Privacy Policy
Last updated: 6 August 2026
TICKTS LTD (Company No. 17029682), registered at 124-128 City Road, London, EC1V 2NX (“we”, “us”, “our”) is the data controller for personal data collected through the Tickts platform. We are registered with the Information Commissioner’s Office (ICO) under registration reference ZC108275. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
1. What We Collect
We collect the following types of personal information:
- Account Information: Name, email address, password (stored as a one-way hash , we never store plain-text passwords), and phone number (optional) when you create an account. If you sign in using Google or Apple, we receive your name and email address from the provider. We do not receive or store your Google or Apple password.
- Profile Information: Organisation name, club details, social media links, and profile images for Organiser accounts.
- Transaction Information: Details of tickets purchased, payment amounts, order history, and payment plan records. We do not store full payment card details , these are handled securely by Stripe.
- Gift Aid Declarations: Where you donate to a verified charity through the Platform and choose to Gift Aid your donation, we collect your name, home address, postcode, and your declaration that you are a UK taxpayer, so the charity can claim Gift Aid from HMRC. This is additional information beyond an ordinary ticket purchase.
- Scanning & Attendance Data: Ticket scan logs including scan time, location (venue), scanning device, and scan result (valid/invalid/already scanned).
- Consent Records: Cookie consent preferences, consent timestamps, and SHA256-hashed IP and user agent for compliance purposes.
- Administrative Activity Logs: If you have an Organiser account, we record state-changing actions you take in your dashboard (route, IP address, user agent, the names of form fields you changed, and field-level diffs of records you edited) for up to 30 days, to support security, debugging, and dispute resolution. Sensitive form values (passwords, payment fields, CSRF tokens) are redacted at capture.
- Administrative Actions by Tickts: Where Tickts staff perform a privileged action against your account (for example, support-led impersonation, manual refund, account suspension), we record the action, the staff member, the time, and the affected account. If you are an Organiser and a member of staff signs in as you for support purposes, you receive an email notification.
- Usage Data: Information about how you interact with our platform, including pages visited, features used, and time spent on the site.
- Device Information: IP address, browser type, operating system, and device identifiers.
- Affiliate Tracking: If you arrive via an affiliate link, we record the affiliate code, your IP address, and user agent to attribute the referral.
- Communications: Any messages you send to us through our contact form or support channels.
- Incomplete Checkouts: If you start a checkout and provide your email address but do not complete the purchase, we keep your email and a snapshot of your basket so we can send you a single reminder (see Section 4). You can opt out via the link in that email, and we suppress future reminders permanently.
- App Device Tokens: If you use the tickts mobile app and allow notifications, we store a push-notification token for your device (platform and last-used date) so we can deliver notifications you have enabled.
- Accessibility & Access Requirements: Where an Event asks for them, any access or accessibility requirements you choose to enter at checkout (a free-text field, up to 1,000 characters) so the Organiser can accommodate you. Because this may reveal information about your health or disability, we treat it as special-category data and process it only with your explicit consent (see Section 2a). It is optional; leaving it blank does not affect your purchase.
- Saved Cards for Call Dibs and Pledges: If you use Call Dibs (reserving a place on a sold-out Event) or a Make-it-happen Pledge, you save a card via Stripe (a Stripe SetupIntent) so it can be charged later if a place opens or the Event is confirmed. As with every payment, we do not store your card details: Stripe holds the saved card, and we hold only a reference to it and its status.
2. Lawful Basis for Processing
We process your personal data on the following lawful bases under Article 6 of the UK GDPR:
- Contract (Art. 6(1)(b)): Processing your account registration, ticket purchases, order fulfilment, ticket delivery, payment plan administration, ticket transfers, and season pass management.
- Legitimate Interests (Art. 6(1)(f)): Platform security and fraud prevention, analytics and performance monitoring, affiliate tracking, improving our services, and communicating service updates.
- Legal Obligation (Art. 6(1)(c)): Retaining transaction records for financial compliance (HMRC requirements), responding to law enforcement requests, maintaining audit and consent logs, and processing Gift Aid declarations to meet HMRC Gift Aid requirements (where the charity is the controller, on its lawful basis).
- Consent (Art. 6(1)(a)): Setting analytics and advertising cookies (Google Analytics, Meta, TikTok), server-side conversion measurement to those advertising platforms, sending marketing emails, and sharing your data with third parties for purposes beyond service delivery.
2a. Special-Category Data (Article 9)
Where you choose to provide access or accessibility requirements at checkout, that information may reveal data about your health or disability, which is “special-category” data under Article 9 of the UK GDPR. We process it only on the basis of your explicit consent (Article 9(2)(a)), given by choosing to enter it, and solely to pass it to the Organiser so they can make reasonable accommodations for you at the Event. It is optional, is shared only with the Organiser of that Event (who becomes an independent controller for it), and you can ask us or the Organiser to delete it at any time. We do not use it for any other purpose, and we do not process special-category data on a large scale.
3. Cookies
We use cookies and similar tracking technologies to enhance your experience on our platform. For detailed information about the cookies we use and the purposes for which we use them, please see our Cookie Policy.
4. Third Parties & Sub-Processors
We share your information with the following third parties who act as sub-processors or independent controllers:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe | Payment processing (Stripe Connect) | Payment details, name, email, transaction data | US (EU SCCs) |
| TicketPlan | Optional refund-protection product offered at checkout (policy administration and claim handling) | Name, email, ticket details, event name and date | UK |
| Google Analytics (GA4) & Measurement Protocol | Website analytics and performance monitoring; where an Organiser has enabled it, server-side purchase measurement (Measurement Protocol) | IP address (anonymised), usage data, device info; for a completed purchase where enabled, a SHA-256 hashed email address (Measurement Protocol) | US (EU SCCs) |
| Brevo (Sendinblue) | Transactional and marketing email delivery, including open and click tracking via embedded pixels and link rewriting | Name, email address, email engagement events (opens, clicks, bounces) | EU |
| Sentry | Error monitoring and crash reporting | Error data, IP address, browser info | US (EU SCCs) |
| Cloudflare | CDN, DDoS protection, DNS | IP address, request metadata | Global (EU SCCs) |
| Apple Wallet | Digital wallet ticket passes | Ticket data (event name, date, venue), attendee name where provided, barcode token, PassKit metadata for lock-screen previews | US (EU SCCs) |
| Google Wallet | Digital wallet ticket passes | Ticket data (event name, date, venue), attendee name where provided, barcode token, Google Wallet metadata for lock-screen previews | US (EU SCCs) |
| Google Places API | Venue address lookup and validation | Search queries, location data | US (EU SCCs) |
| Google OAuth | Social sign-in (“Continue with Google”) | Name, email address | US (EU SCCs) |
| Apple Sign-In | Social sign-in (“Continue with Apple”) | Name, email address (user may choose to hide email) | US (EU SCCs) |
| Google reCAPTCHA v3 | Bot detection and fraud prevention during registration | IP address, browser behaviour, device data | US (EU SCCs) |
| Meta (Facebook) Pixel & Conversions API | Conversion tracking and advertising attribution, in-browser (Pixel) and server-side (Conversions API); consent required | Page views and device info (Pixel); for a completed purchase, a SHA-256 hashed email address and your IP address (Conversions API) | US (EU SCCs) |
| TikTok Pixel & Events API | Conversion tracking and advertising attribution, in-browser (Pixel) and server-side (Events API); consent required | Page views and device info (Pixel); for a completed purchase, a SHA-256 hashed email address and your IP address (Events API) | US / Singapore (SCCs) |
| Companies House | Business identity verification for Organiser accounts | Company registration number, business name | UK |
| Cloudways (DigitalOcean) | Application hosting and managed cloud infrastructure | All data stored on the Platform (encrypted at rest) | UK / EU (London region) |
| Trustpilot | Post-purchase review invitations and review hosting | Name, email, order reference | UK / EU |
| Anthropic (Claude) | AI writing assistance for Organisers (improving event descriptions) and Organiser AI tooling | Event details and draft text the Organiser submits; not used to train Anthropic’s models | US (UK IDTA / SCCs) |
| Klarna / Clearpay | Optional buy-now-pay-later payment methods offered through Stripe at checkout | Payment and eligibility data you provide to the provider if you choose that payment method | EU / US (via Stripe) |
| Stay22 | Accommodation map embedded on some event pages | IP address and page context if you interact with the map | Canada (UK adequacy) |
| Mailchimp (Intuit) | Optional Organiser integration: where an Organiser connects their own Mailchimp account, their buyers’ details sync to that Organiser’s audience (Organiser-directed; the Organiser is the controller) | Name, email, order context | US (UK IDTA / SCCs) |
Server-side conversion measurement. Where an Organiser has enabled it and you have accepted advertising cookies, we send a record of a completed purchase directly from our server to Meta, Google, and/or TikTok to measure the effectiveness of that Organiser’s advertising. This mirrors, and is de-duplicated with, the in-browser pixels. These server-side events contain a SHA-256 hashed (pseudonymised) email address and, for Meta and TikTok, your IP address; they never include your name in the clear or your payment card details. It happens only with your advertising-cookie consent, and not at all for Organisers who have not set it up. Meta, Google, and TikTok act as independent controllers for the advertising measurement they perform with this data, under their own privacy policies.
Email engagement tracking. Email open and click events captured by Brevo are stored against your account for marketing-performance reporting. You can opt out of marketing emails at any time via the unsubscribe link in any marketing email, which also stops engagement tracking for future sends. Transactional emails (order confirmations, password resets, payment-plan notices, ticket-transfer notifications) do not carry a marketing-opt-out and are sent under contractual lawful basis.
Checkout reminder emails. If you start a checkout, provide your email address, and do not complete the purchase, we may send you a single reminder email about that basket (relying on the soft opt-in for electronic marketing, since you provided your details in the course of a sale). We send at most one reminder per event, it contains an opt-out link, and opting out suppresses all future reminders to your address.
Sub-processor changes. The current list of sub-processors is the list above. We will update this list when we add or replace a sub-processor. Organisers acting as data controllers may object to a new sub-processor on reasonable data-protection grounds by emailing [email protected].
5. Organiser Data Sharing
When you purchase a ticket, the Organiser of that event will receive your name, email address, and order details. This is necessary for the Organiser to fulfil the ticket, manage event entry (including QR code scanning), and communicate essential event information to you.
Organisers act as independent data controllers for the buyer data they receive and are responsible for their own compliance with data protection law. We require Organisers to handle buyer data in accordance with our Organiser Terms, but we are not responsible for their data processing practices.
Organiser analytics on event pages. Organisers on paid plans can connect their own Google Analytics property or Meta Pixel to their event pages and checkout confirmation. These fire only if you have consented to analytics or marketing cookies, and the data they collect goes to the Organiser (and Google or Meta) under the Organiser’s own privacy notice, with the Organiser as controller.
Organiser-directed integrations (API, webhooks and Zapier). Organisers on paid plans can connect their events to their own tools using our developer API, webhooks, or Zapier. Where an Organiser does this, order data about their buyers (such as name, email address, and order details) is sent, at the Organiser’s direction, to the endpoint or third-party service the Organiser has configured (for example their own CRM, spreadsheet, or automation). That onward transfer is directed and controlled by the Organiser as the data controller, under the Organiser’s own privacy notice and its arrangements with any tool it uses; tickts transmits the data on the Organiser’s instructions as processor and is not responsible for how the receiving tool handles it. This sharing only happens where an Organiser has set up such an integration for their events.
Where you make a donation to a charity Organiser and choose to Gift Aid it, your name and home address are shared with that charity so it can claim Gift Aid from HMRC. The charity is the data controller for that Gift Aid data and is responsible for making the HMRC claim and retaining the declaration records; tickts processes the data on the charity’s behalf.
5a. Ticket Resale
If you list or sell a ticket through our fan-to-fan resale feature, we process your name, email address and the resale transaction in order to operate the resale, transfer the ticket and pay you. To receive your funds you connect a Stripe Express payout account; Stripe collects and verifies the identity and bank details it needs to pay you (including, where required by law, identity-verification information) as part of that process. Stripe acts as our payment sub-processor for this, as set out in Section 4. When you buy a resale ticket, the seller does not receive your personal data; the handover and a fresh ticket are issued to you automatically by the Platform.
6. Your Rights (UK GDPR)
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you. You can export your data from your account settings at any time.
- Right to Rectification: You can request that we correct any inaccurate or incomplete personal data. You can update most information directly in your account settings.
- Right to Erasure: You can request deletion of your account from your account settings. Where you have no transaction history, your account is permanently deleted. Where you have transaction history (as a buyer or Organiser), your account is anonymised rather than hard-deleted: your name is replaced with “Deleted User”, your email is replaced with a non-routable placeholder, your password and two-factor credentials are removed, and any connected Stripe, social-login, and billing identifiers are cleared. The underlying transaction, ticket, scan, and order records remain in their original form to satisfy HMRC retention and to allow refund and dispute resolution for buyers. Organisers cannot close their account while they have upcoming events with sold tickets, or within 90 days of their most recent transaction.
- Right to Restrict Processing: You can request that we limit how we use your personal data.
- Right to Data Portability: You can request a copy of your data in a structured, commonly used, machine-readable format (JSON).
- Right to Object: You can object to the processing of your personal data for certain purposes, including direct marketing.
- Right to Withdraw Consent: Where processing is based on consent (e.g., analytics cookies or marketing emails), you can withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. If we need more time (up to two additional months for complex requests), we will inform you within the first month.
7. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. Our fraud detection measures may involve automated checks, but these are always subject to human review before any action is taken on your account.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with our services. We may also retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
Specifically:
- Account data: Retained for the lifetime of your account and for up to 2 years after account closure.
- Transaction data: Retained for 7 years to comply with HMRC financial record-keeping requirements.
- Deleted accounts: Personal data is anonymised immediately upon deletion. Transaction records, order history, and event data are retained for 7 years (HMRC compliance).
- Gift Aid declaration records: Retained in line with HMRC requirements. The charity Organiser is the controller for this data and is responsible for meeting that record-keeping obligation; tickts retains the records on its behalf.
- Usage and analytics data: Retained for up to 26 months.
- Scan logs: Retained for 2 years for dispute-resolution and Platform-integrity purposes.
- Support communications: Retained for up to 3 years after the last interaction.
- Consent records (cookies, marketing): Retained for 2 years (automatically purged).
- Organiser administrative activity logs: Retained for 30 days, then automatically purged.
- Migration audit logs (record of an Organiser’s confirmation that they own content imported via the “switch from” tool): Retained for 6 years from the date of import to defend against potential third-party claims relating to imported content.
- Error and security logs: Retained for up to 90 days, except where investigation is ongoing.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. This includes:
- Encryption in transit (TLS/SSL) for all data transmitted to and from the Platform;
- Secure password hashing using bcrypt;
- Regular security reviews and vulnerability assessments;
- Access controls limiting employee and system access to personal data;
- Cloudflare DDoS protection and Web Application Firewall (WAF);
- Optional two-factor authentication (TOTP) with single-use recovery codes; secrets are stored encrypted at rest.
10. International Transfers
Some of our sub-processors (Stripe, Google, Sentry, Apple, Meta, TikTok, Cloudflare) are based in or operate from the United States (TikTok also from Singapore). Application data itself is hosted in the United Kingdom on Cloudways/DigitalOcean (London region). Where personal data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place under Article 46 of the UK GDPR, including the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or reliance on the recipient’s participation in a recognised adequacy framework (for example, the UK extension to the EU-US Data Privacy Framework where applicable).
You can request a summary of the transfer mechanism in place for any specific sub-processor by emailing [email protected].
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, as required by Article 33 of the UK GDPR. Where the breach is likely to result in a high risk to your rights, we will also notify you directly without undue delay.
12. Children’s Privacy
Our Platform is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child under 16, please contact us immediately and we will take steps to delete it.
13. Contact & Complaints
We are not required to appoint a statutory Data Protection Officer under UK GDPR Article 37 because we are not a public authority and our core activities do not consist of large-scale monitoring of individuals or large-scale processing of special-category data. Although we process limited special-category data where you voluntarily provide access or accessibility requirements (see Section 2a), this is optional, occasional, and not on a large scale, so no statutory Data Protection Officer is required. All privacy queries are handled by the Tickts privacy team at the contact below, who acts as our data protection point of contact.
If you have any questions about this Privacy Policy or our data practices, or if you wish to exercise your data rights or make a complaint, please contact us:
- Email: [email protected]
- Post: TICKTS LTD, 124-128 City Road, London, EC1V 2NX
Supervisory authority for Irish residents. If you are resident in Ireland, the supervisory authority for your personal data is the Data Protection Commission (DPC). You have the right to lodge a complaint directly with the DPC if you believe your data protection rights under the EU GDPR or the Data Protection Act 2018 have been violated. You can contact the DPC at dataprotection.ie, by post at 21 Fitzwilliam Square South, Dublin 2, D02 RD28, or by phone at +353 (0) 818 252 231.
UK transfers under adequacy. Personal data of Irish residents is processed by Tickts Ltd in the United Kingdom. Transfers from the European Economic Area to the United Kingdom rely on the European Commission’s adequacy decision for the United Kingdom (Commission Implementing Decision (EU) 2021/1772 of 28 June 2021), which recognises the UK as providing an essentially equivalent level of protection. Should the adequacy decision be withdrawn or expire without renewal, we will put in place EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or another appropriate Article 46 GDPR safeguard before any further transfer.