What we collect
Only what the platform needs to work.
- Account details — your name, email address, phone number, password (stored only as a one-way hash), and any profile picture, city or interests you add.
- Orders and tickets — what you bought, when, for how much, in which currency, and the tickets issued to you, including whether and when each was scanned.
- Payment data — handled by our payment processor, not by us. When you save a payment method we keep the processor's token, the method type and the last four digits. Full card numbers never reach Tiqstar's servers.
- Verification documents — where you apply to sell tickets or offer services, the identity or business documents needed to approve you and to pay you out.
- Payout details — the bank or mobile-money account creators and vendors are paid into.
- Content you post — event pages, vendor portfolios, reviews, messages sent through the platform, and support tickets.
- Technical data — IP address, device and browser information, and session records so you can see and end your own active sessions. Push notification tokens where you turn notifications on.
We do not buy personal data from data brokers, and we do not run advertising trackers on this site. See the cookie policy for exactly what is set in your browser.
Why we use it
- To create and secure your account, and to sign you in.
- To take payment, issue tickets, admit you at the gate, and process refunds and transfers.
- To pay creators and vendors, and to meet the tax, accounting and anti-money-laundering obligations that come with moving money.
- To send you the messages a transaction requires — order confirmations, tickets, transfer notices, event changes.
- To provide support, and to investigate fraud, abuse and safety reports.
- To operate and improve the platform, including search and recommendations.
- To send marketing where you have asked for it, or where we are otherwise permitted to.
Who else sees it
- Event creators — when you buy a ticket, the creator of that event receives the details needed to run it and admit you. See below.
- Vendors — where a creator books a vendor through the platform, the two parties see each other's booking details and messages.
- Payment processors — Paystack, Stripe and Flutterwave, depending on the currency of the event. They are independent controllers of the payment data they hold.
- Infrastructure and messaging providers — hosting, object storage, email delivery and push notification services acting on our instructions.
- Authorities — where we are legally required to, or to establish, exercise or defend legal claims.
We do not sell your personal data.
Creators as controllers
When you buy a ticket, the creator running that event becomes an independent controller of your details for the purpose of running it. They can see who is coming, check you in, and contact you about that event.
Our terms require them to use those details only to run the event, and our platform enforces consent and unsubscribe on every message sent through it. A creator who contacts you outside Tiqstar is doing so on their own responsibility — tell us if that happens.
Email and push
Messages fall into two kinds. Transactional messages — order confirmations, tickets, password resets, event changes — are part of the service and are sent because you have a transaction with us. Marketing messages are sent only where you have opted in, and every one carries an unsubscribe link.
Every address on the platform sits on a consent ledger with a suppression list. Unsubscribing, or a hard bounce or spam complaint, suppresses the address across the whole platform — including messages a creator sends through our tools. You can change what you receive at any time in your notification settings.
What other people can see
Your profile name and picture are visible where you interact publicly — following a performer, posting a review.
Appearing on a public guest list is off by default. Attendee rosters and check-in walls only show people who have turned activity visibility on, in privacy settings. Turning it off removes you from those lists regardless of any individual event's own setting.
How we protect it
Traffic is encrypted in transit. Passwords are stored as one-way hashes and cannot be read back, by us or by anyone else. Card data is tokenised by the payment processor and never stored here. Access to production data is restricted to staff who need it, and administrative actions are logged.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as the law requires.
How long we keep it
- Account data — while your account is open.
- Orders, tickets and payouts — for as long as tax, accounting and anti-money-laundering law requires, which is longer than your account may last. Deleting your account does not delete a financial record we are obliged to keep.
- Verification documents — for the retention period our obligations impose, then deleted.
- Suppression list — kept indefinitely, because forgetting that you unsubscribed would mean emailing you again.
- Support tickets and messages — kept while they are useful for support and dispute history.
Your rights
Depending on where you live, you can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong — most of it you can edit yourself in account settings;
- delete your account and the data we are not required to keep;
- stop using your data for marketing, which you can also do yourself by unsubscribing;
- restrict or object to a particular use, or ask for your data in a portable format.
Email privacy@tiqstar.com and we will respond within the period the applicable law sets. You also have the right to complain to your data protection authority.
Children
Tiqstar is not intended for children. Accounts are for people old enough to enter into a contract where they live. If you believe a child has given us personal data, tell us and we will remove it.
International transfers
Tiqstar operates across several countries, and our infrastructure and payment partners may process data outside the country you are in. Where that happens we rely on the safeguards the applicable law provides for such transfers.
Contact
Privacy questions and rights requests: privacy@tiqstar.com. For anything else, contact us.
See also our terms of service and cookie policy.
