Privacy Policy
Draft · previewVersion 0.1-preview · effective 21 July 2026
[…]and the operating-entity details are still to be confirmed, and the whole document reviewed by a solicitor, before launch.Privacy Policy
DRAFT v0.1 — for solicitor review. Not legal advice and not yet in force. UK GDPR / Data Protection Act 2018. Jurisdiction: England & Wales.
[tckt legal entity name] ("tckt", "we") operates tckt.co.uk. Contact / data queries: [privacy@tckt.co.uk], [registered office], company number [00000000]. [Confirm whether an ICO registration / DPO is required.]
1. Our two roles
- For your tckt account and how we run the platform, tckt is the controller.
- For attendee personal data collected through an organiser's events, the organiser is the controller and tckt is their processor — we handle that data on the organiser's instructions (see the organiser's own privacy notice for how they use it).
This policy covers what tckt does as a controller, and explains our role as a processor.
2. What we collect
- Organisers: email address, organisation name, and payment-connection status (via Square — we do not hold your bank details or card data).
- Attendees/buyers: name, email address, the tickets you bought and their QR codes, and order/ payment metadata (amounts, timestamps). We never see or store card numbers — Square handles all card data.
- Technical: basic logs and minimal cookies needed to run the site and keep you logged in.
3. How and why we use it (lawful bases)
| Purpose | Lawful basis |
|---|---|
| Create/secure accounts, send login links | Contract; legitimate interests (security) |
| Process orders and deliver tickets | Contract (and processing on the organiser's behalf) |
| Send transactional emails (tickets, confirmations) | Contract |
| Operate door check-in and reporting | Contract; legitimate interests |
| Prevent fraud and abuse; keep the service safe | Legitimate interests; legal obligation |
| Product/service emails to organisers [if any] | Consent or legitimate interests [confirm] |
4. Who we share it with (sub-processors)
We use trusted providers to run tckt: Supabase (database & login, hosted in the EU — Ireland), Vercel (hosting), Resend (transactional email), Square (card payments). Each processes data only to provide their service. We share attendee data with the relevant event organiser (who is its controller). We do not sell personal data.
5. International transfers
We aim to keep data in the UK/EEA. Where a provider processes data outside the UK/EEA, we rely on appropriate safeguards (UK IDTA / SCCs). [Confirm each provider's transfer position.]
6. How long we keep it
We keep personal data only as long as we need it, then anonymise it (we keep financial records without the personal details). Our current schedule (draft for preview — periods to be confirmed):
| Data | Kept for | Then |
|---|---|---|
| Attendee name/email on a ticket | ~13 months after the event | Anonymised |
| Buyer name/email on an order | ~13 months after the event | Anonymised (order amounts kept for tax) |
| Order financial records (amounts, dates) | ~6 years (HMRC) [confirm] | Deleted |
| Event reports | ~12 months | Deleted |
| Acceptance records (terms accepted) | ~6 years (legal-claims period) [confirm] | Retained as a legal record |
| Inactive organiser accounts | Reviewed after ~24 months | Handled case by case |
You can ask us to erase your personal data sooner (see Your rights); we will do so except where we must keep a limited record for legal or tax reasons.
7. Your rights
You can request access, correction, deletion, restriction, portability, or object to certain processing, and withdraw consent where we rely on it. Email [privacy@tckt.co.uk]. For data held on an organiser's behalf, we will direct you to, or assist, that organiser. You can complain to the ICO (ico.org.uk).
8. Cookies
We use a small number of essential cookies to keep you signed in and to run checkout. [Confirm any analytics/marketing cookies and add a cookie banner if used.]
9. Security
We use appropriate technical and organisational measures to protect personal data. No system is perfectly secure; we will notify affected people/organisers and the ICO of a reportable breach as required.
10. Changes
We may update this policy; we'll post the new version and update the date.