Skip to content
Legal

Privacy Policy

How we collect, use, and protect your data.

Please note: This is a draft for demonstration. Retention periods and data-subject rights mechanics require privacy/legal counsel before publication.

Controller: ETicketsGo (placeholder) · Effective date: pending.

1. Data we collect

  • Account: name, email, password hash (bcrypt), roles.
  • Orders: buyer and ticket-holder name and email.
  • Payments: provider references only — no card numbers or CVV are stored.
  • Security: refresh-token hashes, IP, and user-agent; an immutable audit log.
  • Notifications: recipient email, phone, or push tokens.

2. How we use data

To provide the service (accounts, ticketing, payments, entry), for security and fraud prevention, support, legal compliance, and — where permitted — service communications.

3. Sharing

Organizers receive attendee data needed to run their events; payment providers process payments; sub-processors (email/SMS/push, hosting, monitoring) operate under contract. We disclose data where legally required.

4. Retention

Concrete retention periods per data category are to be defined with counsel. A self-serve data export/erasure workflow is a planned follow-up; until then, requests are handled operationally.

5. Your rights

Access, rectification, erasure, portability, and objection — scoped by your jurisdiction. Requests via the contact page.

6. Security

Encryption in transit (TLS), hashed passwords, least-privilege authorization, audit logging, secret management, and fail-closed production configuration.

7. Children

The service is not directed to children; we do not knowingly collect their data.

8. Changes & contact

We may update this policy; material changes will be communicated. Contact details are placeholders in this demo.