Skip to content
film exchangeSign in

Privacy Policy

Last updated:

Film Exchange collects the minimum we need to run an at-cost ticket exchange between fans, and we don't sell any of it. This policy explains what we collect, why, who processes it for us, and what happens to it when you leave.

1. Who We Are & Scope

Film Exchange (“we,” “us”) runs a marketplace for reselling specialty film screening tickets at face value. This policy covers the Film Exchange web app and any companion apps we release.

Film Exchange is a United States–only service, currently focused on New York City events, and it isn't directed at residents of other countries. If we expand beyond the US, we'll update this policy first.

2. What We Collect

  • Account basics: your email address, display name, and password (stored only as a secure hash by our auth provider).
  • Optional profile details: a Letterboxd URL if you add one, an avatar, and the contact methods (for example a phone number or messaging handle) you choose to share with matched buyers or sellers.
  • Ticket files: when you vault a ticket for an escrowed sale, the uploaded file (and any barcode we read from it) is stored in a private storage bucket. It's never publicly accessible; it can only be reached through short-lived (60-second) signed links issued to the people entitled to it.
  • Transaction and payment metadata: listings, claims, prices, dispute records, and payment status from Stripe. We never hold your card number: card details go directly to Stripe.
  • Device and log data: IP address, browser type, and request logs that come with operating any web service, plus error telemetry when something breaks.
  • Cookies: only what's needed to keep you signed in (auth session cookies) and remember your theme. No advertising or cross-site tracking cookies.

3. How We Use Your Information

We use your information to:

  • run the marketplace: match listings and claims, process escrow payments, deliver vaulted tickets, and resolve disputes,
  • send you the email the service needs to function: claim updates, handoff reminders, account verification,
  • enforce the at-cost rules and keep fraud, bots, and bad actors out,
  • fix bugs and understand how the service is performing, and
  • meet legal obligations that apply to ticket resale marketplaces.

We don't sell your personal information, we don't share it with advertisers, and we don't use it to train anything.

4. Service Providers

A small set of companies process data on our behalf to run the service. Each receives only what its job requires:

ProviderWhat it does for us
SupabaseAuthentication, database, and file storage (including ticket files)
VercelHosting and content delivery for the web app
StripePayment processing and seller payouts. Stripe acts as an independent controller for some payment data under its own privacy policy
ResendSending transactional email (claim updates, reminders, account email)
SentryError monitoring: receives technical error reports, not your profile
TMDbFilm metadata and poster images. This product uses the TMDB API but is not endorsed or certified by TMDB

We also disclose information when the law genuinely requires it (a valid subpoena or court order) or to protect members from fraud or harm.

5. Buyer–Seller Contact Sharing

Film Exchange exchanges are peer-to-peer: the buyer pays the seller directly, so we share just enough for the two of you to connect, and no more. This part is explicit: the details you choose to share are revealed to the other party only after a claim is accepted. Never before, and never to anyone else.

Once a claim is accepted, the buyer is shown the seller's payment handles (Venmo, PayPal, or Zelle) as deep links and a QR code so the buyer can pay off-platform, along with any other contact methods either party chose to share. You pick which payment handles and contact methods to share in Settings. Buyers and sellers agree to use each other's details only to complete the exchange, not for anything else.

Private Ticket Organizer

The optional NYFF organizer is being prepared for release; cloud transfer is currently disabled. When enabled, you choose individual Seat Atlas tickets, wanted screenings and seat ratings, and whether to include personal statuses and contact notes. Ticket numbers accompany selected tickets for private matching. The extension shows your destination account and selected data before you approve an upload to Film Exchange. A signed request binds that approval to your account, extension and website tab. Film Exchange then shows a second review before saving records to your organizer.

Approved data passes through our Vercel-hosted service and Supabase database. We encrypt staged payloads, ticket numbers and private notes using server-managed keys. This is not end-to-end encryption: our service can decrypt these fields for authorized requests. Account access controls also protect ticket and showtime details, statuses, wants and ratings. The extension receives your account identifier and display name for the handoff; it does not store a Film Exchange login token.

Wallet-link extraction is disabled in this release. Use your official FLC digital-ticket page for Wallet access. Our servers do not log in to FLC, collect its credentials or cookies, scrape ticket QR codes, or generate replacement passes. Wallet links are excluded from all organizer downloads, including private backups.

Connecting does not upload automatically, scan FLC, publish marketplace listings, delete local records, or synchronize cloud edits back to the extension. Organizer edits require a connection. Ordinary exports omit ticket numbers and private notes; the extension's separately labeled private backup includes them and local matching identity material. Downloaded files are unencrypted, and even ordinary exports can reveal attendance and seat locations. Manage those files separately from your local and cloud records.

Disconnecting stops the extension connection and clears its transient transfer buffers; it does not delete data already staged or saved in Film Exchange. Archiving keeps a record and its private details. Deleting an organizer record removes its private details and displayed content from active organizer storage and cancels pending imports that could restore deleted data. Minimal identifiers, keyed matching references, deletion markers and receipts remain to prevent duplicate recovery or silent reimport. A receipt can confirm a completed import without restoring its deleted content.

An upload has a 24-hour staging deadline. Reconnecting before that deadline does not extend it. A review lasts at most 30 minutes and never beyond the upload deadline; expired data cannot be consumed or newly committed. Restarting an expired import clears its old staged payload and requires a fresh upload and review. Successful imports clear staged payloads and preview content while retaining minimal recovery receipts. Expired payloads are physically removed by scheduled cleanup; expiry is not a promise of deletion at that exact instant.

Account deletion blocks organizer access immediately. Organizer records and receipts become eligible for scheduled purge after the 30-day recovery window. Infrastructure backups may retain earlier copies under provider policies; we do not promise a specific provider backup deletion deadline. A backup restore must reapply deletion records before organizer access resumes.

6. Retention & Deletion

We keep your information while your account is active and as long as needed for the purposes above. When you delete your account, it enters a 30-day soft-delete window (you can change your mind during it), after which your profile is removed. Transaction records connected to payments and disputes are kept longer where bookkeeping, tax, or legal obligations require it.

Uploaded ticket files exist to deliver a ticket and back a dispute if one arises; we dispose of them within a reasonable time after they're no longer needed for those purposes, in line with New York's data-disposal requirements.

7. Security

We maintain reasonable administrative, technical, and physical safeguards scaled to the size of the service, in line with the New York SHIELD Act. Concretely: ticket files live in private buckets reachable only through 60-second signed links, data is encrypted in transit and at rest, card numbers never touch our servers, access to production systems is limited, and money-state changes are written through audited, append-only paths. No internet service can promise perfect security, but minimizing what we collect is the first safeguard.

8. Breach Notification

If a security breach affects your private information, we will notify you in the most expedient time possible and without unreasonable delay, consistent with the needs of law enforcement, and we'll notify the New York authorities where the SHIELD Act requires it. We'll tell you what happened, what was involved, and what we're doing about it.

9. Your Rights & Choices

  • Access and correction: your profile, listings, and claims are visible and editable in the app; for anything you can't reach, email us.
  • Deletion: delete your account in Settings (see section 6 for how that unfolds), or email us to ask.
  • Email choices: transactional email (claim updates, reminders) is part of how the service works; we don't send marketing email during beta.
  • Questions: support@filmexchange.nyc. A person reads it.

10. Children

Film Exchange is for adults: you must be 18 or older to use it, and the service is not directed to anyone under 18. We don't knowingly collect information from minors; if we learn we have, we'll delete it.

11. Changes & Contact

We'll update this policy as the service evolves and will give you notice of material changes before they take effect. The “last updated” date at the top is always current. Questions about this policy or your data: support@filmexchange.nyc. Our Terms of Service cover everything else about using Film Exchange.