Privacy policy
Last updated 6 September 2026
This policy explains how tiqet.app, registered at [registered address] ("tiqet", "we"), handles personal data on tiqet.app. It is written for the EU General Data Protection Regulation (GDPR).
1. Who controls your data
tiqet is a controller for the data of organizers who hold an account with us, and for the operation and security of the platform itself.
For attendee data collected while buying a ticket, the organizer of that event is the controller and tiqet is a processor acting on the organizer's documented instructions. Contact the organizer named on the event page about that data; we will pass on a request we receive directly.
Stripe is an independent controller for payment data it collects, under its own privacy policy. Card numbers never reach tiqet's systems.
Our data protection contact: [DPO or privacy contact].
2. What we process, and why
- Organizer account data (name, email, password hash, role, sessions, audit entries) — to run the account. Legal basis: performance of a contract and our legitimate interest in securing the platform.
- Order and ticket data (buyer name, email, quantity, answers to the organizer's checkout questions, ticket status, check-in time) — to issue and admit tickets. Processed for the organizer as controller.
- Payment metadata (amount, currency, Stripe identifiers, refund state) — to reconcile payments and refunds. Legal basis: contract and legal obligation.
- Transactional email records (recipient, subject, delivery state, provider message id) — to prove a ticket was sent and to support the organizer. We do not store message bodies.
- Product analytics (page views, device type, referrer, campaign parameters, a rotating session identifier) — to show organizers how their event page performs. Legal basis: legitimate interest, using data that does not identify a visitor by name.
- Server and security logs (IP address, request path, timing) — to operate the service, apply rate limits, and investigate abuse. Retained for [log retention period].
We do not sell personal data, we do not use it for advertising profiling, and we do not carry out automated decision-making with legal effects.
3. Processors we use
- Stripe — payment processing and organizer payouts.
- Resend — transactional email delivery.
- [hosting provider] — servers and database hosting in [hosting region].
Each is bound by a data processing agreement. Where a transfer outside the EEA is needed, it relies on the European Commission's standard contractual clauses.
4. How long we keep data
Order, ticket, and payment records are kept for [accounting retention period] to meet accounting and tax obligations. Organizer accounts are kept while the account is open and for [account retention period] afterwards. Analytics events are kept for [analytics retention period]. Interest and marketing contacts are deleted on unsubscribe.
5. Your rights
You may request access to your data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interest. Where processing relies on consent you may withdraw it at any time, without affecting prior processing.
Write to support@tiqet.app. If you are unsatisfied you may complain to your national supervisory authority; ours is [supervisory authority].
6. Security
Passwords are stored as PBKDF2-SHA256 hashes, session and ticket credentials are stored only as hashes, admin sessions use secure HTTP-only cookies, and every organizer query is scoped to that organizer's own data. Ticket links and password links travel in the URL fragment so they do not reach server logs.