Privacy Policy

Last updated: 28 July 2026

This policy explains what personal data TicketConnect processes, on what legal basis, who it is shared with, and how you can exercise your rights. It is written to describe how the service actually works, including the parts that are awkward — see section 6 on data written to a blockchain.

This document has not been reviewed by a lawyer. It was drafted from the system’s actual data flows and is accurate about what the software does, but accuracy about the code is not the same as legal sufficiency. Have it reviewed before you rely on it — in particular sections 3, 6 and 7, where this product has genuinely unusual problems.

A Polish-language version is very likely required in practice: the service is aimed at consumers in Poland, and information addressed to them should be in a language they readily understand.

1. Who is responsible for your data

The data controller is [TO FILL IN: registered company name], with its registered office at [TO FILL IN: full address], entered in the register under [TO FILL IN: KRS / NIP / REGON].

For any privacy question, or to exercise the rights in section 7, write to [TO FILL IN: privacy contact email]. We answer within one month, as the GDPR requires.

[TO FILL IN: whether a Data Protection Officer has been appointed — if so, their contact details go here; if not, delete this paragraph]

2. What we collect from you

You can browse the entire event catalogue without an account and without signing in. The data below is processed only once you take an action that requires it.

Wallet addressA blockchain address, created for you by our authentication provider or connected by you. It is the primary identifier for your account, your tickets and your listings. Treat it as persistent and publicly linkable — see section 6.
Account identityAn identifier issued by our authentication provider, and your email address plus its verification status where you provide one.
ProfileUsername, display name, biography and avatar, when you choose to set them.
PreferencesNotification settings, preferred currency, and push notification tokens if you enable notifications on a device.
ActivityEvents you mark as liked or attended, your saved plan, your follows (artists, venues, organizers), and counts of tickets minted, bought, sold and received.
TransactionsPurchases, resale listings, transfers and refunds, together with the payment records our payment provider returns. We never see or store your full card number.
Encryption keyA public key used to encrypt ticket data addressed to you. Public keys only; the corresponding private key never leaves your device.
Support conversationsAnything you send us through the support chat or by email.

If you connect Spotify, we request two read-only permissions, read your top and followed artists once, and keep only the artist names. The access token is used during that single import and then discarded — we do not hold a standing grant, we never write anything to your Spotify account, and re-importing means asking you again.

3. Data about people we did not collect it from

TicketConnect aggregates public event listings from other ticketing platforms. Those listings sometimes name a natural person — an event on a personal calendar is hosted by an individual, not a company — and that name is personal data even though it was published by someone else.

Where we hold such a name, we process it on the basis of our legitimate interest in operating an event search service (Article 6(1)(f) GDPR), limited to what the source already published. This section is our notice under Article 14 GDPR, which covers data not obtained from the person it concerns.

If you are named in a listing we display and you want it removed or corrected, write to [TO FILL IN: privacy contact email] and we will act on it. You do not need to explain why.

Open item for review: reducing how much of this you hold in the first place is cheaper than handling objections. Storing the source platform’s name instead of an individual host’s name, and a short excerpt instead of a full description, would remove most of this exposure without changing what users see.

4. Why we process it, and on what basis

Running your accountPerformance of our contract with you (Art. 6(1)(b)) — authentication, showing your tickets, processing purchases, transfers and refunds.
PersonalisationYour consent (Art. 6(1)(a)) for the Spotify import; legitimate interest (Art. 6(1)(f)) for likes, follows and recommendations you create through ordinary use. You can withdraw consent or delete follows at any time.
Analytics and advertising measurementYour consent (Art. 6(1)(a)). Google Analytics (via Google Tag Manager) and the Meta Pixel / Conversions API only run once you accept analytics or marketing storage respectively — used for ad measurement and campaign optimisation, nothing else. You can withdraw either at any time via Cookie settings in the footer; see the Cookie Policy for what each one stores.
Order attributionLegitimate interest (Art. 6(1)(f)) in knowing which campaign led to a sale. The campaign parameters (UTM codes) that brought you to the event you bought are attached to your order regardless of consent, but stay in our own database — we do not pass them to Google or Meta without your marketing consent.
NotificationsYour consent for marketing messages; contract performance for transactional ones you cannot sensibly opt out of, such as a ticket transfer confirmation.
Fraud and abuseLegitimate interest in keeping the marketplace safe, and our legal obligations where payments are involved.
Accounting and taxLegal obligation (Art. 6(1)(c)) — transaction records are kept for the statutory period regardless of account deletion.

5. Who else sees it

We do not sell personal data. We share it with the providers below, each acting on our instructions or as an independent controller where noted.

Authentication & walletsPrivy — account identity and embedded wallet creation.
PaymentsStripe — card and payment processing. Stripe is an independent controller for its own fraud and compliance purposes.
ImagesCloudinary — hosting and transforming event and profile images.
MapsCARTO, as the basemap tile provider. Loading a map discloses your IP address to them.
Support chatChatwoot — support conversations.
AnalyticsGoogle Ireland Ltd — Google Analytics (GA4), loaded through Google Tag Manager, only once you consent to analytics storage. Used for ad measurement and campaign optimisation.
AdvertisingMeta Platforms Ireland Ltd — the Meta Pixel in your browser and, server-side, the Conversions API, only once you consent to marketing storage. The Conversions API sends Meta a copy of your purchase event, including your hashed email address, your IP address and your user agent — never your email in the clear.
SpotifyOnly if you start an import, and only to read the two scopes above.
Ticket metadataIPFS, via a pinning provider — see section 6, this one does not come back.
InfrastructureOur own databases, cache and search index, hosted at [TO FILL IN: hosting provider and region].

Several of these are established outside the European Economic Area — including Google Ireland Ltd and Meta Platforms Ireland Ltd, whose analytics and advertising tools only run with your consent (see section 4). Where that is the case, transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision. [TO FILL IN: confirm the mechanism actually in place with each provider]

6. Blockchain and IPFS — what we cannot undo

Tickets are issued as tokens on a public blockchain, and their metadata is stored on IPFS. You should understand what that means before you buy one.

Your wallet address, the tickets it holds, and every transfer between addresses are public, permanent and outside our control. Anyone can read them. We cannot edit or delete them, and neither can you. The same applies to ticket metadata pinned to IPFS: it is addressed by its content and may be replicated by parties we have no relationship with.

This genuinely limits your right to erasure. If you ask us to delete your data, we will delete it from our own systems — the account, profile, preferences, follows and activity — but we cannot remove anything already written to the blockchain or to IPFS, because no one can. We flag this rather than promise a deletion we are unable to perform.

A wallet address is pseudonymous, not anonymous. If it is ever linked to your identity anywhere — an exchange, a public post, another service — your entire history on that address becomes linkable too.

7. Your rights

Under the GDPR you may request access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time without affecting what was lawful before.

Write to [TO FILL IN: privacy contact email]. We will not ask you to justify a request or make you jump through hoops. Section 6 explains the one limit we cannot get around.

You also have the right to lodge a complaint with a supervisory authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa.

8. How long we keep it

Account dataUntil you delete your account, plus a short grace period for reversal.
Transaction recordsThe statutory accounting retention period, currently [TO FILL IN: confirm: 5 years from the end of the tax year, per Polish accounting rules].
Support conversations[TO FILL IN: retention period]
Imported artist namesUntil you remove the follows or delete your account.
On-chain and IPFS dataPermanent — see section 6.

9. Security

Ticket payloads are encrypted, private keys stay on your device, and access to production systems is restricted. No system is perfectly secure; if a breach occurs that is likely to put your rights at risk, we will notify you and the supervisory authority as the GDPR requires.

10. Children

The service is not directed at children under [TO FILL IN: 16, or the age set by Polish law]. We do not knowingly create accounts for them. If you believe a child has an account, tell us and we will remove it.

11. Changes

We will update this policy when the service changes. The date at the top always reflects the current version, and we will tell account holders directly about changes that materially affect them rather than relying on you to re-read the page.