TTM Scanner Privacy Policy
This Privacy Policy describes how Talent Tricks Marketing Management ("we", "us") collects, uses, and protects information when you use the TTM Scanner mobile application ("TTM Scanner", the "Service"). TTM Scanner is a venue-operator tool used by door and event staff to verify member QR codes. It is not intended for end-consumers.
1. What TTM Scanner Does
TTM Scanner is a scanner-only application. An administrator pairs the device to a single venue using a short-lived 6-digit code issued from the admin console. Once paired, the device reads QR codes presented by members and records the result.
2. Information We Collect
- Device pairing token: a short, per-device authentication token issued at pairing time and stored in the device secure enclave (Keychain on iOS, Keystore on Android).
- Device context: the tenant, venue, product, device identifier, and token prefix associated with the paired venue. This is fetched from our servers at pairing time.
- Scan events: when a QR code is scanned, we transmit the QR token to our server. The server records the outcome (accepted, rejected, or already-redeemed), the member, the entitlement used, and a timestamp.
- Basic device metadata: device model, OS version, app version, and crash logs, collected for diagnostics and crash reporting.
- Diagnostics & usage analytics: aggregate crash reports (Firebase Crashlytics) and anonymous app-usage / diagnostic events (Google Analytics for Firebase), used only to keep the scanner stable and to roll out fixes. These are not linked to any member and are never used for advertising.
TTM Scanner does not collect names, emails, phone numbers, addresses, payment data, location, contacts, microphone audio, photo library content, or any biometric data. Camera access is used only to decode QR codes in real time; video frames are never stored on the device or uploaded to our servers.
3. How We Use It
- To verify that a member holds a valid entitlement for the paired venue and event.
- To maintain a per-venue ledger of scan activity for operational review and fraud prevention.
- To operate and improve the Service, including crash diagnostics.
4. Third-Party Services
- Expo / EAS — over-the-air app updates and push-token issuance. Expo.
- Google Firebase — Crashlytics (crash & diagnostic reporting), Google Analytics for Firebase (anonymous usage / diagnostics), and Remote Config (server-controlled feature flags). Firebase · Google.
- Apple Push Notification service / Firebase Cloud Messaging — delivery of operational push notifications (e.g. pre-approval pings, venue alerts) to the paired device, addressed by an Expo push token. Apple.
TTM Scanner does not use Stripe, Nomod, or SMTP2GO, does not use any advertising network, and never sells or shares data for advertising. Analytics is limited to anonymous diagnostics that keep the app stable.
5. Data Retention
The device pairing token is valid until the venue administrator unpairs the device, at which point the server revokes it and the device clears it from secure storage. Scan event records are retained on our servers as part of the venue's operational records; ask your venue administrator for the venue's internal retention policy.
6. Device-Side Data Removal
From the TTM Scanner app, open Settings → Unpair Scanner. This deletes the device pairing token, device context, and backend selection from the device secure enclave. You may also uninstall the app at any time.
7. Security
We use industry-standard encryption in transit (TLS). Authentication tokens are stored in the device secure enclave. No personal data leaves the device except scan results routed to the paired venue's backend.
8. Children
TTM Scanner is a staff-facing tool and is not intended for use by children. We do not knowingly collect personal information from children.
9. Changes to This Policy
We will post material changes to this page and update the effective date above.
10. Contact
Questions? Write to support@rizz.ttmdxb.com.