Privacy Policy
Last updated: 28 July 2026
This policy explains what personal data TicketConnect processes, on what legal basis, who it is shared with, and how you can exercise your rights. It is written to describe how the service actually works, including the parts that are awkward — see section 6 on data written to a blockchain.
This document has not been reviewed by a lawyer. It was drafted from the system’s actual data flows and is accurate about what the software does, but accuracy about the code is not the same as legal sufficiency. Have it reviewed before you rely on it — in particular sections 3, 6 and 7, where this product has genuinely unusual problems.
A Polish-language version is very likely required in practice: the service is aimed at consumers in Poland, and information addressed to them should be in a language they readily understand.
1. Who is responsible for your data
The data controller is [TO FILL IN: registered company name], with its registered office at [TO FILL IN: full address], entered in the register under [TO FILL IN: KRS / NIP / REGON].
For any privacy question, or to exercise the rights in section 7, write to [TO FILL IN: privacy contact email]. We answer within one month, as the GDPR requires.
[TO FILL IN: whether a Data Protection Officer has been appointed — if so, their contact details go here; if not, delete this paragraph]
2. What we collect from you
You can browse the entire event catalogue without an account and without signing in. The data below is processed only once you take an action that requires it.
If you connect Spotify, we request two read-only permissions, read your top and followed artists once, and keep only the artist names. The access token is used during that single import and then discarded — we do not hold a standing grant, we never write anything to your Spotify account, and re-importing means asking you again.
3. Data about people we did not collect it from
TicketConnect aggregates public event listings from other ticketing platforms. Those listings sometimes name a natural person — an event on a personal calendar is hosted by an individual, not a company — and that name is personal data even though it was published by someone else.
Where we hold such a name, we process it on the basis of our legitimate interest in operating an event search service (Article 6(1)(f) GDPR), limited to what the source already published. This section is our notice under Article 14 GDPR, which covers data not obtained from the person it concerns.
If you are named in a listing we display and you want it removed or corrected, write to [TO FILL IN: privacy contact email] and we will act on it. You do not need to explain why.
Open item for review: reducing how much of this you hold in the first place is cheaper than handling objections. Storing the source platform’s name instead of an individual host’s name, and a short excerpt instead of a full description, would remove most of this exposure without changing what users see.
4. Why we process it, and on what basis
6. Blockchain and IPFS — what we cannot undo
Tickets are issued as tokens on a public blockchain, and their metadata is stored on IPFS. You should understand what that means before you buy one.
Your wallet address, the tickets it holds, and every transfer between addresses are public, permanent and outside our control. Anyone can read them. We cannot edit or delete them, and neither can you. The same applies to ticket metadata pinned to IPFS: it is addressed by its content and may be replicated by parties we have no relationship with.
This genuinely limits your right to erasure. If you ask us to delete your data, we will delete it from our own systems — the account, profile, preferences, follows and activity — but we cannot remove anything already written to the blockchain or to IPFS, because no one can. We flag this rather than promise a deletion we are unable to perform.
A wallet address is pseudonymous, not anonymous. If it is ever linked to your identity anywhere — an exchange, a public post, another service — your entire history on that address becomes linkable too.
7. Your rights
Under the GDPR you may request access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time without affecting what was lawful before.
Write to [TO FILL IN: privacy contact email]. We will not ask you to justify a request or make you jump through hoops. Section 6 explains the one limit we cannot get around.
You also have the right to lodge a complaint with a supervisory authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa.
8. How long we keep it
9. Security
Ticket payloads are encrypted, private keys stay on your device, and access to production systems is restricted. No system is perfectly secure; if a breach occurs that is likely to put your rights at risk, we will notify you and the supervisory authority as the GDPR requires.
10. Children
The service is not directed at children under [TO FILL IN: 16, or the age set by Polish law]. We do not knowingly create accounts for them. If you believe a child has an account, tell us and we will remove it.
11. Changes
We will update this policy when the service changes. The date at the top always reflects the current version, and we will tell account holders directly about changes that materially affect them rather than relying on you to re-read the page.