<Legal

Privacy Policy

Last updated: 8 July 2026

This policy explains what personal data we process when you use AlphaTicket — as a ticket buyer or as an event organizer — why we process it, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR).

1. Who is responsible for your data

The platform is operated by:

Operator: [Operator legal name]
Address: [Registered address]
Registration: [Company / trade licence ID (IČO)]

If you buy a ticket: the event organizer you buy from is the controller of your purchase data (they decide what event you bought into and handle your refund requests). We act as their processor, and we are an independent controller for running and securing the platform itself and for meeting our own legal obligations.

If you are an organizer: we are the controller of your account and workspace data.

2. What data we process

  • Ticket buyers: name, email address, phone number, the tickets you bought, order amount and payment status, ticket delivery status (whether your ticket email was sent), and check-in status (whether your QR code was scanned).
  • Organizers: email address, hashed password (managed by our authentication provider), workspace name and settings, team membership and roles, and the sales data of your events.
  • Technical data (all visitors): IP address and basic request metadata used for security, rate limiting and error logging. We do not build behavioural profiles and we run no advertising trackers.
  • Payment data: handled entirely by Stripe. We never see or store card numbers; we receive only payment status and fee amounts.

3. Why we process it (legal bases)

  • To perform the contract (Art. 6(1)(b) GDPR): processing your order, delivering your ticket by email, validating it at the door, providing organizers their workspace.
  • Legitimate interests (Art. 6(1)(f)): keeping the platform secure, preventing fraud and abuse, rate limiting, resolving payment disputes.
  • Legal obligations (Art. 6(1)(c)): keeping accounting and tax records of transactions.

We do not use your data for advertising and we do not sell it to anyone.

4. Who we share data with

  • The event organizer you buy from — they see the buyer details for their own events (name, email, phone, order, check-in status) so they can run the event and handle refunds.
  • Stripe (payment processing) — stripe.com/privacy.
  • Supabase (database and authentication hosting).
  • Resend (transactional email delivery — your ticket email).
  • Vercel (application hosting).
  • Authorities, where the law requires it.

These providers act as processors under data-processing agreements and may only use the data to provide their service to us.

5. International transfers

Some providers may process data outside the European Economic Area (typically in the United States). Where that happens, transfers are safeguarded by the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

6. How long we keep data

  • Orders and tickets: for the duration of the event and afterwards for as long as accounting and tax law requires transaction records to be kept (up to 10 years in the Czech Republic).
  • Organizer accounts: until you delete your account, then removed or anonymized except where retention is legally required.
  • Security and delivery logs: for a short period, typically weeks to a few months.

7. Your rights

Under the GDPR you can ask us to:

  • access the personal data we hold about you and get a copy;
  • correct inaccurate data;
  • delete data (where no legal retention duty applies);
  • restrict or object to processing based on legitimate interests;
  • port the data you gave us to another service in a machine-readable format.

To exercise any of these, email hello@alphaticket.app. We respond within one month. For data tied to a specific event, we may route your request to the organizer as controller, or handle it on their behalf.

You can also complain to a supervisory authority — in the Czech Republic, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz), or the authority of your home country.

8. Security

All traffic is encrypted in transit (HTTPS). Database access is restricted and role-based; buyer personal data in organizer reports is limited to roles that need it (owner, admin, finance). Payment credentials never touch our servers.

9. Children

The platform is not directed at children. Buying a ticket requires the legal capacity to enter a contract; events may carry their own age restrictions.

10. Cookies

We use only strictly necessary cookies — see the Cookie Policy.

11. Changes

We will update this policy when our processing changes and announce material changes on the site. The date at the top shows the current version.