SGF Theater App Privacy Policy

Effective August 24, 2026 · Last updated September 3, 2026

Secret Golden Flower, LLC

Part of the SGF Privacy Policy. This page is part of the Secret Golden Flower Privacy Policy. It adds the detail specific to the SGF Theater mobile app and, for the app, governs wherever the two differ.

This policy covers the SGF Theater mobile app, including sign-in, show browsing, physical-ticket checkout when available, tickets, order history, balances, and notifications. Some partner theaters still use a website checkout, and an in-app purchase option may be unavailable for a particular theater or performance. If the app sends you to a theater website, information entered on that site is also covered by the Privacy Policy and any privacy notice shown by that theater.

Who Is Responsible for the Information

Secret Golden Flower, LLC (“SGF,” “we,” “us”) operates the SGF Theater-branded app and ticketing platform for partner theaters. SGF handles app account, platform, and operational information. The theater whose show you view or ticket you buy also receives and controls the customer, order, fulfillment, and marketing records for that theater. Questions about a specific order, event, or theater mailing list should normally go to that theater’s box office.

Information the App Handles

  • Account and contact information. We use your email address to send a one-time sign-in code and match you to existing ticketing records. During an in-app checkout, we collect the first and last name you enter and, if you provide it, a phone number. The order email is the email of the signed-in account.
  • Shows, seats, tickets, prices, and orders. We process the theater, show, performance, ticket type, selected seat or admission quantity, seat hold, unit price, discount, fee, tax, quoted total, order status, order number, ticket, refund, and related transaction information needed to display availability, complete and fulfill a purchase, prevent duplicate sales, support the order, and keep your ticket and order history.
  • Card payments through Stripe. The card number, expiration date, security code, and postal code entered in the Stripe card field are collected directly by Stripe’s mobile software and are not sent through or stored on SGF’s servers. We and the selling theater receive Stripe payment-method and transaction identifiers, payment status, amount, and limited card details such as brand and last four digits so we can charge, reconcile, refund, and support the transaction. Stripe may also process the name, email, optional phone number, purchase and merchant details, IP address, device or network identifiers and signals, app or checkout interactions, and approximate location derived from IP address for payment processing, authentication, fraud and loss prevention, security, and service-performance analytics. Stripe may provide information to payment networks, banks, and other financial participants as needed to process the transaction. Learn more in the Stripe Privacy Policy.
  • Marketing choice. A theater may show an optional, unchecked email-marketing box during checkout. If you check it, we record the choice with your customer and order records and may send your contact information and the theater-specific choice to that theater’s configured communications service. The choice is not required to buy a ticket. Marketing emails may include an open-tracking image or tracked links so the sender can tell whether a message was opened. You can unsubscribe through a marketing email or contact the theater.
  • Notifications and device registration. If you allow push notifications, we process an Expo push token, platform, notification preference, registration identifier, and recent app-activity timestamps so the correct registered device can receive ticket reminders and service updates. Expo relays notifications through Apple Push Notification service or Google Firebase Cloud Messaging.
  • Apple Wallet pass-update registration. If you add an update-enabled ticket pass to Apple Wallet, Apple Wallet sends SGF a device library identifier and an Apple Push Notification service (“APNs”) push token, together with the pass type and ticket serial number. We use them to identify an installed pass that needs an update, ask Apple Wallet through APNs to check for a change, and let Apple Wallet retrieve the updated pass. This Wallet registration is separate from the SGF Theater app’s Expo push token and notification preference.
  • Google Wallet passes. If you choose “Add to Google Wallet,” we send Google the information shown on the pass, which can include the event name, date and time, venue name and address, admission type, the ticket holder name, and the order number, so Google can create the pass in your Google Wallet. Google handles that information under its own privacy policy. SGF does not receive information from Google about how you use the pass.
  • Operational and diagnostic information. When the app communicates with our service, our systems and hosting providers may log source IP address, user agent or app version, device platform, route or feature requested, response status, timing, request or correlation identifiers, and error details. Depending on the request, a log can be associated with an account, theater, show, hold, ticket, order, or payment-operation identifier. We use this information for app functionality, security, fraud prevention, support, reliability, debugging, and performance.
  • Web analytics after App Tracking Transparency permission. When the app opens a supported theater or SGF web page, it passes your current App Tracking Transparency choice to that page. If you allow tracking, the page may use Google Analytics or Vercel Web Analytics to process page views, interactions, browser and device information, referring page, IP-derived general location, and analytics identifiers or cookies. We use this information to understand use of the service and improve its reliability and design. If you ask the app not to track, the supported page does not load SGF-controlled analytics and withholds tracking-capable third-party video and map embeds.
  • Information kept on your device. The app keeps limited ticket, order-history, and balance information so those screens can work with a weak or missing connection. To prevent a lost network response or app restart from causing a duplicate charge, it also keeps a non-sensitive payment-recovery record containing a random request identifier, a one-way checkout fingerprint, theater slug, hold and performance identifiers, recovery phase, creation and expiry timestamps, and an order number if one is created. That recovery record does not contain your name, phone number, raw card details, Stripe payment-method token, seat-hold session token, sign-in token, or full order request.

How We Use Information

  • Authenticate you and show records belonging to your account.
  • Show performances and availability; reserve seats; quote, process, recover, fulfill, refund, and support physical-ticket orders; and prevent duplicate orders or charges.
  • Deliver tickets, receipts, reminders, service messages, and notifications you have enabled.
  • Send theater marketing only when the applicable optional marketing choice has been selected.
  • Detect fraud or misuse, keep the platform reliable, diagnose failures, enforce our terms, and meet accounting, tax, payment, dispute, and other legal obligations.

Providers and Other Recipients

We disclose only the information reasonably needed for the relevant service or legal purpose. Recipients can include:

  • The partner theater and its authorized staff, for ticket sales, event operation, customer service, refunds, reporting, and any marketing you requested from that theater.
  • Stripe and the applicable bank, card network, or other payment participant, for payment processing, authentication, risk, fraud prevention, disputes, and refunds.
  • Railway for application hosting, Neon for database hosting, and Resend for sign-in, ticket, receipt, reminder, and other email delivery.
  • Expo, Apple, and Google for push-notification delivery when notifications are enabled, and Apple or Google system services when you direct the app to add an event or ticket to a device calendar or wallet.
  • Google Analytics or Vercel Web Analytics for app-originated web analytics only when you have allowed tracking through Apple’s App Tracking Transparency prompt.
  • A theater’s configured email or communications provider when you make the corresponding optional marketing choice.
  • Courts, regulators, law enforcement, professional advisers, or a successor in a merger, financing, reorganization, or sale, when disclosure is required or reasonably necessary to protect rights, safety, the service, or a transaction.

These recipients perform different roles. Infrastructure and delivery providers receive only the information needed for the functions described above and are required to protect it at least as carefully as this policy describes. Stripe, payment networks, banks, partner theaters, and device-platform providers may determine some of their own purposes and process information under their own terms, privacy policies, security practices, and legal obligations.

Advertising, Tracking, Location, Camera, and Calendars

  • SGF does not place advertising or ad-network software in the app, sell app personal information, or use app activity for cross-app targeted advertising or advertising measurement.
  • Before supported app-originated web content enables analytics, the app requests permission through Apple’s App Tracking Transparency framework. Allowing enables the conditional web analytics described above. Asking the app not to track keeps those analytics and tracking-capable third-party embeds off; essential ticketing functions and Stripe payment processing remain available. You can change the permission later in iOS Settings, and the app applies the current choice on its next web handoff.
  • Stripe’s payment and fraud-prevention signals are used for the payment purposes described above, not by SGF for targeted advertising.
  • The app does not request device-location permission. SGF does not use IP addresses to determine precise location. Stripe and infrastructure providers may derive a coarse location from an IP address for security or fraud prevention.
  • The app itself does not use the camera. It includes Stripe’s payment software, which contains a card-scanning feature, so the app declares a camera purpose; if you ever scan a card that way, Stripe’s software reads it on your device and SGF does not receive camera images.
  • If you choose “Add to calendar,” the app asks your device to write the show information you selected. The app does not read your calendar.

Retention

  • One-time sign-in codes expire after 10 minutes and are scheduled for deletion once they are 30 days old.
  • Each offline ticket, order-history, and balance cache entry is treated as expired after 30 days and discarded the next time the app reads or updates its cache. The cache is also cleared when you sign out. If the app is not opened, expired bytes can remain on the device until the next app launch, app-storage cleanup, or removal of the app.
  • An unresolved local payment-recovery record remains active so the app can check the same attempt instead of risking another charge. The server recovery window is normally 24 hours. A non-sensitive local tombstone can remain after resolution until app storage is cleared or the app is removed; server operation records can be retained longer with the related order, payment, security, or audit record when needed to prevent duplicates or resolve a payment issue.
  • Device registrations are kept while needed to operate enabled notifications. Turning notifications off updates the preference. Signing out requests removal of that device registration, and “Delete account data” removes server-side registrations associated with the app account and signs you out. If a payment result is unresolved, the app can require you to finish payment recovery before either action so it does not discard the status needed to prevent a duplicate charge.
  • Apple Wallet pass-update registrations are kept while the pass remains registered for updates. When Apple Wallet sends an unregister request, normally after you remove the pass from Wallet, we delete that pass registration. We also delete registrations associated with an APNs token when Apple reports that token as invalid. Removing the SGF Theater app or changing its push-notification setting does not remove a pass already in Apple Wallet; remove the pass in Wallet to unregister it.
  • Order, ticket, customer, payment-identifier, refund, and marketing-choice records are kept by SGF and the relevant theater for as long as reasonably needed for event operation, customer service, accounting, tax, fraud, payment disputes, legal compliance, and enforcing preferences such as an unsubscribe request.
  • Operational and diagnostic logs are kept only as long as needed for security and reliability. SGF’s standard application-log retention period is 365 days. Providers may keep information for different periods under their own policies and legal obligations.

Your Choices

  • You can turn push notifications off in the app or device settings. You can unsubscribe from marketing using the link in the message or by contacting the theater. Operational emails about an order or account are not marketing messages.
  • “Delete account data” in the app removes app-device registrations from our servers and signs you out after any unresolved payment is safely recovered. It does not erase orders, tickets, payment records, or records the theater must keep to operate an event or meet legal obligations.
  • To request access to, a copy of, correction of, or deletion of your information, or to withdraw consent for processing that depends on your consent, without using the app, email office@sgf.theater and identify the email address used in the app. Withdrawing consent applies to future processing only. For an order or theater mailing list, you may also need to contact the theater that holds that record. We will handle requests subject to applicable law and records we or the theater must retain.
  • Clearing the app’s storage or removing the app deletes local caches and local recovery records. Avoid clearing it while a payment result is unresolved; contact the box office if you are unsure whether a charge completed.

How You Sign In

The app has no app password. You enter your email address and we send a one-time code that expires after 10 minutes. After the code is verified, the app stores a sign-in token in the device’s protected credential storage until you sign out or delete app account data.

Children

The app is not directed to children under 17, and we do not knowingly collect personal information from children. Anyone placing an order must have reached the age of majority in their state, as our Ticket Buyer Terms explain. If you believe a child has provided personal information through the app, contact us at the address below.

Safeguards

We use administrative and technical measures intended to limit access and protect information in transit and at rest where appropriate. No method of transmission or storage can be guaranteed completely secure. Never send a full card number or security code to SGF or a theater by email or support message.

Contact Us

Questions about this policy or the app’s data practices? Email office@sgf.theater.

Changes

We may update this policy as the app or our practices change. The current version is posted here, and the dates at the top reflect the latest revision.