Effective date: July 30, 2026 | Last updated: July 30, 2026
Previous versions of this policy are retained and available on request.
1. Who we are
Fire N Ice Arena, doing business as SSS VenuePass (“we”, “us”, “our”), operates the ticketing platform at sssvenuepass.com, where you can browse events, select seats, and buy tickets for Fire N Ice Arena. We are the controller of the personal information described here, and the merchant of record for your purchases.
You can reach us at help@sssvenuepass.com, or by post to Fire N Ice Arena, Attn: Privacy.
This policy covers sssvenuepass.com, the ticket scanning and admission systems we operate at the Venue, and our email communications. It does not cover event organisers, who handle your information under their own policies once we pass it to them, or the third parties named in Section 7.
A note on scope: where a right described below is granted only in certain states, we extend it to everyone. It is simpler for us to run one process than twenty, and it means you do not have to work out whether your state qualifies.
2. Information you give us
When you create an account, we collect your name, email address, and password. Your password is stored only as a cryptographic hash. We never store or have access to the password itself.
You may also add a phone number and a postal address. These are optional, and you can change or remove them at any time from My Account.
When you buy a ticket, we collect your name, email address, phone number, the event and seats you selected, and any promotional code you used.
When you transfer a ticket, we collect the email address of the person you are transferring to, so we can send them the ticket.
When you join a waitlist, we collect your email address and phone number so we can contact you if a seat opens up.
When you request a refund, we collect the reason you give, and we share it with the event organiser who reviews the request.
If you write to us or telephone us — including to ask about accessibility or an accommodation — we have whatever you tell us in that message. Accommodation requests are handled by our staff by email and phone; they are not stored as part of your account, and you can ask us to delete the correspondence at any time.
3. Information we collect automatically
When you place an order, we record the IP address and browser user-agent the order came from, and the time.
Your account holds the date and time you last signed in. Each new sign-in replaces it; we do not keep a history of sign-ins.
We maintain rate-limiting and abuse records that associate IP addresses and browser user-agent strings with sign-in attempts, registrations, password-reset requests, ticket transfers and ticket-code checks. We use these only to detect and block automated abuse of those functions.
We keep a log of the transactional emails we send you. It holds the recipient address, the subject, the type of message, whether delivery succeeded, and a copy of the message itself — which for a ticket email includes your order, seat and ticket details. This lets us confirm your tickets and receipts actually arrived, and investigate when they do not.
Note that the QR code inside a ticket email is loaded from a third-party image service when you open the message, as described in Section 7. That means opening or forwarding a ticket email discloses the ticket code, your IP address, your mail software and the time you opened it to that service.
When you enter the Venue, we record the time, the result, and which staff member scanned each successful ticket check-in. For add-on redemptions such as parking or skate rental, we also record the gate.
We do not collect precise geolocation.
4. Payment
Card payments are processed by Stripe. Your card number, expiry date, and security code are entered directly with Stripe and transmitted to Stripe, not to us. We never receive, see, or store your full card details, and we do not store a payment method for reuse. What we store is the identifier Stripe gives each payment, charge and refund, so we can match a payment to your order, issue refunds, and respond to disputes. Stripe handles your payment information under its own policy at stripe.com/privacy.
How we guard against abuse. We apply rate limits to sign-in, registration, password reset, ticket transfer and ticket-code checks, and we temporarily lock an account after repeated failed sign-ins. These are automatic limits on how often an action can be attempted; they do not profile you, and no automated system decides whether to accept your order. An account is only suspended by a member of staff deciding to suspend it, and you can write to help@sssvenuepass.com to have that decision explained and reconsidered by a person.
We do not use automated systems to set different prices for different people based on their personal characteristics.
5. How we use your information
- create and maintain your account, and keep you signed in;
- process your purchase, issue your tickets, and send receipts and confirmations;
- admit you to events and validate tickets at the door;
- tell you if an event you hold a ticket for is cancelled;
- process ticket transfers, waitlist notifications, and refund requests;
- answer your questions and provide support, including arranging accommodations you ask us for;
- detect and block automated abuse of the platform;
- keep the Venue safe and investigate incidents;
- meet our accounting, tax, and legal obligations, and establish or defend legal claims.
We do not build advertising profiles, and we do not send you marketing about unrelated events.
We use your information only for these purposes or something closely compatible with them. If we ever want to use it for something materially different, we will tell you first and, where the law requires it, ask your permission.
6. Cookies
When you sign in we set a cookie named sssvp_customer_token, which holds the session token that keeps you signed in as you move between pages. It is HTTP-only, so scripts in your browser cannot read it, and it is marked Secure when the site is served over HTTPS. It lasts 30 days, or 90 days if you choose to stay signed in, and it is cleared when you sign out.
Signing in also sets WordPress’s own session cookies (wordpress_logged_in_… and wordpress_sec_…), which the software that runs this site uses to recognise you.
All of these are strictly necessary. Without them you cannot stay signed in or complete a purchase, so they do not require your consent and there is no way to switch them off and still use the site.
We set no advertising cookies of our own, and we run no analytics or tracking scripts. There is no Google Analytics, Tag Manager, Meta Pixel, Hotjar, or comparable product anywhere on this site. However, some event pages embed a YouTube or Vimeo player, and an embedded player loads as soon as the page opens and may set cookies of its own that we do not control. If you would rather it did not, block third-party cookies for those domains in your browser.
Global Privacy Control. We do not sell or share your information and we run no advertising trackers of our own, so there is nothing of ours for a Global Privacy Control signal to switch off. We honour GPC anyway, and if we ever introduce anything it would apply to, GPC will suppress it automatically without you needing an account.
7. Who we share your information with
Event organisers. When you buy a ticket, the organiser of that event can see your name, email address, phone number, and order and seat details, so they can run the event, manage admission, and review any refund request. Organisers may only use your information to run that event. They may not use it for their own marketing, and they may not pass it on.
Stripe. Payment processing, as described in Section 4.
EmailJS. Our transactional email — order confirmations, ticket delivery, password resets, account verification and event notices — is relayed through EmailJS. Your email address and the full contents of those messages pass through it. Where EmailJS is unavailable, the message is sent instead through our web host’s mail servers.
Our web host. The site and its database are hosted by GoDaddy, which necessarily has access to the data stored on it.
A QR code service. Ticket QR codes are rendered by api.qrserver.com. The ticket code is sent to that service in the request, both when a ticket is displayed in your browser and each time a ticket email is opened, which also discloses your IP address, your mail software and the time.
Script and font providers. cdnjs.cloudflare.com, cdn.jsdelivr.net, unpkg.com and fonts.googleapis.com serve the JavaScript libraries and typefaces the site uses. Your browser requests these directly, which discloses your IP address to those providers. WordPress also loads emoji images from s.w.org by default.
YouTube and Vimeo, where an event page embeds a video. The embed contacts those services when the page loads, before you click anything.
None of these are advertising or analytics services.
When the law requires it. We may disclose information where we are legally required to, or where we need to establish or defend legal claims, such as providing evidence of a purchase when contesting a payment dispute. We push back on requests that are broader than the law requires, and we tell you when we receive a legal demand about you unless a law or court order prevents us.
In a business transfer. If we are acquired or merge, your information may transfer as part of that, and this policy continues to apply until we tell you otherwise.
We do not sell your personal information, we do not share it for cross-context behavioural advertising, and we do not give it to advertisers or data brokers. We have not done any of those things in the past 12 months.
8. Third-party links
Event pages include buttons to share an event or add it to your calendar. These are ordinary links. Nothing is sent to Facebook, X, WhatsApp, or Google Calendar unless you click one, at which point that service’s own policy applies.
9. Sensitive information
We do not ask for sensitive information, and you should not send it to us. We do not process biometric identifiers, and we do not use facial recognition anywhere on the platform or in the building.
If you volunteer something sensitive in a message to us — for example a health reason behind an accommodation request — we use it only for the purpose you gave it, we do not use it for anything else, and you can ask us to delete that correspondence.
If we ever introduce anything that processes sensitive information more broadly, or any biometric entry system, we will ask for your specific opt-in consent first and publish an updated policy before launching it, not after.
10. Video surveillance at the Venue
Fire N Ice Arena and its parking areas are under continuous video surveillance for safety, security, and incident investigation. Signs are posted at the entrances.
Footage is retained for a limited period and then overwritten in the ordinary course, unless we need to preserve it for an active incident, insurance claim, or legal request.
Access is limited to authorised security staff. We give footage to law enforcement only on valid legal process, or where it is necessary to prevent someone being seriously harmed.
You can ask for footage of yourself under Section 11. Where footage shows other identifiable people, we will redact them, or where redaction is not practical, describe what it shows instead.
We do not run facial recognition or any other biometric identification on this footage.
11. Your rights
Everyone gets these rights, wherever you live:
| Know and access | Confirmation that we hold information about you, what categories, where it came from, why we have it, who we share it with, and a copy of it |
| Portability | A copy in a structured, machine-readable format |
| Correct | Fix anything inaccurate or incomplete |
| Delete | Have your information erased, subject to Section 13 |
| Opt out of sale, sharing, and targeted advertising | Available on request, though we do none of these |
| Limit use of sensitive information | Restrict us to what is needed to provide the service |
| Withdraw consent | At any time, as easily as you gave it |
| No retaliation | We will never deny you service, charge you differently, or give you a worse experience for exercising a right |
| Appeal | Have a refusal reviewed. See Section 12 |
If you live in the EEA, UK, or Switzerland, you additionally have the right to restrict processing, to object to processing based on our legitimate interests, and to complain to your supervisory authority.
Self-service. You can view and change your name, phone number and postal address yourself at any time from My Account.
Everything else — including changing the email address on your account, closing your account, and any request above — write to help@sssvenuepass.com and a person will handle it.
12. How we handle a request
Verifying you. We check who you are in proportion to what you are asking for. For most requests, confirming you control the account email is enough. We will not ask you for a government ID or a notarised document for a routine access or deletion request. For anything higher-risk we may ask for extra details that match our records, which we use only for verification and then delete.
Timing. We acknowledge your request within 10 days and answer within 45 days. If we genuinely need longer we may take one further 45 days, and we will tell you before that and why. These are commitments made by the people who read that inbox, not automated deadlines.
Cost. Free, up to two requests in any 12-month period. We would only charge for a request that is clearly excessive or made in bad faith, and we would explain why before charging anything.
If we say no. We will tell you exactly which exception applies. You can appeal by replying to our decision and asking for a review. If we refuse the appeal too, we will give you the contact details for your state attorney general or supervisory authority so you can take it further.
Someone acting for you. An authorised agent can submit a request with your signed written permission. We may contact you to confirm.
Transferred tickets. If you transferred a ticket to someone else, their information is theirs. Neither of you can exercise rights over the other’s data.
13. When we cannot delete something
Some requests we cannot fully honour. We may keep information where we need it to:
- complete a transaction you asked for;
- detect and prevent fraud or a security incident;
- meet a legal obligation, including tax and accounting retention;
- establish, exercise, or defend a legal claim, including an open payment dispute.
Where one of these applies, we will tell you which one, and delete everything it does not cover.
14. How long we keep things
| Account profile | While your account is open |
| Order, ticket, payment, and refund records | 7 years, for accounting and tax obligations. This means some order records outlive the account they belong to |
| Ticket check-in and add-on redemption logs | Kept with the order records |
| Rate-limiting and abuse records | 90 days, deleted automatically |
| Email delivery log, including message contents | Kept with the order records |
| Video surveillance footage | A limited period, unless preserved for an incident or claim |
| Correspondence with us | Until you ask us to delete it, or it is no longer needed |
Where a dispute, chargeback, investigation, or legal claim is live, we keep the relevant records until it ends.
15. Security
The site is served over HTTPS, so traffic between your browser and us is encrypted. Passwords are stored as hashes rather than as text. Sign-in tokens and password-reset links expire. Access to customer records is restricted to staff and to the organisers of the events concerned. Card data never reaches our systems at all.
If there is a breach. We will contain and investigate it, and notify you and the relevant regulators without unreasonable delay and in any case within the deadline the law sets, which in Arizona is 45 days. We will tell you what happened, what information was involved, what we are doing about it, and what you can do.
No system is perfectly secure, and we cannot promise a determined attacker will never succeed. What we can promise is the measures above and honest, prompt notice if something goes wrong.
Found a vulnerability? Report it to help@sssvenuepass.com. We will not pursue legal action against anyone acting in good faith who reports responsibly.
16. Children
The platform is not directed at children under 13, and we do not knowingly collect their personal information. Accounts must be held by someone at least 18 and able to enter a binding contract.
Fire N Ice Arena is a family venue, and many of our guests are minors. Where a parent or guardian buys tickets for a child, the account and the order are the adult’s; we do not ask for the child’s details in order to sell a ticket.
We do not use the personal information of anyone we know to be under 16 for targeted advertising, sale, sharing, or profiling, and since we do none of those things for anyone, that is straightforward.
Parents and guardians can contact help@sssvenuepass.com to see, correct, or delete a child’s information. If we learn we hold information about a child under 13 without a guardian’s consent, we delete it promptly.
17. Where your information goes
We are based in Arizona and process your information in the United States. If you use the platform from outside the US, your information is transferred to the US.
For anyone in the EEA, UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum for those transfers, supported by encryption in transit. Ask us at help@sssvenuepass.com for a copy.
18. State-specific notes
California. The categories we collect, where they come from, why we have them, and who we share them with are in Sections 2, 3, 5, and 7. Retention is in Section 14. You have the rights in Section 11, including the right to limit use of sensitive personal information. We do not sell or share personal information, and we have no actual knowledge of selling or sharing the information of anyone under 16. Submit requests at help@sssvenuepass.com.
Colorado, Connecticut, Delaware, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, Washington. You have the rights in Section 11, including the appeal right in Section 12. We do not sell sensitive information, biometric information, or precise geolocation. Minnesota residents can also ask for a list of the specific third parties we disclosed your information to; email help@sssvenuepass.com.
Nevada. You may send a verified request to opt out of the sale of covered information to help@sssvenuepass.com, though we do not sell it.
EEA, UK, Switzerland. Our contact for data protection matters is help@sssvenuepass.com. You can complain to your national supervisory authority, or in the UK to the Information Commissioner’s Office.
19. Changes to this policy
We may update this policy. When we do, we change the date at the top, and where a change materially affects how we use your information we will make that clear rather than relying on the date alone. We will not apply a materially different use to information we already hold without a new legal basis, including your consent where that is required.
Previous versions are retained and available on request.
20. Contact
| Privacy questions, requests and appeals | help@sssvenuepass.com |
| Security reports | help@sssvenuepass.com |
| Post | Fire N Ice Arena, Attn: Privacy |
This policy is governed by the laws of the State of Arizona, consistent with our Terms of Service.
