Privacy Policy
The short version
- Guests don’t make an account and don’t give us payment details. To make a pass we keep the pass code, venue, experience, date, party size, estimated value and check-in time.
- If you ask us to email your pass, we use your email once to send it and then keep only a scrambled (hashed) version, which we delete after 90 days.
- We do not sell your personal information. We do not share it for cross-context behavioral advertising. We have no ad pixels.
- Venues see your pass details, but not your email. Creators, hosts and Business Partners see totals and earnings, never who you are.
- We honor Global Privacy Control automatically. You must be 18 or older to claim a pass, and Tidepass is not for children under 13.
- You can ask to know, delete or correct your information. Email support@gettidepass.com or visit Your Privacy Choices.
1. Who we are and what this covers
Tidepass is run by Tyler Brock Jardine, a sole proprietor doing business as Tidepass (“Tidepass”, “we”, “us”). We are the business responsible for the personal information described in this policy. Our mailing address is 5120 Via Mindanao, Oceanside, CA 92057. This policy explains what personal information we collect through gettidepass.com and related services, why we collect it, who we share it with, and the choices you have.
Who runs Tidepass: Tidepass is a business name of Tyler Brock Jardine, a sole proprietor, 5120 Via Mindanao, Oceanside, CA 92057.
It covers four groups of people:
- Guests: people who get a pass. Guests don’t have accounts.
- Venues: businesses that list experiences on Tidepass, and the people who manage their accounts.
- Partners: creators, vacation-rental hosts and Business Partners (businesses such as hotels, gyms, employers, apartment communities and cafes that offer Tidepass to their guests, members, residents or staff) who recommend venues and earn on verified visits.
- Visitors: anyone browsing the site.
California privacy law. Tidepass is a small business. As far as we can tell, we are below the size thresholds that make a business subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”): we don’t have more than $25 million in yearly revenue (as adjusted by the state), we don’t buy, sell or share the personal information of 100,000 or more people or households, and we don’t make money from selling or sharing personal information. We follow the California Online Privacy Protection Act, and we choose to give everyone the CCPA-style rights and notices in this policy anyway. This policy also works as our notice at collection. If we ever become subject to the CCPA, we’ll follow it in full.
Venues run their own businesses. When you book with a venue, use its booking site, sign its waiver or pay it, that venue’s own privacy policy applies, not this one.
2. What we collect
2.1 Guests
- Pass details: pass code, venue, experience, date, party size, estimated visit value, pass status and check-in time. (CCPA category: commercial information.)
- Hashed email, only if you ask us to email your pass: we use your email address once to send the pass, then throw the readable address away and keep only a hashed version. (CCPA category: identifiers.)
- Hashed IP address and device ID: used to spot fraud, such as many fake check-ins from one phone. The device ID is a random code your browser stores; it is not your name, phone number or advertising ID. (CCPA categories: identifiers; internet or other electronic network activity.)
- Referral credit: which creator or host link or code brought you, if any. (CCPA category: internet or other electronic network activity.)
- Reviews, if you choose to leave one: your first name or initial and what you write. Reviews are public. (CCPA category: identifiers; commercial information.)
- Guest reviews of a stay, if you leave one: your first name, last initial, the month you stayed, your rating, what you write, whether you said you know the host, which pass the review link came with, and a hashed IP address and device ID (to stop fake and duplicate reviews). The name, month, rating and text are public on the host’s page. (CCPA categories: identifiers; commercial information.)
- Return-stay email sign-ups, if you join a host’s list: your email address, optional first name, the property, the consent wording you agreed to with the date, whether you confirmed or unsubscribed, and a hashed IP address. We keep this email address readable, because the host needs it to email you. (CCPA category: identifiers.)
- Guest Guide unlock: if you enter a host’s stay PIN, we set a cookie on your device for 12 hours so the private section stays open. We don’t record which guest unlocked it.
- Messages you send us, such as a support email, including your email address and anything you include.
- Short-lived hashed IP addresses in counters that stop abuse (for example, too many check-in or PIN attempts). They expire within a day.
2.2 Venues
- Account details: account email and the names and contact details of the people who manage the account. (Identifiers; professional information.)
- Business and listing details: business name, address, phone, hours, experiences, prices, photos, booking link and redemption settings. (Commercial and professional information.)
- Visit and billing records: confirmations, adjustments, disputes, invoices, strikes and trust score. (Commercial information.)
- Screening answers: your answers to our eligibility questions (business type, alcohol license type) and your certification that they’re true, with the date, the question version and a hashed IP address. We keep them as a record of what you certified. (Commercial and professional information.)
- Payment card: held by Stripe. We never see or store full card numbers.
- Insurance details: your insurer, policy expiry date and, if we ask, your certificate of insurance. (Commercial information.)
2.3 Partners (creators, hosts and businesses)
- Account details: account email. You sign in with a link we email you, so there is no password. (Identifiers.)
- Profile details: handle, display name, photo, bio, social links, your picks and notes. Your public page shows what you choose to publish. (Identifiers; professional information.)
- Business details, for Business Partners: business name, category, website, phone, address, booking link, brand color, headline and intro text. Most of it appears on your public co-branded page. (Identifiers; professional information.)
- Logos and images you upload: for example, a business logo or hero photo. We store them and show them on your page and printables. (Identifiers, if an image shows a person.)
- Performance and earnings records: codes and links, campaign codes for each placement (for example, a QR card, poster or email), claims, verified visits, tier, earnings and payout history. (Commercial information.)
- Screening answers: your answers to our eligibility questions (business type, professional licenses, alcohol license type and, if it applies, your agreement to tell clients you earn), your certification that they’re true, the date, the question version and a hashed IP address. We use them to decide whether you can join and earn, and keep them as a record of what you certified. (Commercial and professional information.)
- Payout and tax details: collected and held by Stripe through Stripe Express. We never see your bank account numbers or full tax ID. We receive payout status from Stripe.
2.4 Visitors
- Basic technical information needed to load pages and keep the site secure.
- Sponsored placement counts: when a Sponsored listing is shown or clicked, we record an event with the listing, the page type and the time, so we can count impressions and clicks for the venue that paid for it. These events don’t include your name, email, IP address or device ID, and we don’t use them to build a profile of you.
- First-party, aggregate analytics: counts such as how many people viewed a page. These counts don’t store your IP address, device ID or any cookie, and we don’t build profiles of individual visitors. We use no third-party ad or tracking pixels. You can turn analytics off (see section 9).
- Venue videos, only if you press play: some venue pages have a video. Nothing loads from the video provider until you press play. Then the video loads from YouTube (in its privacy-enhanced mode) or Vimeo (with its “do not track” setting), and that provider receives your IP address and may set its own cookies or storage under its own privacy policy.
2.5 Sensitive personal information
We do not ask guests, visitors or partners for sensitive personal information as defined by the CCPA, and we do not use any to infer characteristics about you. Stripe collects the payout and tax details it needs (which can include a tax ID) directly, under its own privacy policy.
3. What “hashed” means, in plain words
Hashing runs a piece of information, like an email address, through a one-way math formula. Out comes a scrambled string of letters and numbers. The same email always makes the same string, so we can tell “this is the same person as before” (for example, to stop someone claiming dozens of passes). But we can’t read the scrambled string back into your email.
Hashing makes information much harder to misuse, but it isn’t magic. We still treat hashed information as personal information, protect it, and delete it on schedule.
4. Where we get it
- From you, when you claim a pass, check in, write a review, apply as a venue, join as a partner or contact us.
- From your device, automatically, when you use the site (for example, the device ID and IP address, which we hash).
- From venues, when they confirm, adjust or dispute a visit linked to your pass.
- From partners, when you use their link or code (we learn which partner referred you, not anything else about you).
- From Stripe, about payment and payout status for venues and partners.
5. Why we use it
- To create, deliver and show your pass, and let you check in.
- To confirm visits, bill venues and pay partners correctly.
- To credit the right creator or host for a visit.
- To prevent and investigate fraud and abuse, such as fake check-ins, self-referrals, or venues not honoring passes. This includes our automatic watchdog checks, venue trust scores and mystery shops.
- To show verified reviews.
- To run, secure, fix and improve the site, using aggregate analytics.
- To count impressions and clicks on Sponsored placements and show venues and partners their totals.
- To answer your messages and send service emails (like your pass, sign-in links, invoices and payout notices).
- To meet legal, tax and accounting duties, and to enforce our terms.
We don’t use your information for purposes that don’t fit these without telling you first.
6. Who we share it with
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We haven’t done either in the past 12 months. We share information only as follows.
6.1 With the venue on your pass
When you claim a pass, you are asking us to pass it to that venue so it can honor your discount. The venue receives: pass code, experience, date, party size, estimated value and check-in time. The venue does not receive your email address from us. Our Venue Partner Agreement forbids venues from using pass data to market to you without your consent.
6.2 With creators, hosts and Business Partners
Partners see counts (claims, check-ins, verified visits), the venues and dates involved and what they earned. They never see who you are.
Exception: return-stay email lists. If you join a host’s list and confirm, that host receives your email address, first name (if you gave it), the property and the date you confirmed, so they can email you. You’re directing us to give it to them, so this isn’t a sale or sharing of your information. The host becomes responsible for it as an independent business, under its own privacy policy. Hosts must include an unsubscribe link, and you can unsubscribe at any time. This list is the only time we give personal information to another business for its own marketing, and only when you ask us to. Hosts also see the guest reviews you post about their property, as everyone can.
Business Partners see totals only, by campaign, placement and venue. To keep anyone from being picked out (for example, one employee or one hotel guest), any group with fewer than 5 visits is hidden or combined.
Venues see totals of views, impressions, clicks, claims and visits in their Insights, by source, partner and campaign. They don’t see who you are.
6.3 With service providers
We use service providers who handle information only to provide services to us, under contracts that limit how they can use it:
- Stripe: venue card payments, partner plan payments and partner payouts (Stripe Express), and preparing and delivering partners’ tax forms. On the pages where account holders add a card, Stripe’s own script runs and may set cookies and collect device information to prevent fraud, under Stripe’s privacy policy.
- An email delivery provider: to send passes, sign-in links and service emails.
- Hosting and infrastructure providers: to run the site and store data.
6.4 Publicly
Reviews (with your first name or initial) and partner public pages, including Business Partners’ co-branded pages with their logo and images, are visible to anyone.
6.5 For legal reasons and business changes
We may disclose information if the law requires it, to protect people’s safety, to protect our rights or to fight fraud. If the Tidepass business moves to another entity (for example, a company its owner forms to run it) or is merged, sold or otherwise transferred, personal information moves with it to the new operator. This transfer is not a sale. The new operator becomes the business responsible for it, is named on this page and in the site footer from the date of the move, and must keep the promises in this policy. If it ever wants to use or share your information in a way that’s materially different from this policy, it must tell you before it does.
7. How long we keep it
We keep personal information only as long as we need it for the reasons in section 5. These are the periods we use:
- Pass records: the hashed IP address and device ID linked to a pass are erased 24 months after the pass was claimed. After that, the pass record (code, venue, experience, date, party size and amounts) is kept for billing and tax records but can’t be tied to a person or device.
- Hashed email: deleted 90 days after collection.
- Readable email for sending your pass: used once to send, then discarded.
- Venue reviews: for as long as they’re published, unless you ask us to delete yours.
- Guest reviews of a stay: for as long as the host’s page exists, unless you ask us to remove yours or we remove it under our content rules. The hashed IP address and device ID stored with a stay review are erased 24 months after it was posted. Removed reviews are kept as a moderation record until 24 months after they were posted, then deleted. Ask for removal at support@gettidepass.com.
- Return-stay sign-ups: while you’re on the list. If you never confirm, we delete the sign-up after 30 days. If you unsubscribe, we keep only your address and the date for 24 months so you aren’t added again by mistake, then delete it.
- Aggregate analytics and Sponsored counts: deleted after about 13 months (400 days).
- Abuse counters: expire within a day.
- Venue and partner accounts: while the account is open. When an account closes, its public page or listing comes down right away. Profile and contact details are deleted or de-identified 24 months after closing (kept that long for disputes, fraud checks and unpaid amounts), except what’s in the records below.
- Billing, payout, tax and agreement records (invoices, statements, charges, payouts, plan subscriptions and the consent you gave to them, agreement acceptances, screening answers and certifications, strikes and the audit log): 7 years after the end of the year they relate to, to meet tax, accounting and legal duties, then deleted.
- Support messages: 24 months after our last reply, unless they’re part of a dispute or legal matter, in which case until it’s resolved.
8. Security
We collect as little as we can. We hash guest emails, IP addresses and device IDs. We never handle card or bank numbers. Stripe does. We use encrypted connections, limit staff access to what each job needs, and use reasonable safeguards for the kind of information we hold. No system is perfectly secure, so we can’t promise that information will never be accessed without permission. If a breach affects you, we’ll notify you as the law requires.
9. Cookies and local storage
We use a small number of cookies and browser storage items. None are used for advertising.
| Name | Type | What it does | How long |
|---|---|---|---|
tp_ref |
Cookie | Remembers which creator or host link brought you, so they get credit if you claim a pass. | 30 days |
tp_spc |
Cookie | Set only when you click a listing marked Sponsored. Lets the venue see that a pass came from its sponsored placement. Holds the placement number, not who you are. Not set if you opted out. | 7 days |
tp_dev |
Cookie | A random device ID, set when you open a partner link, claim a pass, check in or leave a review. Links the passes you grab on this browser and helps us spot fraud, such as self-referrals or insider reviews. We store only a hashed copy on our side. | 1 year |
Saved passes (tp_passes) |
Browser storage | Lists the passes you grabbed on this browser so “My passes” can show them. Stays on your device. | Until you clear your browser data |
Guest Guide unlock (tp_gpin_ followed by a number) |
Cookie | Set only after you enter a host’s stay PIN. Keeps that host’s private Guest Guide section open on this browser. Doesn’t say who you are. | 12 hours |
Privacy choice (tp_privacy, tp_privacy_seen) |
Browser storage | Remembers your analytics choice and that you’ve seen the privacy notice. Stays on your device. | Until you clear your browser data |
Opt-out signal (tp_optout) |
Cookie | Tells our server your analytics choice, so it stops counting your page views and Sponsored views and clicks. | 1 year |
Dashboard view (tp_mode, tp_venue) |
Cookie | For signed-in venue and partner accounts only: remembers which dashboard and venue you last opened. | 1 year |
Viewing options (tp-a11y-prefs) |
Browser storage | Remembers your accessibility settings (text size, contrast and so on). Stays on your device; never sent to us. | Until you reset them or clear your browser data |
Wi-Fi printables (tp_wifi: followed by your handle) |
Browser storage | For hosts and business partners only, and only if you tick “remember”: keeps the Wi-Fi details you typed on the print page. Never sent to us. You can forget it with one click. | Until you forget it or clear your browser data |
Sign-in session (WordPress cookies whose names start with wordpress_logged_in_ and wordpress_sec_) |
Cookie | Keeps venue and partner accounts signed in after you use a sign-in link. Not used for guests. | 14 days, or until you sign out |
| Stripe (set by Stripe) | Cookies | Only on the card pages of venue and partner accounts. Stripe uses them to prevent fraud and keep payments secure. See Stripe’s cookie policy. | Set by Stripe |
Our analytics is first-party and aggregate, and it doesn’t set any cookie or storage of its own. You can turn it off on Your Privacy Choices or with the cookie notice. If you clear your browser data, “My passes” on that browser will be empty, so keep your pass code or emailed pass. A venue video you choose to play may set the video provider’s own cookies (see section 2.4).
9.1 Do Not Track
Some browsers send a “Do Not Track” signal. There is no common standard for it, so we don’t respond to it differently. We don’t track you across other sites over time. We don’t allow advertising or analytics companies to collect information about your activity on Tidepass. The only other companies that can collect information on Tidepass pages are Stripe, on account holders’ card pages (for fraud prevention), and YouTube or Vimeo, only if you press play on a venue video; each does so under its own privacy policy. We do honor Global Privacy Control (see section 10.1).
10. Your California privacy rights
If you live in California, you have these rights. (As explained in section 1, we give them voluntarily even though the CCPA may not yet apply to us.)
- Right to know: ask what personal information we have collected about you, where it came from, why we use it and who we disclosed it to, and get a copy.
- Right to delete: ask us to delete it, with some legal exceptions (for example, records we must keep for billing, tax or fraud prevention).
- Right to correct: ask us to fix information that is wrong.
- Right to opt out of sale or sharing: we don’t sell or share, but you can still record your choice, and we will honor it if our practices ever change.
- Right to limit use of sensitive personal information: we don’t use sensitive personal information for anything beyond what the law allows, so there is nothing to limit. You can still contact us.
- Right to non-discrimination: we won’t deny you a pass, charge you differently or give you worse service for using your rights.
We try to give the same choices to people outside California too.
10.1 Global Privacy Control
If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out of sale and sharing for that browser, and we turn off optional analytics. You don’t need to do anything else.
10.2 How to make a request
- Email support@gettidepass.com, or
- Use Your Privacy Choices.
We’ll confirm we got your request within 10 business days and answer within 45 calendar days. If we need more time (up to 45 more days), we’ll tell you why.
10.3 How we check it’s you
Because guests don’t have accounts, we match what you send us against what we hold. For a guest, that usually means your pass code(s), and if you had a pass emailed, the email address you used (we hash it and compare). For venues and partners, we’ll ask you to confirm from your account email. We’ll ask only for what we need, and we use it only to verify you. If we can’t verify you, we’ll tell you why. Opt-out requests don’t need verification.
Because we keep so little about guests, we often can’t link information to you without your pass code. If you’ve lost it and didn’t have it emailed, we may have nothing we can tie to you.
10.4 Authorized agents
You can have someone else make a request for you. We’ll ask for signed permission from you, and we may ask you to confirm your identity with us directly, unless the agent has a valid power of attorney.
11. Children and teens
Tidepass is not for children under 13. It is not directed to them, businesses mainly for children under 13 can’t join, and we don’t knowingly collect personal information from children under 13. You must be 18 or older to claim a pass, leave a review or open an account; children can come along on a pass an adult claims for the party. If we learn we collected information from a child under 13, we’ll delete it. Write to support@gettidepass.com if you think this happened.
We do not sell or share the personal information of anyone, including consumers under 16.
12. Changes to this policy
We may update this policy. We’ll change the “Last updated” date at the top and, for big changes, post a notice on the site and email account holders. We won’t use information we already have in a materially different way without telling you first and, where the law requires, getting your consent.
13. Contact us
Tyler Brock Jardine, a sole proprietor doing business as Tidepass
5120 Via Mindanao, Oceanside, CA 92057
Email: support@gettidepass.com