com/data-deletion. We email a one-time confirmation link to the address on the account; it expires after 24 hours and nothing is deleted until you open it.
A request made while signed in starts immediately, and we email you a cancellation link in case it was not you. You then have 7 days to cancel, from that email or from your account settings. After the 7 days your account and personal data are erased automatically; we complete every verified request within 30 days. Accounts that own events, venues or payouts are reviewed by a person first, and we contact you if something has to be transferred, but those requests are completed within 30 days too.
What erasure means: your name, email address, phone number, password, saved preferences, device and push registrations and marketing history are deleted, and your sessions and app logins stop working. The records listed in Section 6 that we are legally required to keep are stripped of your name, email and phone number, so what remains does not identify you. Erasure cannot be undone once the 7-day window has passed. The full list, and what happens to tickets you have already bought or sold, is on the data deletion page.
8. Cookies and Tracking
We use cookies and similar identifiers to:
- Keep you signed in to your account (a session cookie set by us; the mobile apps use a stored login token instead)
- Remember your preferences and the contents of your cart
- Measure advertising through Meta's `_fbp` and `_fbc` cookies, as described in Section 4.2
You can block or delete cookies in your browser settings, and you can block the Meta pixel with a content blocker. Blocking the session cookie will sign you out and prevent checkout; blocking the advertising cookies does not affect any part of the Service. See Section 4.2 for how to stop the sharing with Meta entirely, or email privacy@plausor.com.
9. Children's Privacy
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
10. International Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your information in accordance with this Policy.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Policy on this page and updating the "Last updated" date. We encourage you to review this Policy periodically.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Email: support@plausor.com
Privacy Inquiries: privacy@plausor.com
Mailing address: Crowd Pass, LLC, 79 Wood Manor Place, The Woodlands, TX 77381, US
13. California Privacy Rights
California residents have additional rights under the California Consumer Privacy Act, as amended by the CPRA: the right to know what personal information we collect and disclose, the right to delete it (Section 7.1), the right to correct it, and the right to opt out of its sale or sharing for cross-context behavioural advertising. We do not sell personal information for money. We do share purchase and hashed identity data with Meta for advertising measurement, which California treats as "sharing" — see Section 4.2 for what is sent and how to stop it, or email privacy@plausor.com with "Do Not Share My Personal Information" and we will suppress it for your account. We will not discriminate against you for exercising any of these rights.
14. European Privacy Rights
If you are located in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR), including the rights described in Section 7. Our legal basis for processing your information includes contract performance, legitimate interests, and consent.