1. The short version
GridMagik helps operators run attractions — bookings, payments, waivers, CRM. To do that we store data you and your guests give us. We do not sell it. We do not use it to train external AI models. Access, correction, export, and deletion requests are handled subject to contractual, security, and legal-retention requirements.
2. Data we collect
- Account data — operator name, email, role, workspace preferences.
- Guest data — name, email, phone, booking history, preferences, and any waiver-status information supplied through GridMagik. Provided by guests or venue staff during booking and operations.
- Payment data — transaction amounts, currency, payment status, and provider references. Card-entry fields are hosted by Stripe; GridMagik does not intentionally collect or store full card numbers.
- Usage data — pages visited, features used, and errors encountered. Used to improve the product, never sold or shared.
3. How we use it
- To operate the GridMagik service (scheduling, payments, messaging, reporting).
- To send transactional communications (booking confirmations, receipts, reminders, and password resets). We do not send marketing email from your guest list on your behalf unless you explicitly configure a campaign.
- To secure the service (fraud detection, abuse prevention, incident response).
- To comply with legal obligations (tax, subpoena, accessibility standards).
4. Sharing
We share data only with sub-processors needed to run the service (payment processors, email/SMS providers, cloud infrastructure, error monitoring). A current list is available on request. We do not sell personal data. We do not share it with advertisers or data brokers. Ever.
5. Your rights
- Access — contact us to request a copy of covered personal data.
- Correction — your guests can request corrections to their profile; you, as the operator, can also edit on their behalf.
- Deletion — request deletion through the operator or GridMagik. We verify scope and retain records where a contract, dispute, fraud-prevention need, or law requires it.
- Portability — we provide supported exports or another appropriate format after verification.
- Objection — GDPR, CCPA, and CPRA opt-outs honored. Honored globally, not just in the jurisdictions that require it.
6. Data residency
Hosting location depends on the configured production environment and its service providers. If a deployment requires a particular region or cross-border transfer term, that requirement must be documented in the applicable order form or data-processing agreement before launch.
7. Retention
We retain data while it is needed to provide the service and for the periods required by the applicable contract, dispute, security, tax, or legal obligation. Deletion from active systems and backups follows the production retention schedule agreed for the deployment. Operators remain responsible for defining lawful waiver-retention needs.
8. Security
We use access controls, audit records, managed hosting safeguards, and Stripe-hosted card entry to reduce security and payment-card exposure. These controls do not imply a certification that has not been expressly provided in writing. See our security page for the full posture.
9. Children
Venue operators are responsible for obtaining required guardian consent and configuring age-appropriate booking practices. If a parent or guardian believes a child's data was submitted without proper authority, contact the venue and GridMagik so the request can be verified and handled subject to applicable retention duties.
10. Changes
We update this policy when our data practices change. Where law or contract requires advance notice, we provide it through an appropriate account or contact channel. The “last updated” date reflects the most recent revision.
11. Contact
Questions, requests, or complaints: use our contact form. For formal data subject requests, subject your message with “DSR” and we will respond within 30 days (or whatever applicable law requires, whichever is shorter).