Privacy Policy
Effective date: September 16, 2026
Last updated: September 25, 2026
SOATERA LLC ("SOATERA," "we," "us," or "our") operates this website and the SOATERA Event Passport mobile application. This Privacy Policy explains, in plain language, how we collect, use, share, and protect information.
This page is the public Privacy Policy URL intended for Apple App Store and Google Play listings of SOATERA Event Passport. It is not a certification of GDPR, CCPA, COPPA, HIPAA, or any other regulatory framework.
Who we are
SOATERA LLC is a strategy, operations, and technology advisory firm. We also build and operate SOATERA Event Passport, a reusable event platform used by organizations to run event companion experiences, participation, and authorized check-in.
Contact: [email protected]
Website: www.soatera.com
What this policy covers
This policy applies when you:
- visit SOATERA websites, including www.soatera.com;
- contact us through the website or by email;
- install or use SOATERA Event Passport; or
- are registered as a participant, volunteer, or organizer on an event that uses the platform.
Event organizers may also have their own notices for a specific event. Those notices, if provided, describe that organizer's practices and do not replace this policy for SOATERA's operation of the platform.
SOATERA Event Passport
SOATERA Event Passport is a reusable event companion. A single app can serve different events and organizations. Features such as Passport challenges, points, surveys, giveaways, push notifications, and volunteer scanning are available only when that event has enabled them. This policy describes the platform. It does not mean every listed feature is turned on for every event.
Information you provide
Depending on how you use the app, we may process:
- Email address — used to send a one-time sign-in code (OTP). There is no password login and no Apple Sign In or other social login in the current product.
- Profile name — first and last name when you complete a Passport profile.
- Adult or minor confirmation — a yes/no confirmation collected with the profile. We do not collect date of birth.
- Optional mobile number — only if you choose to provide it.
- Event engagement you create in the app — for example survey answers, when a survey is enabled for that event.
- Support messages — if you email us about the app.
You can browse published event information (such as schedule, map, food, vendors, or sponsors, when those surfaces are published for the event) without creating an account.
Participant and registration information
Event organizers may import or enter participant information so the event can operate check-in and related credentials. That information typically includes names and contact details supplied by the organizer or by a related registration source. SOATERA processes this information to operate the event platform for that organizer.
If Passport registration is enabled for an event, completing a profile and registering creates an event registration record and a Passport identifier. A Passport number is an event identifier. It is not a password and does not by itself grant volunteer or administrative access.
OTP authentication and volunteer access
Signing in with email OTP authenticates you (proves control of that email). It does not automatically authorize volunteer or staff scanning.
Volunteer and staff access is assigned separately, for a specific event, by an authorized operator. Only then can that person use volunteer check-in or other assigned event tools.
Participant QR credentials and check-in
When an event uses participant QR credentials, the platform may process:
- QR credential records used to check a participant in;
- delivery status when a credential is emailed to a participant; and
- check-in timestamps and related operational records.
Raw QR secret values are not treated as public identifiers. Operational records may store a fingerprint or status rather than the secret itself. Authorized volunteers and event staff can record a successful check-in for an assigned event.
Passport activity, points, challenges, and giveaways
When the relevant features are enabled for an event, the platform may record:
- Passport stop scans and related scan outcomes;
- points and challenge progress;
- giveaway entries created from configured rules; and
- survey submissions used as event feedback or as configured Passport evidence.
Points and challenge progress are event-engagement records. Unless an event's own official rules say otherwise, they have no cash value. Giveaway official rules, if any, are published separately for that event and are not this Privacy Policy.
Administrative and audit records
The platform keeps operational and audit records needed to run an event securely — for example registration creation, credential issuance or replacement, authorized check-in, and administrative corrections. Audit records are intended for operators, not for public display.
Device and app technical information
The app may process technical information needed to operate on your device, such as:
- app version and operating system;
- a session used to keep you signed in;
- camera permission, used only to scan official event QR codes when you open scanning;
- notification permission and a push token, if you enable notifications; and
- limited diagnostic or error information needed to operate the service.
The current product does not collect GPS location, your contacts list, your photo library, microphone audio, or payment-card details. Camera access is requested for QR scanning, not for unrelated photography.
SOATERA website
If you use the contact form or email us, we collect the information you submit, which may include:
- name, organization, email, phone number, and message content.
The public website does not require an account. It may load webfonts from a font provider so pages can display correctly.
How we use information
We use information to:
- operate the website, Event Passport, and related event services;
- send OTP codes and service emails;
- create and maintain Passport profiles and event registrations;
- issue and validate participant QR credentials and record check-in;
- provide event-specific features that an organizer has enabled;
- allow assigned volunteers and staff to perform authorized event work;
- send in-app announcements, and push notifications if you enable them;
- respond to support and privacy requests;
- protect the service against abuse, fraud, or unauthorized access; and
- comply with law and enforce applicable terms.
We do not use Event Passport as an advertising network, and we do not show third-party ads in the current app.
When information is shared
We share information as described in this section so the website, Event Passport, and each event can operate. Those operational disclosures are not the same as advertising or data brokerage.
Event organizers. Information needed to run an event is available to the organization operating that event and to people they authorize (for example event administrators and assigned volunteers). That commonly includes participant names and contact details, registration and check-in status, and — when enabled — Passport activity, survey responses, or giveaway eligibility.
Service providers. We use processors that host infrastructure, send email, deliver push notifications, or otherwise help us operate the service. They process information as needed to provide those services to SOATERA.
We may also disclose information when reasonably necessary to:
- comply with law, regulation, legal process, or a governmental request;
- protect the rights, property, safety, or security of SOATERA, users, event organizers, or others;
- investigate fraud, security incidents, or misuse; or
- support a merger, acquisition, restructuring, or transfer of applicable business assets.
We do not use Event Passport to sell personal information for money, to operate a data-brokerage service, or for cross-context behavioral advertising. Sharing with event organizers and service providers, as described above, is part of operating the platform.
Service providers we actually use
Based on the current architecture, relevant providers include:
- Supabase — authentication (email OTP), database, and related backend infrastructure for Event Passport.
- Expo — push-notification delivery when notifications are enabled.
- Resend — transactional email used to deliver participant QR credentials when that feature is used for an event, and to send an account-deletion completion notice after an operator fulfills a verified request.
- Microsoft Azure and Cloudflare — hosting and delivery of this public website.
- Microsoft 365 / Microsoft Graph — delivery of website contact-form messages when that integration is enabled.
Apple and Google operate the app stores through which the mobile app may be distributed. Those platforms have their own terms and privacy policies.
We do not currently use in-app advertising SDKs, payment processors, or a third-party analytics SDK in Event Passport. If that changes, we will update this policy.
Security
We use reasonable administrative, technical, and organizational measures intended to protect information, including access controls, encryption in transit to our services, and role-based authorization so that volunteer tools are not granted by sign-in alone.
No internet transmission, application, or electronic storage system is completely secure. We do not claim absolute security.
Retention
We retain personal information only as long as reasonably needed to:
- operate the event and the platform;
- provide support and security;
- keep operational and audit records; and
- meet legal obligations.
We do not publish a single automatic deletion period. Retention can differ by record type (for example authentication records, check-in history, and audit logs) and by the event organizer's operational needs.
Your choices and requests
You may:
- browse published event information without signing in;
- decline optional profile fields such as mobile number;
- deny camera or notification permission (some features will not work without them);
- disable notifications for the current installation, when that control is available in the app; and
- sign out of the app.
Account deletion. Request deletion in the app (More → Delete account) or on the public account-deletion page. A request is not immediate deletion. After a verified individual request, an operator may fulfill once pending-scan and prize-claim safeguards are satisfied. Some operational or legal records may be retained. A SOATERA operator sends a completion email after fulfillment.
Depending on where you live, you may have additional rights under applicable law. This policy does not certify compliance with any particular privacy statute. To make a request, use the contact information below.
Children and minors
SOATERA Event Passport is an event platform. It is not directed at children under 13. We do not knowingly collect personal information from children under 13.
The app may ask whether a person completing a Passport profile is an adult. Date of birth is not collected. There is no separate guardian-consent workflow in the current product. Event organizers and SOATERA must confirm how minors may participate in a given event before relying on that event's registration for children.
If you believe we have collected personal information from a child under 13, contact [email protected] so we can review and, where appropriate, delete it.
Changes to this policy
We may update this Privacy Policy when our services, providers, or legal requirements change. The "Last updated" date at the top of this page will change when we do. Material changes will be posted here, and we may provide additional notice when appropriate.
Contact
Privacy questions and requests:
SOATERA LLC
Email: [email protected]
Support: soatera.com/support
Website: www.soatera.com