PurposePass Privacy and Data Protection Policy
How PurposePass handles organizer, supporter, ticketing, fundraising, demo-request and platform-administration information.
Reviewed August 30, 2026 · PurposePass portalOur privacy commitments
1. Scope and privacy roles
This policy applies to the PurposePass public website, organizer console, ticket checkout, My Tickets, organization workspaces, Customer Demo Workspaces, forms, communications, and related PurposePass services. Depending on the activity, CollabLynx may act as a business/controller for platform administration and its own communications, while a nonprofit organization may control the supporter, member, volunteer, sponsor, and event information it submits or collects through its workspace.
If you interact with PurposePass on behalf of or through a nonprofit, that organization may also provide its own privacy notice and control organization-specific marketing choices.
2. Information PurposePass may process
- Account and organization information: name, work email, phone, organization name, roles, workspace assignments, authentication and security events.
- Event and ticket information: ticket orders, attendee names, ticket status, QR credential references, check-in records, refunds or payment-status evidence.
- Supporter information: donations, sponsor contacts, volunteer information, membership/roster data, communication preferences and engagement history submitted or generated within an organization.
- Commercial information: PurposePass plan, agreements, invoices, platform-fee records and limited payment-provider metadata. Full payment-card numbers should remain with the applicable payment provider.
- Demo and verification information: Customer Demo Workspace requests, legal organization name, website, authorized representative details, EIN when supplied for potential live-workspace verification, verification status, and encrypted W-9 or IRS determination-letter documents voluntarily submitted by an organization.
- Technical information: IP address, browser/device data, timestamps, session/security data, diagnostics and product usage needed for security, reliability and support.
3. Ticket payments and third-party providers
Ticket proceeds are processed through the payment provider configured by the applicable nonprofit organization, such as Zeffy, Stripe, PayPal, Square, or another supported provider. Those providers operate under their own terms and privacy notices. PurposePass may receive transaction identifiers, payment status, amounts, fees and reconciliation metadata needed to issue tickets, maintain the ledger and support reporting.
4. Communications and consent
Transactional ticket, account, security, billing and service messages are separate from optional marketing. Organization email consent, PurposePass platform email consent and PurposePass SMS consent are stored separately and are not treated as interchangeable.
Platform administrators may access administrative contact records for legitimate platform operations. Administrative access is not blanket marketing consent. PurposePass marketing exports include only contacts who explicitly opted in to PurposePass email and have not unsubscribed. Organization marketing exports and Newsletters & Supporter Updates are scoped to that organization and its applicable consent records. PurposePass maintains organization-specific suppression records so a newsletter unsubscribe is not silently reversed by a later roster or contact import.
5. Organization uploads and member rosters
Organizations may optionally upload member rosters or other operational records to provide membership benefits or run events. Authorized organization users may also submit W-9 or IRS determination-letter documents for nonprofit verification; those documents are encrypted before storage and are made available only through authorized PurposePass download requests. Organizations are responsible for having the authority, notices and permissions needed to upload and use that information. PurposePass uses organization-scoped access controls so one organization should not receive another organization’s private data.
6. How information is used
- Provide ticketing, fundraising, supporter, sponsor, volunteer, membership, check-in, newsletters, reporting, nonprofit verification and organization-workspace functions.
- Authenticate users, enforce roles and tenant isolation, prevent abuse and investigate security issues.
- Process demo requests, support inquiries, commercial agreements, PurposePass billing and account administration.
- Maintain ledgers, audit records, reconciliation evidence, reporting and legally required business records.
- Send requested or consented communications and maintain opt-out/suppression records.
- Improve reliability and usability using appropriately limited, aggregated or de-identified information where practical.
8. Public Content and Search Engines
Organizations may choose to publish organization profiles, events, ticket information, public sponsor information, images, logos, descriptions and other content through PurposePass. When an organization enables public search visibility, PurposePass may make that public content available to search engines and discovery services through public webpages, structured metadata, canonical URLs, XML sitemaps, social-preview metadata and change-notification services such as IndexNow. Search engines and other third parties independently determine how and when they crawl, index, rank, cache, summarize or display public information.
PurposePass may use search-engine verification tools and may submit public URLs and limited public metadata to search/discovery providers for indexing and discovery. PurposePass does not intentionally submit private organization data to public search engines. If public information is later changed, removed or marked noindex, third-party search engines or caches may take additional time to refresh or remove previously collected copies.
9. Retention, export and deletion
Retention depends on the data type, organization configuration, transaction history, audit needs, legal obligations and account status. Financial, ticket, consent, newsletter suppression, nonprofit-verification, security and audit records may be retained where needed for accounting, fraud prevention, dispute resolution or legal compliance. Temporary Customer Demo Workspace data is governed by the demo expiration/cleanup process and is not copied into a live workspace except for approved configuration.
10. Security
PurposePass uses safeguards such as role-based access, tenant scoping, secure sessions, encryption where configured, logging, validation, anti-forgery controls and limited administrative access. No online system can be guaranteed completely secure; users should protect credentials and promptly report suspected compromise.
11. Rights and choices
Depending on applicable law, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or other privacy choices. For data controlled by a nonprofit organization, contact that organization first when appropriate. Promotional messages should provide an unsubscribe path; transactional, security, billing and legal messages may still be sent when necessary.
12. Children and restricted data
PurposePass is intended to support organizations and event transactions and is not designed as a general-purpose service directed to children. Organizations should not submit sensitive or specially regulated information unless the applicable PurposePass agreement and configuration expressly support it. Public forms should not be used to submit passwords, private keys, full payment-card data, medical records or other unnecessary sensitive information.
13. Contact
Questions or privacy requests can be submitted through the protected PurposePass contact form. PurposePass may verify identity and authority before acting on a request.