Privacy Notice
Last updated: September 24, 2026
The statistics signal sent by versions 1.0.33 through 1.0.37 has been withdrawn: since September 24, 2026 the server has discarded those requests, and version 1.0.38 removes the request from the App. Older versions may keep attempting to send it until updated. Team mode starts on by default and syncs a pseudonymous copy of tickets; you can turn it off at any time. There are no accounts, advertising identifiers, ads, or selling or renting of data.
1. Who is responsible?
The party responsible for processing information associated with the mobile app Taquillita (the "App") is Oscar Reyes, an individual developer based in Querétaro, Mexico. Contact details appear at the end of this document.
2. What personal data does the App collect?
No identity details are required to use the App. It does not require an account or verify your identity. Team mode does send operational data to the server and may include an alias that the organizer enters to identify a phone within the event (section 7). Specifically:
- It does not require registration, an account, an email address, or a phone number. The optional phone alias may be a person's name if the organizer enters one.
- It does not collect GPS or precise location. In older versions, the API derived an approximate state/region and country from the IP when it received the statistics signal and did not save that IP in the statistics table (see section 3). The web server may retain technical access logs. Team mode uses the approximate location of synchronization connections (section 7).
- It does not collect advertising identifiers.
- Versions 1.0.33 through 1.0.37 sent a usage signal separate from the App's operating functions; it has been withdrawn (see section 3).
- It does not use ad networks or third-party trackers.
- Team mode (section 7) starts on by default and syncs tickets with pseudonymous phone identifiers and, when configured, their visible alias; you can turn it off in Settings.
3. Withdrawn statistics signal
Versions 1.0.33 through 1.0.37 attempted to send a signal when the App opened or returned to the foreground to count active installations by version and region. This request was not needed to operate Taquillita and was enabled by default. Since September 24, 2026 the server has responded without saving new records; version 1.0.38 removes the request and its switch from the App.
- Data sent by those versions: a stable random installation identifier converted to SHA-256 before it left the phone, plus the version and build number. It distinguished the same installation across days.
- Approximate area: the API derived state/region and country from the connection IP. Its statistics table kept the approximate label, not the IP; the web server may retain technical access logs.
- Data not sent: tickets, folios, QR codes, names, events, sales or validation counts, visited screens, actions, IMEI, phone number, Google account, or advertising identifier.
- Purpose: aggregated counts of active installations, versions, and general geographic reach; never advertising, profiling, or cross-app tracking.
- Control and retention: in older versions you can turn off Anonymous statistics in Settings; the App then attempts to delete its previous record and stops sending signals. The server no longer saves new signals. Inactive previous records are automatically deleted after 90 days.
- Infrastructure: the service is hosted in Finland through Hetzner Online GmbH and uses HTTPS (TLS). No third-party analytics provider is involved.
4. Information you generate inside the App
For Taquillita to work, you generate certain information locally — for example:
- Names and configuration of the events you organize.
- Generated tickets (folio, QR code, zone, digital or printed medium, number of people, dates, validation status, and identifiers of the phones that created and checked them).
- Records of when each ticket was sold or validated.
This information:
- Is first stored in your device's internal storage, in a local database (SQLite).
- While Team mode is on (section 7), a copy is synced containing each ticket's folio, consecutive number, zone, medium, number of people, dates, status, and identifiers of the phones that created and checked it. The App does not ask for attendee or customer names.
- The local copy is only accessible from the App. The web report in section 7 shows summary data only and never the secret folio.
- The local copy is wiped when you uninstall the App or clear its Android data. The synced copy follows the retention and deletion controls in sections 7 and 12.
You decide what information you enter. If you capture data about third parties (e.g., customer names), you — as the event organizer — are responsible for that data under applicable law.
5. Device permissions and what they're used for
- Camera: used exclusively to scan ticket QR codes during validation at the event entrance. Camera frames are processed in real time on the device, are not stored, are not sent to any server, and are not shared with third parties. You can revoke this permission at any time from Android settings; if you do, validation will no longer be available.
6. Sharing tickets via WhatsApp or other apps
When you choose to send a ticket via WhatsApp or another app, Taquillita uses Android's standard "share" function. At that moment the ticket image is handed to the app you select, which applies its own terms and privacy policy. Taquillita does not control what those apps do with the shared information.
7. Team mode (on by default, can be turned off)
Taquillita includes Team mode, designed to back up tickets and let several phones validate and sell the same event while staying up to date with each other. It starts on by default and syncs a copy of your tickets through a server operated by the developer, with these properties:
- Control: it starts on by default and you can turn it off at any time. While it is off, no new ticket or event changes are synced; any existing server copy follows the retention period below.
- The server is a messenger, not a judge: validation at the door is always local against the phone's own database. The server never decides who gets in; it only propagates redemptions between the phones of the same event as soon as possible. Without internet, each phone keeps validating on its own and they catch up when they reconnect.
- Pseudonymous identifiers: each phone uses a short identifier generated by the App —not a hardware identifier— and the event uses a random key (UUID). They are not automatically linked to your name, email, or phone number.
- Phone aliases: the organizer may give each phone a visible name to recognize who creates or checks tickets. That text is synced within the event; it may contain a person's name if the organizer chooses to enter one. Role names or nicknames such as “Box office” or “Door 2” are recommended.
- Synced contents: folio, consecutive number, zone, digital or printed medium, number of people (1–99), creation and validation dates, status (used / unused), and pseudonymous identifiers of the phones that created and checked each ticket. It does not ask for attendee, customer, or event names.
- Approximate room area: when a synchronization arrives, the server may derive state/region and country from the connection IP for aggregate statistics such as “Room in Querétaro.” The App never requests or sends GPS or device location; the room retains only the approximate label. When a new room is created, a separate anti-abuse log may retain the IP for up to 2 hours and then deletes it automatically.
- Server location: Finland, on Hetzner Online GmbH infrastructure. This is an international transfer, subject to applicable law.
- Encrypted connection: the transfer between the App and the server is over HTTPS (TLS).
- Retention: events with no activity for 90 days are deleted automatically from the server (the data on each phone is unaffected). You can turn Team mode off or leave the event at any time.
- Web report (optional): in Team mode, the App can share a web report with QR and people counts, zones, media, times, and the aliases or identifiers of the phones that created and checked tickets. That report never shows the folio (the ticket's secret code), only the visible number, so it cannot be used to forge tickets. The link uses a read-only identifier derived (hashed) from the event key; the clear-text key is not included and the server does not accept it on report routes. It is served over HTTPS and not indexed.
8. Internet connection
The App is designed to work offline during normal operation (generating and validating tickets, viewing local reports). It makes network requests when you share a ticket through another app, when Team mode is on to sync with the server, and when you open the web report. Versions 1.0.33 through 1.0.37 also made the statistics request described in section 3; version 1.0.38 removes it.
9. Transfers to third parties
The developer does not sell, rent, or share personal data with third parties for commercial purposes. Team mode (section 7) uses infrastructure from Hetzner Online GmbH in Finland; the former statistics signal used this infrastructure too. These services are not used for advertising or sent to analytics providers.
10. Children and minors
The App is not specifically directed to minors and does not knowingly collect data from minors. Since no personal information is collected, there is no processing of minors' data tied to use of the App.
11. Security
The information you generate starts in your device's private storage, protected by Android's security model. Protecting your device (screen lock, password) is the user's responsibility. With Team mode on, the pseudonymous copy described in section 7 also exists; another phone in the same event can rebuild it after reconnecting.
12. Your rights
Under Mexico's Federal Law for the Protection of Personal Data Held by Private Parties (LFPDPPP) and its regulations, you have the right to access, rectify, cancel, and oppose the processing of your personal data (ARCO rights), and to revoke consent. If you reside in the European Economic Area or another jurisdiction with data-protection laws (GDPR, UK GDPR, CCPA, etc.), you may have additional or equivalent rights.
For Taquillita, since ordinary information lives on your device, those rights are exercised directly from it:
- Access and rectification: from inside the App.
- Local cancellation / deletion: by clearing the App's data from Android settings, or uninstalling.
- Usage statistics in older versions: turn off Anonymous statistics in Settings to request deletion of the previous record and stop send attempts. If offline, the record expires after 90 days of inactivity. Version 1.0.38 no longer sends that signal.
- Team mode: turn it off or leave the event to stop syncing. Server data is deleted automatically after 90 days of inactivity; to have it deleted sooner, write to the developer with the event identifier. See also the data deletion page.
- Revoking the camera permission: from Android settings, at any time.
If you believe any processing infringes your rights, you can contact us. Mexican users may also contact the Ministry of Anti-Corruption and Good Government (Secretaría Anticorrupción y Buen Gobierno), the competent authority under current Mexican law.
13. Changes to this notice
If the App's privacy behavior changes in the future, this notice will be updated and the "Last updated" date will reflect it. The current version will always be at this same URL.
14. Contact
Oscar Reyes — Taquillita developer
Email: oscar@mercax.com
WhatsApp: +52 442 774 4366
Querétaro, Mexico