Privacy
What GREENWAY collects, why, who sees it, and how to have it removed. This describes what the software actually does.
Last updated 2026-08-31. These terms are between you and Pocket Holding LLC.
What is collected
When you buy a ticket:
- Your name and email address, because the ticket has to reach you and the door has to have a list.
- Your phone number, only if you enter one.
- What you bought, what it cost, and when.
- The IP address the order came from, kept with the order and in the audit log, because a platform that takes money has to be able to investigate fraud.
- Whether you agreed to hear from the organizer again. That is a separate choice and it is off unless you make it.
If somebody passes you a ticket, the name and email they entered for you are stored so the pass can reach you and the door knows who is coming.
No card number ever reaches GREENWAY. Payment happens on the processor’s own page.
Cookies
GREENWAY sets three cookies and none of them are for advertising or analytics:
- gw_session — keeps an organizer signed in.
- gw_csrf — stops a different site submitting forms as you.
- gw_oauth — a short-lived value that proves a Google sign-in started here.
There is no analytics script, no advertising pixel and no third-party JavaScript on these pages. The content security policy blocks it, and directions to a venue are a link to a map rather than an embedded one, so nothing loads from anywhere else while you read an event page.
Who else sees it
- The organizer of the event you bought from — they get your name, email, what you bought and, if you agreed to it, permission to contact you again. They do not see anything about other organizers’ events.
- The payment processor, which takes the payment and tells us it succeeded.
- The email transport, which is given your address in order to deliver the ticket.
- The database host, which stores it.
Nothing is sold, and nothing is shared with advertisers. GREENWAY is multi-tenant: one organizer cannot read another organizer’s customers, and that is enforced in the data layer as well as in the application.
Agents acting for you
If software buys on your behalf, the order records which mandate placed it and what that agent said about who it was acting for. That claim is stored labelled as a claim, because GREENWAY cannot verify it.
Keeping and deleting
Order and ticket records are kept for 7 years after the event, because a business that takes money has to be able to account for it, and a card payment can be disputed long after the night. After that they are deleted or reduced to figures with nobody attached.
Nothing deletes itself automatically yet. That period is the policy, and today it is applied by hand rather than by a scheduled job. It is stated this way round because claiming an automatic deletion that does not run would be the kind of promise this page exists to avoid.
You can ask the organizer, or us, to remove your details. Doing so redacts the customer record — the name, email, phone and consent are replaced and the record is marked redacted. The order and the ledger entry behind it remain, without your details attached, because a business has to be able to account for money it took.
Ask at: support@successagenticlabs.com
A ticket confirmation is sent because you bought something. Marketing only follows if you chose it, and a spam complaint withdraws that consent immediately — because that is what the complaint means.
If your address permanently rejects our mail, it is recorded as undeliverable and we stop sending to it rather than continuing to try.
Your rights over your own details
You can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be removed, by writing to support@successagenticlabs.com. These are offered to everybody who buys here regardless of where they live, rather than only to people in places that require them, because operating one policy is simpler than operating five and this is the one that is easiest to keep.
Where your details are held, it is on one of three grounds: to perform the purchase you asked for, to meet a legal obligation such as keeping financial records, or because you separately chose to hear from an organizer again. That last one is the only one that is consent, and you can withdraw it at any time — every marketing email carries the link and a spam complaint does it immediately.
Your details are stored and processed in the United States. If you are buying from outside it, that is a transfer out of your own country and you should read this page with that in mind.
Where this is still incomplete
The clauses specific to individual privacy regimes are not drafted — the named disclosures under the California, Virginia, Colorado and Connecticut acts, and the full GDPR set if this ever sells into the EU or UK. What is written above is the honest general position and it is deliberately the more generous one; it is not a substitute for those, and this is the part that most needs a lawyer once there are buyers in those places.
Questions: support@successagenticlabs.com