Summary
Festro Inc. (“Festro,” “we,” “us,” or “our”) is a corporation incorporated under the Canada Business Corporations Act, based in Montreal, Quebec, Canada. We operate the Festro mobile application and the website at festro.com (together, the “Service”). This policy explains what personal information we collect, why we collect it, how we use and share it, and the rights you have over it.
We do not sell your personal information. Ever. We do not rent or trade it either. If you want your data gone, request deletion through our contact form and we will action it within 30 days, subject to the limited legal-retention exceptions described in Section 9.
This policy is provided in English and French. In case of any discrepancy, the version corresponding to the language you selected governs your relationship with us to the extent permitted by law.
Who is responsible for your information
Festro is the controller (and, under Quebec law, the enterprise) responsible for the personal information processed through the Service.
We have designated a Person in charge of the protection of personal information (our Privacy Officer), as required by Quebec Law 25. You can reach this person using the contact details in Section 14.
Information we collect
Information you give us
- Account information — your email address and the display name you choose. We use passwordless email sign-in, so we do not store a password.
- Profile information — an optional avatar photo and short bio, if you add them.
- Reservation and ticket data — the events you reserve, the ticket tier, and a short check-in code.
- Payment information — when you buy a paid ticket, payments are processed by our payment provider (Stripe). We do not store your full card number; we receive limited transaction details (for example, the last four digits, the result, and an identifier) needed to confirm and support your purchase.
- Communications — messages you send to us (for example, support requests) and your contact preferences.
- Phone number (optional) — if you choose to verify a phone number, we collect it and use Twilio to send you a one-time verification code. If you separately opt in, we use your number to send you SMS updates and marketing about events and organizers; you can withdraw that consent at any time (reply STOP, or change it in your settings). We keep a record of your consent — the date and the wording you agreed to — as required by anti-spam law (Canada's CASL and the US TCPA).
- Inquiries — if you contact us through a form without an account (for example our contact form or an early-access / interest form), we collect the details you choose to provide, such as your name, email address, phone number, organization, and message.
Information from services you connect
- Google Calendar (optional) — if you turn on calendar sync, you authorize us, through Google, to create and manage a dedicated “Festro” calendar in your Google Account so we can add the events you reserve (and, if you opt in, the events you save). We use the narrowest available Google permission for this — the `calendar.app.created` scope — which lets us manage only the calendar we create, not the rest of your calendar. We store your Google account email and your sync preferences. You can disconnect at any time in your settings, which stops future syncing.
Information we collect automatically
- Usage data — how you use the Service (screens viewed, actions taken), collected via Firebase Analytics in aggregated form to improve the Service.
- Crash and diagnostic data — if the app crashes, Firebase Crashlytics collects your device type, OS version, and app state at the time, so we can fix the problem.
- Device and connection data — device identifiers, app version, and a truncated/approximate IP address used for security, fraud prevention, and abuse mitigation.
- Follows and activity — the organizers, artists, and venues you follow, and the events you save, so we can surface relevant events and (where you have enabled notifications) tell you about them.
- Push notification tokens — if you allow notifications, we store a token so we can notify you about events from the organizers, artists, and venues you follow.
- Cookies and similar technologies — on the website only. See our Cookie Policy for the full list and your choices.
How we use your information
We use your personal information to:
- Provide, operate, and maintain the Service;
- Authenticate you securely through passwordless email sign-in;
- Process your reservations, tickets, and payments, and enable check-in;
- Send you transactional messages about your account, reservations, and receipts;
- Send event announcements from the organizers, artists, and venues you follow (only where you have enabled notifications);
- Verify your phone number and, only where you have opted in, send you SMS updates and marketing (you can opt out at any time);
- Add events to a dedicated calendar in your Google Account, if you connect calendar sync;
- Monitor, debug, and improve performance, and develop new features;
- Protect the Service, our users, and the public against fraud, abuse, and security threats; and
- Comply with our legal obligations and enforce our Terms of Service.
We do not use your personal information for automated decision-making that produces legal or similarly significant effects about you.
Our legal bases (consent and otherwise)
Where Quebec Law 25 or PIPEDA applies, we rely on your consent or another lawful ground, and we limit our collection to what is necessary for the purposes above. Where the EU/UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you ask for (accounts, reservations, payments).
- Consent — for optional processing such as analytics cookies and push notifications. You can withdraw consent at any time (see Section 10).
- Legitimate interests — to secure, debug, and improve the Service and to prevent fraud and abuse, balanced against your rights.
- Legal obligation — to meet tax, accounting, and other legal requirements.
Where your information is stored and transferred
Your account data and reservation records are stored on servers located in Montreal, Quebec, Canada (Google Cloud Platform, northamerica-northeast1 region).
Some service providers (for example, certain Firebase analytics and crash-reporting functions, and our payment provider) may process or store data in the United States or other countries. Before transferring personal information outside Quebec, we assess whether it receives adequate protection, as required by Law 25, and we rely on contractual safeguards such as Standard Contractual Clauses where the GDPR applies.
How we protect your information
We use technical and organizational safeguards appropriate to the sensitivity of the information, including encryption in transit (TLS), access controls and least-privilege principles, network segmentation, and audit logging. No method of transmission or storage is perfectly secure, but we work to protect your information and to limit access to those who need it.
If a confidentiality incident creates a risk of serious injury, we will notify the Commission d’accès à l’information du Québec (CAI) and affected individuals as required by law, and will keep a register of such incidents.
How long we keep information
We retain your account data for as long as your account is active. When you delete your account, we delete or anonymize your personal information within 30 days, except where a longer period is required by law — for example, transaction and tax records are kept for up to 7 years. Backups are purged on a rolling schedule.
Your rights and choices
Depending on where you live, you have some or all of the following rights. Under PIPEDA and Quebec Law 25 you may:
- Access the personal information we hold about you and obtain a copy;
- Have inaccurate or incomplete information corrected;
- Request deletion of your account and associated information;
- Withdraw consent for optional processing (such as analytics or notifications); and
- Request that computerized personal information you provided be communicated to you or, where technically feasible, to another organization (data portability).
If the GDPR applies to you, you also have the right to restrict or object to certain processing and to lodge a complaint with your local supervisory authority. If you are a California resident, you have the right to know, delete, and correct your personal information, and to not be discriminated against for exercising your rights; because we do not sell or share personal information, no opt-out of sale is required.
To exercise any of these rights, use our contact form. We respond within 30 days and will not charge you a fee in ordinary cases. We may need to verify your identity before acting on a request.
To change your analytics-cookie choice on the website at any time:
Current: not setChildren
The Service is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, reach us through our contact form and we will delete it.
Changes to this policy
We may update this policy from time to time. For material changes, we will notify you in the app or by email at least 14 days before they take effect, and we will update the “Last updated” date above. Your continued use of the Service after the effective date means you accept the updated policy.
Contact and complaints
For privacy questions or to exercise your rights, contact our Privacy Officer:
Title: Privacy Officer (Person in charge of the protection of personal information) — the Founder of Festro Inc.
Email: [email protected]
Online: our contact form
If you are not satisfied with our response, Quebec residents may contact the Commission d’accès à l’information du Québec (CAI) at www.cai.gouv.qc.ca. Other Canadians may contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca. EU/UK residents may contact their local supervisory authority.
Also see: Terms of Service · Cookie Policy