Johnson Farms

Legal policy

Privacy Notice

How Johnson Vegetable Farms collects, uses, shares, protects, and retains website and ticketing information.

Effective 2026-09-16

Version 2026.09.16 governs current use of this website and ticketing service.

Scope

This notice is effective as of September 16, 2026.

This notice applies to the Johnson Vegetable Farms website, Nightfall ticketing, electronic participation agreements, ticket delivery, admission, customer support, and administrator operations. It does not control the independent privacy practices of Square, Supabase, Vercel, Postmark, Sentry, or another website linked from this site.

Who is responsible and how to contact us

Johnson Vegetable Farms operates this website and determines why the farm uses ticketing information. Privacy questions and requests may be sent to Michaelmgj96@gmail.com, by telephone at +1 541-343-9594, or by mail to 89733 Armitage Rd, Eugene, OR 97408.

For security, the farm may need to verify the requester’s identity and relationship to an order before disclosing, correcting, or deleting information.

Information provided by purchasers and participants

Checkout collects the purchaser’s first and last name and email address. For each additional participant, it collects first and last name and whether the person is an adult or minor. It also collects an email address for each additional adult. Birthdates are not collected.

The purchaser records that they are at least 18 years old and, when minors are listed, that they are each minor’s parent or legal guardian. The purchaser and each additional adult provide an electronic agreement acceptance and identifying information used to match the acceptance to the reservation.

Customer-support communications may contain information a customer chooses to provide. Customers should not send full payment-card numbers, security codes, government identification numbers, medical records, or other information the farm has not requested.

Orders, payments, tickets, and admission records

The application records the selected event date and arrival window, participant quantity, price, order and payment state, Square transaction references, limited card details such as brand and last four digits when Square returns them, ticket references, ticket delivery history, and refund information.

Square’s hosted payment fields collect payment credentials and return a payment token. Full card numbers and card security codes do not pass through or remain in the Johnson Vegetable Farms application.

Agreement records include the displayed version, a cryptographic hash of its text, the signer’s supplied name and email, the covered participants, and the acceptance time. Admission records include check-in and reversal history, the administrator who performed the action, and the related ticket. Private ticket and agreement links are stored as cryptographic hashes rather than readable bearer tokens.

Technical, security, and administrator information

Hosting and security systems receive ordinary technical information such as request time, page or route, browser or device characteristics, referring page, network information, and service or error identifiers. The application converts network addresses used for abuse prevention into keyed hashes and does not intentionally place raw network addresses in its application tables or logs.

Administrator records include authentication identity, authorization status, configuration changes, searches, exports, resends, refunds, check-ins, reversals, and other audit events. Error monitoring is configured not to request default personally identifiable information, although an operational event may contain limited technical context needed to investigate a failure.

The site uses necessary browser storage or cookies for security, administrator authentication, and transaction continuity. Vercel Web Analytics measures aggregate site usage. The farm does not use this application for targeted advertising, cross-site behavioral tracking, or profiling that produces legal or similarly significant effects.

How information is used

Information is used to display availability; hold capacity; calculate prices; process and reconcile payments; issue, deliver, and display tickets; obtain and preserve agreements; activate party admission; check in attendees; process refunds; answer support requests; report sales; investigate failures or misuse; protect customers, staff, and the service; maintain business and legal records; and comply with applicable obligations.

Johnson Vegetable Farms does not sell personal information and does not use transactional email addresses for unrelated marketing through this application.

Service providers and other disclosures

The farm discloses information to service providers only as reasonably necessary for their work: Square processes payments and refunds; Supabase provides PostgreSQL database hosting and administrator authentication; Vercel hosts the application and provides aggregate web analytics; Postmark delivers transactional email; and Sentry supports error monitoring. These providers may process identifiers, commercial or transaction information, communications, and technical information according to their services and contracts.

Information may also be disclosed to professional advisers, insurers, payment networks, banks, law enforcement, courts, regulators, or transaction counterparties when reasonably necessary to obtain advice, handle a claim or dispute, prevent fraud or harm, comply with law or legal process, or evaluate an actual business transfer. The farm does not make participant rosters public.

Information about minors

The online ticketing service is for adult purchasers and is not directed to children. A child should not submit information or complete an agreement directly. A parent or legal guardian supplies a minor participant’s name and minor designation and consents to its use for the reservation, participation agreement, safety, support, and admission purposes described in this notice.

The application does not request a minor’s email address, birthdate, precise location, photograph, audio, or government identifier. A parent or legal guardian may contact the farm to ask about a minor’s information, subject to identity verification and records the farm must retain.

Retention

Completed order, payment-reference, refund, agreement, ticket, delivery, administrator-audit, and check-in records are retained for seven years to support tax, accounting, insurance, dispute, safety, and transaction-history needs. Failed or abandoned order records are retained for 60 days and then deleted or minimized through scheduled cleanup.

A provider may retain information for a different period under its own legal obligations, account settings, backup cycle, fraud-prevention program, or contract. The farm may retain information longer when reasonably necessary for an active dispute, legal hold, security investigation, or applicable legal requirement, and may retain deidentified or aggregated information that no longer identifies a person.

Privacy choices and requests

A person may contact Michaelmgj96@gmail.com to request access to, correction of, or deletion of personal information associated with them or their minor child, or to ask how it was used or disclosed. The request should identify the relevant order without including full card information. The farm will respond as required by applicable law and may deny or limit a request when identity cannot be verified or when retention is reasonably necessary for payment, tax, fraud prevention, safety, legal, insurance, or dispute purposes.

If applicable law provides a right to appeal a denied privacy request, the requester may reply with the subject line “Privacy Appeal” and explain the basis for the appeal. Because the farm does not sell personal information or use it for targeted advertising or legally significant profiling through this application, it does not currently offer opt-out controls for those activities.

Security, incidents, and changes

The farm uses measures designed for the nature and size of the service, including encrypted transport, restricted administrator access, server-side authorization and validation, hashed access tokens, provider signature verification, minimized logging, database transaction controls, monitoring, and retention cleanup. No security measure can guarantee that information will never be lost, misused, or accessed without authorization.

If a security incident creates a notification obligation, the farm will investigate and provide notice as required by applicable law. Material changes to this notice will be published as a new version with a new effective date and, when appropriate, additional notice.