This document is a draft and requires formal legal review before publication.
1. Information We Collect
We collect information to provide and improve the TicketPlug platform. The types of information we collect include:
Information You Provide
- Account information: Name, email address, phone number, and password when you create an account
- Payment information: Bank account details for organisers and sellers receiving payouts (payment card details are processed by our payment provider and not stored by TicketPlug)
- Event information: Event details, descriptions, images, and venue information provided by organisers
- Communications: Messages and correspondence you send to us or other users through the Platform
Information Collected Automatically
- Usage data: Pages visited, features used, actions taken, and time spent on the Platform
- Device information: Browser type, operating system, device type, and screen resolution
- Location data: Approximate location based on IP address (we do not collect precise GPS location)
- Log data: IP address, access times, referring URLs, and error logs
2. How We Use Information
We use the information we collect to:
- Provide, maintain, and improve the Platform
- Process ticket purchases, refunds, and payouts
- Send transactional communications (order confirmations, ticket delivery, payout notifications)
- Verify user identity and prevent fraud
- Provide customer support
- Send marketing communications (with your consent, where required)
- Analyse usage patterns to improve the Platform
- Comply with legal obligations
3. Information Sharing
We do not sell your personal information. We may share information with:
- Event organisers: When you purchase a ticket, we share your name and email with the event organiser so they can manage attendance
- Payment processors: We share necessary payment information with our payment processing partners to complete transactions
- Service providers: We use third-party services for hosting, analytics, email delivery, and SMS messaging
- Legal requirements: We may disclose information when required by law, court order, or to protect our rights and safety
- Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction
4. Data Security
We implement appropriate technical and organisational measures to protect your information, including:
- Encryption of data in transit (TLS/SSL)
- Encryption of sensitive data at rest
- Regular security assessments
- Access controls and authentication requirements
- Secure payment processing through PCI-compliant providers
While we take reasonable precautions, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your information.
5. Cookies
We use cookies and similar technologies to provide and improve the Platform. For detailed information about our use of cookies, please see our Cookie Policy.
6. Your Rights (GDPR)
Under the UK General Data Protection Regulation (UK GDPR), you have the following rights:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data (subject to legal obligations)
- Right to restrict processing: Request that we limit how we use your data
- Right to data portability: Request your data in a structured, machine-readable format
- Right to object: Object to processing of your data for certain purposes, including direct marketing
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated.
7. Data Retention
We retain your personal data for as long as necessary to provide the Platform and fulfil the purposes described in this policy:
- Account data: Retained while your account is active and for 2 years after deletion
- Transaction data: Retained for 7 years to comply with financial regulations
- Usage data: Retained for 2 years in identifiable form, then anonymised
- Marketing preferences: Retained until you withdraw consent
8. International Transfers
Your data is primarily processed and stored within the United Kingdom and European Economic Area. If we transfer data outside these regions, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Government.
9. Children's Privacy
The Platform is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will take steps to delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Platform and, where appropriate, by email.
11. Contact
If you have questions about this Privacy Policy or how we handle your data, please contact us at:
- Email: [email protected]
- Website: ticketplug.co.uk
Our data controller is TicketPlug Ltd, registered in England and Wales.