Privacy Policy
Privacy Policy of Saint George Climbfest
Readable in five minutesThe developer behind these festival platforms is Saint George Climbfest. We operate this website and our related booking, clinic, guiding, vendor, and community services to help people find joyful and responsible climbing in the red rock country around St George. This Privacy Policy explains what information we collect, why we collect it, how we look after it, and the choices available to you. Please read the entire policy before you use our services.
Saint George Climbfest LLC2875 E 850 N, St George - 84790-5841, United States (US)
talk@saintgeorgeclimbfest.lol · +19157799690
1. Introduction and the Company behind this site
Saint George Climbfest LLC is a limited liability company that produces an annual climbing festival, clinics, guided sessions, route setting events, vendor expositions, community film nights, and additional responsible outdoor programmes. The company is based in St George in the state of Utah and operates across the United States (US). We hold ourselves to a plain and honest standard of privacy practice that matches the way we climb: clear communication, reliable protection, and mutual care for every person who joins us.
The developer name associated with the creation and maintenance of these website and booking surfaces is Saint George Climbfest. That single name refers to the studio founders, designers, engineers, and support staff who jointly produce the digital experience you are reading right now. Whenever this policy says the Company, Saint George Climbfest LLC, we, or us, we mean the organisation that owns and operates the festival services and this website.
When you book a pass, register for a clinic, sign a waiver, become a volunteer, apply for vendor space, ask a question, or simply browse the routes and schedules, you share some form of personal information. This policy tells you exactly what happens after that point, so that your decision to climb with us is made with open eyes. We update this page whenever our practices evolve, and the revision date at the top always reflects the newest version.
2. Scope of this policy and privacy for children
This Privacy Policy applies to this website, our mobile friendly registration portal, the contact and enquiry facilities, festival event pages, clinic and guiding booking flows, our email communications that link back to this policy, and the administrative systems we use internally to run events. It does not apply to third party websites that you reach through links we provide, such as partner ticketing solutions or social media channels, unless we say otherwise. The privacy for children rule is covered right here.
The Company sells many family friendly festival products, yet we treat information about children with special discipline. Where verifiable parental consent is required by law, we do not collect, use, or store the personal details of a young person without that consent in place. When a parent registers a child for a youth clinic or competition, we collect only the details that the activity genuinely requires, such as name, birth month and year for category placement, an emergency contact, and medical notes needed to keep that child safe.
We never sell or rent the personal information of children, and we never use children information for behavioural advertising. Unsupervised direct marketing is not sent to addresses that we know belong to minors. If the Company ever learns that personal information has been collected from a child without proper consent, we remove that information promptly and follow the required reporting steps.
3. Information we collect from visitors and guests
The information the Company collects falls into clear categories. Browsing data is small and technical. Booking data is the detail needed to deliver a real event on real rock. Support data appears when you write to us. Together these give us a picture just large enough to run a festival well, and never larger than that.
When you register for the festival or book a service, we may collect your full name, email address, phone number, postal address, emergency contact name and relation, age or date of birth where a category or insurance needs it, billing address, payment confirmation references, and your chosen programme selections such as clinic times, competition categories, shuttle seats, and gear hire options. Waivers and liability documents ask for a signature and a few details needed to verify that signature belongs to you.
Volunteers provide availability, relevant experience and first aid certificates, t shirt size, and dietary notes. Vendors provide business names, tax and banking details for settlement, insurance certificates, stall equipment needs, and power or vehicle requirements. In each case we collect the minimum necessary and store it only where it supports the service you asked for.
4. Information collected automatically and by our network
Every website observes a little of what happens on it so that pages load sensibly and errors are found. Our servers and analytics helpers may see technical signals such as the general geographic region of an internet connection, the type and version of your browser, your operating system, screen size, language preference, referring web pages, the date and time of your visit, and which pages you viewed. This information is generally aggregated and does not identify you personally on its own.
We also apply safeguards across the network that protect against abuse. Anti fraud checks may examine signs of automated traffic, attempts to buy tickets in very large volumes, or patterns that suggest a bot is scraping our schedules. These checks help keep real climbers ahead in the queue for limited competition seats and keep prices fair for everyone. Network logs are kept short and are used almost always for stability and protection rather than profiling.
Some of our event and booking pages include interactive elements such as the schedule accordion and the contact form. These behave entirely on your device using standard web technology and do not by themselves transmit personal details except when you deliberately submit the form with your own message and name on board.
6. Data from third party platforms and payment partners
Some information reaches us through third parties rather than directly from you. When you arrive at our pages from a social media post, a search engine, a partner gym notice, or an outbound link, the referring platform may hand over limited visit context such as which campaign or link you used. When an organiser books a private event or school trip on behalf of a group, they may provide participant name lists and emergency contacts to the Company before the event date.
Payment processing is handled by regulated payment partners. When you pay with a card, we generally receive a confirmation token rather than the full card number. The raw card details stay inside the secure vaults of the payment processor, which follows its own independent security and privacy standards. We recommend you read the privacy policy of any payment provider before completing checkout.
Where we use partners for email delivery, calendar scheduling, text messaging, or document signing, we share only the information needed for that specific job and we require those partners to protect it. We enter into written agreements with every partner that handles personal data, restricting how they may use it and requiring them to delete or return it when the relationship ends.
7. The ways Saint George Climbfest uses personal information
The Company uses the data it holds for a handful of honest purposes. First, to confirm your place, issue your pass or wristband, build your festival schedule, allocate shuttles, reserve gear, and deliver the clinic or competition you chose. Second, to communicate essential updates, such as weather postponements, venue changes, safety notices, and final instructions. Third, to handle payment, refunds, disputes, and our accounting records.
Fourth, we use data to keep everyone safe: matching emergency contacts, reviewing medical notes against an activity in advance, informing the first aid tent of anything it needs to know, and coordinating where volunteers and medics are needed. Fifth, we use aggregate statistics to plan for future events, decide course capacities, and improve accessibility so the festival gets better every single season. Sixth, where you have consented, we send you occasional news, early booking notice for next year, and offers that matter to climbers.
We do not build personality profiles for sale, we do not use personal data to make automated decisions with legal or significant effect about you, and we do not mine your photos or your messages. Where an automated tool helps allocate volunteer shifts fairly or category seats by age, a staff member always review the outcome.
8. Legal bases relied upon for such processing
Where data protection law such as the General Data Protection Regulation or its regional equivalents recognises specific legal bases for processing, the Company relies on the most appropriate one for each activity. Handling your registration and fulfilling your festival or clinic booking is necessary for the performance of the contract you entered when you purchased a pass or service.
Meeting our obligations around waivers, insurance, health and safety, emergency response, tax, and audits is necessary for compliance with a legal obligation we must satisfy. Operating secure systems, preventing fraud, balancing capacities, and analysing anonymous usage serves the legitimate interests of the Company so long as those interests do not override your own rights and freedoms.
Where none of the above plainly applies, we rely on your consent given freely and clearly. Consent may be withdrawn at any time, and withdrawing consent does not affect the lawfulness of processing that happened before you withdrew it. We keep a record of the basis we rely on for each category of data so that we can answer quickly if you ever ask.
10. Data retention time frames
The Company keeps personal information only for as long as it serves a real purpose. Registration and booking records connected to waivers and insurance are kept for the period your local law requires and for the term of the relevant insurance cover, so that we can respond properly to any genuine claim or inquiry that arises later. Financial and tax records are held for the retention windows set by taxation rules.
Directories of emergency contacts and team rosters that support a single event are deleted a short time after the event and its follow up work finish, once no claims or review remain open. Marketing contact details are kept until you unsubscribe or until a reasonable period of inactivity passes, whichever comes first in your case. Enquiries and support messages are kept for a modest period so we can maintain helpful continuity if you write again.
When a retention period ends, personal data is destroyed through secure deletion so that it cannot be rebuilt or repurposed. Aggregated statistics that no longer identify individuals may be kept indefinitely because they help us plan a better festival, as may records that are genuinely required by a regulator or a current dispute.
11. Security, breach response, and safeguards
Good security is a matter of respect. The Company applies sensible technical and organisational measures to protect personal information against accidental loss and against unauthorised access, alteration, or disclosure. Access to our systems is limited to the people who truly need it, guarded with strong passwords, two step verification where available, and clear accountability for any shared account.
Our website serves over an encrypted connection wherever that is technically possible, and sensitive data is encrypted in transit and at rest. We carry out regular backups, keep our software patched, review access logs, and train our crew to recognise phishing and to handle personal information with the same care they show a rope when someone depends on it.
If a security incident does occur, the Company investigates without delay, works to contain any impact, notifies the relevant authorities where the law demands, and informs affected individuals when there is a realistic risk to them. We document each incident so that we can learn from it, and our breach response plan is simply the festival emergency plan applied to data rather than to rock.
12. Your rights over your own information
Depending on where you live, data protection law gives you a set of clear rights over your own information. You may ask for access to the personal data the Company holds about you and for a copy of it. You may ask us to correct anything that is wrong or incomplete. You may ask to have your data erased where no legal reason requires us to keep it, and you may ask us to restrict or object to processing in certain situations.
You may ask for your personal data to be provided in a structured, machine readable format so that you can move it to another service where the processing is based on consent or on your contract with us. You may also request the withdrawal of consent where that was the basis we used. None of these actions ever costs you a fee for exercising a right, and none of them means the withholding of a genuine statutory duty.
To act on any of these rights, contact the Company using the details in the final section of this policy. We respond within the time frames your law allows, normally within one month, and we may ask you to confirm your identity before action so that we never hand your records to the wrong person. If you share data on behalf of a group, we treat group members with the same genuine responsiveness whenever we can verify authority.
13. Marketing, email, and how to opt out
The Company does not like clutter and assumes you do not either. We send marketing only to people with an active relationship with the festival or to people who have given clear consent, and we keep those messages relevant to climbing, our festival, or responsible outdoor events. Every marketing email carries a working unsubscribe link, and unsubscribing removes you from our list promptly without any guilt trip attached.
Event necessary communications are a separate category from marketing. Because these messages carry details you genuinely need, such as a changed start time or a weather update, they are not governed by the unsubscribe control the way promotional mail is. If a storm moves, we need to reach you, even when you have opted out of newsletters.
If you prefer not to receive optional marketing from the very beginning, simply tell us, tick nothing, or follow the unsubscribe link in any email you do receive. You may also set preferences through our contact form by selecting a subject that notes your wish. We honour these choices without condition and we record them so that they survive from one season to the next.
14. Guidance aimed at parents and guardians
Parents and guardians hold the steering wheel when it comes to privacy for children and young climbers. We encourage families to talk about why registration needs certain details and what staying safe online means. The festival celebrates outdoor courage, yet courage on the internet looks different, so we underline that children should never hand over passwords or accept friend requests from strangers who claim to work for the Company.
We ask young people not to submit the contact form pretending to be adults, and we design our youth registration so that a guardian supplies the information and consents on the young person behalf. Guardians may ask at any time to see, correct, or remove the information we hold about a child in their care, and we act on those requests quickly and thoroughly.
The Company follows the age thresholds set by the laws of the regions where it operates and by the payment and insurance partners it works with. Where you discover that a child gave us information without your consent, please contact us right away. We treat such reports as a safety priority and remove the information wherever we can lawfully do so.
15. Notice to California residents
If you are a resident of the state of California, the California Consumer Privacy Act and related rules give you additional rights and information beyond the general description above. Under those rules, categories of personal information the Company may collect resemble the lists described in this policy, such as identifiers, commercial records, internet activity, and geolocation signals when you allow them.
California residents have the right to know what personal information is collected, to request that it be deleted, to ask that it be corrected, and to opt out of any sale or sharing of personal information for cross context behavioural advertising. The Company does not sell personal information in the ordinary meaning of that word, and we do not knowingly sell the personal information of children under sixteen years of age.
To exercise a California privacy right, use the contact route in the final section and tell us you are making a request under the California Consumer Privacy Act. We verify your identity before acting, we respond within the statutory window, and we treat any choice you make free from discrimination in the quality of service you receive. An authorised agent may act for you when they provide proper authority as required by law.
16. International transfers of personal data
The Company is based in the United States (US) and stores the personal information it collects on servers and in trusted systems that may be located in the United States or with approved partners in other countries. If you are visiting from outside the United States, your information may be transferred to, and stored in, a country whose data protection rules differ from those where you live.
For any transfer of personal data from a jurisdiction that constrains such transfers, such as the European Economic Area, the United Kingdom, or Switzerland, the Company relies on appropriate safeguards recognised by those rules. Those safeguards include standard contractual clauses and the binding protections our partners accept, together with the practical security described throughout this policy.
This paragraph does not weaken the protections you hold. Wherever your data travels, the Company keeps the promises contained in this Privacy Policy as the working floor, and it raises its standards whenever the law of a particular region demands more. Your rights trace across borders with your information just as easily as a good pair of shoes travels from the airport to the crag.
17. Changes to this Privacy Policy
The outdoor events that Saint George Climbfest LLC runs evolve each season, and so does the technology that supports them. This Privacy Policy may therefore be revised from time to time to reflect new services, new partners, changed laws, or improvements in our own practices. When we make a material change, we update the revision date shown at the top of this page and we make the changed version easy to find.
Where a change matters to you personally, such as a new sharing arrangement or a new category of collected data, we give reasonable notice through the website and, where we have your email for such updates, through a direct message. Your continued use of our services after a revised policy is published tells us that you have accepted the new version as it applies to future activity.
If you do not agree with a revised policy, the clearest remedy is simply not to register for new events under the new version and to exercise the deletion or restriction rights described earlier for the data already held. The version that applied at the time you made a booking is the version that governs that booking, and we honour that distinction.
18. Contacting the Company about privacy
Questions, comments, and requests about privacy are welcome at any time. The easiest route is to write an email describing your question or your request, and we will reply to confirm we have received it and to set expectations about timing. Alternatively you may telephone during office hours, or post a letter to the street address below using the contact methods that suit you best.
Details of the party responsible for the processing described in this policy are: Saint George Climbfest LLC, based at 2875 E 850 N, St George - 84790-5841, United States (US). The named developer is Saint George Climbfest. Requests that require us to confirm your identity, such as access or erasure of records held with another partner, may take slightly longer because protecting you against impersonation comes first.
We aim to respond to every privacy message inside one month, and faster in most cases. If you are unhappy with an answer we give, you may also raise a concern with the supervisory or enforcement authority that has jurisdiction over where you live, and we will cooperate fully with any legitimate investigation. We thank you for trusting us with your details and we do not take that trust lightly out on the desert floor or back in the office.