What we collect, why we collect it, and the control you have over it.
Short version: we collect what we need to run ticketing for winter events - account details, order records, and usage data. We do not sell your personal information. Card numbers are handled by our payment providers, not stored by us. You can request a copy of your data, or its deletion, at any time.
This policy covers personal information handled by SantaTicket, a product of Hytix Inc. ("we", "us", "our"), through www.santaticket.com, the organizer web application, the box office app, and the ticket buyer portal (together, the "Services").
Our role depends on whose data it is, and this distinction matters:
We do not collect or store full payment card numbers. See section 6.
You can unsubscribe from marketing at any time using the link in any email, or by emailing info@hytix.com. We will still send you essential service messages such as order confirmations and security notices.
We use cookies and similar technologies - including web beacons, pixels, and scripts - to operate and improve the Services. The categories we use are:
Cookies may be session-based or persistent. Most browsers let you refuse or delete cookies; if you block strictly necessary cookies, parts of the Services will not work. We honour the Global Privacy Control (GPC) signal as an opt-out of sale or sharing where applicable law requires it.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We share it only as follows:
A current list of our sub-processors is available on request at info@hytix.com.
Card payments are processed by PCI-DSS compliant payment providers, which may include our integrated gateway or a third-party gateway an Organizer connects, such as Stripe, Square, Authorize.Net, or CardConnect. Full card numbers are submitted directly to those providers.
We retain only limited transaction data - such as card brand, the last four digits, authorization result, amount, and timestamp - to reconcile orders, process refunds, and handle disputes. Each payment provider handles your information under its own privacy policy.
We are based in the United States and our infrastructure and service providers are primarily located there. If you access the Services from outside the US, your information will be transferred to and processed in the US, where data protection law may differ from your own. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards - principally the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.
Attendee Data held on behalf of an Organizer is retained according to that Organizer's instructions. When a retention period ends we delete the data or irreversibly anonymise it.
We use industry-standard measures including encryption in transit, access controls, least-privilege permissions, logging, and regular review of our providers. Payment card data is handled by PCI-DSS compliant processors.
No system can be guaranteed completely secure. You are responsible for keeping your password confidential and for enabling multi-factor authentication where offered. If we become aware of a breach affecting your personal information, we will notify you and the relevant regulator where the law requires it.
Depending on where you live, you may have the right to:
To exercise any of these, email info@hytix.com. We will verify your identity and respond within the period the law allows - generally 30 days, or 45 days in California. We will not discriminate against you for exercising a right. If we hold your data as a processor for an Organizer, we will refer your request to them, or act on their instructions.
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you have rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of targeted advertising, sale, or profiling with significant effects.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the California Consumer Privacy Act as amended. We have not done so in the preceding twelve months, including for consumers under 16.
The Services are not directed at children, and we do not knowingly collect personal information from anyone under 16 - or under 13 in the United States - without appropriate consent. Ticket purchases must be made by an adult. Many winter events are family attractions where an adult buys tickets covering children; in that case we collect only what the Organizer requires for admission.
Our Services link to and integrate with sites we do not control, including organizer websites, payment providers, and social platforms. Their privacy practices are their own, and this policy does not apply to them.
Please do not send us sensitive personal information - such as government identification numbers, financial account credentials, health information, racial or ethnic origin, political opinions, religious beliefs, biometric data, precise geolocation, or criminal history - unless we specifically request it.
We may update this policy as our Services and the law change. For material changes we will give at least 30 days' notice by email or in-product notice before they take effect for existing users; other updates take effect when posted. The "last updated" date above always reflects the current version.
Questions, requests, or complaints about privacy? Email info@hytix.com or call +1 201-244-4454. Please put "Privacy" in the subject line so it reaches the right person quickly.