Privacy Policy

Draft — pending legal review. This page has not yet been checked by a solicitor and must not be relied on as legal advice.

TicketKind is operated by Asdfx Labs Limited (Company No. 16319069), registered in England and Wales ("we", "us"). This policy explains what personal data we collect, why, and what rights you have over it under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Who this covers

This policy covers organisers who create an account, staff members they invite, and buyers who purchase tickets. Buyers do not need an account to buy tickets.

What we collect

  • Account details for organisers and staff: name, email address and role.
  • Order details for buyers: name, email address, the tickets purchased, and the IP address the order was placed from.
  • Event content organisers add: titles, descriptions, dates, venues and cover images.
  • Payment card details are collected and processed directly by Stripe; we never see or store full card numbers.

Why we process it, and the lawful basis

  • Contract: creating your account, processing an order, issuing tickets, and running check-in.
  • Legitimate interests: preventing fraud and abuse of checkout, and improving the service.
  • Legal obligation: keeping financial records for tax purposes.

Who we share it with

  • Stripe processes payments on behalf of the organiser under a direct charge — the organiser is the seller of the ticket, and Stripe is the payment processor for that sale.
  • AWS SES sends our transactional email, and Sentry captures application errors.
  • Cloudflare Turnstile checks that a form submission (contact and checkout) is from a person, not a bot. It receives the visitor's IP address and some device signals.
  • Google Fonts serves the typefaces used on this site. Loading a page sends the visitor's IP address to Google.

Stripe, AWS and Sentry are only permitted to use your data to provide their service to us, not for their own purposes. Cloudflare and Google are separate controllers for the data their own services receive; see their own privacy policies for how they use it.

How long we keep it, and how we delete it

Order totals, refunds and booking fees are kept indefinitely, as tax and accounting law requires. What we erase on request is the identifying data attached to them — the figures themselves are never changed:

  • Erasing a buyer's data replaces their name, email address, IP address and any attendee names with an anonymised placeholder everywhere we hold it — orders, tickets, refund notes and the waitlist. It also removes it from our own internal logs of what happened to an order, so those logs are not kept unchanged forever.
  • An email that has bounced or complained is kept on our suppression list indefinitely, so that we don't try to email it again. This is the one exception to erasure: keeping it is what stops further contact.
  • Payment webhook records from Stripe are kept for idempotency, but the underlying message content (which can include a buyer's email) is cleared automatically 90 days after we receive and successfully process it, or immediately if we act on an erasure request first. A message we could not yet process is kept in full for longer, so that we can still investigate and retry it.
  • A payment that completes for an event whose organiser has since been suspended or deleted is never turned into tickets. It is refunded in full automatically — including the booking fee — and the buyer is emailed to say so.
  • An organiser can delete their organisation once none of its events, still to happen or still running, has a pending or confirmed order. This unpublishes its future events, revokes its check-in links, replaces its name with "Deleted organisation", anonymises any team member left with no other organisation, and removes everyone's access — while keeping the organisation's financial records. Its Stripe account is left connected; the owner closes it directly with Stripe if they wish. A member who also belongs to another organisation only loses access to the one that was deleted.
  • A user can delete their own account — after confirming their password — unless doing so would leave an organisation with no owner.

To ask us to export or erase your data, use the contact page.

Your rights

Under UK GDPR you can ask to access, correct, delete or export your personal data, and to object to or restrict some kinds of processing, subject to the retention rules above. Contact us using the details below, or via the contact page. You can also complain to the Information Commissioner's Office (ICO) if you believe we have not handled your data correctly.

Cookies

TicketKind only uses cookies that are strictly necessary to run the site — for example, to keep you signed in and to remember your selected organiser. We do not use advertising cookies, so there is no cookie consent banner: strictly necessary cookies do not require one under UK law.

Where enabled, we use cookie-free analytics (Plausible or a compatible service) on our marketing and public event pages to see aggregate visit counts. It sets no cookies, does not track you across sites, and does not identify you individually.

Contact

For any question about this policy or your data, use the contact page.