Privacy Policy
Flite City Corporation · Last Updated: August 11, 2026
1. Introduction
This Privacy Policy explains how Flite City Corporation ("Flite," "we," "our," or "us") collects, uses, discloses, and safeguards personal information when you access or use our website, mobile applications, organizer tools, or related services (collectively, the "Services").
This Policy is incorporated into the Flite Terms of Service. By accessing or using the Services, you acknowledge the practices described here. If you do not agree, you must not use the Services.
This Policy is designed to meet the requirements of, among others:
- the EU General Data Protection Regulation (GDPR) and the UK GDPR
- the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and other US state privacy laws
- the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada
- the Digital Personal Data Protection Act, 2023 (DPDP Act) in India
- UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
Privacy contact: privacy@flite.city. General contact: success@flite.city.
2. Our Role
For most processing described in this Policy, Flite acts as a controller (a "business" under US state law, a "data fiduciary" under the DPDP Act) -- we determine why and how personal information is processed.
Where an Organizer independently collects or uses information about Attendees and Members for the Organizer's own purposes, that Organizer is an independent controller and is responsible for its own privacy practices. Where Flite processes personal information on an Organizer's documented instructions, Flite acts as a processor and, where required, will enter into a data processing agreement with that Organizer.
3. Information We Collect
Information you provide
- Account and profile data -- name, email address, phone number, password, username, profile photo, and social handles such as Instagram, where you choose to provide them.
- Optional profile data -- gender and date of birth, where you choose to provide them.
- Transaction data -- billing address, order history, ticket and Membership purchases, attendance and scan records, and add-on selections.
- Payment data -- collected and stored by our payment processors. Flite does not store full payment card numbers.
- Organizer and verification data -- business registration details, tax identification numbers, payout bank details, beneficial ownership information, and government-issued identification, collected by us or by our payment processors for identity verification, anti-fraud, and regulatory compliance.
- Event and content data -- Event listings, descriptions, images, questionnaire responses, comments, and other User Content you submit.
- Support and communications data -- messages you send us, support tickets, Resolution Center submissions, survey and feedback responses, and dispute correspondence.
- Job applicant data -- where you apply for a role with Flite: contact details, employment and education history, professional credentials, and any other information in your application materials.
Information collected automatically
- Device data -- IP address, device and application identifiers, hardware model, operating system, browser type, language and locale settings, mobile carrier, and system configuration.
- Usage and log data -- pages and screens viewed, searches, features used, referring URLs, timestamps, crash reports, and diagnostic and performance data.
- Location data -- approximate location derived from IP address. Where you grant permission, precise location from your device for nearby-event discovery and check-in features. You can revoke this in your device settings.
- Cookies and similar technologies -- as described in Section 8.
- Session replay and product analytics -- we use third-party tools that record interactions such as clicks, scrolls, taps, and time on screen in order to diagnose usability problems and improve the Services.
Information from third parties
- Payment processors -- transaction outcomes, verification results, risk signals, and dispute records.
- Commerce partners -- where a purchase is initiated or processed through a third-party storefront or checkout, we receive order and customer records for that transaction.
- Organizers -- attendance, guest list, and eligibility information relating to Events you attend.
- Authentication and social login providers -- basic profile information you authorize them to share.
- Advertising, analytics, and anti-fraud providers -- measurement, attribution, and risk signals.
- Publicly available sources -- where lawful and relevant to Organizer verification.
Sensitive information
We do not seek to collect special categories of personal data (GDPR Article 9) or "sensitive personal information" as defined under US state privacy laws, and we ask that you do not submit it. Where government-issued identification, precise geolocation, or account credentials are processed, they are used solely to provide the Services, verify identity, secure accounts, and prevent fraud -- never to infer characteristics about you, and never for advertising.
4. How We Use Personal Information
- To provide the Services -- create and manage accounts, process ticket, Membership, and add-on purchases, deliver tickets, facilitate check-in, enable Organizer•Attendee communication, and process payouts.
- To operate and improve -- analyze usage, troubleshoot, test, develop features, and measure performance.
- To personalize -- recommend Events, tailor discovery feeds, and adapt content to your interests and location.
- To communicate -- send transactional confirmations, receipts, ticket delivery, Event updates, security alerts, service notices, and responses to support requests.
- For marketing and advertising -- send promotional messages where permitted, measure campaign effectiveness, and work with advertising partners to deliver more relevant advertising. You can opt out as described in Section 9.
- For safety, security, and fraud prevention -- authenticate users, detect and investigate fraud, abuse, chargeback fraud, bot activity, and violations of our Terms, and protect the rights and safety of users and third parties.
- For legal and regulatory compliance -- comply with tax, accounting, audit, sanctions, and other legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
- For research and aggregation -- create de-identified and aggregated datasets for analytics, reporting, and business purposes. We do not attempt to re-identify such data.
Legal bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract -- providing the Services, processing purchases, delivering tickets, administering Memberships, and providing support.
- Legitimate interests -- securing the platform, preventing fraud and abuse, improving and developing the Services, measuring advertising effectiveness, and direct marketing to existing customers, in each case balanced against your rights.
- Consent -- precise location, marketing communications where consent is required, non-essential cookies and similar technologies, and optional profile fields. You may withdraw consent at any time without affecting processing carried out before withdrawal.
- Legal obligation -- tax and financial record-keeping, identity verification, sanctions screening, and responding to lawful requests.
- Vital interests / public interest -- in rare cases involving safety or emergencies at an Event.
Automated decision-making
We use automated systems to screen transactions and accounts for fraud, chargeback risk, bot activity, and policy violations. These systems may delay, decline, or flag a transaction or restrict an account. Where such a decision produces legal or similarly significant effects and is made solely by automated means, you may request human review by contacting privacy@flite.city. We do not engage in automated decision-making for the purpose of profiling you for advertising in a way that produces legal or similarly significant effects.
5. How We Share Personal Information
- Service providers and processors -- cloud hosting and storage, payment processing, identity verification, communications and messaging (email, SMS, push), analytics and session replay, customer support tooling, security and anti-fraud, and marketing and advertising technology. These providers are bound by contract to use personal information only to provide services to us.
- Commerce partners -- where a purchase is initiated or processed through a third-party storefront or checkout, order and customer data is shared with that partner as necessary to complete and support the transaction.
- Organizers -- if you register for, purchase a ticket to, or attend an Event, or purchase a Membership, the relevant Organizer receives your name, email address, phone number where provided, purchase and attendance details, Membership dates and benefit usage, and any questionnaire responses you submit. Organizers may use this information only for purposes directly related to that Event or Membership. Our Terms of Service prohibit Organizers from exporting this information for unrelated marketing or from contacting users outside the platform. Organizers are independently responsible for their own use of your information.
- Other users -- your public profile and any content you post publicly are visible to other users. Your phone number is not displayed to other users unless you choose to disclose it.
- Advertising partners -- we may share limited identifiers and usage data with advertising partners to deliver and measure advertising. Some privacy laws characterize this as a "sale" or "share" even where no money is exchanged. See Section 9 for how to opt out.
- Professional advisors -- lawyers, auditors, accountants, bankers, and insurers, where necessary for the services they provide to us.
- Legal, regulatory, and safety disclosures -- to comply with law, respond to subpoenas, court orders, or government requests, enforce our Terms, investigate fraud, defend legal claims, or protect the rights, property, or safety of Flite, our users, or the public.
- Business transfers -- in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or insolvency, personal information may be transferred as a business asset. Your information will remain subject to this Policy unless you are notified otherwise, and we will provide notice by email or prominent notice on the Services.
- With your consent -- for example, a co-branded promotion, where sharing occurs only with your explicit consent.
- Aggregated and de-identified data -- shared freely; it cannot be used to identify you.
We do not sell personal information for money.
6. Notice at Collection (US State Privacy Laws)
In the twelve months preceding the date of this Policy, we have collected the following categories of personal information, used them for the business and commercial purposes in Section 4, and disclosed them to the categories of recipients in Section 5.
- Identifiers -- name, email, phone, IP address, device and account identifiers. Sources: you, your device, Organizers, commerce partners, authentication providers. Retention: while your account is active plus the periods in Section 10.
- Customer records -- billing address, payment-related records, order history. Sources: you, payment processors, commerce partners.
- Commercial information -- tickets and Memberships purchased, attendance, browsing and purchase history. Sources: you, your device, Organizers.
- Internet and network activity -- usage, log, session replay, and interaction data. Sources: your device, analytics providers.
- Geolocation data -- approximate location from IP; precise location where you permit it. Sources: your device.
- Audio, electronic, and visual information -- support recordings, photos you upload, event imagery. Sources: you, Organizers.
- Professional or employment information -- for Organizer verification and job applicants. Sources: you, public sources.
- Inferences -- preferences and interests derived from your activity, used for recommendations and marketing. Sources: derived by us.
- Sensitive personal information -- government identifiers and account credentials, and precise geolocation where permitted. Used only for the purposes permitted under applicable law, as described in Section 3. We do not use or disclose sensitive personal information for purposes that require the right to limit.
We share identifiers, internet and network activity, and inferences with advertising partners for cross-context behavioral advertising. We do not sell or share the personal information of consumers we know to be under 16.
7. International Data Transfers
Flite operates globally. Personal information may be transferred to, processed in, and stored in the United States and other countries whose data protection laws may differ from those where you live.
- EEA and UK transfers -- we rely on European Commission or UK adequacy decisions where available, and otherwise on Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with supplementary technical and organizational measures.
- Canada -- transfers of Canadian personal information are made under contractual safeguards consistent with PIPEDA, and we remain accountable for information processed on our behalf.
- India -- transfers outside India are made in accordance with the DPDP Act and applicable government restrictions.
- UAE -- transfers outside the UAE are made in accordance with UAE Federal Decree-Law No. 45 of 2021, relying on adequacy, contractual safeguards, or another lawful basis.
- Other jurisdictions -- by using the Services, you acknowledge that your information may be transferred to countries with different data protection laws.
You may request details of the safeguards applied to a specific transfer by contacting privacy@flite.city.
8. Cookies and Tracking Technologies
We and our partners use cookies, pixels, SDKs, local storage, and similar technologies to:
- Strictly necessary -- authenticate you, maintain sessions, secure checkout, prevent fraud, and remember consent choices. These cannot be disabled.
- Functional -- remember preferences such as language, locale, and saved filters.
- Analytics and performance -- measure usage, diagnose errors, and run session replay to improve the Services.
- Advertising -- deliver and measure advertising on and off the Services, including cross-context behavioral advertising.
Where required by law, non-essential technologies are used only with your consent, which you can give, refuse, or withdraw through our cookie banner or preference center. You can also block or delete cookies through your browser settings, use privacy-focused browsers or extensions, and reset or limit ad tracking through your mobile device settings. Blocking cookies may affect how parts of the Services function.
We honor the Global Privacy Control (GPC) and similar opt-out preference signals where required by law, treating them as a valid request to opt out of sale/sharing for that browser or device. Because there is no finalized standard for "Do Not Track" browser signals, we do not currently respond to DNT signals.
9. Your Rights and Choices
Depending on where you live, you may have some or all of the following rights:
- Access and portability -- obtain a copy of the personal information we hold about you, in a portable, machine-readable format where applicable.
- Correction -- correct inaccurate or incomplete information.
- Deletion -- request deletion of your personal information.
- Restriction and objection -- restrict or object to certain processing, including direct marketing and processing based on legitimate interests.
- Withdraw consent -- where processing is based on consent, without affecting prior processing.
- Opt out of sale or sharing -- opt out of the sharing of personal information for cross-context behavioral advertising.
- Opt out of profiling -- opt out of profiling in furtherance of decisions producing legal or similarly significant effects, where applicable.
- Limit use of sensitive personal information -- where applicable.
- Non-discrimination -- you will receive equal service and pricing for exercising your rights.
- Appeal -- if we decline a request, you may appeal by replying to our decision or writing to privacy@flite.city. We will respond to appeals within the period required by applicable law and will explain the reasons for our decision.
How to exercise your rights
Email privacy@flite.city, or use the privacy controls in your account settings where available. We may need to verify your identity before acting on a request, and may decline requests that are manifestly unfounded, excessive, or that would infringe the rights of others or our legal obligations. Where permitted, an authorized agent may submit a request on your behalf, subject to proof of authority.
We respond within 30 days, or within the period required by applicable law, and will tell you if we need an extension.
Marketing and messaging choices
- Reply STOP to any Flite SMS message to opt out of that message program; reply HELP for assistance. Message and data rates may apply and message frequency varies.
- Use the unsubscribe link in marketing emails.
- Adjust push notification permissions in your device settings.
- Transactional and operational messages relating to your orders, tickets, account, and security will continue regardless of marketing preferences.
Complaints
You may lodge a complaint with your local supervisory authority, including: your EEA member state supervisory authority, the UK Information Commissioner's Office, the Office of the Privacy Commissioner of Canada, the Data Protection Board of India, or the UAE Data Office. We ask that you contact us first so we can try to resolve the matter.
10. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy or as required by law.
- Account data -- retained while your account is active. On a verified deletion request, data is deleted or anonymized within 30 days unless retention is legally required.
- Transaction and financial records -- retained for 5 years, or longer where tax, audit, accounting, or anti-money-laundering law requires.
- Support, Resolution Center, and dispute records -- retained for the period needed to resolve the matter and defend claims, and generally not longer than 3 years after closure.
- Marketing data -- retained until you opt out or after a period of prolonged inactivity.
- Logs and security data -- retained for a limited period appropriate to security monitoring and incident investigation.
- Aggregated and de-identified data -- retained indefinitely.
- Records subject to a dispute, investigation, or legal hold -- retained until the matter is resolved.
Deletion process
On a deletion request, we verify your identity, delete or anonymize your data within 30 days, and confirm completion by email. Some information may be retained where required for fraud prevention, legal compliance, dispute resolution, or enforcement of our Terms.
11. Security
We maintain administrative, technical, and organizational measures designed to protect personal information, including encryption of data in transit and at rest, access controls and least-privilege permissions, network and endpoint security monitoring, logging and audit trails, secure development practices, vendor security review, and staff confidentiality obligations and training.
No system is perfectly secure. Transmission of information over the internet carries inherent risk, and we cannot guarantee absolute security.
Breach notification. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required by applicable law, affected individuals, without undue delay and within the timeframes required by applicable law.
Report a suspected vulnerability or security issue to security@flite.city.
12. Children's Privacy
The Services are intended for individuals aged 18 and over. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected such information without appropriate consent, we will deactivate the account and delete the data promptly.
If you believe a person under 18 has provided us with personal information, contact privacy@flite.city and we will investigate and act.
We comply with applicable laws protecting children's data, including the Children's Online Privacy Protection Act (COPPA) in the United States, provincial laws in Canada, the DPDP Act in India, and the GDPR provisions applicable to children.
Where an Organizer permits attendance by minors at a specific Event, tickets must be purchased by a parent or legal guardian, who is responsible for that minor's information and attendance.
13. Regional Disclosures
European Economic Area and United Kingdom
Flite is the controller for the processing described in this Policy. You have the rights set out in Section 9 and may lodge a complaint with your supervisory authority.
Where Flite does not have an establishment in the EEA or UK but is subject to the GDPR or UK GDPR, our Article 27 representatives are identified on our website at flite.city and may be contacted for matters relating to EU and UK data protection law.
Canada
Flite complies with PIPEDA. We collect, use, and disclose personal information with your consent, express or implied depending on sensitivity and context, and you may withdraw consent at any time, subject to legal and contractual restrictions, though this may limit your ability to use certain features. You may challenge the accuracy of your information and file a complaint with the Office of the Privacy Commissioner of Canada.
India
Flite acts as a Data Fiduciary under the DPDP Act. We obtain informed consent before collecting or processing personal data where required, clearly explain what is collected and why, and allow you to withdraw consent at any time without affecting prior lawful processing.
Data Principals in India have the rights to access, correction, erasure, nomination, and grievance redressal. Our Grievance Officer can be reached at privacy@flite.city or at the postal address in Section 15. We will address grievances within 30 days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.
United Arab Emirates
Where UAE Federal Decree-Law No. 45 of 2021 applies, we process personal data on a lawful basis, including your consent, the performance of a contract, and our legitimate interests, and you have rights of access, correction, erasure, restriction, objection, and data portability, exercisable at privacy@flite.city. Cross-border transfers from the UAE are made in accordance with that law. Complaints may be directed to the UAE Data Office.
United States
In addition to the rights in Section 9 and the disclosures in Section 6, residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have the rights afforded by those laws, including access, correction, deletion, portability, opt-out of targeted advertising and sale, and, where applicable, appeal.
Shine the Light. California residents may request information about disclosures of personal information to third parties for their direct marketing purposes by writing to privacy@flite.city.
14. Changes to This Policy
We may update this Policy from time to time. The updated version is indicated by the "Last Updated" date and takes effect when posted, unless a later effective date is stated.
If we make material changes to how we collect, use, or share personal information, we will provide advance notice by email to the address associated with your account or by prominent notice on the Services. Where required by law, we will obtain your consent. If you do not agree with the updated Policy, you may stop using the Services and request deletion of your account. The current version is always available on our website.
15. Contact Us
Privacy and data protection: privacy@flite.city
Grievance Officer (India): privacy@flite.city
Security reports: security@flite.city
General support: success@flite.city
Flite City Corporation
1521 Concord Pike, Suite 201
Wilmington, Delaware 19803
United States
We aim to respond to all privacy inquiries within 30 days, or sooner where required by applicable law.