Legal
Privacy Policy
Lepews LLC, a limited liability company formed in Delaware, United States, in 2023, operates MyPass. We use business account, event, attendee, usage, and support information to provide and secure the platform. Payment details are processed by our payment provider and are not stored as full card numbers or security codes by MyPass.
1. Scope and roles
This Privacy Policy applies to mypass.vip, Client subdomains, MyPass administrative tools, digital access passes, support, and related services.
For information submitted by a Client about its VIP attendees, the Client generally determines why and how the information is used, and Lepews acts as its service provider or data processor. For account administration, billing, security, website analytics, and direct communications with Lepews, Lepews may act as the data controller or business responsible for the information.
2. Information we collect
- Business and account information: names, business contact details, role, organization, login information, permissions, and account settings.
- VIP attendee and event information: names, contact information, access level, event, schedule, itinerary, companion or guest information, pass identifiers, validation status, and related notes provided by the Client.
- Digital pass information: wallet pass identifiers, device registration details, delivery status, and updates needed to issue and maintain a pass.
- Billing information: billing contacts, invoices, agreed pricing, measured usage, payment status, transaction references, and limited payment-method details such as brand and last four digits.
- Support and communications: demo requests, emails, form submissions, refund requests, and other communications.
- Technical and usage information: IP address, device and browser data, timestamps, logs, authentication activity, pages viewed, feature usage, and security events.
- Cookies and analytics: information collected through essential cookies and analytics technologies used to operate, understand, and improve the Service.
3. How we use information
- Provide, configure, and support the Service.
- Create, deliver, update, and validate VIP access passes.
- Send event information and operational notifications requested by the Client.
- Authenticate users, prevent misuse, investigate incidents, and protect the Service.
- Measure agreed usage, issue invoices, process payments, and respond to billing or refund requests.
- Maintain records, comply with law, enforce agreements, and resolve disputes.
- Analyze and improve performance and user experience.
- Respond to support, sales, and demo inquiries.
4. Legal grounds
Depending on the applicable law and context, we process information to perform a contract, follow a Client’s documented instructions, comply with legal obligations, protect legitimate business and security interests, or based on consent. Clients are responsible for establishing the lawful basis for attendee data they provide to MyPass.
5. Payment processing
When payment processing is enabled, card and payment credentials are collected and processed by Stripe or another disclosed payment provider. MyPass does not store full card numbers or card security codes. Payment providers may process information under their own privacy terms and as our service providers where applicable.
6. How we share information
We may share information:
- With the Client that provided or controls the information and its authorized users.
- With service providers supporting hosting, infrastructure, payment processing, email delivery, analytics, digital wallets, customer support, security, and ticketing integrations.
- When directed by the Client, including with event partners and access personnel.
- To comply with law, legal process, or valid government requests, or to protect rights, safety, and security.
- In connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate protections.
We do not sell personal information for money.
7. International processing
MyPass and its service providers may process information in countries other than the country where it was collected. Where required, we use contractual or other lawful safeguards for international transfers.
8. Retention
We retain information for as long as needed to provide the Service, follow Client instructions, maintain security and audit records, meet billing and legal obligations, and resolve disputes. Retention periods depend on the type of data, contractual instructions, event lifecycle, and applicable law. Data may remain in protected backups for a limited period after deletion from active systems.
9. Security
We use administrative, technical, and organizational measures designed to protect information. No system is completely secure. Clients must use appropriate permissions, strong credentials, and secure devices, and must promptly report suspected incidents. Additional information is available in our Security Overview.
10. Privacy choices and rights
Depending on location, individuals may have rights to access, correct, delete, restrict, or object to certain processing, or to receive a portable copy of information. VIP attendees should normally contact the event organizer or Client that collected their data. We assist Clients with valid requests as required by contract and law.
Requests concerning information controlled directly by Lepews may be sent to [email protected]. We may need to verify the requester’s identity and authority.
11. Children
MyPass is a business service and is not directed to children. Clients must ensure they have any consent or authority required before submitting information about minors participating in an event.
12. Changes and contact
We may update this Policy as the Service and applicable requirements change. The effective date above identifies the latest version.
Privacy questions may be sent to Lepews LLC at [email protected].