Keyed accounts and recovery
Protected attendee fields are readable while a keyed administrator is signed in. The server unlocks the user's wrapped data key at the start of each session and discards it when the session ends.
Chobble staff do not receive the passwords for organiser-created accounts as part of managed hosting. Owners, managers, and logistics agents have their own credentials and key material. Content-only editors receive no attendee data key and cannot decrypt bookings.
When you invite a team member, they set their own password at a self-activation link. The invite is single-use, and the keys are re-wrapped under the new password as part of joining. The person who sent the invite never sees the new password.
An owner can choose to enable a recovery owner account when the host has configured a valid recovery email address and email delivery works. Chobble Tickets creates separate random credentials, wraps the same site data key for that account, and emails the credentials to the host-configured recovery address. Whoever controls those credentials can decrypt protected attendee fields and invite a replacement owner.
Organisers need to retain at least one keyed account or the enabled recovery credentials. Losing one person's password does not cause data loss while another keyed account remains available.
Read the full cryptography documentation for implementation details, or see who can see your attendee data for a list of every company that can access your attendees' information. A record whose note cannot be read still opens, and still shows the counts, which are kept in plain sight. Saving over it gives a working note back without losing what was counted.
