CALMVILLE AIR · PASSENGER DATA

Privacy Policy

Effective 2026-08-22. This is the first version; when it changes materially we will update this date and keep a note at the top of this page for 30 days.

Who we are

Tickets to Calmville (ticketstocalmville.com) is run by Tickets to Calmville, an individual operator in California, United States. Questions: sam@ticketstocalmville.com.

What this covers

This policy covers this website only. Optional tips are paid on Stripe's website under Stripe's privacy policy. Our email delivery provider and our hosting provider have their own policies, linked below.

What we collect, and why

When someone books a ticket, we store the following. Nothing else is collected: there are no accounts, no analytics, no advertising, and this site sets no cookies. Everything in the first table is kept until the ticket is hidden or removed. A hidden ticket stays in the database marked hidden so it cannot be re-issued, and is shown nowhere.

Data stored when a ticket is booked
WhatWhyWho can see it
The passenger's name (the person the ticket is for), as the sender typed it.It is printed on the ticket.Anyone with the ticket link. Shown in full in the link-preview image when the ticket link is shared. Initials only on the homepage departures board.
The sender's name, as typed.It is printed on the ticket.First name only on the ticket page and in the link-preview image; initials on the departures board. The full name is sent in the delivery email and kept in the database.
The optional note (up to 280 characters).It is printed on the ticket.Anyone with the ticket link.
Class of service chosen.Ticket details.Anyone with the ticket link, and the homepage departures board (alongside initials only).
Number of tickets (1, 2 or 4).Ticket details.Anyone with the ticket link, and the homepage departures board (alongside initials only).
Whether the ticket is a calm-down ticket or an apology.Ticket details.Anyone with the ticket link, and the homepage departures board (alongside initials only).
Who travels on an apology ticket (both of you, or the sender alone).Ticket details.Anyone with the ticket link, and the homepage departures board (alongside initials only).
A made-up seat number generated at booking.Ticket details.Anyone with the ticket link.
A made-up gate generated at booking.Ticket details.Anyone with the ticket link.
A made-up flight number generated at booking.Ticket details.Anyone with the ticket link. Also on the homepage departures board once the ticket is boarded ("T.S. boarded flight CV-108").
The sender's approximate region (for example, "California"), as reported by our hosting provider from the sender's connection.Shown on the departures board ("California, US").Homepage departures board, with initials only.
The sender's approximate country, as reported by our hosting provider.Shown on the departures board.Homepage departures board, with initials only.
A keyed hash (HMAC-SHA-256) of the sender's IP address; for IPv6, of the network prefix. We do not store the address itself. The key is a secret held by the hosting platform, separately from the database and its backups; without it, the hash cannot be matched back to an address, even by testing every possible address. We still treat it as personal information and keep it only as long as the ticket.To limit how many tickets one connection can send per hour, and to count how many different people reported a ticket.Only the operator, in the database.
A simplified form of the passenger's name (lower-case, punctuation and spacing removed).To limit how many tickets can be sent to one name per hour, so a person cannot be piled on.Only the operator, in the database.
Whether the ticket is issued, has been "boarded" (the reader reached the end of the flight on the ticket page, including by skipping ahead), or is hidden.To show the right page, and to keep hidden tickets hidden."Boarded" is shown on the departures board, with initials only.
When the ticket was booked.Departures board ordering and the hourly limits.Relative time ("4 min ago") on the departures board.

When someone reports a ticket, we store:

Data stored when a ticket is reported
WhatWhyHow longWho can see it
Which ticket a report is about.To hide a ticket once enough different people report it.With the ticket.Only the operator, in the database.
The optional reason given with a report (up to 500 characters).To review reports.With the ticket.Only the operator, in the database.
A hash of the reporter's IP address (same method and same limits as above).To count distinct reporters and limit reports per hour.With the ticket.Only the operator, in the database.
When the report was made.Hourly report limits.With the ticket.Only the operator, in the database.

When someone removes a ticket with "This is me — take it down", or the operator blocks a name or a sender, we store a stop:

Data stored for a stop or block
WhatWhyHow longWho can see it
What a stop applies to: one sender for one name ("self" — created when the person named removes a ticket), a name for every sender, or a sender for every name.To refuse a repeat booking before it is created or emailed.Until the stop expires (90 days by default, never more than a year) or the operator revokes it. Expired rows are deleted the next time a stop is recorded or the operator opens the blocks list; for a "self" stop only the ticket id is kept (see below).Only the operator, in the database.
The simplified passenger name the stop applies to (same form as above).To match a future booking to the stop.Until the stop expires (90 days by default, never more than a year) or the operator revokes it. Expired rows are deleted the next time a stop is recorded or the operator opens the blocks list; for a "self" stop only the ticket id is kept (see below).Only the operator, in the database.
The sender hash the stop applies to — copied from the ticket that was removed, i.e. the sender's connection, hashed as above. Nothing about the person who clicked "take it down" is stored.To match a future booking from the same sender to the stop.Until the stop expires (90 days by default, never more than a year) or the operator revokes it. Expired rows are deleted the next time a stop is recorded or the operator opens the blocks list; for a "self" stop only the ticket id is kept (see below).Only the operator, in the database.
For a "self" stop, which ticket the person named removed. Empty on operator blocks.So the operator can see the ticket was removed by the person named, and can never restore it.After the stop expires, the name and sender hash on the row are cleared and only this ticket id remains, for as long as the ticket does, so the ticket can never be restored. Deleted if the operator revokes the stop while it is active.Only the operator, in the database.
When the stop ends.Stops are temporary.Until the stop expires (90 days by default, never more than a year) or the operator revokes it. Expired rows are deleted the next time a stop is recorded or the operator opens the blocks list; for a "self" stop only the ticket id is kept (see below).Only the operator, in the database.
When the stop was created.Ordering in the operator view.Until the stop expires (90 days by default, never more than a year) or the operator revokes it. Expired rows are deleted the next time a stop is recorded or the operator opens the blocks list; for a "self" stop only the ticket id is kept (see below).Only the operator, in the database.

What we deliberately do not collect or keep

What is public

A ticket page is visible to anyone who has its link. It shows the passenger's full name, the sender's first name, the note, and the ticket details. The link-preview image shown when a ticket link is shared carries the passenger's full name (and, on a companion fare, the sender's first name). The homepage departures board shows initials, class, number of tickets, and region only — "A.S. sent T.S. two first-class tickets — California, US" — and notes when a ticket has been boarded. A hidden ticket is shown nowhere. Only the operator can restore one, and only when a report turns out to have been mistaken; it never comes back on its own. A ticket removed by the person named on it cannot be restored at all.

Who we share with

We do not sell personal information, and we do not share it for advertising.

Your choices

Do Not Track and third-party tracking

We do not track visitors across websites, and this site sets no cookies and uses no analytics, so browser "Do Not Track" signals have nothing to act on. No third party collects information about your activity on this site over time or across other sites. When you follow the tip link you leave this site for Stripe's, which has its own policy.

Children

This site is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child's information is on a ticket, email us and we will remove it.

Security

The site is served over HTTPS. IP addresses are stored only as hashes (see the table above for what that does and does not protect), email addresses are never stored, and logs are short-lived. No method is perfect; we keep as little as the site needs to work.

California

This policy is posted to comply with the California Online Privacy Protection Act. The California Consumer Privacy Act does not apply to this site (it is far below the law's revenue and volume thresholds); regardless, we do not sell or share personal information.

Changes

We have no accounts and keep no email addresses, so the only way we can tell you about a change is here: a new effective date at the top of this page, plus a short note of what changed, kept for 30 days.

Contact

sam@ticketstocalmville.com · PO Box 841, Blue Lake, CA 95525