Privacy Policy
Last updated: August 25, 2026
This Privacy Policy explains how PLURTiX LLC ("PLURTiX," "we," "us," or "our") collects, uses, discloses, and retains personal information when you use the PLURTiX mobile application, our websites (including plurtix.com and shared event pages), and related services (together, the "Platform"). It also serves as our Notice at Collection for California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
The short version: we collect only what the marketplace needs to work. We never see your card or bank details (PayPal processes all payments). We do not sell your personal information, do not share it for cross-context behavioral advertising, and do not use third-party advertising or analytics trackers in the app. Location is opt-in, encrypted, and blurred before other users ever see anything derived from it.
1. Information We Collect
Information you provide:
- Account information: your email address, username (public @-handle), and password (stored only as a secure hash — we never store your actual password). When you set a password we check it against known breached-password lists using a privacy-preserving method: only a partial hash prefix is sent to the checking service (Have I Been Pwned) — never the password itself or any account information.
- Profile and shipping information: if you buy or sell a shipped ticket, your first and last name and shipping address, which are snapshotted onto the order at checkout so the seller ships to the address you approved.
- Payment linkage (sellers): when a seller connects PayPal, we receive and store the PayPal merchant ID and the PayPal account's primary email so payments can be routed. Payments are processed entirely by PayPal; PLURTiX never sees or stores card numbers, bank accounts, or PayPal credentials. For each order we store provider transaction identifiers, statuses, and fee/refund amounts needed to reconcile our records with PayPal.
- Location (optional): if you grant permission, your device's precise location, used to (a) sort events near you and (b) if you list a ticket for in-person delivery, show buyers a generalized distance estimate. You may instead provide a ZIP code, which we convert to an approximate centroid. Your stored coordinates are encrypted at rest; a listing's coordinates are rounded (to roughly 1 km) before any value derived from them is sent to a buyer's device — buyers never receive your exact coordinates or address. You can revoke location access at any time in your device settings or clear your saved location in the app.
- User-generated content: ticket listings (event, price, section/row/seat, description), chat messages (encrypted at rest), chat photo attachments, and delivered ticket files. Ticket files may contain the name or barcode of the original purchaser.
- Support, feedback, and event requests: messages you send through in-app feedback, event requests, or the website contact form, with the email address needed to respond — even if you do not have an account.
- Consent records: when you accept our Terms and this policy, we record the version accepted, the time, and your IP address, so we can demonstrate consent.
Information collected automatically:
- Device and notification data: a push-notification token (stored encrypted) if you enable push notifications. We access your photo library or camera only when you choose to attach a photo or upload a ticket; we do not read your contacts or other device data.
- Log and usage data: IP address, request metadata, device type, and app version, plus server error logs, used for security, rate limiting, fraud prevention, and keeping the Platform working. If we enable in-app crash reporting (Sentry), crash reports will include device information and app state at the time of the crash; crash reporting is currently disabled.
- Order and delivery data: order status, delivery method, tracking numbers (stored encrypted) and carrier tracking status for shipped tickets.
Information from third parties:
- PayPal: seller onboarding status, merchant ID, and primary email (with the seller's consent given during PayPal onboarding); payment capture and dispute status via PayPal webhooks.
- Shipping carriers (UPS, USPS, FedEx, DHL): tracking status for a tracking number a seller entered.
- Edmtrain: public event data (names, dates, venues, artist lineups) — this is event information, not personal information about you.
2. California Notice at Collection — Categories, Purposes, Retention
| CCPA category | What we collect & why | Disclosed to | Retention |
|---|---|---|---|
| Identifiers | Email, username, IP address, push token, PayPal merchant ID/email (sellers) — for accounts, login, notifications, payments, security | Service providers (Section 5); your counterparty sees your username | Life of account; transaction records up to 7 years after deletion (Section 4) |
| Customer records (Civ. Code § 1798.80(e)) | Name, shipping address — for shipping fulfillment | The seller in your transaction; file storage provider | Life of account; order snapshots per Section 4 |
| Commercial information | Listings, orders, purchases/sales, prices, fees, refunds, disputes — to operate the marketplace and comply with financial obligations | PayPal; your counterparty | Up to 7 years |
| Internet or network activity | Log data, app version, device type, request metadata — for security, rate limiting, fraud prevention, debugging | Hosting provider; crash-reporting provider if enabled | Short-term operational logs |
| Geolocation (precise = sensitive PI) | Optional GPS coordinates or ZIP centroid; listing coordinates (blurred before display) — to sort nearby events and show distance estimates | Never disclosed in precise form; buyers see only a rounded distance | Until you clear it or delete your account |
| Audio/visual information | Photos you attach to chats or deliveries; ticket files — to deliver tickets and coordinate orders | Your counterparty; file storage provider | Deleted 180 days after the related event |
| Sensitive personal information | Precise geolocation (above) and account login credentials (password hash) — only to provide the services you request | Not disclosed | As above |
| Inferences; biometric; health; protected classifications | Not collected | — | — |
We do not sell personal information, do not share it for cross-context behavioral advertising, and have not done so in the preceding 12 months. We use sensitive personal information (precise geolocation) only to provide the services you request, a use for which the CPRA does not require a "Limit the Use of My Sensitive Personal Information" option; we offer no other uses.
3. How We Use Your Information
We use personal information to: operate and improve the Platform; create and secure accounts; process and track orders and deliveries; route payments through PayPal and handle refunds; send transactional push notifications and emails (order updates, delivery reminders, verification codes, security notices); provide the in-app chat between transaction parties; respond to support requests; investigate fraud, enforce our Terms, and moderate content; and comply with legal obligations. We may create and use aggregated or de-identified data that can no longer reasonably identify you (for example, overall sales statistics), and we will not attempt to re-identify it.
We do not use your personal information for third-party advertising, and the app contains no advertising or third-party analytics SDKs.
4. Data Retention
- Account data: kept while your account is active.
- Chat messages, chat attachments, and delivered ticket files: automatically and permanently deleted 180 days after the event they relate to.
- Abandoned checkouts: pending orders that are never paid are deleted entirely.
- Verification codes and sessions: verification codes expire within minutes; refresh tokens are deleted on logout, deletion, or expiry.
- Account deletion: if you delete your account (Profile screen in the app, or www.plurtix.com/data-request), we immediately and permanently remove your profile information — name, shipping address, location, ZIP code, PayPal details, password, and push token — and the account can no longer be used. We retain records of completed transactions, and the account email associated with them, for legal and financial compliance, fraud prevention, and dispute handling, for up to 7 years; consent records (policy version, timestamp, IP) are retained as evidence of consent for as long as a claim could arise. Residual copies may persist in encrypted backups for a limited period before being overwritten.
5. How We Disclose Information
We disclose personal information only as follows — never for anyone else's marketing:
With your transaction counterparty: a buyer sees the seller's username, listing details, and (for in-person listings) an approximate distance; a seller sees the buyer's username and, for shipped orders, the buyer's name and shipping address; both parties see the order chat.
With service providers (CCPA "service providers"/"contractors"), bound by contract to use data only to provide their service: PayPal (payment processing, fund custody, seller onboarding, disputes), Expo (push-notification delivery), Resend (transactional email delivery), Cloudflare R2 (file storage for ticket files, chat attachments, and delivery photos), Railway (cloud hosting and databases), Have I Been Pwned (breached-password check — receives only a partial hash prefix, never your password or identity), and, if crash reporting is enabled, Sentry (crash diagnostics).
With shipping carriers: for shipped tickets we send the carrier (UPS, USPS, FedEx, or DHL) the tracking number the seller entered, to look up delivery status. We do not send the carrier your name or address; sellers purchase postage outside the Platform.
For legal reasons: if required by law, subpoena, or court order, or to protect the rights, property, or safety of PLURTiX, our users, or the public (including fraud investigation and cooperation with law enforcement regarding counterfeit tickets).
Business transfers: if PLURTiX is acquired, merges, or sells assets, personal information may be transferred as part of that transaction, subject to this policy.
6. Security
We protect personal information with: TLS encryption in transit; hashed passwords; field-level encryption at rest for sensitive fields (email, name, addresses, coordinates, PayPal email, push tokens, tracking numbers, and chat messages); redaction of personal information and credentials from server logs; verification of payment-webhook signatures; and access controls. Authorized PLURTiX staff can access account, order, and dispute information through internal admin tools solely to provide support, moderate listings and users, investigate fraud, and resolve disputes. No system is completely secure, and we cannot guarantee absolute security. If a breach affects your unencrypted personal information, we will notify you and regulators as required by California Civil Code § 1798.82 and other applicable law.
7. Your Choices
- Push notifications: turn them off in device settings at any time.
- Location: revoke the app's location permission in device settings, or clear your saved location in the app; you can use the Platform without location (ZIP or no location at all).
- Access, correct, update: edit your profile, shipping address, and username in the app.
- Delete: delete your account in the app (Profile screen) or, without signing in, at www.plurtix.com/data-request (deletion requires confirming a code emailed to the address on file, so no one else can delete your account).
- Export: request a copy of your data at www.plurtix.com/data-request; we email it to the address on file.
8. California Privacy Rights (CCPA/CPRA)
California residents have the right to: (a) know/access the personal information we collect, use, and disclose, including the specific pieces; (b) correct inaccurate personal information; (c) delete personal information, subject to statutory exceptions (e.g., completing transactions, security, legal compliance); (d) portability — receive a copy in a usable format; (e) opt out of sale or sharing — we do not sell or share personal information, so there is nothing to opt out of; (f) limit use of sensitive personal information — we use it only for exempt service purposes, so no limit option is required; and (g) non-discrimination for exercising any right.
How to exercise these rights: use the data request page at www.plurtix.com/data-request, the in-app tools described in Section 7, or email support@plurtix.com with the subject line "Privacy Request." We verify requests by acting only on — and delivering results only to — the email address on file for the account; deletion additionally requires confirming an emailed one-time code. We respond within 45 days (extendable once by 45 days with notice). You may designate an authorized agent; we may require proof of the agent's authorization and may still verify your identity directly. We do not charge a fee for requests unless they are excessive or repetitive.
Opt-out preference signals. We honor the Global Privacy Control (GPC) where applicable; because we do not sell or share personal information, there is no sale or sharing for such a signal to opt out of.
Shine the Light. California Civil Code Section 1798.83 lets California residents request, once a year and free of charge, information about personal information disclosed to third parties for those third parties' own direct-marketing purposes in the prior calendar year. We do not disclose personal information to third parties for their own direct-marketing purposes, but you may still submit a request to support@plurtix.com.
9. Other U.S. State Privacy Rights
If you are a resident of a state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Texas, Oregon, or others), you may have similar rights to access, correct, delete, and obtain a copy of your personal information, and to opt out of targeted advertising, sale, or profiling (we do none of these). To exercise these rights, use the channels in Section 8.
If we decline to act on your request, you may appeal by emailing support@plurtix.com with the subject line "Privacy Appeal." We will respond to your appeal within 45 days. If we deny your appeal, you may contact your state attorney general.
10. Children
The Platform is for adults 18 and older and is not directed at children. We do not knowingly collect personal information from anyone under 18 (and in no event from children under 13). If you believe a minor has created an account, contact support@plurtix.com and we will delete it.
11. International Users
The Platform is intended for users in the United States, and your information is processed and stored in the United States. If you access the Platform from outside the United States, you do so at your own initiative and consent to the processing of your information in the United States.
12. Do Not Track
Some browsers offer a "Do Not Track" signal. There is no accepted industry standard for responding to DNT, so we do not respond to it. (This is separate from the Global Privacy Control, which we honor as described in Section 8.)
13. Changes to This Policy
We may update this Privacy Policy periodically. If we make a material change, you must review and explicitly accept the updated policy in the app before you can continue using the Platform. We do not send an email notice of changes — if you do not accept the updated policy, you will not be able to use the Platform.
14. Contact
PLURTiX LLC
5101 Santa Monica Blvd Ste 8 #273
Los Angeles, CA 90029
Phone: (818) 505-4263
support@plurtix.com — or the contact form at www.plurtix.com/contact