Data Privacy & FERPA Compliance
We hold every account to the strictest privacy standard any of our customers is subject to. For organizations covered by FERPA, here is exactly what that means.
Every organization on Its1Ticket gets the same privacy protections. Some of our customers carry additional legal obligations — the Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records, and if your organization is covered by it, any covered information we process on your behalf is handled under FERPA and applicable state privacy laws. Here is our commitment.
In plain terms
- •Your organization signs our FERPA Data Privacy Addendum alongside our Terms of Service. Doing so makes us a “school official” — a trusted extension of your own staff — so we can lawfully handle student data on your behalf.
- •You stay the owner and controller of the data. We use it only to run your ticketing — never to sell, market, profile students, or train AI.
- •If a data breach ever occurs, we notify you in writing within 48 hours. If we ever change a vendor that touches covered data, you get 30 days’ notice and the right to object.
- •Parent or student requests to view or delete records are routed back to your organization, which stays in control of those rights.
- •Ticket photos auto-delete after each event, and when our agreement ends we return or securely destroy your covered data.
We act as a "School Official"
When a covered organization uses Its1Ticket, we handle student information as a "school official" under the FERPA exception (34 CFR § 99.31(a)(1)) — performing a service the school would otherwise do itself, under the school’s direct control.
No selling. No marketing. No AI training.
We never sell, rent, or trade your data, never use it for advertising or profiling, and never use it to train third-party or general-purpose AI models. It is used only to provide the ticketing service.
Security built in
Encryption in transit (TLS 1.2+) and at rest (AES-256), row-level security and role-based access, an append-only access log recording who viewed rosters and photos, and a "sensitive field" marker for medical/DOB data.
A small, vetted set of subprocessors
Covered data is processed only by the vendors listed in our Privacy Policy, each under a data-processing agreement, and only to provide the service to us.
Return or destroy on request
Ticket photos auto-purge after each event. On request or when a contract ends, we return or securely destroy covered data — and can certify destruction.
You stay in control
Your organization owns the data, decides what is collected, and can access, export, or delete it at any time. Parent/eligible-student rights requests are referred back to you.
Our FERPA Data Privacy Addendum
Read and download our FERPA Data Privacy Addendum (DPA), which formally designates Its1Ticket as a “school official” and documents these commitments. When you are ready to execute it — or if your organization requires its own DPA or a state-specific addendum — contact us and we will get it signed.
See also our Privacy Policy (including the full subprocessor list) and Data Management page.