Privacy Policy

Effective September 29, 2026

Holy Fool is a Colorado nonprofit corporation, tax-exempt under section 501(c)(3) of the Internal Revenue Code (EIN 33-3015829). This policy explains what personal information we collect, how we use it, who we share it with, and the choices you have. It covers:

  • our website, www.holyfoolco.com;
  • our tickets and giving site, give.holyfoolco.com, including the guest and donor portal there;
  • the emails we send; and
  • the sign-in our staff use to run these sites.

Questions or requests: holyfoolco@gmail.com.

What we collect

When you buy tickets or give. Your name, email address and, if you enter it, phone number; what you bought or gave and the amount; whether you chose to cover processing fees; any promo code you used; and a record of your agreement to our ticket terms. We also record the internet (IP) address the order came from, to help us spot fraud.

Payment details. Payments are handled by Stripe, our payment processor. Your card number goes to Stripe, never to us. Stripe sends us a reference for the payment and, for monthly gifts, a reference for your subscription. Stripe may also collect your billing address and other details for its own fraud checks, under its own privacy policy at stripe.com/privacy.

Monthly gifts. If you set up a monthly gift, we keep the details needed to record each month's gift and send you a receipt. If a giving option includes something we mail you, such as a merch box, we collect your shipping address through Stripe and keep it so we can ship to you.

Guests at giving events. If you buy more than one seat at a giving event, you can name a guest for each seat: their name, their email address and, when the event asks for it, a short note such as dietary restrictions. We email each guest their own ticket. A note about dietary needs can reveal something about a person's health or religion, so please share only what the event needs, and only for people who have agreed that you may share it.

At the door. The time each ticket was checked in.

Mailing list and waitlist. Your email address, when and where you signed up, the wording you agreed to, and a scrambled (hashed) form of your IP address. We keep the readable IP address for 90 days as proof of your sign-up, then delete it.

Portal sign-in. Signing in to the portal takes your email address (we send you a sign-in link) or the code on your ticket. We keep a session record so you stay signed in for up to seven days.

Staff sign-in with Google. Our staff sign in to our admin tools with their Google accounts. From Google we receive the staff member's name, email address and Google account ID, and nothing else: we do not read Gmail, Drive, contacts or any other Google data. We use these three details only to check that the person is on our staff list, to keep them signed in, and to record which staff member did what in our admin tools. We do not share them with anyone and do not use them for any other purpose. When someone leaves our staff, their access ends; their name stays only in the history of what was done in our admin tools.

Automatically. Like most sites, our servers record the IP address, browser type, pages requested and time of each request in server logs, which we use to keep the sites running and secure and to limit abuse. Our giving site uses Cloudflare Turnstile to tell people from automated programs when you check out, sign in or submit a form; Turnstile looks at your browser and connection to do this, under Cloudflare's privacy policy at cloudflare.com/privacypolicy. Our main website is hosted by Squarespace, which sets its own cookies so the site works and to count visitors, under Squarespace's cookie policy.

Email engagement. Our updates and newsletters may contain a tiny image and tracked links, so we can see whether a message was opened and which links were clicked. Ticket emails, receipts and sign-in links contain no tracking.

How we use it

  • To deliver what you asked for: tickets, guest tickets, receipts, confirmations and sign-in links; to let you name guests; to check tickets at the door.
  • To take payments and run monthly gifts, handle failed payments and disputes, and prevent fraud.
  • To give you the receipt the IRS requires and to keep our own financial and tax records.
  • To tell you about Holy Fool's events, campaigns and the musicians we support. We may send these updates to people who bought tickets, gave, or joined the mailing list. Every update lets you unsubscribe, with the link in it, with your mail app's unsubscribe button, or by replying, and unsubscribing never stops your receipts or tickets.
  • To run, protect and improve the sites: logs, rate limits and bot checks.

We do not sell personal information, and we do not share it with anyone for advertising.

Who we share it with

  • Stripe processes payments and monthly gifts and runs the page where you update your card or cancel a monthly gift.
  • Amazon Web Services hosts our giving site and its database, in Oregon in the United States, and delivers our email.
  • Cloudflare provides the bot check described above.
  • Google handles staff sign-in, as described above. Google never receives information about ticket buyers or donors from us.
  • Squarespace hosts our main website.
  • The venue, the caterer and our event team receive guest names and any dietary or similar notes, so that the event can be prepared.
  • The person who bought your ticket can see the name, email address and note they entered for you, and can change them until the event's guest-naming deadline.
  • Our accountant, lawyers and similar advisers, when needed, and anyone we are required to share with by law, such as in response to a valid legal request.

Our staff and volunteers who run events can see orders, gifts and guest lists in our admin tools. Ticket codes are never exported from those tools.

How long we keep it

  • Orders, gifts, receipts and monthly-gift records: as long as our financial and tax records require, generally seven years.
  • Guest names, guest notes and check-in times: with the event's records. Ask us and we will delete your guest note after the event.
  • Mailing list: until you unsubscribe. We keep unsubscribed addresses on a do-not-email list so that we never email them again by mistake.
  • Sign-in links: fifteen minutes. Portal sessions: seven days. Staff sessions: seven days.
  • Server logs: about two weeks. Database backups and disk snapshots: about two weeks.

Your choices

  • Unsubscribe from updates any time, using the link or button in any of them or by replying to one.
  • See and manage your tickets and gifts in the portal at give.holyfoolco.com/my. You can change or cancel a monthly gift there any time; cancelling stops future charges.
  • Ask us to see, correct or delete the personal information we hold about you by emailing holyfoolco@gmail.com. We will do it, except for the records we are required to keep, such as the record of a donation. We may ask you to confirm the request from the email address on the record.
  • Our sites do not track you across other websites, so there is nothing for a "Do Not Track" signal to turn off, and we do not respond to one.

Security

Everything travels over encrypted connections. Card details stay with Stripe. Sign-in links and session records are stored in scrambled (hashed) form. Ticket codes work like passwords: we never publish or export them, and you should share yours only with the person who will use that seat. Access to personal information is limited to the people who need it. No system is perfectly secure; if we learn of a breach that affects you, we will tell you.

Where your information is kept

Our sites and the services we use are in the United States. If you use them from elsewhere, your information is transferred to and handled in the United States.

Changes

We may update this policy. The date at the top tells you when it last changed. We will announce a material change on the site or by email to the people it affects.

Contact

Holy Fool holyfoolco@gmail.com