Privacy Policy

Effective 2026-07-20. Applies to the Passetta app for HubSpot.

Passetta issues digital membership passes from HubSpot contacts and records check-ins back to HubSpot. HubSpot remains your CRM and system of record. We store only the minimal data described below — never a copy of your full contact database.

What we store

What we do not store

How we use it

Stored data is used only to render pass pages, validate QR scans, record check-ins, and write those check-ins back to HubSpot. We use aggregate, non-identifying product analytics to understand feature usage. We do not sell personal data, and we do not share it with advertisers or data brokers.

Who else sees it

Passetta runs on Cloudflare's infrastructure (hosting, database, and edge network) as our processor. HubSpot receives the check-in and activity data we write back to it, under your own agreement with HubSpot. No other third party has access to member data.

Retention and deletion

Questions about your data, or a deletion request that hasn't been honored? Contact support@passetta.com — see the Support page for what to include so we can respond quickly.

Security

OAuth tokens and pass snapshots are encrypted at rest. QR tokens are never stored in reversible form, only hashed. Every request from a HubSpot UI extension is signature-verified before it reaches application logic, and data is scoped per HubSpot account so one customer's data is never reachable from another's.

Changes to this policy

If this policy changes materially, we will update the effective date above and, where practical, notify installed accounts through HubSpot.