California Consumer Privacy Rights

Your California Privacy Rights

Under the California Consumer Privacy Act (CCPA, Cal. Civ. Code § 1798.100 et seq.) and its 2023 amendments (CPRA), if you are a California resident you have specific rights over the personal information sbTix holds about you. This page explains those rights and how to exercise them.

Short version: Individual event pages MAY load a Meta (Facebook) advertising pixel — only if the specific event organizer has enabled it, and only after you consent via the tracking banner. If you don't accept, nothing loads and no data is shared. You have full rights to access, delete, and correct anything we hold — the endpoints below work for every request regardless of where you live. Your Privacy Choices link at the bottom of every event page lets you change your mind any time.

Right to know

You can request a complete export of every piece of personal information sbTix holds about you — orders, tickets, subscribers, consent history, actions you've taken. The response is a machine-readable JSON file suitable for import into another platform.

We respond within 45 days as required by CCPA.

Right to delete

You can request deletion of your account and all personal information associated with it. Financial records (past ticket purchases, refunds) may be retained for up to 7 years as required by IRS regulations (26 U.S.C. § 6001), but your identifying information is anonymized on receipt of a deletion request. Marketing subscriber records are removed entirely.

Right to correct

You can update inaccurate personal information at any time by signing in to your account. For information you can't self-serve edit, email security@synthbridge.net.

Right to opt-out of sale or sharing

Under the CPRA definition of "share" (Cal. Civ. Code § 1798.140(ah)), transmitting personal information to a third-party advertising platform for cross-context behavioral advertising counts as sharing. On event pages where the organizer has enabled the Meta (Facebook) advertising pixel, page-view and view-content events are transmitted to Meta when — and only when — you accept via the tracking consent banner. This is opt-in: nothing loads if you do not accept.

Other third parties we use — a PCI DSS Level 1 payment processor and a SOC 2 Type II email delivery provider — act as our contractual processors only, and cannot use your data for their own purposes. They are NOT the Meta advertising pixel; those are separate.

Cookies & tracking technologies

The only third-party tracking technology sbTix loads on public event pages is the Meta (Facebook) advertising pixel, and only under the conditions described above (organizer-enabled and buyer-consented). We do not use Google Analytics, session-replay tools, third-party chatbots, or fingerprinting scripts on public buyer-facing pages. First-party cookies used for authentication, checkout session tracking, and consent-preference storage are strictly necessary and are not shared with third parties.

We record your consent decision on our servers (decision, notice version, timestamp, GPC signal state) so we have proof of what you consented to. This log is retained for 2 years to defend against tracker-consent claims, then purged. You may request its deletion at any time via the Right to Delete process above.

Right to limit sensitive personal information use

The only sensitive personal information sbTix collects is financial account information (limited to Stripe payment tokens — we do not store card numbers). This is used solely for processing your ticket purchases and cannot be used for any secondary purpose.

Right to non-discrimination

Exercising any of the rights above will not result in denial of service, different pricing, or reduced quality. Every sbTix feature remains available to you.

Categories of personal information we collect

Authorized agent requests

You may authorize another person or business to submit a rights request on your behalf. Email security@synthbridge.net with a signed authorization document and proof of your identity.

Verification

For account-based requests, being signed in verifies your identity. For requests made by email or by an authorized agent, we may ask for additional information to confirm the request is legitimate — typically the email address associated with your account plus a recent order number.

How to reach us

Privacy contact: security@synthbridge.net
Postal: SynthBridge Consulting LLC, 973-220-8280
We aim to respond to every privacy request within 10 business days and complete the request within 45 days as required by CCPA.

Last updated: 2026-08-06 · Related: General Privacy Policy · Security · Trust · Accessibility