This Privacy Policy explains how Aethyra LLC ("Aethyra," "we," "us," or "our") collects, uses, discloses, and protects the personal information you provide when you use the Seatium platform — including our website, mobile application, and related services (collectively, the "Platform"). Please read this Policy carefully. By using the Platform, you agree to the practices described here.
01
Introduction
Seatium is an event ticketing and management platform operated by Aethyra LLC, a limited liability company. We take your privacy seriously. This Policy describes the types of personal information we collect across our Platform, how that information is used and shared, and the rights and choices available to you.
This Policy applies to all visitors and users of the Platform, including event attendees, guest purchasers, and event organizers. It does not apply to third-party websites or services that may be linked to or integrated with the Platform, even if those links appear on our Platform.
02
Who We Are
The Platform is owned and operated by:
3609 Chain Bridge Road, Suite C
Fairfax, VA 22030
Email: legal@seatium.co
Website: seatium.co
For purposes of data protection law, Aethyra LLC is the "data controller" with respect to personal information collected through the Platform.
03
Information We Collect
A. Information You Provide Directly
We collect information you submit to us when you create an account, make a purchase, or communicate with us. This includes:
- ▸Account Registration: Your username, email address, first and last name, password (stored as a secure hash — never in plain text), phone number, and profile photo (avatar).
- ▸Organizer Profile: Organization name, logo, and information required to set up a Stripe Connect payout account (collected and processed directly by Stripe).
- ▸Ticket Purchases (Registered Users): Name, email address, and ticket selection details.
- ▸Guest Checkout: Name and email address provided at the time of purchase, without creating an account. A one-time access token is generated to allow ticket retrieval.
- ▸Payment Information: We do not collect, store, or process your credit or debit card numbers. All payment processing is handled directly by Stripe, Inc. on our behalf. We receive confirmation of payment status and references (such as a Stripe Payment Intent ID or Charge ID), but never raw card data.
- ▸Organizer-Imported Contacts: If you are an organizer and use our email campaign feature, you may upload a CSV file containing names and email addresses of your contacts. You are solely responsible for having obtained all necessary consents from those individuals prior to uploading their information.
- ▸Communications and Support: Messages you send us through support channels or contact forms.
- ▸User-Generated Content: Event cover images, organizational logos, and other media you upload to the Platform.
B. Information Collected Automatically
When you use the Platform, we and our service providers collect certain information automatically, including:
- ▸Device Information: Device type (mobile, desktop, or tablet), browser type and version, and operating system.
- ▸Usage and Navigation Data: Pages you visit, time spent on each page, navigation paths, app sections visited, and page engagement duration. This data is collected via PostHog (see Section 7).
- ▸Traffic Source: How you arrived at the Platform — for example, direct, social media, organic search, or referral link.
- ▸IP Address and Geolocation: Your IP address is recorded at certain events (such as account login). We may derive approximate city- or region-level geolocation from your IP address. We do not collect GPS-level location data from your device without your explicit permission.
- ▸Session Identifiers: Unique identifiers for your session (PostHog session ID, PostHog distinct ID) used for analytics correlation and fraud detection.
- ▸Checkout Fingerprint: A non-reversible fingerprint generated during the checkout process solely for fraud detection and chargeback dispute purposes.
- ▸Ticket Scan Data: Timestamp and status recorded when a QR-coded ticket is scanned at an event for check-in verification.
- ▸Authentication Logs: Records of successful and failed login attempts, including timestamp, IP address, user agent, and geolocation data, for security monitoring purposes.
C. Information From Third Parties
- ▸Stripe: We receive payment status, account verification status, and payout account information from Stripe, Inc. in connection with payment processing and organizer onboarding.
- ▸PostHog: Aggregated product analytics data.
04
How We Collect Information
We collect information through the following means:
- ▸Direct Submission: When you register, purchase tickets, fill out forms, or contact us.
- ▸Cookies and Local Storage: We use browser cookies and local storage to maintain your login session, remember your UI preferences (such as dark/light mode), and support CSRF security protections. See Section 9 for details.
- ▸Analytics SDK (PostHog): Our Platform loads the PostHog analytics client on all pages. PostHog collects page view data, session information, and behavioral events through a JavaScript SDK embedded in the Platform.
- ▸Server-Side Logging: Our backend servers log login attempts, API errors, and other security-relevant events automatically.
- ▸Third-Party Integrations: Stripe and Mailgun may share event data with us in connection with payments and email delivery, respectively, as described in Section 7.
05
How We Use Your Information
We use the personal information we collect for the following purposes:
- ▸Providing the Platform: Creating and managing your account, processing ticket purchases, issuing QR-coded tickets, and facilitating event check-in.
- ▸Payment Processing: Transmitting purchase details to Stripe to authorize and complete your transaction; processing organizer payouts via Stripe Connect.
- ▸Transactional Communications: Sending order confirmations, ticket delivery emails, event reminders, event updates, and refund notifications via Mailgun.
- ▸Customer Support: Responding to your inquiries, resolving disputes, and providing assistance.
- ▸Fraud Detection and Security: Using checkout fingerprints, IP addresses, login logs, and behavioral signals to detect and prevent fraudulent transactions, unauthorized account access, and abuse.
- ▸Analytics and Platform Improvement: Understanding how users navigate the Platform, identifying usability issues, measuring feature adoption, and improving our product — using aggregated and anonymized analytics data (PostHog).
- ▸Legal Compliance and Dispute Resolution: Complying with applicable laws, responding to legal process, and enforcing our Terms of Service, including in connection with chargeback and dispute proceedings.
- ▸Marketing (With Consent): Sending promotional emails and product announcements where you have opted in or where permitted by law. You may opt out at any time.
07
Third-Party Services
The following third-party services process personal information in connection with the Platform. Each service operates under its own privacy policy, which we encourage you to review.
Stripe, Inc.
Purpose: Payment processing, Stripe Connect organizer payout accounts.
Data Shared: Payment card data (processed exclusively on Stripe's servers — we never receive or store raw card numbers), payment status, transaction metadata, and organizer banking information for payouts.
Privacy Policy: stripe.com/privacy
PostHog, Inc.
Purpose: Product analytics — page views, session recording, feature usage, and behavioral event tracking.
Data Shared: Device type, browser, IP address, page URLs (sanitized of sensitive path parameters), session duration, navigation events, and a pseudonymous distinct ID. Data is hosted on PostHog's U.S. infrastructure (us.i.posthog.com).
Privacy Policy: posthog.com/privacy
Mailgun Technologies, Inc.
Purpose: Transactional email delivery — order confirmations, ticket delivery, event reminders, and organizer campaign emails.
Data Shared: Recipient email address, sender name, and email content (including your name and order details).
Privacy Policy: mailgun.com/privacy-policy
Amazon Web Services, Inc. (AWS)
Purpose: Cloud file storage for user-uploaded media — profile avatars, organization logos, and event cover images.
Data Shared: Uploaded image files stored in Amazon S3. Files may be served via a CloudFront CDN. Maximum file size: 10 MB.
Privacy Policy: aws.amazon.com/privacy
Face Recognition (Planned Feature): Seatium's platform architecture includes a face recognition microservice intended to support optional AI-assisted photo matching for event check-in. This feature is not yet active. Before it is enabled, we will provide a separate, prominent disclosure and obtain explicit opt-in consent from all affected users. Processing of biometric identifiers may be subject to state biometric privacy laws, including but not limited to the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifiers Act (CUBI), and the Washington My Health MY Data Act, and we will comply with all applicable requirements before enabling this feature.
08
Organizer Data Responsibilities
If you use Seatium as an event organizer, you act as a data controller with respect to personal information belonging to your attendees and any contacts you import into the Platform. By using organizer features, you represent, warrant, and agree that:
- ▸You have obtained all legally required consents and authorizations before importing contact information (names and email addresses) into the Platform for use in email campaigns.
- ▸Any email campaign you send through the Platform complies with the CAN-SPAM Act (15 U.S.C. § 7701 et seq.) and all other applicable federal and state marketing and anti-spam laws, including providing a clear and functional opt-out mechanism.
- ▸You will use attendee personal data received through the Platform only for purposes related to your event (e.g., attendee communication, check-in, and legitimate event management) and not for unrelated marketing or commercial purposes without separate consent.
- ▸You will maintain appropriate security measures to protect any attendee data you download or store outside the Platform.
- ▸You will promptly honor any attendee data deletion or opt-out request that is directed to you.
Aethyra LLC processes attendee data on behalf of organizers in connection with event-specific functions (ticket sales, check-in, transactional emails). Aethyra is not responsible for an organizer's independent use of personal data outside the Platform.
10
Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention practices:
- ▸Account Data: Retained for the duration of your active account. Following account deletion, we retain certain data for a commercially reasonable period (typically up to 90 days) to allow for account recovery, then delete or anonymize it, subject to the exceptions below.
- ▸Financial and Transaction Records: Order records, payment metadata, and ledger entries are retained for a minimum of seven (7) years to comply with IRS recordkeeping requirements, tax obligations, and financial regulations — even after account deletion.
- ▸Security Logs: Login event logs and authentication records are retained for up to two (2) years for security monitoring and incident response purposes.
- ▸Analytics Data: Retained in accordance with PostHog's own retention policies. Aggregated or de-identified analytics data may be retained indefinitely.
- ▸Imported Contacts (Organizer): Retained until the organizer deletes them or closes their account.
- ▸Backup Systems: Data deleted from our live databases may persist in encrypted backups for up to 30 days before being purged.
11
Data Security
We implement industry-standard technical and organizational security measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- ▸Encryption in Transit: All communications between your browser and our servers are encrypted using TLS (HTTPS). We enforce HTTP Strict Transport Security (HSTS) to prevent downgrade attacks.
- ▸Secure Password Hashing: Passwords are hashed using Argon2 (the winner of the Password Hashing Competition) and are never stored in plain text.
- ▸No Card Data on Our Servers: We do not store payment card numbers, CVVs, or banking account details. All payment data is handled by Stripe, which is PCI DSS Level 1 certified.
- ▸Rate Limiting: Authentication endpoints are rate-limited to 5 requests per minute to protect against brute-force attacks.
- ▸Access Controls: Internal access to production systems is restricted to authorized personnel on a need-to-know basis.
- ▸Fraud Detection: Checkout fingerprinting and behavioral analytics are used to detect and prevent fraudulent transactions.
Despite our efforts, no security system is impenetrable. In the event of a data breach that affects your personal information, we will notify you and applicable regulatory authorities as required by law.
12
Your Privacy Rights
Depending on your state of residence, you may have certain rights with respect to your personal information. We honor these rights to the extent required by applicable law.
Rights Available to All U.S. Users
- ▸Access and Portability: You may request a copy of the personal information we hold about you.
- ▸Correction: You may update or correct inaccurate information in your account settings or by contacting us.
- ▸Deletion: You may request that we delete your personal information. Note that certain data (financial records, security logs) may be retained as described in Section 10.
- ▸Opt-Out of Marketing: You may opt out of promotional emails at any time by clicking "unsubscribe" in any marketing email or by contacting us.
- ▸Non-Discrimination: We will not discriminate against you for exercising any privacy rights.
California Residents — CCPA/CPRA
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- ▸Right to Know: The right to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes of collection, and the categories of third parties with whom we share it.
- ▸Right to Delete: The right to request deletion of your personal information, subject to exceptions.
- ▸Right to Correct: The right to correct inaccurate personal information.
- ▸Right to Opt-Out of Sale or Sharing: We do not sell your personal information as defined under the CCPA/CPRA. We do not share personal information for cross-context behavioral advertising.
- ▸Right to Limit Use of Sensitive Personal Information: The right to limit the use of sensitive personal information (such as biometric data) to certain permitted purposes.
Other U.S. State Rights
Residents of Colorado (CPA), Virginia (CDPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with comprehensive privacy laws may have rights similar to those described above, including rights to access, correct, delete, and obtain a portable copy of their data, and to opt out of targeted advertising and profiling for certain decisions. We will honor valid requests in accordance with applicable law.
Submitting a Request
To exercise any of the above rights, please contact us at legal@seatium.co. We will verify your identity before processing your request and respond within the timeframe required by applicable law (generally 45 days, with a possible extension for complex requests). We will not charge a fee for reasonable requests.
13
Children's Privacy
The Platform is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected personal information from a child under 13 without verifiable parental consent, we will take steps to delete that information as quickly as reasonably practicable.
If you are a parent or guardian and believe your child has provided personal information to us without your consent, please contact us at legal@seatium.co. If you are between 13 and 18 years of age, you may use the Platform only with the involvement and consent of a parent or legal guardian, and only in connection with events that are appropriate for your age.
Some events listed on the Platform may have age restrictions (such as 18+ or 21+). Attendees are responsible for ensuring they meet any age requirements stated by the event organizer.
14
International Users
Seatium is primarily designed for use within the United States. Our servers and infrastructure are located in the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country of residence.
By using the Platform from outside the United States, you acknowledge and consent to this transfer and processing. If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, please be aware that your personal information may not receive the same level of protection as it would in your home jurisdiction. We are primarily focused on U.S. privacy compliance and do not currently operate a GDPR-compliant framework for EU residents.
15
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email (to the address associated with your account), by posting a prominent notice on the Platform, or by updating the "Last Updated" date at the top of this page — whichever method is most appropriate given the nature of the change.
Your continued use of the Platform after any such update constitutes your acceptance of the revised Policy. If you do not agree to the updated Policy, you must stop using the Platform and may request deletion of your account.
16
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our privacy team:
3609 Chain Bridge Road, Suite C
Fairfax, VA 22030
Email: legal@seatium.co
General inquiries: info@seatium.co
We aim to acknowledge all privacy-related inquiries within five (5) business days and to resolve them within the timeframe required by applicable law.
This Privacy Policy is provided for informational purposes and does not constitute legal advice. Aethyra LLC recommends consulting qualified legal counsel for advice specific to your jurisdiction and circumstances.