← Legal Centre

Privacy Policy

Draft · preview

Version 0.1-preview · effective 21 July 2026

Draft for review. A plain-English starting point, not final legal advice. Items in […]and the operating-entity details are still to be confirmed, and the whole document reviewed by a solicitor, before launch.

Privacy Policy

DRAFT v0.1 — for solicitor review. Not legal advice and not yet in force. UK GDPR / Data Protection Act 2018. Jurisdiction: England & Wales.

[tckt legal entity name] ("tckt", "we") operates tckt.co.uk. Contact / data queries: [privacy@tckt.co.uk], [registered office], company number [00000000]. [Confirm whether an ICO registration / DPO is required.]

1. Our two roles

  • For your tckt account and how we run the platform, tckt is the controller.
  • For attendee personal data collected through an organiser's events, the organiser is the controller and tckt is their processor — we handle that data on the organiser's instructions (see the organiser's own privacy notice for how they use it).

This policy covers what tckt does as a controller, and explains our role as a processor.

2. What we collect

  • Organisers: email address, organisation name, and payment-connection status (via Square — we do not hold your bank details or card data).
  • Attendees/buyers: name, email address, the tickets you bought and their QR codes, and order/ payment metadata (amounts, timestamps). We never see or store card numbers — Square handles all card data.
  • Technical: basic logs and minimal cookies needed to run the site and keep you logged in.

3. How and why we use it (lawful bases)

PurposeLawful basis
Create/secure accounts, send login linksContract; legitimate interests (security)
Process orders and deliver ticketsContract (and processing on the organiser's behalf)
Send transactional emails (tickets, confirmations)Contract
Operate door check-in and reportingContract; legitimate interests
Prevent fraud and abuse; keep the service safeLegitimate interests; legal obligation
Product/service emails to organisers [if any]Consent or legitimate interests [confirm]

4. Who we share it with (sub-processors)

We use trusted providers to run tckt: Supabase (database & login, hosted in the EU — Ireland), Vercel (hosting), Resend (transactional email), Square (card payments). Each processes data only to provide their service. We share attendee data with the relevant event organiser (who is its controller). We do not sell personal data.

5. International transfers

We aim to keep data in the UK/EEA. Where a provider processes data outside the UK/EEA, we rely on appropriate safeguards (UK IDTA / SCCs). [Confirm each provider's transfer position.]

6. How long we keep it

We keep personal data only as long as we need it, then anonymise it (we keep financial records without the personal details). Our current schedule (draft for preview — periods to be confirmed):

DataKept forThen
Attendee name/email on a ticket~13 months after the eventAnonymised
Buyer name/email on an order~13 months after the eventAnonymised (order amounts kept for tax)
Order financial records (amounts, dates)~6 years (HMRC) [confirm]Deleted
Event reports~12 monthsDeleted
Acceptance records (terms accepted)~6 years (legal-claims period) [confirm]Retained as a legal record
Inactive organiser accountsReviewed after ~24 monthsHandled case by case

You can ask us to erase your personal data sooner (see Your rights); we will do so except where we must keep a limited record for legal or tax reasons.

7. Your rights

You can request access, correction, deletion, restriction, portability, or object to certain processing, and withdraw consent where we rely on it. Email [privacy@tckt.co.uk]. For data held on an organiser's behalf, we will direct you to, or assist, that organiser. You can complain to the ICO (ico.org.uk).

8. Cookies

We use a small number of essential cookies to keep you signed in and to run checkout. [Confirm any analytics/marketing cookies and add a cookie banner if used.]

9. Security

We use appropriate technical and organisational measures to protect personal data. No system is perfectly secure; we will notify affected people/organisers and the ICO of a reportable breach as required.

10. Changes

We may update this policy; we'll post the new version and update the date.

Questions about this document? Contact help@tckt.co.uk.
Privacy Policy — tckt