Tickestra
Sign inStart selling

Privacy

What we know about you

Written to be read. If anything here is unclear, that is our fault and we would like to know — hello@tickestra.com.

The short version

Who we are

Tickestra operates this platform. We are the data controller for your account, your ticket purchases and how you use the site.

Event organisers are separate controllers for the attendee information they receive. When you buy a ticket you are dealing with both of us: with Tickestra for the transaction, and with the organiser for the event itself.

For anything about your data, write to support@tickestra.com.

What we collect, and why

Only what the platform needs to work. Each item below has a lawful basis under UK GDPR, which is the legal reason we are allowed to hold it.

WhatWhyLawful basis
Your email addressTo send your ticket and let you sign inPerforming our contract with you
Your name, if you give itSo the door knows who you arePerforming our contract with you
What you bought, and whenYour ticket, your receipt, and our accountsContract, and our legal duty to keep records
Your IP address at checkoutDetecting fraud and card testingOur legitimate interest in not being defrauded
Which events you looked atCounting visits, using a hash that changes dailyOur legitimate interest in knowing what is popular
Events you save or organisers you followShowing them back to youPerforming our contract with you
Your two-factor secret, if you set one upProtecting your accountContract, and our duty to keep data secure

What we deliberately do not collect

Your card number, expiry or security code. These go directly from your browser to Stripe and never touch our servers. We could not show you your own card number if we wanted to.

Your date of birth, address or identity documents, unless you are an organiser setting up payouts — and even then those go to Stripe, not to us.

We do not use advertising cookies, and we do not have a tracking pixel from any advertising network.

Who else sees it

A short list, and it does not include anyone who wants to sell you something.

WhoWhat they getWhy
The event organiserYour name, email, ticket type and whether you turned upThey are running the event and the door
StripeYour email and payment detailsThey take the payment and hold the card data
Our email providerYour email address and the messageTo deliver your ticket
Our hosting providerWhatever is in the database, at restThe servers the platform runs on

How long we keep it

Orders and tickets: seven years after the event. Not our choice — HMRC requires records of transactions to be kept for six years after the end of the accounting period they fall in.

Your account, if you have one: until you ask us to delete it.

Visit counts: the daily hash means these stop being linkable to anyone after twenty-four hours. The counts themselves are kept indefinitely because by then they are just numbers.

Audit logs of administrative actions: three years, because they exist to answer questions about what happened.

Failed sign-in attempts and rate limiting counters: these live in memory and disappear when the server restarts.

Your rights

You can ask us for a copy of everything we hold about you, ask us to correct it, or ask us to delete it. Write to support@tickestra.com and we will respond within one month.

Deletion has a limit worth knowing about: we cannot delete a completed order, because we are legally required to keep transaction records. We can remove your name and email from it, which leaves the accounting record without the personal detail.

You can also object to processing based on legitimate interests, ask us to restrict processing while a complaint is resolved, and ask for your data in a portable format.

If you are not happy with how we have handled something, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first, but it is your right either way.

Cookies

We use cookies to keep you signed in, to remember a referral link for thirty days if you arrived through one, and to hold display choices — the country you are browsing, your last search, whether to keep you signed in on this device. That is all of them.

None is used for advertising and none tracks you to another site, which is why there is no consent banner: the regulations exempt cookies that are strictly necessary or that only remember a preference you set yourself.

We do not use analytics cookies either. Visit counting is done on our servers with a hash of your address and browser, salted with a value that changes at midnight — so yesterday's count cannot be linked to today's, and neither can be linked to you.

Where your data is

Where an organiser uses our AI features, the flyer or web page they ask us to read is sent to Anthropic to be read. Nothing about a ticket buyer is sent — the assistant is given figures we have already worked out, never the underlying records.

Our servers are in the European Union. Stripe, our email provider and Anthropic are US companies and may process data outside the UK, under the transfer mechanisms their own agreements provide.

Changes

If we change this notice in a way that matters, we will tell you rather than quietly updating the page. The version is at the bottom.

Version 2026-09-13