· Legal ·
Privacy Policy
Last updated: June 2026
1. Who we are
FirstRow ("we", "us") operates the verified fan identity platform at itsfirstrow.com. This policy explains what personal data we process and why. For questions, contact hello@itsfirstrow.com.
2. Data we collect
- Account: email, display name, password (hashed), nationality, and optional OAuth identifiers (Google, Apple).
- Passport & attendance: the events you add, the artists you follow, your verified shows and loyalty tiers.
- Ticket uploads: images or PDFs you submit to verify attendance, stored privately and accessible only to you and FirstRow admins.
- Payments: when you buy a drop, Stripe processes the transaction; we receive limited metadata (amount, status, last 4 digits) but never your full card details.
- Technical: IP address, browser, and basic usage logs for security and abuse prevention.
3. How we use it
To run your passport, verify attendance, compute loyalty tiers, determine drop eligibility, process payments and payouts, send transactional emails (verification, password reset, drop confirmations), and prevent fraud.
4. Who we share it with
- Stripe — payment processing and Connect payouts to artists.
- Lovable Cloud — our database, auth, and storage provider.
- Google / Apple — only if you choose social sign-in.
- Email provider — for transactional email delivery (notify.firstrow.com).
- Artists you attend or buy from — see aggregate attendance and loyalty data about you (never spending or financial data).
5. Cookies
We use strictly necessary cookies for sign-in and session persistence. No advertising or third-party tracking cookies.
6. Retention
Account and passport data are kept while your account is active. Ticket uploads are kept for as long as the attendance is verified. You can request deletion at any time by emailing hello@itsfirstrow.com.
7. Your rights
Depending on your jurisdiction (including the EU/UK under GDPR), you have the right to access, correct, export, or delete your data, and to object to processing. Email hello@itsfirstrow.com and we'll action requests within 30 days.
8. Security
Data is encrypted in transit (HTTPS) and at rest. Ticket uploads sit in a private storage bucket with row-level access control. We never expose other users' tickets or financial data.
9. Changes
We may update this policy. Material changes will be announced by email or on the site.
10. Contact
This is a template. Review with legal counsel before relying on it for compliance.