Privacy and your data

Use only the data needed to deliver and protect the event journey.

This notice explains the platform’s processing. An organizer may be a separate controller for event fulfillment, guest management and its legal obligations; its details are shown with the event.

Last updated: 30 July 2026

Controller and scope

The configured platform operator is responsible for platform accounts, security, technical ticket delivery, support and platform administration. Organizers are responsible for their own event and seller processing where applicable.

Data we process

Depending on how you use the service, this may include:

  • account identifiers, email address, display name and locale;
  • orders, ticket entitlements, invoices, refunds and payment-provider references;
  • ticket scans, transfers, waitlist, rewards and event notifications;
  • support messages, approved attachments and privacy requests;
  • security, audit and consent records, including short-lived abuse-prevention signals.

Purposes and legal bases

Data is processed to perform contracts and requested pre-contract steps, meet legal obligations, protect the service and users through legitimate interests, and—where required—on the basis of consent. Optional advertising or third-party analytics is not loaded before the relevant consent.

Recipients and service providers

Data is shared only as needed with the relevant organizer and vetted providers for identity, payments, email delivery, hosting, security and support. Stripe processes payment details; the platform stores only provider references and transaction records. Provider roles and international-transfer safeguards must be finalized in the production subprocessor register.

Retention and deletion

Optional profile and marketing data is removed when no longer needed. Order, accounting, fraud, dispute and audit records may be retained or pseudonymized for the applicable legal period. Backups expire through controlled rotation rather than ad-hoc editing.

Your rights

Subject to the GDPR conditions, you may request information, access, rectification, erasure, restriction, portability or object to processing. You may withdraw consent at any time without affecting earlier lawful processing. Requests are available in the dashboard and may require identity verification.

Complaints and security

You may complain to the Cyprus Commissioner for Personal Data Protection or another competent supervisory authority. Technical and organizational safeguards include role-based access, encrypted credentials, audit records and data minimization; no internet service can promise absolute security.

Configured provider details

Entriza

Legal name
Not configured
Address
Not configured
Represented by
Not configured
Registration number
Not configured
VAT number
Not configured
Support email
Not configured
Privacy email
Not configured