SoldOutRadar Privacy Policy
Effective date: July 2, 2026
This Privacy Policy explains what personal data SoldOutRadar collects, why we collect it, who we share it with, and the rights you have over your information. We aim to collect as little data as possible and to use it only to deliver the availability-alert service you sign up for.
1. Who we are
SoldOutRadar ("SoldOutRadar," "we," "us," or "our") is an independent availability-alert service. We monitor official ticketing calendars 24/7 and notify you by email and instant push notification the moment a sold-out spot becomes available again (SMS alerts may be offered later, on an opt-in basis). Our first service watches Statue of Liberty Crown access on the official ticketing site, Statue City Cruises (statuecitycruises.com).
We sell the monitoring and the alert (the information) only. We never sell, resell, or book tickets, and we never touch your reservation. When we alert you that a spot has opened, you book the ticket yourself, in your own name, on the official site.
We are independent. SoldOutRadar is not affiliated with, endorsed by, or sponsored by Statue City Cruises, City Experiences, the National Park Service, or any ticketing provider. All trademarks belong to their respective owners.
SoldOutRadar is operated by Jean-Baptiste Renaldi, a French sole proprietorship (micro-entreprise / auto-entrepreneur), SIREN 977 775 451 (SIRET 977 775 451 000 15), registered at 330 Chemin du Vallon des Gavots, 13400 Aubagne, France. Our service is aimed at users in the United States, but because the operator is based in the European Union (France), we comply with the EU General Data Protection Regulation (GDPR) in addition to applicable U.S. state privacy laws.
For any privacy question or to exercise your rights, contact us at hello@soldoutradar.com. We act as the "data controller" for the personal data described in this policy.
2. Data we collect
We collect only the information needed to set up and deliver your alerts:
- Email address — to create your account, send you alerts, and contact you about your watches.
- Mobile phone number (optional — only if you opt in to SMS alerts, when that channel becomes available) — to deliver alerts by SMS.
- Travel dates — the date or date range you want us to watch.
- Departure point — your starting location (New York/Battery Park, New Jersey/Liberty State Park, or both), used to match relevant availability.
- Group size — the number of people in your party, so we can match availability that fits your group.
- Technical and log data — information automatically generated when you use the site, such as IP address, browser type, device information, and timestamps. This is used to operate, secure, and troubleshoot the service.
What we do NOT collect
We never see or store your payment card numbers. All payments are handled directly by Stripe, our payment processor. Your card details are entered on Stripe's secure systems, not ours, and we only receive a confirmation that a payment succeeded along with limited billing metadata (such as a payment status). Because our plans are a one-time fee per trip and not a recurring subscription, we do not store recurring billing profiles. We do not collect government IDs, precise GPS location, or any special categories of sensitive personal data.
3. Why we use your data and our legal bases
Under the GDPR, we must have a valid legal basis for each use of your personal data. Our uses and legal bases are:
- To deliver alerts and operate your account (email, travel dates, departure point, group size) — legal basis: performance of a contract with you. Without this data we cannot provide the service you requested.
- To send alerts by SMS, when that channel becomes available (mobile phone number) — legal basis: your consent, which you give if you provide your number and opt in to SMS alerts. You can withdraw this consent at any time (see Section 8).
- To process payment (billing metadata from Stripe) — legal basis: performance of a contract and compliance with our legal and accounting obligations.
- To operate, secure, and improve the service (technical and log data) — legal basis: our legitimate interests in keeping the service running, preventing abuse, and protecting against fraud and security threats.
4. Who we share data with (sub-processors)
We do not run all of our infrastructure ourselves. We share limited personal data with carefully selected service providers ("sub-processors") who process it on our behalf, under contract, and only to provide their service to us:
- Stripe — payment processing. Receives the billing information needed to charge you. Stripe handles your card details directly; we never see them.
- Brevo (formerly Sendinblue) — email delivery. Receives your email address to send your alerts and account messages.
- Twilio — SMS delivery. Would receive your mobile phone number to send alert text messages, only if and when SMS alerts are offered and you opt in.
- Supabase — database and authentication hosting. Stores your account and watch data securely.
- Vercel — website and application hosting. Serves the SoldOutRadar site and processes technical/log data.
We never sell your personal data, and we do not share it with third parties for their own marketing purposes.
5. SMS data
SMS alerts are not yet available. If and when they launch and you opt in by providing a mobile phone number, we use it solely to deliver the availability alerts you signed up for and related account or service messages. We do not share your phone number or SMS opt-in data with any third party for that third party's own marketing, and we do not sell it. Your SMS consent is never shared with third parties for marketing. Message and data rates may apply, and you can stop SMS messages at any time by replying STOP.
6. International data transfers
The operator of SoldOutRadar is located in the European Union (France), while most of our customers are in the United States. As a result, your personal data may be transferred to, stored in, and processed in countries outside your own, including the United States and the EU/EEA, depending on where our sub-processors operate.
When personal data is transferred out of the EU/EEA, we rely on appropriate safeguards recognized under the GDPR, such as the European Commission's Standard Contractual Clauses, to ensure your data continues to receive an adequate level of protection.
7. How long we keep your data (retention)
We keep your personal data only as long as we need it:
- We retain your account and watch data while your watch is active and you have an account with us.
- After a watch ends or your account is closed, we keep the associated data for a limited additional period to handle support requests, resolve disputes, and meet legal, tax, and accounting obligations, after which it is deleted or anonymized.
- Technical and log data is kept for a shorter period needed for security and troubleshooting.
You can ask us to delete your data sooner (see Section 8), subject to any obligations that require us to retain certain records.
8. Your rights
If you are in the EU/EEA (GDPR)
You have the following rights over your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data ("right to be forgotten").
- Restriction — ask us to limit how we process your data in certain circumstances.
- Objection — object to processing based on our legitimate interests.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Withdraw consent — where we rely on consent (such as SMS alerts), withdraw it at any time. You can stop SMS messages by replying STOP, and unsubscribe from emails using the link in any message. Withdrawing consent does not affect processing carried out before withdrawal.
You also have the right to lodge a complaint with your local data protection authority. In France, this is the CNIL (www.cnil.fr).
If you are in California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, the right to delete the personal information we hold about you, the right to correct inaccurate personal information, and the right to opt out of the "sale" or "sharing" of your personal information. We do not sell or share your personal information as those terms are defined under California law, so there is nothing to opt out of. We will not discriminate against you for exercising any of your privacy rights.
How to exercise your rights
To exercise any of these rights, email us at hello@soldoutradar.com. We may need to verify your identity before acting on your request, and we will respond within the timeframes required by applicable law. These rights are free to exercise, subject to legal limits.
9. Cookies and analytics
The SoldOutRadar site is mostly static and uses only the cookies necessary to make the site work and keep you signed in. We do not use advertising cookies or sell data to advertisers.
We currently use no third-party advertising or cross-site tracking cookies. If we later add a privacy-conscious, cookieless analytics tool (such as Vercel Web Analytics) to understand aggregate, non-identifying usage of the site (such as page views), we will ask for your consent where required by law.
10. Children
SoldOutRadar is not intended for anyone under 18 years of age, and our service is available only to users who are 18 or older. We do not knowingly collect personal data from children. If you believe a minor has provided us with personal data, contact us at hello@soldoutradar.com and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our service, technology, or legal requirements. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you by email. We encourage you to review this policy periodically.