Privacy
What we know about you
Written to be read. If anything here is unclear, that is our fault and we would like to know — hello@tickestra.com.
The short version
- We hold your name, email and what you bought. Not your card details — those go straight to Stripe.
- Organisers see the names and emails of people who bought tickets to their events. They have to, to run the door.
- We don't sell anything to anyone, and we don't run advertising.
- You can ask for a copy of your data, or ask us to delete it, and we have a month to respond.
Who we are
Tickestra operates this platform. We are the data controller for your account, your ticket purchases and how you use the site.
Event organisers are separate controllers for the attendee information they receive. When you buy a ticket you are dealing with both of us: with Tickestra for the transaction, and with the organiser for the event itself.
For anything about your data, write to support@tickestra.com.
What we collect, and why
Only what the platform needs to work. Each item below has a lawful basis under UK GDPR, which is the legal reason we are allowed to hold it.
| What | Why | Lawful basis |
|---|---|---|
| Your email address | To send your ticket and let you sign in | Performing our contract with you |
| Your name, if you give it | So the door knows who you are | Performing our contract with you |
| What you bought, and when | Your ticket, your receipt, and our accounts | Contract, and our legal duty to keep records |
| Your IP address at checkout | Detecting fraud and card testing | Our legitimate interest in not being defrauded |
| Which events you looked at | Counting visits, using a hash that changes daily | Our legitimate interest in knowing what is popular |
| Events you save or organisers you follow | Showing them back to you | Performing our contract with you |
| Your two-factor secret, if you set one up | Protecting your account | Contract, and our duty to keep data secure |
What we deliberately do not collect
Your card number, expiry or security code. These go directly from your browser to Stripe and never touch our servers. We could not show you your own card number if we wanted to.
Your date of birth, address or identity documents, unless you are an organiser setting up payouts — and even then those go to Stripe, not to us.
We do not use advertising cookies, and we do not have a tracking pixel from any advertising network.
Who else sees it
A short list, and it does not include anyone who wants to sell you something.
| Who | What they get | Why |
|---|---|---|
| The event organiser | Your name, email, ticket type and whether you turned up | They are running the event and the door |
| Stripe | Your email and payment details | They take the payment and hold the card data |
| Our email provider | Your email address and the message | To deliver your ticket |
| Our hosting provider | Whatever is in the database, at rest | The servers the platform runs on |
How long we keep it
Orders and tickets: seven years after the event. Not our choice — HMRC requires records of transactions to be kept for six years after the end of the accounting period they fall in.
Your account, if you have one: until you ask us to delete it.
Visit counts: the daily hash means these stop being linkable to anyone after twenty-four hours. The counts themselves are kept indefinitely because by then they are just numbers.
Audit logs of administrative actions: three years, because they exist to answer questions about what happened.
Failed sign-in attempts and rate limiting counters: these live in memory and disappear when the server restarts.
Your rights
You can ask us for a copy of everything we hold about you, ask us to correct it, or ask us to delete it. Write to support@tickestra.com and we will respond within one month.
Deletion has a limit worth knowing about: we cannot delete a completed order, because we are legally required to keep transaction records. We can remove your name and email from it, which leaves the accounting record without the personal detail.
You can also object to processing based on legitimate interests, ask us to restrict processing while a complaint is resolved, and ask for your data in a portable format.
If you are not happy with how we have handled something, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first, but it is your right either way.
Cookies
We use cookies to keep you signed in, to remember a referral link for thirty days if you arrived through one, and to hold display choices — the country you are browsing, your last search, whether to keep you signed in on this device. That is all of them.
None is used for advertising and none tracks you to another site, which is why there is no consent banner: the regulations exempt cookies that are strictly necessary or that only remember a preference you set yourself.
We do not use analytics cookies either. Visit counting is done on our servers with a hash of your address and browser, salted with a value that changes at midnight — so yesterday's count cannot be linked to today's, and neither can be linked to you.
Where your data is
Where an organiser uses our AI features, the flyer or web page they ask us to read is sent to Anthropic to be read. Nothing about a ticket buyer is sent — the assistant is given figures we have already worked out, never the underlying records.
Our servers are in the European Union. Stripe, our email provider and Anthropic are US companies and may process data outside the UK, under the transfer mechanisms their own agreements provide.
Changes
If we change this notice in a way that matters, we will tell you rather than quietly updating the page. The version is at the bottom.
Version 2026-09-13