Last Updated: July 28, 2026
This Privacy Policy explains how PLANPILOT LLC, which operates NFTIX.COM (“NFTIX,” “we,” “us,” or “our”), collects, uses, discloses, stores, and protects information in connection with:
- nftix.com and other websites operated by NFTIX;
- NFTIX ticketing, event, support, and related services;
- NFTIX Festival Apps and progressive web apps;
- NFTIX-provided or NFTIX-powered calendar, schedule, lineup, background, FAQ, gallery, weather, map, information, and other embedded widgets or content tools; and
- the NFTIX Festival App Connector and related integrations, including the Instagram and Facebook services provided by Meta.
This Privacy Policy applies only to processing performed by or on behalf of NFTIX. Festival organizers, venues, promoters, and other businesses that use NFTIX products (“Clients”) may independently collect and use information through their websites, apps, ticketing operations, and events. Their privacy notices also apply to their processing.
1. Our Role and Client Responsibilities
Depending on the service, NFTIX may determine why and how information is processed, or may process information on behalf of a Client.
For example:
- NFTIX generally determines how information is processed on nftix.com and in connection with NFTIX account administration, billing, support, security, and the central Festival App Connector.
- A Client generally determines the event content displayed in its Festival App or widgets and how visitor analytics stored on the Client’s own WordPress installation are used.
- Event organizers, venues, promoters, and ticket sellers may independently determine how purchaser and attendee information is used for ticket fulfillment, admission, event communications, safety, legal compliance, and other event operations.
Clients are responsible for providing any additional privacy notices and obtaining any consents required for their websites, apps, widgets, analytics, content, and events. A Client should not rely on this NFTIX Privacy Policy as a substitute for its own privacy notice when the Client independently controls personal information.
2. Information We Collect
A. Information You Provide Directly
We may collect information you provide when you purchase tickets, communicate with us, request support, create or administer a Client service, connect an integration, or otherwise use the Services. This may include:
- name, email address, telephone number, mailing or billing address;
- event, order, ticket, attendee, and transaction information;
- account, business, venue, organizer, and authorized-user information;
- support messages, feedback, correspondence, and information you choose to submit;
- widget, Festival App, event, schedule, lineup, FAQ, background, image, link, and other configuration or content information; and
- billing and payment-related information.
Payment card information is generally collected and processed directly by a third-party payment processor. NFTIX does not intend to store complete payment-card numbers or card security codes on its own servers.
B. Information Collected Automatically
When you visit or interact with a website, Festival App, or widget, NFTIX or the applicable Client site may automatically process:
- IP address as part of ordinary internet transmission and server/security logs;
- browser, operating system, device category, and app or browser display mode;
- timestamps, requested pages, page paths, referring domain, and links or controls selected;
- service errors, security events, and diagnostic information;
- a randomly generated visitor identifier stored in local storage and a randomly generated session identifier stored in session storage; and
- information indicating whether a Festival App is used in an installed or browser-based mode.
The current first-party Festival App analytics feature converts its visitor and session identifiers into one-way, site-specific hashes before storing analytics events in the Client’s WordPress database. It stores page views, clicks, page or content identifiers, abbreviated interaction labels, device and operating-system categories, app mode, referring host, and time information. The Festival App analytics table is not designed to store visitor IP addresses. Web hosts, security services, and ordinary server logs may nevertheless process IP addresses separately.
C. Cookies, Local Storage, Session Storage, and Offline Caches
Our websites, Festival Apps, and widgets may use cookies and similar browser technologies. Festival Apps currently use browser storage and caches for purposes such as:
- remembering that a launch screen has been dismissed during a browser session;
- creating pseudonymous analytics identifiers;
- temporarily caching weather information;
- supporting installation and offline or faster access through a service worker; and
- storing previously visited public Festival App pages and static resources.
A persistent visitor identifier may remain in local storage until it is cleared by the user, the site, or the browser. A session identifier generally remains for the browser session. Weather information may be cached locally for up to approximately 12 hours. Offline content may remain in a browser cache until refreshed or cleared.
Your browser may allow you to block or delete cookies, local storage, service workers, and cached data. Doing so may affect analytics, offline access, saved preferences, installation behavior, and other functionality.
D. Festival App Connector and Meta Platform Information
When an authorized Client connects an Instagram Professional account through the NFTIX Festival App Connector, NFTIX may process:
- the Client website URL, return URL, installation identifier, and connection status;
- the connecting Facebook user’s platform-scoped identifier;
- Facebook Page and Instagram Professional account identifiers;
- Page name, Instagram username, account name, and profile image URL;
- connection, update, and token-expiration dates;
- encrypted Facebook user and Page access tokens; and
- the permissions and account information needed to verify and operate the connection.
NFTIX does not request or store a person’s Facebook or Instagram password. Authentication occurs through Meta. Access tokens are stored only by the central NFTIX Connector and are not returned to the distributed Client plugin.
To provide an Instagram gallery, NFTIX may retrieve and temporarily cache public hashtagged media information made available through Meta’s authorized APIs, including media identifiers, captions, media types, media and thumbnail URLs, permalinks, timestamps, and hashtag query information. NFTIX may add additional authorized feed modes in the future, such as media owned by the connected Professional account. If we materially change the categories or purposes of Platform Data we process, we will update this Privacy Policy as appropriate.
Meta processes information under its own terms and privacy policy. Connecting an account does not transfer ownership of Facebook Pages, Instagram accounts, or Instagram content to NFTIX.
E. Information from Clients and Other Sources
We may receive information from Clients, event organizers, venues, promoters, payment processors, fraud-prevention providers, hosting and security providers, Meta, and other service providers. We may also process publicly available event and social-media information when permitted by law and applicable platform terms.
3. How We Use Information
We may use information to:
- process and administer ticket orders, payments, refunds, receipts, and admission;
- provide, configure, host, maintain, secure, and improve websites, Festival Apps, widgets, ticketing, and integrations;
- verify Client installations and authorized integrations;
- connect and operate Instagram Professional account features;
- retrieve, cache, sanitize, and display authorized event or social-media content;
- provide schedules, lineups, FAQs, maps, weather, backgrounds, galleries, event information, and other Client-selected content;
- measure page views, sessions, clicks, installed-app usage, device categories, popular content, and usage times;
- communicate service, event, transaction, safety, schedule, policy, and support information;
- personalize or configure a service at the direction of a Client;
- detect, prevent, investigate, and respond to fraud, abuse, security incidents, unlawful conduct, and violations of our terms;
- comply with law, legal process, contractual obligations, platform rules, accounting requirements, and enforceable governmental requests;
- establish, exercise, or defend legal claims; and
- create aggregated or de-identified information that does not reasonably identify an individual.
We do not use Meta Platform Data obtained through the Festival App Connector for data brokerage or unrelated advertising.
4. Legal Bases for Processing
Where applicable law requires a legal basis, NFTIX relies on one or more of the following:
- performance of a contract or steps requested before entering a contract;
- legitimate interests, including operating, securing, supporting, measuring, and improving the Services;
- consent, where consent is required or requested;
- compliance with legal obligations; and
- protection of vital interests or the safety of attendees and others where applicable.
You may withdraw consent where processing is based on consent, but withdrawal does not affect processing that occurred before withdrawal or processing supported by another lawful basis.
5. How We Disclose Information
We may disclose information:
- to the Client, event organizer, promoter, venue, ticketing party, or other business responsible for the applicable event or service;
- to payment processors, hosting providers, cloud and database providers, security and fraud-prevention vendors, communications providers, professional advisers, and support contractors;
- to Meta when an authorized person uses Facebook Login for Business, the Instagram API, or related account tools;
- to weather, mapping, media, content, or other providers when a Client enables a feature that uses those services;
- to a successor or potential successor in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of a business, subject to appropriate safeguards;
- when required by law, subpoena, court order, or other valid legal process;
- when reasonably necessary to protect rights, safety, security, property, users, events, or the public; and
- with your direction or consent.
We do not sell or rent personal information for money. Certain privacy laws define “sale,” “sharing,” or targeted advertising more broadly. Where those laws apply, we will provide any legally required notice and choice mechanism for practices falling within those definitions.
Clients may independently use analytics, advertising, social-media, or other technologies on Client-controlled sites. Those practices are governed by the Client’s notices and choices, not solely by this Privacy Policy.
6. Third-Party Services and External Links
The Services may link to or interact with services operated by others, including payment processors, Meta/Facebook/Instagram, Open-Meteo, mapping providers, event organizers, venues, ticketing providers, and external websites.
Third parties may receive technical information such as an IP address, browser headers, requested content, or account information needed to provide their service. Their privacy policies and terms govern their processing. NFTIX is not responsible for the privacy, security, accuracy, or availability of independently operated third-party services.
The optional Festival App weather feature requests forecast information from Open-Meteo for a configured location. Open-Meteo states that its API logs may include IP addresses, URLs, and geographic coordinates and that individual logs are generally deleted after 90 days. The Festival App does not currently request a visitor’s precise device location for the standard Asheville weather display.
7. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain security and business records, satisfy legal, tax, accounting, contractual, and platform requirements, resolve disputes, and enforce agreements.
Retention varies by category:
- Transaction and ticket records may be retained for the period required for payment, tax, accounting, fraud, chargeback, and legal purposes.
- Support, Client, configuration, and contract records may be retained for the relationship and a reasonable period afterward.
- Festival App analytics stored on a Client’s WordPress installation remain subject to that Client’s retention and deletion practices. Unless separately deleted or configured, those records may remain until the Client deletes them, removes the applicable database table, or decommissions the site.
- Connector credentials and account identifiers are retained while the connection is active and as needed for security, troubleshooting, legal compliance, or documented backup cycles. Disconnecting, deauthorizing, or deleting a connection removes the active stored credentials associated with that connection.
- Cached Instagram gallery results are ordinarily retained for short operational periods measured in minutes, although copies may temporarily persist in browser, server, security, or backup caches.
- Browser-stored identifiers and offline content remain until expiration, refresh, or deletion by the site, app, user, or browser.
We may retain aggregated or de-identified information where it can no longer reasonably be linked to an individual.
8. Security
We use reasonable administrative, technical, and organizational measures designed to protect information. These measures include access controls, HTTPS transmission, restricted server-side credential handling, signed service requests, rate limiting, and encryption of stored Connector secrets and Meta access tokens.
No system or transmission method is completely secure. We cannot guarantee that unauthorized access, loss, misuse, or alteration will never occur. You are responsible for using secure devices, protecting account credentials, maintaining appropriate access controls, and promptly notifying us of suspected unauthorized activity.
9. Your Choices and Privacy Rights
Depending on your location and applicable law, you may have rights to:
- request access to or a copy of personal information;
- request correction of inaccurate information;
- request deletion;
- object to or request restriction of certain processing;
- withdraw consent;
- request portability of information you provided;
- appeal a decision concerning a privacy request; and
- opt out of certain sales, sharing, profiling, or targeted advertising where applicable.
We may need to verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law, subject to verification. We will not unlawfully discriminate against you for exercising privacy rights.
To exercise a right, contact us using the information in Section 15. If information is controlled by a Client or event organizer, we may direct your request to that organization or assist it as required by contract or law.
You may unsubscribe from optional marketing email using the link in the message. Transactional, security, event, and service communications may continue where necessary.
10. Meta Connection, Revocation, and Data Deletion
An authorized Client administrator may disconnect Instagram from the Festival App settings. Disconnecting removes the active NFTIX Connector authorization for that Client installation. A Meta user may also revoke access through Facebook or Instagram account settings and Business Integrations.
Meta may send NFTIX a signed deauthorization or data-deletion request. NFTIX uses its configured callback endpoints to locate and clear associated Connector records and may provide a deletion-status confirmation code.
You may also request deletion of Connector data by contacting NFTIX using Section 15. Include enough information to identify the Client website and connected account, but do not send passwords, full access tokens, payment-card information, or other secrets by email.
Deletion may be limited where retention is required by law, necessary for security or fraud prevention, needed to establish or defend legal claims, or technically present in limited-duration backups. Where an exception applies, information will be restricted and retained only for the applicable purpose.
11. Public Event and Instagram Content
Festival Apps may display event information and public Instagram content selected by a hashtag or another authorized source. Public display through a Festival App does not mean NFTIX owns that content or endorses the person who posted it.
Clients are responsible for selecting appropriate hashtags and content sources, obtaining any permissions or licenses required for their use, providing campaign or submission rules where appropriate, honoring removal requests where legally required, and moderating content displayed in connection with their event.
If you believe content displayed through an NFTIX-powered service infringes your rights or should be removed, contact the applicable event organizer and NFTIX using Section 15, and identify the content and where it appears.
12. Children’s Privacy
The Services are not directed to children under 13, and NFTIX does not knowingly collect personal information online from a child under 13 without legally required authorization. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.
Events may admit minors under rules established by the organizer and venue. A parent or guardian should make purchases and provide information on behalf of a minor when required.
13. International Processing
NFTIX is based in the United States. Information may be processed in the United States and other countries where NFTIX, Clients, or service providers operate. Those countries may have data-protection laws different from those in your location. Where required, we use appropriate mechanisms for international transfers.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our Services, technology, legal obligations, or business practices. We will post the revised Policy and update the “Last Updated” date. We will provide additional notice when required by law or when a change is material.
15. Contact Information
For privacy questions, rights requests, Connector data deletion, or complaints, contact:
NFTIX Privacy Contact
Email: legal@nftix.com
Mailing Address:
PLANPILOT LLC
ATTN: NFTIX.COM
825-C MERRIMON AVE
SUITE 388
ASHEVILLE, NC 28804
Website: https://nftix.com/
Please do not send passwords, Meta access tokens, full payment-card numbers, or other sensitive credentials with a privacy request.

