Privacy Policy
Last updated: September 9, 2026
This Privacy Policy explains how Hydra Check-in (“Hydra”, “we”, “us” or “our”) handles personal information when you use hydracheckin.com, the Hydra Check-in application, the Hydra support portal and related services (collectively, the “Service”).
1. Scope and roles
Hydra is a tool used by event organisers to validate tickets and manage event access. For attendee data processed through an organiser’s own ticketing system, WordPress site or Hydra Bridge installation, the organiser is generally the data controller. Hydra is not the ticketing platform and does not route that attendee data through hydracheckin.com.
For website, licensing, telemetry and support information described below, Hydra Check-in is responsible for the processing described in this policy.
2. Information we process
a) Website and security information
When you visit our website, our infrastructure and security providers may process technical information such as IP address, browser and device information, request URLs, timestamps and security-event data. We use this information to deliver the website, prevent abuse and keep the Service secure.
b) Analytics
Where analytics are enabled, we may collect standard usage information such as page visits, device and browser type, approximate location and interaction data. We use analytics to understand and improve the website. Analytics technology is configured and disclosed through the website’s applicable cookie controls.
c) Licensing and product telemetry
Hydra processes limited operational telemetry needed to provide licensed functionality, enforce usage limits, investigate reliability issues and administer refunds. This may include a license identifier, plan information, allowed-device information, aggregate check-in totals, session totals, product version information, last-connected timestamps and a pseudonymous site identifier.
This telemetry is not intended to include attendee names, email addresses, ticket contents or ticket identifiers.
d) Support requests
When you contact support, we process the information you choose to provide, including your name, email address, ticket subject, message content, attachments and any technical information included in your request. Attachments may contain personal or sensitive information; please send only what is necessary to resolve the issue.
We use a time-limited one-time code sent to your email address to protect access to a support ticket. We process the email address, code-verification attempts and session information necessary to provide that access.
3. How we use information
We use the information described in this policy to:
- operate, secure and improve the Service;
- provide customer support and respond to requests;
- provide and administer licenses, subscriptions and refunds;
- detect, investigate and prevent fraud, abuse and security incidents;
- comply with legal obligations and enforce our Terms of Use; and
- communicate service-related information, including support replies and access codes.
4. Service providers and sharing
We do not sell or rent personal information. We share information only where necessary to operate the Service, comply with law or protect our rights and users.
Relevant providers may include:
- Freemius, which processes purchases, payment information, invoices, subscriptions and customer account information as our reseller and payment provider;
- Resend, which delivers transactional support emails and one-time access codes;
- Cloudflare, which provides DNS, performance and security services and may process network and request metadata; and
- hosting, backup and infrastructure providers that process information only as needed to run and secure the Service.
Each provider processes information according to its own terms and privacy documentation, as applicable.
5. Attendee data and direct connections
Hydra Bridge is designed to communicate directly between the Hydra application and the organiser’s own system. Hydra does not operate as an intermediary for attendee data exchanged in that connection. We do not intentionally collect attendee names, email addresses, ticket identifiers or check-in records from an organiser’s event system through the public website or telemetry service.
Hydra may store attendee data locally on devices to enable offline functionality. That local data remains under the organiser’s control, and organisers are responsible for securing their devices and complying with applicable data-protection obligations.
6. Retention
We retain information only for as long as necessary for the purposes described in this policy, unless a longer period is required by law or needed to establish, exercise or defend legal claims.
Support tickets remain available while active and for a configurable period after resolution. Attachments have a separate, normally shorter retention period. After the applicable retention period, attachments are physically deleted and ticket information is deleted or anonymised. Where a resolved case has useful technical value, we may retain a structured, anonymised knowledge entry that does not contain the original ticket, attachments or identifying information.
One-time support access codes expire after a short period and are not retained as a reusable password. Licensing and telemetry records are retained only for as long as reasonably necessary to administer licenses, refunds, security and service reliability.
7. Security
We use reasonable administrative, technical and organisational measures to protect information. Support attachments are stored outside the public web root and access is restricted to the relevant customer session or authorised support agents. No system is completely secure, and you should avoid sending passwords, API keys or other secrets through support unless strictly necessary.
8. International processing
Our service providers may process information in countries other than the country where you live. Where required, we rely on appropriate safeguards provided by the relevant provider or applicable law.
9. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict or object to certain processing of your personal information, and to request data portability. To make a request, contact us using the details below. Requests concerning attendee data held by an event organiser should be directed to that organiser.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the “Last updated” date.
11. Contact
For privacy questions or requests, contact us at legal@hydracheckin.com.