Privacy Policy
How we collect, use, and protect your data.
Controller: ETicketsGo (placeholder) · Effective date: pending.
1. Data we collect
- Account: name, email, password hash (bcrypt), roles.
- Orders: buyer and ticket-holder name and email.
- Payments: provider references only — no card numbers or CVV are stored.
- Security: refresh-token hashes, IP, and user-agent; an immutable audit log.
- Notifications: recipient email, phone, or push tokens.
2. How we use data
To provide the service (accounts, ticketing, payments, entry), for security and fraud prevention, support, legal compliance, and — where permitted — service communications.
3. Sharing
Organizers receive attendee data needed to run their events; payment providers process payments; sub-processors (email/SMS/push, hosting, monitoring) operate under contract. We disclose data where legally required.
4. Retention
Concrete retention periods per data category are to be defined with counsel. A self-serve data export/erasure workflow is a planned follow-up; until then, requests are handled operationally.
5. Your rights
Access, rectification, erasure, portability, and objection — scoped by your jurisdiction. Requests via the contact page.
6. Security
Encryption in transit (TLS), hashed passwords, least-privilege authorization, audit logging, secret management, and fail-closed production configuration.
7. Children
The service is not directed to children; we do not knowingly collect their data.
8. Changes & contact
We may update this policy; material changes will be communicated. Contact details are placeholders in this demo.