Privacy Policy
Last updated 2 September 2026
Tixy collects as little as it can: enough to sign organisers in, sell tickets and get them to the right inbox. This policy explains what that involves and the rights you have. We do not sell personal data, and we do not use advertising or analytics trackers.
1. Who is responsible for your data
The data controller is Eventotron Ltd (company number 13923634), 86-90 Paul Street, London, EC2A 4NE, United Kingdom. Questions about this policy or your data go to [email protected].
Organisers who collect guest details through Tixy are separate, independent controllers of that data for their own event. Section 6 explains what they can see.
2. What we collect
If you organise an event
- Your email address, and your name if you give it or if Apple shares it at sign-in.
- The events you create: title, description, dates, venue, images, ticket types, prices and discount codes.
- Your payments status. Stripe holds your identity and bank details; we store only your Stripe account identifier and whether it is ready to receive payouts.
- Sales, refunds, comps and check-ins for your events, so you can see them in the app.
- If you turn on sale notifications, a push subscription for your device. You can switch it off in your browser at any time.
If you buy a ticket
- Your name and email address, so we can issue and send your tickets.
- Your order: the event, ticket types, quantities, any discount code, amounts paid and refunded.
- Payment details are entered directly into Stripe and never reach our servers. We receive only a payment reference and whether the payment succeeded.
- Whether and when each ticket was scanned at the door.
Everyone
- Server logs: IP address, browser type, the pages requested and when. We use these to keep the service running and secure, and to investigate abuse.
- Emails you send us, and our replies.
We do not knowingly collect data from children under 16, and Tixy is not aimed at them. If you believe a child has given us data, email [email protected] and we will remove it.
3. How and why we use it
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Creating your account, signing you in, publishing your event | Performance of a contract |
| Taking orders, issuing tickets, sending confirmations and reminders about your order | Performance of a contract |
| Paying organisers, processing refunds, handling disputes | Performance of a contract; legal obligation |
| Keeping the service secure, preventing fraud, enforcing our terms | Legitimate interests (running a safe service) |
| Answering your emails and support requests | Legitimate interests; performance of a contract |
| Sale notifications on your device | Consent (you turn them on) |
| Keeping financial records; responding to lawful requests from authorities | Legal obligation |
| Telling organisers about important changes to Tixy | Legitimate interests; legal obligation |
We do not send marketing email. Every email from Tixy is about your account, your event or your order.
4. Who we share it with
- Stripe processes payments and organiser payouts, and runs identity checks on organisers. Stripe is an independent controller for some of this; see Stripe’s privacy policy.
- Cloudflare delivers our email (tickets, sign-in links, confirmations) and protects the site.
- Hosting and database providers store the service and its data on our behalf, under contracts that only allow them to act on our instructions.
- Apple, if you choose Sign in with Apple, tells us your verified email address and, at your choice, your name.
- Organisers see their guests’ details, as described in section 6.
- Authorities and advisers where the law requires it, to protect someone’s safety, or to enforce our terms.
- A buyer of our business, if Tixy or Eventotron Ltd is sold or merged. We would tell you before your data was transferred.
5. International transfers
We store data in the United Kingdom and the European Economic Area wherever we can. Some providers, including Stripe and Cloudflare, operate globally. Where data leaves the UK we rely on the UK Government’s adequacy decisions or on the International Data Transfer Agreement and standard contractual clauses approved for the UK, and on the safeguards those providers commit to.
6. What organisers can see
The organiser of an event can see the name, email address, order details and check-in status of everyone who buys a ticket to it, so they can run the door and contact guests about the event. Organisers agree in our terms to use those details only for the event and in line with data protection law. If you have a concern about how an organiser has used your data, contact them first; you can also tell us at [email protected].
7. How long we keep it
| Data | Kept for |
|---|---|
| Organiser accounts and events | Until you ask us to close your account, plus 30 days |
| Orders, tickets, refunds and payout records | 6 years after the end of the financial year, as UK tax law requires |
| Unfinished orders that were never paid | Tickets are released after 15 minutes; the unpaid record is kept with other order records |
| Draft events created without signing in | Your browser forgets them after 30 days; unclaimed drafts are removed in periodic clean-ups |
| Sign-in links and sessions | Links expire in 15 minutes; sessions after 30 days |
| Server logs | Up to 90 days |
| Support emails | Up to 2 years after the matter is closed |
When a record is no longer needed we delete or anonymise it. Copies may persist in encrypted backups for up to 35 days after deletion.
8. Security
All traffic to Tixy is encrypted with TLS. Sign-in uses one-time links rather than passwords, and session tokens are stored hashed. Card details go straight to Stripe, which is certified to PCI DSS Level 1. Access to production data is limited to the people who need it to run the service. No system is perfectly secure; if we discover a breach that puts you at risk we will tell you and the ICO as the law requires.
9. Your rights
Under UK data protection law you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct data that is wrong (rectification);
- delete your data (erasure), subject to records we must keep by law;
- stop or limit how we use it (restriction and objection);
- send your data to you or another service in a machine-readable form (portability);
- withdraw consent, where consent is what we rely on, such as push notifications.
To exercise any of these, email [email protected] from the address on your account, or describe your order so we can find it. We answer within one month. There is no charge unless a request is clearly unfounded or excessive.
You can also complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to sort things out first.
10. Cookies
Tixy sets only the cookies it needs to sign you in and take payment. Our cookie policy lists each one.
11. Changes to this policy
We will update this page when our practices change and show the date at the top. If a change significantly affects how we use your data we will email organisers, or show a notice in the app, before it takes effect.