Privacy

Privacy policy

PHPass is the operator of this service. This policy describes the information the passport and the organizer workspace collect. It is written for the Data Privacy Act of 2012.

Updated 10 October 2026.

Attendees

When you open a passport we collect the email you enter. Sign-in is either a one-time code sent to that email or a password you choose. Passwords are stored only as a hash. A session lasts about 30 days. We also store the name you put on the passport, your progress, your votes, and your quiz answers.

If the event asks for a survivor image or video, we collect the selfie you submit and send it to Higgsfield to create that image or video.

The phone keeps the event, scan codes, and progress in its browser storage so you can scan and take quizzes offline. That copy stays on your phone.

Organizers

Organizer accounts use Amazon Cognito. We store the name, email, and password for that account, plus the events, text, images, and video the organizer uploads.

Contact form

The contact form stores the name, email, organization, and message you send.

Who processes this

Amazon Web Services hosts sign-in, the database, email, file storage, and delivery. Higgsfield receives a selfie only when an attendee asks for a survivor image or video.

How long we keep it

One-time sign-in codes last about 10 minutes. Attendee and organizer sessions last about 30 days. Event data stays until the organizer deletes the event or the account.

Your choices

You can stop using the passport. To ask for your attendee data to be deleted, use the contact form. Organizers delete events and participant records from the dashboard.