CALMVILLE AIR · PASSENGER DATA
Privacy Policy
Who we are
Tickets to Calmville (ticketstocalmville.com) is run by Tickets to Calmville, an individual operator in California, United States. Questions: sam@ticketstocalmville.com.
What this covers
This policy covers this website only. Optional tips are paid on Stripe's website under Stripe's privacy policy. Our email delivery provider and our hosting provider have their own policies, linked below.
What we collect, and why
When someone books a ticket, we store the following. Nothing else is collected: there are no accounts, no analytics, no advertising, and this site sets no cookies. Everything in the first table is kept until the ticket is hidden or removed. A hidden ticket stays in the database marked hidden so it cannot be re-issued, and is shown nowhere.
| What | Why | Who can see it |
|---|---|---|
| The passenger's name (the person the ticket is for), as the sender typed it. | It is printed on the ticket. | Anyone with the ticket link. Shown in full in the link-preview image when the ticket link is shared. Initials only on the homepage departures board. |
| The sender's name, as typed. | It is printed on the ticket. | First name only on the ticket page and in the link-preview image; initials on the departures board. The full name is sent in the delivery email and kept in the database. |
| The optional note (up to 280 characters). | It is printed on the ticket. | Anyone with the ticket link. |
| Class of service chosen. | Ticket details. | Anyone with the ticket link, and the homepage departures board (alongside initials only). |
| Number of tickets (1, 2 or 4). | Ticket details. | Anyone with the ticket link, and the homepage departures board (alongside initials only). |
| Whether the ticket is a calm-down ticket or an apology. | Ticket details. | Anyone with the ticket link, and the homepage departures board (alongside initials only). |
| Who travels on an apology ticket (both of you, or the sender alone). | Ticket details. | Anyone with the ticket link, and the homepage departures board (alongside initials only). |
| A made-up seat number generated at booking. | Ticket details. | Anyone with the ticket link. |
| A made-up gate generated at booking. | Ticket details. | Anyone with the ticket link. |
| A made-up flight number generated at booking. | Ticket details. | Anyone with the ticket link. Also on the homepage departures board once the ticket is boarded ("T.S. boarded flight CV-108"). |
| The sender's approximate region (for example, "California"), as reported by our hosting provider from the sender's connection. | Shown on the departures board ("California, US"). | Homepage departures board, with initials only. |
| The sender's approximate country, as reported by our hosting provider. | Shown on the departures board. | Homepage departures board, with initials only. |
| A keyed hash (HMAC-SHA-256) of the sender's IP address; for IPv6, of the network prefix. We do not store the address itself. The key is a secret held by the hosting platform, separately from the database and its backups; without it, the hash cannot be matched back to an address, even by testing every possible address. We still treat it as personal information and keep it only as long as the ticket. | To limit how many tickets one connection can send per hour, and to count how many different people reported a ticket. | Only the operator, in the database. |
| A simplified form of the passenger's name (lower-case, punctuation and spacing removed). | To limit how many tickets can be sent to one name per hour, so a person cannot be piled on. | Only the operator, in the database. |
| Whether the ticket is issued, has been "boarded" (the reader reached the end of the flight on the ticket page, including by skipping ahead), or is hidden. | To show the right page, and to keep hidden tickets hidden. | "Boarded" is shown on the departures board, with initials only. |
| When the ticket was booked. | Departures board ordering and the hourly limits. | Relative time ("4 min ago") on the departures board. |
When someone reports a ticket, we store:
| What | Why | How long | Who can see it |
|---|---|---|---|
| Which ticket a report is about. | To hide a ticket once enough different people report it. | With the ticket. | Only the operator, in the database. |
| The optional reason given with a report (up to 500 characters). | To review reports. | With the ticket. | Only the operator, in the database. |
| A hash of the reporter's IP address (same method and same limits as above). | To count distinct reporters and limit reports per hour. | With the ticket. | Only the operator, in the database. |
| When the report was made. | Hourly report limits. | With the ticket. | Only the operator, in the database. |
When someone removes a ticket with "This is me — take it down", or the operator blocks a name or a sender, we store a stop:
| What | Why | How long | Who can see it |
|---|---|---|---|
| What a stop applies to: one sender for one name ("self" — created when the person named removes a ticket), a name for every sender, or a sender for every name. | To refuse a repeat booking before it is created or emailed. | Until the stop expires (90 days by default, never more than a year) or the operator revokes it. Expired rows are deleted the next time a stop is recorded or the operator opens the blocks list; for a "self" stop only the ticket id is kept (see below). | Only the operator, in the database. |
| The simplified passenger name the stop applies to (same form as above). | To match a future booking to the stop. | Until the stop expires (90 days by default, never more than a year) or the operator revokes it. Expired rows are deleted the next time a stop is recorded or the operator opens the blocks list; for a "self" stop only the ticket id is kept (see below). | Only the operator, in the database. |
| The sender hash the stop applies to — copied from the ticket that was removed, i.e. the sender's connection, hashed as above. Nothing about the person who clicked "take it down" is stored. | To match a future booking from the same sender to the stop. | Until the stop expires (90 days by default, never more than a year) or the operator revokes it. Expired rows are deleted the next time a stop is recorded or the operator opens the blocks list; for a "self" stop only the ticket id is kept (see below). | Only the operator, in the database. |
| For a "self" stop, which ticket the person named removed. Empty on operator blocks. | So the operator can see the ticket was removed by the person named, and can never restore it. | After the stop expires, the name and sender hash on the row are cleared and only this ticket id remains, for as long as the ticket does, so the ticket can never be restored. Deleted if the operator revokes the stop while it is active. | Only the operator, in the database. |
| When the stop ends. | Stops are temporary. | Until the stop expires (90 days by default, never more than a year) or the operator revokes it. Expired rows are deleted the next time a stop is recorded or the operator opens the blocks list; for a "self" stop only the ticket id is kept (see below). | Only the operator, in the database. |
| When the stop was created. | Ordering in the operator view. | Until the stop expires (90 days by default, never more than a year) or the operator revokes it. Expired rows are deleted the next time a stop is recorded or the operator opens the blocks list; for a "self" stop only the ticket id is kept (see below). | Only the operator, in the database. |
What we deliberately do not collect or keep
- The passenger's email address. If the sender chooses email delivery, the address is sent once to our email provider to deliver the ticket and is not stored or written to any log.
- Phone numbers. We never ask for one. "Text it yourself" opens the sender's own messaging app; the message leaves from their phone and the number never reaches us.
- Anything chosen during the breathing exercise on a ticket page. That stays in the reader's browser (session storage, cleared when the tab closes) and is never sent to us. Reaching the end of the exercise does mark the ticket "boarded", which the departures board shows with initials only.
- IP addresses. We store only a hash, described in the table above, together with what that does and does not protect.
- Tracking, analytics, advertising identifiers. None. This site sets no cookies; see the Cloudflare note below for the one security cookie the network may set.
What is public
A ticket page is visible to anyone who has its link. It shows the passenger's full name, the sender's first name, the note, and the ticket details. The link-preview image shown when a ticket link is shared carries the passenger's full name (and, on a companion fare, the sender's first name). The homepage departures board shows initials, class, number of tickets, and region only — "A.S. sent T.S. two first-class tickets — California, US" — and notes when a ticket has been boarded. A hidden ticket is shown nowhere. Only the operator can restore one, and only when a report turns out to have been mistaken; it never comes back on its own. A ticket removed by the person named on it cannot be restored at all.
Who we share with
- Cloudflare (hosting, database, and the network in front of the site). As the network, Cloudflare sees visitors' IP addresses under its own policy, even though this application stores only a hash. Cloudflare keeps technical request logs for up to 7 days for debugging; they can include request URLs, headers, and approximate location. The application never writes email addresses, IP addresses, or ticket notes to those logs. If Cloudflare's network challenges a request it believes is automated, it may set a short-lived security cookie (
cf_clearance, or__cf_bmif bot protection is turned on) so you are not challenged again for about 30 minutes; it is used only to pass that check, not to identify you across websites. - Resend (email delivery, United States), only when the sender chooses email delivery. Resend receives the passenger's email address and the ticket email, and keeps delivery records under its own policy.
- Stripe (optional tips). Tipping happens on Stripe's website (buy.stripe.com) under Stripe's privacy policy. Stripe collects the payment details and email address you enter there and, for fraud detection, identifying information about the device and connection used, including its IP address. In Stripe's dashboard we can see what Stripe recorded for a payment: amount, receipt number, the email address and name you entered, card brand, last four digits, expiry and issuing country, billing country and postal code if asked for, and Stripe's fraud-screening details (including an approximate location), for as long as Stripe keeps them. We use that only for accounting and refunds, and we do not export or copy it anywhere else.
We do not sell personal information, and we do not share it for advertising.
Your choices
- If a ticket names you and you want it gone, use "This is me — take it down" at the bottom of the ticket page. It is hidden instantly, no questions asked, and the sender of that ticket is refused if they try to book you another within 90 days. We never ask you to prove who you are, and nothing about you is stored when you do this. If that does not work, Support explains the email fallback.
- If you sent a ticket and regret it, the same control works for you.
- We do not offer a way to edit a ticket after booking — only to remove it.
Do Not Track and third-party tracking
We do not track visitors across websites, and this site sets no cookies and uses no analytics, so browser "Do Not Track" signals have nothing to act on. No third party collects information about your activity on this site over time or across other sites. When you follow the tip link you leave this site for Stripe's, which has its own policy.
Children
This site is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child's information is on a ticket, email us and we will remove it.
Security
The site is served over HTTPS. IP addresses are stored only as hashes (see the table above for what that does and does not protect), email addresses are never stored, and logs are short-lived. No method is perfect; we keep as little as the site needs to work.
California
This policy is posted to comply with the California Online Privacy Protection Act. The California Consumer Privacy Act does not apply to this site (it is far below the law's revenue and volume thresholds); regardless, we do not sell or share personal information.
Changes
We have no accounts and keep no email addresses, so the only way we can tell you about a change is here: a new effective date at the top of this page, plus a short note of what changed, kept for 30 days.
Contact
sam@ticketstocalmville.com · PO Box 841, Blue Lake, CA 95525