Privacy Policy

Your privacy and data protection are fundamental to how we operate. Learn about what data we collect, how we use it, and your rights.

Last updated: October 11, 2025

Download Your Data

Export all personal data we have about you

Delete Your Data

Request complete removal of your personal information

Cookie Preferences

Manage your cookie and tracking preferences

Privacy Questions

Contact us about privacy concerns or requests

Introduction

The Comedy Stand Productions ("we," "our," or "us") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, purchase tickets, or interact with our services.

We operate under the principles of data minimization, transparency, and user control, ensuring compliance with applicable privacy laws including GDPR, CCPA, and PIPEDA.

Information We Collect

Personal Information You Provide

  • Account Information: Name, email address, phone number when creating an account
  • Payment Information: Credit card details, billing address (processed securely through Stripe)
  • Event Preferences: Show preferences, venue selections, communication preferences
  • Communications: Messages sent through contact forms, customer support interactions

Information Automatically Collected

  • Usage Data: Pages visited, time spent, click patterns, referral sources
  • Device Information: Browser type, operating system, device identifiers
  • Location Data: IP address, general geographic location (city/region level)
  • Cookies & Tracking: Preference cookies, analytics cookies, marketing pixels (with consent)

Information from Third Parties

  • Social Media: Public profile information when you interact with our social media
  • Analytics Providers: Aggregated usage statistics and demographics
  • Payment Processors: Transaction status and fraud prevention data

How We Use Your Information

Service Provision (Legal Basis: Contract Performance)

  • Process ticket purchases and event reservations
  • Send booking confirmations and event updates
  • Provide customer support and resolve issues
  • Manage your account and preferences

Business Operations (Legal Basis: Legitimate Interest)

  • Analyze website performance and user experience
  • Improve our services and develop new features
  • Prevent fraud and ensure security
  • Comply with legal obligations and resolve disputes

Marketing (Legal Basis: Consent)

  • Send promotional emails about upcoming shows (opt-in only)
  • Display targeted advertising on social media platforms
  • Personalize content based on your preferences
  • Measure advertising effectiveness

Cookies & Tracking Technologies

Types of Cookies We Use

Data Sharing & Disclosure

Service Providers

We share personal information with trusted third parties who provide services on our behalf:

  • Payment Processing: Stripe (PCI DSS compliant)
  • Email Services: Mailchimp, SendGrid (with unsubscribe options)
  • Analytics: Google Analytics (with IP anonymization)
  • Cloud Hosting: AWS, Google Cloud (with data residency controls)

Legal Requirements

We may disclose your information when required by law or to:

  • Comply with legal processes, court orders, or government requests
  • Protect our rights, property, or safety
  • Investigate fraud or security incidents
  • Enforce our Terms of Service

Your Privacy Rights

Access & Portability

Request a copy of all personal data we hold about you in a machine-readable format.

Correction & Update

Update or correct your personal information through your account settings or by contacting us.

Update Account

Deletion & Erasure

Request deletion of your personal data, subject to legal retention requirements.

Consent Management

Withdraw consent for marketing communications and tracking cookies at any time.

Object to Processing

Object to processing based on legitimate interests or for marketing purposes.

Restrict Processing

Request restriction of processing while we resolve accuracy or lawfulness concerns.

Jurisdiction-Specific Rights

🇪🇺 European Union (GDPR)

  • Right to lodge a complaint with your local Data Protection Authority
  • Right to withdraw consent without affecting lawfulness of prior processing
  • Right to object to automated decision-making and profiling

🇺🇸 California (CCPA/CPRA)

  • Right to know what personal information is collected, sold, or disclosed
  • Right to opt-out of the sale of personal information
  • Right to non-discrimination for exercising privacy rights

🇨🇦 Canada (PIPEDA)

  • Right to file a complaint with the Privacy Commissioner of Canada
  • Right to request access to personal information held by organizations
  • Right to request correction of inaccurate personal information

Data Security & Retention

Security Measures

  • Encryption: All data transmitted using TLS 1.2+ and data at rest using AES-256
  • Access Controls: Role-based access with multi-factor authentication
  • Regular Audits: Quarterly security assessments and penetration testing
  • Incident Response: 72-hour breach notification procedures

Data Retention Periods

  • Account Data: Until account deletion or 7 years after last activity
  • Transaction Records: 7 years for tax and regulatory compliance
  • Marketing Data: Until consent withdrawal or 3 years of inactivity
  • Analytics Data: 26 months (anonymized after 14 months)

International Data Transfers

Your personal information may be transferred to and processed in countries other than your country of residence. We ensure adequate protection through:

  • Adequacy Decisions: Transfers to countries with adequate protection findings
  • Standard Contractual Clauses: EU-approved clauses for third-country transfers
  • Certification Schemes: Privacy Shield successors and equivalent frameworks
  • Data Residency: Canadian data stored within Canadian data centers where possible

Contact Information

Data Protection Officer

privacy@thecomedystand.ca

1-902-123-JOKE (5653)

Mailing Address

The Comedy Stand Productions
Privacy Department
Halifax, Nova Scotia
Canada

Response Time

We respond to privacy requests within:

  • GDPR: 1 month (extendable to 3 months)
  • CCPA: 45 days (extendable to 90 days)
  • PIPEDA: 30 days

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes by:

  • Posting the updated policy on our website
  • Sending email notification for material changes
  • Displaying a prominent notice on our homepage

Your continued use of our services after policy updates constitutes acceptance of the changes.