Privacy Policy
Passetta issues digital membership passes from HubSpot contacts and records check-ins back to HubSpot. HubSpot remains your CRM and system of record. We store only the minimal data described below — never a copy of your full contact database.
What we store
- Account and connection data: your HubSpot portal ID, the connected HubSpot user identity, and OAuth refresh tokens, which are encrypted at rest.
- Your configuration: the pass template and the specific HubSpot contact properties you choose to map (for example name, member ID, tier, expiry).
- A per-contact pass snapshot: only the mapped fields you selected, encrypted at rest, so a pass can render and be validated quickly without calling HubSpot on every scan. This is not your full HubSpot contact record.
- The pass's QR token, stored only as a one-way hash. The original token cannot be reconstructed from what we store.
- Check-in records: the time of each confirmed check-in and, if you configure one, a location label — enough to write an accurate activity back to HubSpot.
What we do not store
- Your full HubSpot contact record — only the fields you explicitly map.
- Payment details (Passetta does not process membership payments).
- Precise device or GPS location of a check-in.
- Email address or phone number, unless you deliberately map one onto the pass.
How we use it
Stored data is used only to render pass pages, validate QR scans, record check-ins, and write those check-ins back to HubSpot. We use aggregate, non-identifying product analytics to understand feature usage. We do not sell personal data, and we do not share it with advertisers or data brokers.
Who else sees it
Passetta runs on Cloudflare's infrastructure (hosting, database, and edge network) as our processor. HubSpot receives the check-in and activity data we write back to it, under your own agreement with HubSpot. No other third party has access to member data.
Retention and deletion
- While your Passetta installation is active, we retain the mapped snapshot and check-in history needed to keep issued passes working.
- When HubSpot notifies us that a contact was deleted or a privacy-deletion request was made, we purge that contact's pass snapshot and revoke the associated pass.
- Uninstalling the app, or emailing support@passetta.com with a deletion request, deletes your tenant's stored data, including encrypted OAuth tokens, within a reasonable operational window.
- Encrypted OAuth tokens are deleted immediately on uninstall or confirmed deauthorization.
Security
OAuth tokens and pass snapshots are encrypted at rest. QR tokens are never stored in reversible form, only hashed. Every request from a HubSpot UI extension is signature-verified before it reaches application logic, and data is scoped per HubSpot account so one customer's data is never reachable from another's.
Changes to this policy
If this policy changes materially, we will update the effective date above and, where practical, notify installed accounts through HubSpot.