Legal
Privacy & Data Policy
Effective date: June 21, 2026 · Synaptis Technologies LLC
1. Introduction
This Privacy & Data Policy explains how Synaptis Technologies LLC (the data controller) collects, uses, stores, and protects your personal information when you use the TamashaGo platform (www.tamashago.com), and describes your rights under applicable law.
This policy applies to all visitors, registered buyers, and registered organizers. It covers personal data collected through the platform, via email, through customer support, and through cookies and similar tracking technologies.
2. Information We Collect
Account data — full name, email address, phone number, and hashed password. Organizers additionally provide business name and information required for Stripe Express identity verification.
Payment data — all payment processing is handled by Stripe, Inc. (PCI DSS Level 1 certified). TamashaGo does not store, transmit, or have access to raw card numbers, CVV/CVC codes, or full bank account numbers. We retain only: last four card digits, card type, and transaction identifiers.
Transaction data — events purchased, ticket quantities, face values, service fees charged, transaction dates, and order confirmation numbers.
Device & technical data — IP address, browser type, device model, operating system, and pages visited.
Usage data — search queries, event pages viewed, filters applied, and links clicked. Collected primarily through cookies (see Section 11).
Communications data — content of customer support communications.
3. How We Use Your Information
- Ticket fulfillment & account management — processing purchases, issuing e-tickets, and providing support.
- Transactional communications — order confirmations, e-tickets, event reminders, and cancellation notices. These cannot be opted out of while your account is active.
- Fraud detection & platform security — detecting BOTS Act violations, chargeback fraud, and unauthorized access.
- Platform improvement — analyzing aggregated, anonymized data to improve functionality and performance. We do not use individual profiles for advertising targeting.
- Legal compliance — tax reporting (IRS 1099-K), responses to valid legal process, and applicable consumer protection law.
- Dispute resolution — investigating and resolving disputes between buyers and organizers.
4. What We Never Do — Binding Commitments
- We do not sell personal data. TamashaGo does not sell, rent, trade, or exchange personal data of any user for monetary or other consideration — including under the CCPA/CPRA's broad definition of “sale.”
- We do not run competitor ads based on purchase history.
- We do not cross-market using organizer attendee data without that organizer's explicit prior written consent.
- We do not share buyer email lists with any party other than the organizer of the specific event and our transactional email processor (for delivery only).
5. Third-Party Processors
TamashaGo shares personal data only with the following limited sub-processors for the purposes described:
- Stripe, Inc. — payment processing and organizer payouts. Governed by stripe.com/privacy.
- Supabase — database infrastructure (SOC 2 Type II certified, US-based data storage).
- Vercel — web hosting and CDN for the application front-end.
- Resend — transactional email delivery (ticket confirmations, event reminders). Does not retain email content beyond time necessary for delivery.
- Cloudflare — CDN, DDoS protection, and DNS. Does not have access to personal data stored in our database.
We share data with other parties only as required by valid legal process, to protect the rights or safety of TamashaGo or its users, or in connection with a merger or acquisition (with advance user notice).
6. Organizer Data Rights
Organizers are the data controllers for their attendees' personal data. TamashaGo acts solely as a data processor for that data, processing it only for ticket fulfillment, authorized event communications, fraud prevention, and legal compliance.
Organizers may export a complete CSV of their attendee data (names, emails, ticket details, check-in status) at any time via the organizer dashboard.
Upon account termination or written request, TamashaGo will export all attendee data and purge it from active systems within 30 days, except where legally required to retain it (transaction records are kept 7 years).
In the event of a confirmed data breach affecting organizer attendee data, TamashaGo will notify the affected organizer within 72 hours of confirming the breach.
7. California Residents (CCPA/CPRA)
California residents have the following rights:
- Right to Know — request disclosure of categories and specific pieces of personal information collected.
- Right to Delete — request deletion, subject to legal retention requirements.
- Right to Opt Out of Sale — TamashaGo does not sell personal information (see Section 4).
- Right to Correct — request correction of inaccurate personal information.
- Right to Non-Discrimination — we will not deny services or charge different prices for exercising these rights.
To exercise these rights, email support@tamashago.com with your full name, registered email, and a description of your request. We will respond within 45 calendar days.
8. EU/UK Users (GDPR / UK GDPR)
EU and UK users have the following additional rights: access, rectification, erasure (“right to be forgotten”), data portability, restriction of processing, and the right to object.
Lawful bases for processing: performance of a contract (ticket fulfillment); legitimate interests (fraud detection, security); legal obligation (tax reporting); and consent (marketing communications).
Data transfers to the US are made under Standard Contractual Clauses (SCCs)as approved by the European Commission.
To exercise your rights or lodge a complaint, contact support@tamashago.com. We will respond within 30 calendar days. You may also lodge a complaint with your local supervisory authority (e.g., UK ICO or relevant EU DPA).
9. Data Retention
| Data Category | Retention Period |
|---|---|
| Active account data | Retained while account is active |
| Transaction records | 7 years from transaction date (US tax law) |
| Support communications | 2 years from last interaction |
| Device & log data | 90 days from collection |
| Deleted accounts | Purged within 30 days of deletion |
| Organizer attendee data | Purged within 30 days of request or termination |
10. Children's Privacy (COPPA)
TamashaGo is intended for users 18 years of age or older. We do not knowingly collect personal information from any person under 13 as defined by COPPA (15 U.S.C. § 6501). If we discover we have collected such data, we will immediately delete it. If you believe we have inadvertently collected data from a child under 13, contact us at support@tamashago.com with the subject “COPPA Concern.”
12. SMS & Email Communications (TCPA / CAN-SPAM)
TamashaGo will not send SMS messages without your explicit prior written consent (TCPA, 47 U.S.C. § 227). When enabled, we send a maximum of 3 transactional SMS messages per event purchased: purchase confirmation, 24-hour reminder, and post-event receipt. We do not send promotional SMS without a separate opt-in.
Reply STOP to any SMS to opt out immediately. Standard carrier rates apply.
Marketing emails comply with CAN-SPAM (15 U.S.C. § 7701) and include an unsubscribe link. TamashaGo will process unsubscribe requests within 10 business days. Transactional emails (ticket confirmations, cancellation notices, security alerts) cannot be opted out of while your account is active.
13. Contact
Synaptis Technologies LLC d/b/a TamashaGo — Privacy & Data
1309 Coffeen Ave, STE 18826, Sheridan, WY 82801
Email: support@tamashago.com
See also: Terms of Service · Refund Policy · Cookie Policy