1. Scope
This Privacy Policy explains how Stardust Garage collects, uses, discloses, retains, and protects personal information when you visit sdgatx.com, use SDG Mobile (our iOS and Android application), create an account, apply for or use a membership, buy or claim an event ticket, visit our venue, or otherwise interact with us (collectively, the "Services").
This Policy does not change the terms of any separate liability waiver, ticket terms, membership terms, or written agreement you accept. Where a separate agreement specifically addresses a record, that agreement may control for that record.
2. Personal information we collect
We collect information you provide, information generated through your use of the Services or venue, and limited technical information collected automatically.
Account and identity information
When you create or use an account, we may collect your first and last name, display name, email address, phone number, birthdate, account credentials, and authentication information. Passwords are handled through Supabase Auth; we do not keep your plaintext password. If you choose Apple or Google sign-in, our authentication providers may process provider account identifiers and authentication tokens needed to sign you in.
We use birthdate to help verify age eligibility for our 23+ venue admission policy (except for events expressly designated as all ages) and our account rules. We do not use birthdate to make automated decisions about you.
Membership, ticket, and venue records
We may collect your membership tier, membership status, application responses, subscription and billing status, ticket and order history, QR or other admission credentials, check-in times, attendance and admission history, and records of denied entry or service, including the reason. We use these records to operate memberships, issue and validate admission, prevent fraud and misuse, manage venue safety, and provide support.
Payment information
Payments are processed by Stripe. We receive payment-related records needed to operate the transaction, such as Stripe customer or payment references, payment status, subscription state, transaction history, amount, currency, and refund information. We do not store full payment-card numbers, CVV codes, or complete card details on our systems.
Agreements, waivers, signatures, and photos
When you sign a contract, agreement, or liability waiver, we collect the signature or electronic acceptance record and related evidence, which may include the agreement or waiver version, document hash, timestamp, IP address, and user-agent information. If you choose to provide a profile or member-ID photo, we collect and store it for membership and door verification. Venue or event photo/video recordings are governed by the applicable waiver or photo/video release.
Device and technical information
We collect information about the device and connection you use with the Services, including IP address, user-agent, device platform, app version, push-notification token, timestamps, and feature or service usage. SDG Mobile uses Expo to deliver notifications through Apple Push Notification service (APNs) and/or Firebase Cloud Messaging (FCM), depending on your device. You can control push notifications through your device settings.
Advertising measurement on our website
On public pages of sdgatx.com, we use the Meta Pixel and Meta Conversions API, provided by Meta Platforms, Inc., to measure and improve our advertising on Facebook and Instagram. When you view a public page, view an event, or start checkout, Meta may receive the page address, the type of action, cookie identifiers (such as _fbp and _fbc), your IP address, and browser information. When an online ticket or membership purchase is completed, we send Meta the purchase value, currency, and event or plan reference, together with a hashed (scrambled) version of your email address and account identifier, so Meta can tell us whether an ad led to the purchase. We do not send Meta payment-card details, birthdate, photos, waiver records, or admission and check-in history.
We do not use Meta advertising tools on account, member, staff, ticket-wallet, or login pages, on pages reached through a private or unlisted link, or for activity that begins in SDG Mobile. Meta uses this information under its own terms and privacy policy, available at facebook.com/privacy/policy.
Information from communications and forms
We collect information you send in applications, inquiries, support requests, venue-rental forms, emails, or other communications with us. This may include contact information and the contents of your message.
3. App Store data-disclosure summary
For App Store privacy disclosures, the data categories below may be collected and linked to you when you use SDG Mobile or the Services:
- Contact information: name, email address, and phone number.
- Identifiers: account identifiers and admission or QR credentials.
- Purchases: membership, subscription, ticket, order, and refund history; payment-card entry is handled by Stripe.
- User content: application responses, support communications, contracts, agreement signatures, and waiver acceptances.
- Photos: a profile or member-ID photo only if you choose to provide one.
- Usage data: feature interactions, timestamps, ticket and admission history, and check-in or denial records.
- Device and technical data: IP address, user-agent, device platform, app version, and push-notification token.
- Other information relevant to eligibility and safety: birthdate and waiver-related records.
We use these categories for app functionality, account management, payments, security and fraud prevention, venue access, legal compliance, and, where configured, de-identified product analytics. SDG Mobile does not track you across apps or websites owned by other companies for targeted advertising, and activity that begins in SDG Mobile is excluded from the website advertising measurement described in Section 2.
4. How we use personal information
We use personal information to:
- provide, maintain, and improve the Services, memberships, tickets, venue access, and customer support;
- create and secure accounts, authenticate users, and prevent fraud, abuse, and unauthorized access;
- process membership applications, subscriptions, ticket orders, refunds, and related communications;
- issue, validate, and administer tickets, QR credentials, check-ins, and venue access;
- verify eligibility and enforce our age, safety, and conduct rules;
- obtain, preserve, and enforce waivers, contracts, releases, and other agreements;
- send transactional messages, security notices, event updates, membership information, and, if you opt in, marketing communications;
- deliver requested push notifications;
- understand feature use and improve the Services through aggregated or de-identified analytics where practicable;
- measure and improve our advertising on Meta platforms, as described in Section 2;
- comply with legal obligations, enforce our agreements, protect the safety of guests and staff, and establish, exercise, or defend legal claims; and
- carry out another purpose disclosed to you when we collect the information or with your consent where required.
5. How we disclose personal information
We do not sell personal information for money. On our website, we use Meta advertising tools as described in Section 2. Some privacy laws may treat this as sharing personal information for targeted advertising, also called cross-context behavioral advertising. You can opt out as described in Section 7. We disclose personal information only as reasonably necessary for the purposes described in this Policy, including:
- Service providers and infrastructure. Supabase provides authentication, database, and storage services; Vercel provides hosting and related infrastructure; Stripe processes payments; Expo helps deliver push notifications through APNs/FCM; Mailchimp may deliver marketing email when you opt in; and PostHog may provide de-identified or pseudonymous product analytics if configured.
- Advertising measurement. Meta Platforms, Inc. receives website activity and hashed purchase information as described in Section 2.
- Legacy ticketing. TicketTailor may process ticket information for the limited legacy events that remain on that system while we complete the transition to our ticketing platform.
- Professional advisors and business operations. We may disclose relevant information to lawyers, auditors, insurers, or professional advisors when reasonably necessary. QuickBooks is used for internal business accounting; we do not send customer personal information to QuickBooks as part of normal product operation.
- Safety, legal, and rights protection. We may disclose information to law enforcement, regulators, insurers, emergency responders, courts, or other parties where we reasonably believe disclosure is required by law or needed to protect the rights, safety, property, or operations of Stardust Garage, our guests, or others.
- Business transfers. Information may be disclosed in connection with a merger, financing, acquisition, sale of assets, reorganization, bankruptcy, or similar transaction, subject to applicable law.
- With your direction or consent. We may disclose information when you ask us to do so or give consent.
Third parties may handle information under their own privacy notices and terms. In particular, Stripe, Apple, Google, APNs, FCM, and TicketTailor may have their own obligations and privacy practices. We encourage you to review their policies.
6. Retention
We retain personal information only for as long as reasonably necessary for the purposes described above, including legal, accounting, safety, and dispute-resolution needs.
- We generally retain account information while your account remains active.
- We retain signed waiver evidence for at least four years, and longer if reasonably necessary for legal claims, insurance, or legal obligations.
- We retain payment and tax-related records for seven years where required or reasonably appropriate for accounting and tax compliance.
- We retain ticket, admission, and security records for an appropriate period to operate the venue, address safety issues, prevent fraud, and meet legal obligations. Where practicable, we anonymize or de-identify records that must be kept after an account is deleted.
Retention periods can be extended for a legal hold, active dispute, investigation, or another lawful purpose.
7. Your choices and privacy rights
Depending on where you live and applicable law, you may have the right to request access to, correction of, deletion of, or a portable copy of certain personal information we hold about you. You may also object to or ask us to limit certain processing where the law provides that right. To make a request, email hello@sdgatx.com from the address associated with your account. We may need to verify your identity before acting on a request and may retain or decline to delete information where the law permits or requires us to do so, including waiver, payment, tax, safety, fraud-prevention, and legal-claim records.
In-app account deletion. You can request deletion of your SDG Mobile account through the in-app account-deletion control. The same request can be made through the web account settings when available or by emailing hello@sdgatx.com. Account deletion removes account access and deletes or anonymizes personal information as described above, subject to records we must retain for legal, accounting, safety, and fraud-prevention purposes. Deleting your account does not cancel an active membership automatically; contact us to cancel any recurring membership before requesting deletion.
Marketing email. You can opt out of marketing email using the unsubscribe link in the message or by contacting us. We may still send non-marketing messages about your account, tickets, transactions, membership, security, or legal notices.
Advertising measurement. We honor Global Privacy Control (GPC) signals sent by your browser; when your browser sends one, we do not use Meta advertising tools for your visit. You can manage how Meta uses information for ads in your Facebook or Instagram ad settings. Blocking or clearing cookies may also limit this measurement.
Push notifications. You can disable push notifications in your device settings. Turning off push notifications does not stop email or other transactional communications that are necessary to provide the Services.
If a privacy law gives you a right to appeal a decision about your request, you may reply to our response and ask us to reconsider. You may also have the right to contact the applicable privacy regulator.
8. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. For example, payment-card entry is handled by Stripe rather than our systems, profile photos are stored in access-controlled storage, and we use authentication, access controls, logging, and rate-limiting measures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children and age restrictions
Stardust Garage is a 23+ venue. Guests must be at least 23 years old to enter unless Stardust Garage expressly designates the event as all ages. For attendees under 18 at an all-ages event, a parent or legal guardian must complete any required minor waiver.
Online account creation is limited to users age 18 or older. An account does not establish eligibility for venue admission. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information in violation of this Policy, contact us at hello@sdgatx.com.
10. International users
Stardust Garage is based in Austin, Texas, and the Services are operated in the United States. If you use the Services from outside the United States, you understand that your information may be processed in the United States and other locations where our service providers operate, subject to applicable law.
11. Changes to this Policy
We may update this Policy from time to time. We will post the updated Policy here and change the effective date. For material changes, we will provide additional notice when required by law, such as by email, in-app notice, or a prominent notice on the Services. Your continued use of the Services after the updated Policy takes effect is subject to the updated Policy to the extent permitted by law.
12. Contact us
For privacy questions or requests, contact:
Simple Boring Office LLC d/b/a Stardust Garage Austin, Texas hello@sdgatx.com