Privacy Policy
Last updated: August 8, 2026
Blucifer's First Rodeo is a Denver music festival run by Blucifer's Rodeo LLC, a Colorado limited liability company ("we," "us," "the festival"). This policy covers bluciferfest.com and everything that runs on it: wristband and merch checkout, the attendee portal, the artist and crew portals, our mailing list, and our email and text updates.
The plain-English promise up front: we collect what we need to run a festival, and that's it. No ads, no analytics, no selling your information. Ever.
the short version
- What we collect: your name, email, and order details when you buy something. Your phone number only if you choose to give it. A shipping address only if we're mailing you merch.
- What we never do: sell or rent your information, share it for anyone else's marketing without your consent, or run advertising and analytics trackers on our site.
- Your choices: every update email has a one-click unsubscribe. Text STOP to stop texts. Email help@bluciferfest.com for anything else.
What we collect
Buying a wristband. Your name, email address, an optional phone number, whether you checked the text-updates box, and any promo code you use. Your QR code is tied to this order, and it works like a key to your attendee portal: anyone who has it can sign in as you, see your order, and even manage it (transfers, contact preferences), so treat it like a ticket.
Buying merch. Your name and email. If your order ships, you enter your shipping address with Stripe during payment and Stripe shares it with us so we can mail your stuff; we also keep the tracking number. Local pickup orders skip all that.
Paying. Card numbers go directly to Stripe and never touch our servers. We keep order records (what you bought, the amount, and Stripe's transaction identifiers), not payment card details. If you pay by Venmo, that happens in your Venmo app under Venmo's own privacy policy; we record your name, your email if you give it, and the Venmo transaction reference (including any note you attached to the payment) so we can issue your wristband or merch.
Donating. Donations happen on Stripe's hosted donation page for our nonprofit partner Holy Fool. We don't collect donor information on our site.
Joining the mailing list. Your email address. We also record the internet address (IP) you signed up from as a consent record and abuse check; we delete the raw IP after 90 days and keep only a scrambled version after that.
Opting in to texts. Your phone number, plus a record of exactly what you agreed to and when.
The Baker neighborhood discount. The address you type, the standardized version of it, its map coordinates, your email, and your IP address, so we can verify residency and prevent abuse. Addresses are checked against the neighborhood boundary using AWS's geocoding service.
Using the attendee portal. Your email address, for password-free login links. Anything you save in the portal, like schedule picks or quiz answers, is stored with your account email.
Volunteering. Contact info, emergency contact, shift preferences, your waiver signature, and any medical or accessibility notes you choose to share. Medical and emergency details are visible only to festival organizers and are never included in the rosters we share with venue coordinators.
Playing, shooting, or working the fest. Artists, media, and crew give us application and confirmation details: contact info, member lists, bios, photos, stage plots, and similar. The public schedule shows only what's meant to be public (band name, bio, photo, music links). Tax paperwork (W-9s) is stored in our document system, not on our web servers. So shows can run, working contact info is shared among the people on the same bill: bands see their show captain's and sound engineer's names and contact details (and vice versa), bandmates can see each other's emails, and photographers' chosen credit info is shown to the artists they photographed.
Signing things. When you agree to something on our site (the volunteer waiver, a photo-credit agreement, a confidentiality pledge), we keep a record of exactly what you agreed to, when, and the internet address it came from.
Transferring a wristband. You give us the recipient's name and email so we can invite them; they see your name on the invite, and you get an email when they accept. We keep the transfer record.
Picking up your wristband. At pickup stations, check-in volunteers can look up wristbands by name or email to hand them out. We record which wristbands were picked up, when, and by which check-in volunteer, and we email you when your wristband is picked up so you know it happened.
Emailing us. If you write to help@bluciferfest.com, we keep the conversation so we can help you.
Automatically. Server and application logs (IP address, pages requested, and technical details of requests, which can include information you submitted on a form) for security and debugging, the internet address behind checkouts and sign-ups for fraud prevention, bot checks via Cloudflare Turnstile on our forms, and open/click information on our bulk emails (details in the Email section). We do not use analytics services, advertising trackers, or tracking tools from other companies. We do tally our own aggregate numbers (sales totals, how many people opened a mailing) from the records described on this page, but nothing on our site watches your browsing. We never collect your device's location, and we do not collect biometric data.
How we use it
To get you your wristbands, QR codes, and merch. To run the festival: pickup stations, transfers, schedules, day-of updates. To send the emails and texts described below. To prevent fraud and abuse. To keep the books and comply with the law. That's the whole list.
Payments and Stripe
We use Stripe for card payments, sales tax, and fraud screening. Stripe collects payment information directly, may set its own cookies on checkout pages, and collects transaction and device information to run its services and detect fraud. Card data is handled entirely by Stripe; our servers never see it. For the Baker discount, we pass Stripe the ZIP code we verified so its fraud tools can check it against your card's billing ZIP. You can read Stripe's privacy policy at stripe.com/privacy.
Text messages
If you opt in (the box is never pre-checked, and buying a wristband never requires it), we send festival updates by text: pickup reminders, schedule changes, can't-miss moments. We also send one-time login codes if you request one.
- Message and data rates may apply. When you opted in we promised no more than 10 messages a month, and we hold ourselves to that.
- Text STOP (or UNSUBSCRIBE, CANCEL, END, or QUIT) at any time to stop. Text HELP for help. You can also opt out in the attendee portal or by emailing us. We honor opt-outs promptly, and in all cases within 10 business days.
- No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are never shared with third parties or affiliates for marketing; the only companies that touch them are service providers acting for us, solely to run the program (Stripe carries your number and checkbox choice from checkout to our server, and AWS delivers the messages). We do not sell or rent information obtained through our text program.
For attendees, two kinds. Transactional email (order confirmations, login links, transfer notices, shipping updates) goes to the address on your order, because the service doesn't work without it. Update email (festival news, merch drops) goes only to people who gave us their email by signing up, buying from us, or working with us on the festival, and every one carries a one-click unsubscribe that works immediately: no login, no questions.
Our bulk update emails may include a small first-party open-tracking image and wrapped links, so we can tell whether a mailing was opened or clicked. Those records are pseudonymized: they store a coded reference instead of your address, along with browser info and a scrambled IP. Transactional email carries no tracking.
We also send working email to artists, volunteers, media, and crew about their sets, shifts, and passes. Those messages may use the same open and click measurement and don't carry an unsubscribe link, because they're how we run the event; email help@bluciferfest.com to stop them, and an unsubscribe you make anywhere covers these too.
When you unsubscribe, we add you to a permanent do-not-email list, which is why we keep that record instead of deleting it. The public sign-up form can never override an unsubscribe; if you change your mind, email help@bluciferfest.com and a human will add you back.
Who we share it with
We never sell or rent personal information, and we never share it so someone else can market to you. The companies that do touch it are service providers doing work for us:
- Stripe (payments, sales tax, fraud screening)
- Amazon Web Services (our servers and database, email delivery, text delivery, file storage, and address geocoding for the Baker discount)
- Cloudflare (the Turnstile bot check on our forms sees your IP address, like every bot check does)
- Google Workspace (organizer spreadsheets and documents, like order and volunteer rosters, our help@ mailbox, plus organizer sign-in; attendees never sign in with Google)
- Other technology service providers (the services our band-match feature use to characterize bands; these receive band names, genre tags, and band-provided bios, never anything about you)
- Shipping carriers and postage services (to print labels and get you tracking for mailed merch)
A few festival pages embed content from other companies. Opening a band's card on the schedule can load a music player from Spotify, YouTube, or Apple Music, and those players may set their own cookies, same as visiting those sites directly. Searches in our band-match feature are looked up against outside music databases (like MusicBrainz) and characterized by the AI service above; in every case they see the band you searched for, never who searched.
One more case: sharing you agree to. If we offer a way to connect you with someone else (for example, one-click joining a band's mailing list from your festival schedule), nothing is shared unless you choose it, we share only what's needed to do the thing you consented to (usually your email address), and from there the band or organization you connected with handles it under their own privacy practices.
If the festival's operations are ever transferred or reorganized, records would go with them under commitments at least as protective as these.
Cookies and local storage
We use first-party cookies for signing you in to the portals (attendee, artist, crew, organizer) and keeping those sessions secure. They're secure, HttpOnly where possible, and expire on their own after 4 to 30 days depending on the portal. Login links expire after 15 minutes. The merch store keeps your cart in your browser's local storage (no personal info, and it clears itself after 24 hours or checkout).
There are no advertising or analytics cookies here, and we don't track you across other websites, so there's nothing for a Do Not Track or Global Privacy Control signal to turn off. We don't respond to those signals because there's no tracking to disable.
How long we keep things
Festival and order records are kept after the event for accounting, taxes, and running future rodeos. Unsubscribe and opt-out lists are kept permanently, because that's how we honor them. Raw mailing-list sign-up IPs are deleted after 90 days (we keep the scrambled version described above). Login links stop working after 15 minutes, and expired sessions are deleted automatically. Automated database backups are kept for 7 days, and we keep a small number of offline archival snapshots of festival records, under restricted access, for disaster recovery and migrations. If you want something gone sooner, ask us (see Your choices).
Security
Everything travels over HTTPS. Email login links and text codes are stored hashed and expire quickly. Sessions live on our servers, not in your cookies. Card data never touches our systems. Our database and private file storage are encrypted at rest. Access to attendee data is limited to festival organizers and vetted event staff (like check-in volunteers), always behind sign-in, and organizer tools use role-based permissions. We will comply with all Colorado law requiring notification of any breaches that affect your personal information.
Your choices
- Unsubscribe from update email with the link in any of those emails.
- Stop texts by texting STOP, or toggle them off in the attendee portal.
- Update your phone number and text preferences in the attendee portal.
- Want to know what we have about you, fix something that's wrong, or have data deleted? Email help@bluciferfest.com. We'll tell you what we have, correct errors, and delete what we can. Some records we need to keep (completed orders for tax and accounting, and opt-out lists so we never contact you again), and we'll tell you when that's the case.
We honor these requests as a matter of practice.
Kids
Our website and services are for a general audience and are not directed to children under 13, and we don't knowingly collect personal information from children under 13. If you believe a child gave us their information, email help@bluciferfest.com and we'll delete it.
Visiting from outside the US
We're a Denver festival. Our services are operated from the United States and your information is processed and stored in the United States. If you order merch from abroad, your information is handled the same way as everyone else's, under this policy.
Changes
If this policy changes, we'll update it here and change the effective date at the top. If a change actually matters (a new kind of data, a new use), we'll say so prominently on this page and, for subscribers, in email.
Contact
Questions, requests, complaints, compliments about the horse: help@bluciferfest.com.