This is a template. Have it reviewed by qualified legal counsel before launch.

Privacy Policy

Last updated: August 2026

This Privacy Policy explains how Let’s Go Ticket collects, uses, and protects your personal data when you use our event-ticketing and QR-entry platform, in accordance with the EU General Data Protection Regulation (GDPR) and applicable national law.

Who We Are / Data Controller

Let’s Go Ticket is the data controller for personal data processed in connection with your account and use of the platform. For data relating to a specific event, the organizer of that event may act as an independent or joint controller. You can reach our Data Protection contact at info@inveroi.com.

What Data We Collect

We collect: account data (name, email, password hash, date of birth for age-restricted events, and preferences); sign-in data (if you use Google, Apple, or Facebook to log in, we receive your name and email address from that provider); order data (events, tickets, purchase and refund history); rewards data (loyalty points and tier, account credit, referral activity, and offers you redeem); payment metadata (transaction identifiers, amounts, and card brand/last digits — full card numbers are handled solely by our payment processor); QR / entry data (ticket codes, scan timestamps, and check-in status at venues); content you post (such as photos you add to an event photo wall); and usage data (device, browser, IP address, consent records, and interaction logs used for security, rate-limiting, and analytics).

Information About Other People

Some features let you give us another person's details — for example the email address of a friend you invite to a group split payment or to join via your referral link, or an email you add to an event waitlist. Only provide someone else's email if you are entitled to, and expect them to be contacted about it. We use those details solely to send the relevant invitation or notification, and the person can unsubscribe or ask us to remove their data at any time.

Legal Bases

We rely on the following GDPR legal bases: performance of a contract (to deliver tickets and manage entry), legitimate interests (to secure and improve the Service and prevent fraud), legal obligations (accounting and tax records), and consent (for non-essential cookies and optional marketing, which you may withdraw at any time).

How We Use Your Data

We use personal data to create and manage your account, process purchases and issue QR tickets, validate entry at venues, provide customer support, send service-related communications, detect and prevent fraud or abuse, comply with legal obligations, and improve the reliability and performance of the platform.

Cookies, Analytics & Marketing

We use cookies and similar technologies grouped into necessary, functional, analytics, and marketing categories. Analytics (e.g. Google Analytics, with IP anonymisation) and marketing technologies (e.g. the Meta and TikTok pixels for campaign measurement) run only with your consent and never before you opt in. If you subscribe to our newsletter, we process your email to send you event news and offers; you can unsubscribe at any time. We record your consent choice and its timestamp so we can honour it. See our Cookie Policy for the full list and to change your choice.

Email communications

We send two kinds of email. Service (transactional) emailsare needed to deliver what you asked for — order confirmations and e-tickets, password resets, refund and split-payment notices, and reminders about a checkout you started but didn't finish. These are sent on the basis of our contract with you or our legitimate interest. Marketing emails— such as our newsletter, event highlights and weekly digest, new-event alerts for organizers you follow, promotional campaigns, and re-engagement ("we miss you") offers — are sent only where you have opted in, and every one includes a one-click unsubscribe. You can opt out of marketing at any time without affecting service emails.

Sharing Your Data & Processors

We share data only as necessary, with providers who act as our processors or as independent controllers under data-protection agreements:

  • Payments — Stripe: to take card payments and issue refunds (Stripe handles full card details as its own controller).
  • Event organizers: the organizer of an event you buy from receives the data needed to manage admission and their attendee list, as controller for their event.
  • Email delivery — Resend: to send the service and (where you opted in) marketing emails described above.
  • Sign-in providers — Google, Apple, Meta (Facebook): if you choose to log in with them, to authenticate you and share your basic profile (name, email).
  • Hosting & infrastructure — Vercel (hosting) and Neon (database): to run the platform and store your data securely.
  • Analytics & advertising — e.g. Google, Meta, TikTok: only where you consent to the relevant cookie category, for measurement.
  • Digital wallets — Apple & Google Wallet: if you add a ticket to a wallet, the ticket data needed to create the pass.

We may also disclose data where required by law. We do not sell your personal data.

Data Retention

We retain personal data only for as long as needed for the purposes described above, including to satisfy legal, accounting, and tax requirements. Order and invoice records are typically retained for the statutory period; account data is retained until you delete your account, after which residual copies are removed from active systems within a reasonable period.

Your GDPR Rights

Subject to applicable law, you have the right to access your data, rectify inaccurate data, request erasure, obtain a portable copy (portability), restrict or object to certain processing, and withdraw consent. You can export or delete most of your data yourself from Account → Settings. You also have the right to lodge a complaint with your national data-protection supervisory authority.

International Transfers

Where personal data is transferred outside the European Economic Area — for example to a processor operating globally — we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision to ensure your data remains protected.

Contact / DPO

For any privacy request or to contact our Data Protection Officer, email info@inveroi.com. We will respond within the timeframes required by the GDPR.