Your data, plainly explained.
Lit Galaxy collects what it takes to sell you a ticket, get you through the gate, run your wristband wallet, and keep the app working — on the website and in the mobile app. No ad tracking, no data brokers, no surprises.
Who this covers
This policy applies to everything Lit Galaxy runs for attendees, staff and vendors: litgalaxyfestival.com, the ticketing web app at app.litgalaxyfestival.com, the LitPay wallet, and the Lit Galaxy mobile app for iOS and Android. Lit Galaxy is the data controller. Our festival is held in Ontario, Canada, and we follow PIPEDA, Canada's federal privacy law.
The mobile app and the website share one account system, so a request you make in either place (correction, export, deletion) applies everywhere.
What we collect
We collect what is needed to sell you a ticket, get you through the gate, run the cashless wristband, and reply when you write to us. The categories below are every type of data Lit Galaxy holds about you.
- Account & contact: name, email, phone number, username, password (stored hashed), and a profile photo if you add one.
- Orders & payments: tickets purchased, order and transaction IDs, tax province, wallet top-ups and on-site purchases. Card numbers are entered directly into Stripe's secure fields and never touch our servers; we keep only the card brand and last four digits Stripe returns.
- Festival activity: sessions you save to your schedule, crews you join, artists you follow, rewards and challenges you complete, polls you answer, posts and comments you publish in the Festival Feed, and check-in scans at the gate.
- Wristband: the NFC serial of the wristband linked to your ticket and its wallet balance and transactions.
- Device & diagnostics (mobile app): a push-notification token, device model and OS version, app version, and crash reports (via Firebase Crashlytics) so we can fix what breaks. Crash data is not linked to your name.
- Precise location (mobile app, opt-in only): if you turn on live location sharing, your GPS position is shared with the crew members you choose, only while the feature is on, and stops the moment you turn it off. The venue map itself does not need your location.
- Camera & photos (mobile app): the camera is used to scan ticket QR codes (staff) and to take a profile picture; the photo library only to pick a profile picture. Images never leave your device except the profile picture you choose to upload.
- Face ID / Touch ID / fingerprint: used only to unlock the app locally. Biometric data stays on your device and is never sent to us.
- Communications: the content of any email, contact-form message or support thread you start with us.
- Website analytics: page views, referrer, anonymized IP and device type on this website only, to spot broken pages.
We do not collect government ID numbers, health records, contacts from your address book, or your location when live sharing is off.
How we use it
Each piece of data has an explicit purpose. We do not use your information for anything not listed here.
- Issue your ticket, verify it at the gate, and link it to your wristband.
- Process payments, wallet top-ups and refunds, and calculate the sales tax for your province.
- Send essential festival notifications: order receipts, gate times, schedule reminders you asked for, safety and weather alerts, and wallet activity. Marketing messages are only sent if you opted in.
- Run the in-app features you use: your schedule, crews, rewards, the Festival Feed and live location sharing.
- Respond to your messages and support requests.
- Detect fraud, protect the box office and keep accounts secure.
- Diagnose crashes and performance problems in the app.
We never sell your data, rent your email list, or share information with advertisers or data brokers, and we do not track you across other companies' apps or websites.
Your rights & deleting your account
Under PIPEDA and equivalent rules in your jurisdiction, you have the right to:
- Access a copy of the personal data we hold about you (request an export from the ticketing web app under Settings).
- Correct anything inaccurate — edit your profile in the app or the web app at any time.
- Delete your account and associated data.
- Withdraw consent from marketing emails at any time via the unsubscribe link, and from live location sharing by turning it off in the app.
- Object or restrict our processing on specific grounds.
To delete your account: in the mobile app go to Profile → Security → Delete account, or on the web visit litgalaxyfestival.com/settings/account/delete (sign-in required). Deletion is scheduled 14 days out so you can change your mind; signing back in lets you cancel it. After that your profile, contact details, preferences, schedule, crews, rewards progress and wallet settings are permanently removed. Tickets already issued stay valid on your wristband, and we keep the purchase records the law requires (see below) without your profile attached.
For any other request, email support@litgalaxyfestival.com with the word "privacy" in the subject and a brief description. We reply within 5 business days.
How long we keep it
- Account & profile — until you delete your account (14-day cool-off), then permanently removed.
- Ticket, order & wallet records — 7 years, as required for Canadian tax / consumer-protection regulations, kept without your profile after deletion.
- Live location — the current position only while sharing is on; nothing is kept once you turn it off.
- Push tokens & device diagnostics — until you sign out or uninstall; crash reports for 90 days.
- Newsletter subscriptions — until you unsubscribe.
- Contact-form messages — 24 months from your last reply, then purged.
- Website analytics — 13 months in aggregated form, then deleted.
Children
Lit Galaxy accounts are for people 13 and older; the festival itself has its own age rules for entry. We do not knowingly collect data from children under 13. If you believe a child has created an account, email us and we will delete it.
How we protect it
Lit Galaxy data is stored on TLS-encrypted infrastructure with at-rest encryption. Passwords are hashed, two-factor authentication is available on every account, and access to production systems is limited to named team members with two-factor authentication enforced. We review permissions quarterly and rotate keys yearly.
In the unlikely event of a security breach affecting your data, we will notify you and the Office of the Privacy Commissioner of Canada within 72 hours.
Changes to this policy
We may update this policy from time to time. Material changes are emailed to anyone with an active account at least 30 days before they take effect. The "last updated" date above always reflects the most recent revision.
Questions about your data?
Email the team — we read every message and reply within five business days.
Email Privacy Team