Fete LabsAll policies

Privacy Notice

What FetePass collects, why, how long it is kept, who it is shared with, and how to get a copy of it or have it deleted.

Last updated 23 September 2026.

FetePass is in private preview. The software is complete and runs against the real systems it will run against in service — the same database, the same payment rail, the same gate. What is not settled is the company behind it: FetePass is not yet incorporated, holds no money-services licence, and has not taken a real payment. So the registered company name and number, the registered office, the published contact addresses, the fee schedule and some retention periods are marked to be confirmed before launch rather than invented. They will be filled in here, with a new date on this page, before FetePass takes its first real payment.

During the preview: no real money moves — the fiat top-up is switched off in the product, not merely unlinked — and anything you are shown in a demonstration may be reset. Everything on the screen still comes from real data: FetePass does not put invented events, venues, prices or people in front of anyone, so an empty surface is an empty surface rather than a mock-up.

1. Who is responsible for your data

Saltwater Brands, operating FetePass, is the data controller. FetePass is a FeteLabs product managed under Saltwater Brands, and it is not incorporated yet. When it is, this page will name the company instead, with a new date on it, and we will say so in the app rather than change it quietly. The address for privacy requests is to be confirmed before launch.

We would rather tell you that than leave the question blank. A privacy notice that cannot say who is accountable is not a privacy notice, and “a company” would have been a company that does not exist.

Anguilla has no general data protection statute and no data protection commissioner. That is not a reason to do less. FetePass covers islands where stronger law is in force — Guadeloupe, Martinique and Saint-Martin are EU territory and the GDPR applies there; Antigua and Barbuda’s Data Protection Act 2013 is in force; Saint Lucia’s data protection principles are in force — and most of our users are visitors who bring their own law with them. So we apply one standard everywhere, set at the highest of those.

2. What we collect, and why

A guest account, before you have signed in
The moment you tap Guest Mode on the opening screen, FetePass creates an anonymous account for you on its own server and keeps the token for it on your device. It holds no email address, no phone number and no name you gave us: the row is created with a placeholder display name and a default island, and stays that way until you choose otherwise. It exists so the app can show you anything at all: our database answers no request that is not attached to some account, so without it the feed and the island tab would be blank. Nothing is created before that tap — opening the app, following a link straight to a ticket or the feed, or reading these notices all leave our server with no record of you.
Account
Your email address, the sign-in codes we send to it, and — only if you choose to add them — a phone number and a passkey. Needed to give you an account and let you back into it. Basis: the contract with you.
Passkeys
If you add a passkey, what we store is the public half of a key pair, a name your device chooses for itself (“iCloud Keychain”, “Google Password Manager”), and when it was added and last used. The private half never leaves your device and we never see it — that is the whole point of a passkey, and it is why there is nothing here anyone could phish out of you or ask you to read out. Nothing about your face or your fingerprint reaches us either: your device checks those itself and only tells us that it was satisfied. Removing a passkey on your account page stops it opening this account; your device keeps its own copy until you delete it there. Basis: the contract with you.
Preferences
Your island, display currency and colour mode, so the app opens the way you left it. These stay on your device. They are not copied to your account and we do not read them from our side — the island your account row carries is a default, not the one you picked. Clearing this site’s data in your browser is enough to erase all of them.
Tickets, bookings and orders
What you bought, from whom, when, for how much, and whether it was scanned at the gate. Needed to give you the thing you paid for, and to settle with the promoter or business.
Payments
If you pay in USDC: your Solana public key, the transaction signature and the amount. Note that a blockchain is public and permanent — that payment is visible to anyone, for ever, and we cannot remove it. If you sell a ticket for USDC, the wallet you linked is the address the buyer pays, so the buyer’s wallet and the blockchain show it. If you pay cash: the record the promoter makes at the door, and any event credit issued to you. We never see or hold card numbers, because there is no card rail yet.
Messages and support
What you send to a promoter, a business or us through the app, so we can answer it.
Device and diagnostics
Ordinary server logs — IP address, browser, the page requested, the time — kept to keep the service up and to spot abuse. Basis: our legitimate interest in a service that works and is not being attacked.

3. What we do not collect

  • No biometrics. The identity selfie has been dropped. FetePass does not take a photo of your face or your ID, and does not store a face template or a photo hash. If identity verification is added later, the document will be handled by a specialist provider and FetePass will keep only a “verified” flag and the date — and this page will say so before it happens.
  • Location, only when you allow it, and never kept. When you open the app we ask whether you want it to use your location, and if you choose to attach a location to a post we ask again there. Only if you tap Allow does your browser ask your permission and hand us a reading. We use it for one thing: to work out which island you are on, so the app can open on it and file your post under it. Your yes or no is remembered on this device only, so we do not keep asking. The coordinates are not stored. They are not written to any table, they are not logged, and the only thing kept on the post is the island and the fact that it came from a location reading rather than from the tab you were looking at. Refusing costs you nothing — the post is filed under the island you are browsing instead. We never read the location tag inside a photograph you upload; that information is stripped before the file is saved.
  • Limin’, and what it does not share. Limin’ lets you show people you choose that you are out, and where. It is off unless you start it, it runs for a few hours and then stops on its own, and you can end it at any moment. What is shared is a venue and how accurate the reading was — the same island resolution described above, applied to a place. No coordinate of yours is stored by Limin’ either. There is no column anywhere in FetePass that can hold your latitude and longitude, and no history of where you have been: the record is one row that says where you are now, it is overwritten each time, and stopping deletes it. Who may look is yours to set and starts at nobody. Blocking someone ends any sharing with them immediately.
  • Choosing a spot instead of being found. You can put yourself on Limin’ by tapping a venue from the island’s directory, and that way nothing is read from your device at all — no location permission, no reading, nothing to discard. Beside it you may add one of five set words for what you are doing, such as “inside” or “at the bar”. It is a fixed list rather than a message box, it is shared with exactly the same people your Limin’ setting allows, and it is deleted with the rest when you stop.
  • Asking somebody where they are. You can send one person a short “wya?”, which reaches them only if your messages already do. It sends them a notification and nothing else: it never causes their location to be shared — replying is theirs to decide. We keep one row per pair of people holding only when the last one was sent, so the same person cannot be asked repeatedly, and it is overwritten rather than added to. There is no record of who asked whom where they were.
  • Where the island is. Limin’ can show how many people are sharing from a venue. It counts only people sharing with an audience rather than with one named person, and a venue is left out entirely unless at least five people are there — never as a smaller number, never as “a few”. Nobody is named.
  • No advertising or analytics trackers. See the Cookie and Tracking Notice for every piece of storage we do use.

4. Marketing, and how consent will work here

FetePass sends no marketing messages today. Not by email, not by text. The only messages it sends are service messages: the sign-in code, a ticket receipt, a gate update. You get those because you are using FetePass. There is no SMS gateway connected and no mailing list, so there is also nothing to unsubscribe from — and this section is written in the future tense on purpose, because describing machinery we have not built would be a false statement in a published notice.

Before the first marketing message is ever sent, and not afterwards:

  • We will ask separately for email marketing and for SMS marketing, and neither will be a condition of buying anything.
  • We will record what you agreed to, when, and the exact wording you were shown.
  • You will be able to stop either at any time — the link in the email, replying STOP to a text, or a message to us — and a stop request will be honoured within ten business days at the outside, in practice immediately.
  • Every marketing email will carry a postal address, as US law requires. That address is to be confirmed before launch.
  • This page will say so before it happens, with a new date on it.

5. Who else sees it

  • The promoter or venue whose event you hold a ticket for sees your name, ticket type and whether it has been scanned. They are responsible for what they then do with it, and the Partner Terms forbid them selling it or using it for unrelated marketing.
  • The pro or kitchen you booked or ordered from sees what they need to serve you.
  • Our suppliers. Supabase hosts the database and the sign-in system; Vercel hosts and serves the app. There is no third-party error reporting today: when a screen breaks, nothing about it leaves your device. If that changes, this sentence names the company before it does. They process data on our instructions. This list is kept current on this page.
  • Nobody else. We do not sell your data, and publishers whose headlines we link to receive nothing about you.
  • We disclose data when the law actually requires it, and we ask for the request in writing.

6. Where it is processed

Our suppliers run in data centres outside the islands, and your data is therefore transferred internationally. The exact regions for the database and the app, and the transfer terms with each supplier, are to be confirmed before launch and will be listed here.

7. How long we keep it

  • Sign-in codes: minutes. They expire and are not reusable.
  • A guest account you never signed in to: it holds no name or contact detail, but it is a row on our server and it does not expire on its own today. Clearing this site’s data in your browser ends your side of it; Contact is how you have the row itself removed. We would rather say that plainly than imply it disappears.
  • Your account: while it is open, and deleted when you close it. Your preferences are never sent to us, so there is nothing of them for us to keep.
  • Tickets, bookings, orders and payments: kept while they are live, then kept as long as tax and accounting law requires for the seller and for us. The exact period per island is to be confirmed before launch.
  • Server logs and abuse records: a short rolling window; the exact period is to be confirmed before launch.
  • A payment made on a public blockchain cannot be deleted by anyone, including us.

8. Your rights

Wherever you live, and whatever your island’s law says, you can ask us to: give you a copy of your data; correct it; delete it; export it in a portable form; stop using it for marketing; or object to a use you think is unfair. Ask through Contact. We answer within one month. We will not charge you, and we will not make the service worse for you because you asked.

If we get it wrong you can complain to the supervisory authority where you live. In Guadeloupe, Martinique and Saint-Martin that is the French authority, the CNIL.

9. Children

FetePass is not built for children. Do not create an account for someone under sixteen, and note that events set their own age limits at the door.

10. Keeping it safe

Every table in our database has row-level security, so a query can only return the rows the signed-in person is allowed to see; every write goes through a checked function rather than direct table access; payout account details are kept out of the publicly readable records. If a breach ever affects you, we will tell you and the relevant authority.

Questions, or something to report

Data requests, corrections and deletions are answered within one month, whoever you are and wherever you live. Everything on this page can also be asked about through Contact.

Designed by FeteLabs

More from FetePass

Every islandThirty islands, a page eachHelp & FAQHow it works, and the data credits
PoliciesSee all
TermsPrivacyCookiesGuest WiFiPartnersCreatorsAdvertisersContact
CreditsDetails

Maps OpenFreeMap © OpenMapTiles. Venue and map data © OpenStreetMap contributors, ODbL. Weather from the islands’ own met services, the US National Weather Service and MET Norway.

FetePass is a FeteLabs product, managed under Saltwater Brands, operated from Anguilla by the FeteLabs Scientists.