Privacy Policy
Last updated: 8 July 2026
TICKTS LTD (Company No. 17029682), registered at 124-128 City Road, London, EC1V 2NX (“we”, “us”, “our”) is the data controller for personal data collected through the Tickts platform. We are registered with the Information Commissioner’s Office (ICO) under registration reference ZC108275. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
1. What We Collect
We collect the following types of personal information:
- Account Information: Name, email address, password (stored as a one-way hash , we never store plain-text passwords), and phone number (optional) when you create an account. If you sign in using Google or Apple, we receive your name and email address from the provider. We do not receive or store your Google or Apple password.
- Profile Information: Organisation name, club details, social media links, and profile images for Organiser accounts.
- Transaction Information: Details of tickets purchased, payment amounts, order history, and payment plan records. We do not store full payment card details , these are handled securely by Stripe.
- Gift Aid Declarations: Where you donate to a verified charity through the Platform and choose to Gift Aid your donation, we collect your name, home address, postcode, and your declaration that you are a UK taxpayer, so the charity can claim Gift Aid from HMRC. This is additional information beyond an ordinary ticket purchase.
- Scanning & Attendance Data: Ticket scan logs including scan time, location (venue), scanning device, and scan result (valid/invalid/already scanned).
- Consent Records: Cookie consent preferences, consent timestamps, and SHA256-hashed IP and user agent for compliance purposes.
- Administrative Activity Logs: If you have an Organiser account, we record state-changing actions you take in your dashboard (route, IP address, user agent, the names of form fields you changed, and field-level diffs of records you edited) for up to 30 days, to support security, debugging, and dispute resolution. Sensitive form values (passwords, payment fields, CSRF tokens) are redacted at capture.
- Administrative Actions by Tickts: Where Tickts staff perform a privileged action against your account (for example, support-led impersonation, manual refund, account suspension), we record the action, the staff member, the time, and the affected account. If you are an Organiser and a member of staff signs in as you for support purposes, you receive an email notification.
- Usage Data: Information about how you interact with our platform, including pages visited, features used, and time spent on the site.
- Device Information: IP address, browser type, operating system, and device identifiers.
- Affiliate Tracking: If you arrive via an affiliate link, we record the affiliate code, your IP address, and user agent to attribute the referral.
- Communications: Any messages you send to us through our contact form or support channels.
- Incomplete Checkouts: If you start a checkout and provide your email address but do not complete the purchase, we keep your email and a snapshot of your basket so we can send you a single reminder (see Section 4). You can opt out via the link in that email, and we suppress future reminders permanently.
- App Device Tokens: If you use the tickts mobile app and allow notifications, we store a push-notification token for your device (platform and last-used date) so we can deliver notifications you have enabled.
2. Lawful Basis for Processing
We process your personal data on the following lawful bases under Article 6 of the UK GDPR:
- Contract (Art. 6(1)(b)): Processing your account registration, ticket purchases, order fulfilment, ticket delivery, payment plan administration, ticket transfers, and season pass management.
- Legitimate Interests (Art. 6(1)(f)): Platform security and fraud prevention, analytics and performance monitoring, affiliate tracking, improving our services, and communicating service updates.
- Legal Obligation (Art. 6(1)(c)): Retaining transaction records for financial compliance (HMRC requirements), responding to law enforcement requests, maintaining audit and consent logs, and processing Gift Aid declarations to meet HMRC Gift Aid requirements (where the charity is the controller, on its lawful basis).
- Consent (Art. 6(1)(a)): Setting analytics cookies (Google Analytics), sending marketing emails, and sharing your data with third parties for purposes beyond service delivery.
3. Cookies
We use cookies and similar tracking technologies to enhance your experience on our platform. For detailed information about the cookies we use and the purposes for which we use them, please see our Cookie Policy.
4. Third Parties & Sub-Processors
We share your information with the following third parties who act as sub-processors or independent controllers:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe | Payment processing (Stripe Connect) | Payment details, name, email, transaction data | US (EU SCCs) |
| TicketPlan | Optional refund-protection product offered at checkout (policy administration and claim handling) | Name, email, ticket details, event name and date | UK |
| Google Analytics (GA4) | Website analytics and performance monitoring | IP address (anonymised), usage data, device info | US (EU SCCs) |
| Brevo (Sendinblue) | Transactional and marketing email delivery, including open and click tracking via embedded pixels and link rewriting | Name, email address, email engagement events (opens, clicks, bounces) | EU |
| Sentry | Error monitoring and crash reporting | Error data, IP address, browser info | US (EU SCCs) |
| Cloudflare | CDN, DDoS protection, DNS | IP address, request metadata | Global (EU SCCs) |
| Apple Wallet | Digital wallet ticket passes | Ticket data (event name, date, venue), attendee name where provided, barcode token, PassKit metadata for lock-screen previews | US (EU SCCs) |
| Google Wallet | Digital wallet ticket passes | Ticket data (event name, date, venue), attendee name where provided, barcode token, Google Wallet metadata for lock-screen previews | US (EU SCCs) |
| Google Places API | Venue address lookup and validation | Search queries, location data | US (EU SCCs) |
| Google OAuth | Social sign-in (“Continue with Google”) | Name, email address | US (EU SCCs) |
| Apple Sign-In | Social sign-in (“Continue with Apple”) | Name, email address (user may choose to hide email) | US (EU SCCs) |
| Google reCAPTCHA v3 | Bot detection and fraud prevention during registration | IP address, browser behaviour, device data | US (EU SCCs) |
| Meta (Facebook) Pixel | Conversion tracking and advertising attribution (consent required) | Page views, anonymised event data, device info | US (EU SCCs) |
| Companies House | Business identity verification for Organiser accounts | Company registration number, business name | UK |
| Cloudways (DigitalOcean) | Application hosting and managed cloud infrastructure | All data stored on the Platform (encrypted at rest) | UK / EU (London region) |
| Trustpilot | Post-purchase review invitations and review hosting | Name, email, order reference | UK / EU |
| Anthropic (Claude) | AI writing assistance for Organisers (improving event descriptions) and Organiser AI tooling | Event details and draft text the Organiser submits; not used to train Anthropic’s models | US (UK IDTA / SCCs) |
| Klarna / Clearpay | Optional buy-now-pay-later payment methods offered through Stripe at checkout | Payment and eligibility data you provide to the provider if you choose that payment method | EU / US (via Stripe) |
| Stay22 | Accommodation map embedded on some event pages | IP address and page context if you interact with the map | Canada (UK adequacy) |
| Mailchimp (Intuit) | Optional Organiser integration: where an Organiser connects their own Mailchimp account, their buyers’ details sync to that Organiser’s audience (Organiser-directed; the Organiser is the controller) | Name, email, order context | US (UK IDTA / SCCs) |
Email engagement tracking. Email open and click events captured by Brevo are stored against your account for marketing-performance reporting. You can opt out of marketing emails at any time via the unsubscribe link in any marketing email, which also stops engagement tracking for future sends. Transactional emails (order confirmations, password resets, payment-plan notices, ticket-transfer notifications) do not carry a marketing-opt-out and are sent under contractual lawful basis.
Checkout reminder emails. If you start a checkout, provide your email address, and do not complete the purchase, we may send you a single reminder email about that basket (relying on the soft opt-in for electronic marketing, since you provided your details in the course of a sale). We send at most one reminder per event, it contains an opt-out link, and opting out suppresses all future reminders to your address.
Sub-processor changes. The current list of sub-processors is the list above. We will update this list when we add or replace a sub-processor. Organisers acting as data controllers may object to a new sub-processor on reasonable data-protection grounds by emailing [email protected].
5. Organiser Data Sharing
When you purchase a ticket, the Organiser of that event will receive your name, email address, and order details. This is necessary for the Organiser to fulfil the ticket, manage event entry (including QR code scanning), and communicate essential event information to you.
Organisers act as independent data controllers for the buyer data they receive and are responsible for their own compliance with data protection law. We require Organisers to handle buyer data in accordance with our Organiser Terms, but we are not responsible for their data processing practices.
Organiser analytics on event pages. Organisers on paid plans can connect their own Google Analytics property or Meta Pixel to their event pages and checkout confirmation. These fire only if you have consented to analytics or marketing cookies, and the data they collect goes to the Organiser (and Google or Meta) under the Organiser’s own privacy notice, with the Organiser as controller.
Where you make a donation to a charity Organiser and choose to Gift Aid it, your name and home address are shared with that charity so it can claim Gift Aid from HMRC. The charity is the data controller for that Gift Aid data and is responsible for making the HMRC claim and retaining the declaration records; tickts processes the data on the charity’s behalf.
5a. Ticket Resale
If you list or sell a ticket through our fan-to-fan resale feature, we process your name, email address and the resale transaction in order to operate the resale, transfer the ticket and pay you. To receive your funds you connect a Stripe Express payout account; Stripe collects and verifies the identity and bank details it needs to pay you (including, where required by law, identity-verification information) as part of that process. Stripe acts as our payment sub-processor for this, as set out in Section 4. When you buy a resale ticket, the seller does not receive your personal data; the handover and a fresh ticket are issued to you automatically by the Platform.
6. Your Rights (UK GDPR)
Under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you. You can export your data from your account settings at any time.
- Right to Rectification: You can request that we correct any inaccurate or incomplete personal data. You can update most information directly in your account settings.
- Right to Erasure: You can request deletion of your account from your account settings. Where you have no transaction history, your account is permanently deleted. Where you have transaction history (as a buyer or Organiser), your account is anonymised rather than hard-deleted: your name is replaced with “Deleted User”, your email is replaced with a non-routable placeholder, your password and two-factor credentials are removed, and any connected Stripe, social-login, and billing identifiers are cleared. The underlying transaction, ticket, scan, and order records remain in their original form to satisfy HMRC retention and to allow refund and dispute resolution for buyers. Organisers cannot close their account while they have upcoming events with sold tickets, or within 90 days of their most recent transaction.
- Right to Restrict Processing: You can request that we limit how we use your personal data.
- Right to Data Portability: You can request a copy of your data in a structured, commonly used, machine-readable format (JSON).
- Right to Object: You can object to the processing of your personal data for certain purposes, including direct marketing.
- Right to Withdraw Consent: Where processing is based on consent (e.g., analytics cookies or marketing emails), you can withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. If we need more time (up to two additional months for complex requests), we will inform you within the first month.
7. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. Our fraud detection measures may involve automated checks, but these are always subject to human review before any action is taken on your account.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with our services. We may also retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
Specifically:
- Account data: Retained for the lifetime of your account and for up to 2 years after account closure.
- Transaction data: Retained for 7 years to comply with HMRC financial record-keeping requirements.
- Deleted accounts: Personal data is anonymised immediately upon deletion. Transaction records, order history, and event data are retained for 7 years (HMRC compliance).
- Gift Aid declaration records: Retained in line with HMRC requirements. The charity Organiser is the controller for this data and is responsible for meeting that record-keeping obligation; tickts retains the records on its behalf.
- Usage and analytics data: Retained for up to 26 months.
- Scan logs: Retained for 2 years for dispute-resolution and Platform-integrity purposes.
- Support communications: Retained for up to 3 years after the last interaction.
- Consent records (cookies, marketing): Retained for 2 years (automatically purged).
- Organiser administrative activity logs: Retained for 30 days, then automatically purged.
- Migration audit logs (record of an Organiser’s confirmation that they own content imported via the “switch from” tool): Retained for 6 years from the date of import to defend against potential third-party claims relating to imported content.
- Error and security logs: Retained for up to 90 days, except where investigation is ongoing.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. This includes:
- Encryption in transit (TLS/SSL) for all data transmitted to and from the Platform;
- Secure password hashing using bcrypt;
- Regular security reviews and vulnerability assessments;
- Access controls limiting employee and system access to personal data;
- Cloudflare DDoS protection and Web Application Firewall (WAF);
- Optional two-factor authentication (TOTP) with single-use recovery codes; secrets are stored encrypted at rest.
10. International Transfers
Some of our sub-processors (Stripe, Google, Sentry, Apple, Meta, Cloudflare) are based in or operate from the United States. Application data itself is hosted in the United Kingdom on Cloudways/DigitalOcean (London region). Where personal data is transferred outside the United Kingdom, we ensure appropriate safeguards are in place under Article 46 of the UK GDPR, including the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or reliance on the recipient’s participation in a recognised adequacy framework (for example, the UK extension to the EU-US Data Privacy Framework where applicable).
You can request a summary of the transfer mechanism in place for any specific sub-processor by emailing [email protected].
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach, as required by Article 33 of the UK GDPR. Where the breach is likely to result in a high risk to your rights, we will also notify you directly without undue delay.
12. Children’s Privacy
Our Platform is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child under 16, please contact us immediately and we will take steps to delete it.
13. Contact & Complaints
We are not required to appoint a statutory Data Protection Officer under UK GDPR Article 37 because we are not a public authority and our core activities do not involve large-scale monitoring of individuals or processing of special category data. All privacy queries are handled by the Tickts privacy team at the contact below, who acts as our data protection point of contact.
If you have any questions about this Privacy Policy or our data practices, or if you wish to exercise your data rights or make a complaint, please contact us:
- Email: [email protected]
- Post: TICKTS LTD, 124-128 City Road, London, EC1V 2NX
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your data protection rights have been violated. Our ICO registration reference is ZC108275. You can contact the ICO at ico.org.uk or by calling 0303 123 1113.