Privacy Policy
Last updated: October 10, 2026 · Version: 2026-10-10
TicketTuck is in beta. We may update this policy as we finalize it; we’ll tell you about material changes by email or in the app.
The short version
- TicketTuck builds and hosts event, ticket, registration, fee and donation pages for organizations such as colleges, schools, churches, nonprofits and venues.
- If you bought a ticket, registered or donated on an organization’s page, that organization decides how your information is used, and TicketTuck handles it for them. Start with the organization’s own privacy policy, and contact the organization first about your information. If you contact us, we’ll pass your request on and help.
- We never see your full card number. Card details go straight into secure fields run by the payment gateway, NMI. We receive only a one-time token, the card brand and the last four digits.
- We don’t sell personal information. We don’t use advertising or tracking cookies, and we don’t email buyers for marketing. Only the organization can email you news, and only if you ticked the box to ask for it.
- Questions: privacy@tickettuck.com.
1. Who we are
We’re TicketTuck (“TicketTuck”, “we”, “us”). This policy covers three places:
- tickettuck.com, our marketing site;
- app.tickettuck.com, where organization staff sign up and sign in to the Studio and the event-day app;
- organizations’ pages that we host, at
<name>.tickettuck.comor at an organization’s own web address (for example,tickets.example.edu).
2. Our two roles
When TicketTuck decides how data is used (we are the “controller” or “business”), this policy applies. That covers:
- visitors to tickettuck.com and people who contact us;
- organization staff, as TicketTuck account holders;
- billing contacts and the people named on a payment application;
- security records about how the Service is used.
When we handle data for an organization (we are its “processor” or “service provider”), the organization is in charge. That covers:
- buyer, donor, registrant and attendee information collected on that organization’s pages;
- the organization’s staff records in its Studio, such as its team list and activity log.
We follow the organization’s instructions under our contract with it (our Data Processing Addendum). We don’t use this data for our own purposes, except as that contract allows, for example to keep the Service secure. The organization’s privacy policy explains how it uses your information.
3. What we collect
3.1 Visitors to tickettuck.com
- The “Get started” form: your name, email, organization name and type, your message, and whether you ticked “Send me TicketTuck news and tips.”
- Technical data: IP address, browser type and the security signals used by Cloudflare’s bot check (Turnstile). See Section 9.
- We don’t use analytics or advertising tools on tickettuck.com. Some pictures on the site are loaded from Unsplash, an image service, so your browser contacts Unsplash to fetch them.
3.2 Organization staff (Studio and event-day app)
- Signing up: your name, work email, password, your organization’s name, type and web address, and a record that you accepted our Terms of Service and this policy (which version, and when). We email you a link to confirm your address.
- Account: name, email, password (stored only as a salted, one-way hash), your role in each organization, and when the account was created and last used.
- Two-step sign-in, if you turn it on: an authenticator secret, which we store encrypted, and one-time recovery codes, which we store only as hashes.
- Sign-in and security records: session records (a hash of the session cookie, IP address, browser description and expiry), failed sign-in counts (keyed by a hash of your email, never the email itself), and invitation and password-reset links (stored as hashes).
- Activity log: what you did in the Studio, when, and from which IP address. Examples: signing in, publishing a page, changing payment settings, inviting a colleague, downloading a buyer export, issuing a refund, selling at the door.
- TicketTuck news: whether you asked for TicketTuck news and tips, and when. It’s always off unless you turn it on, and you can turn it off at any time under Your account.
- Your messages to us, such as support emails.
3.3 Organizations applying for payments and paying for a plan
- Payment application: the organization’s legal and trade names, type, EIN, year founded, website, phone and address; the authorized signer’s name, title, email and phone; and what the organization sells and its expected card sales. We never ask for Social Security numbers, dates of birth or bank account numbers, and the form rejects text that looks like them. Those details go directly on the payment processor’s own secure application.
- Plan billing: the organization’s billing contact, and the card used to pay for its plan. The card is captured and stored by our payment gateway’s secure vault (NMI). We keep only the card brand, the last four digits and the expiry date.
3.4 Buyers, donors, registrants and attendees (on behalf of the organization)
When you use an organization’s page, we collect the following for that organization:
- Contact details: first and last name and email. Phone is optional.
- Billing details: billing ZIP code, and a full billing address only if the organization requires it for card payments.
- Your order: the event, items, quantities, prices, discounts and promo codes, any donation amount and fund designation, and the order number.
- Answers to the organization’s questions, such as meal choice, T-shirt size or other details it asks for. The organization chooses these questions.
- Attendee names, if the organization asks for a name on each ticket, plus any answers it asks for about each attendee.
- Payment results: card brand, last four digits, the gateway’s transaction ID and approval code, and address and security-code match results. We never receive your full card number or security code.
- “Send me news” from the organization: whether you ticked this box. It always starts unticked. The list belongs to the organization, and we never use it for TicketTuck’s own mail.
- Event-day records: when each ticket was scanned at the door, and by which staff member or door; refunds and cancelled tickets; and door sales (paid in cash, by card or as a complimentary ticket).
- Technical data: your IP address, which we store with your order and share with the payment gateway to help prevent fraud, and Turnstile bot-check signals.
Card details. When you pay by card, you type your card number, expiry date and security code into fields hosted by NMI, the payment gateway. Those fields sit inside the page but are run by NMI, so your card details go directly to NMI. NMI gives our system a one-time token that we use to complete the charge through the organization’s own merchant account. Neither TicketTuck nor the organization receives or stores your card number.
3.5 Information about minors
Some organizations run events for minors, such as camps, youth programs and school events. In those cases, a parent, guardian or the organization usually enters the minor’s name and any details the organization asks for. See Section 10.
4. How we use information
| Purpose | Whose data | Legal basis (only where EU/UK-style law applies; see Section 13) |
|---|---|---|
| Run organizations’ pages, checkout, tickets and receipts | Buyers (for the organization) | Performance of the organization’s contract with the buyer; we act on the organization’s instructions |
| Process payments through the organization’s own merchant account, and confirm uncertain payments | Buyers (for the organization) | Same as above |
| Send receipts, refund and cancellation notices, and “your payment didn’t go through” emails for the organization | Buyers (for the organization) | Same as above |
| Run check-in and door sales | Buyers and attendees (for the organization) | Same as above |
| Provide staff accounts, roles, two-step sign-in and invitations | Staff | Contract; legitimate interests in security |
| Keep the Service secure: prevent fraud, card testing and account takeover, and keep the activity log | Everyone | Legitimate interests; legal obligations |
| Respond to inquiries and support requests | Visitors, staff | Legitimate interests; steps before a contract |
| Help organizations apply for a merchant account | Applicant contacts | Contract and steps before a contract |
| Bill for plans | Billing contacts | Contract |
| Send TicketTuck news and tips | Staff and visitors who opted in | Consent |
| Improve the Service with aggregated statistics that don’t identify anyone | Everyone | Legitimate interests |
| Meet legal, tax and accounting obligations, and respond to lawful requests | As needed | Legal obligation |
We don’t sell personal information. We don’t “share” it for cross-context behavioral advertising, as California law defines that term. We don’t use it for automated decisions with legal or similarly significant effects. We don’t use buyer data to train AI models.
5. How information is shared
With the organization running the event. Your buyer information is the organization’s information. Its staff can see orders, attendee lists and answers, download exports, and see the list of people who opted in to its news. Downloads of buyer data are recorded in the organization’s activity log.
With the payment gateway and the organization’s processor. To complete a card payment, we send NMI:
- the amount, order number and description;
- your name, email, phone, billing address and IP address;
- accounting references the organization sets, such as department, GL code, fund and donation designation.
NMI and the organization’s processor (for example, Paysafe) handle the payment under the organization’s own merchant agreement. For merchant applications, we send the application details to the processor.
With our service providers (subprocessors), who host and run the Service for us under contracts that protect the data: Cloudflare (hosting, database, file storage, bot check), Resend (email delivery) and NMI. See our subprocessor list.
TicketTuck staff. A small number of TicketTuck administrators can access organizations’ accounts, to support organizations and keep the Service running. Their access requires two-step sign-in, and their sign-ins last one day. Their sensitive actions are recorded in the organization’s activity log, including exports, payment-setting changes, refunds, and viewing the organization’s orders or buyer details.
For legal reasons. We share information to comply with the law or valid legal process, to protect the rights, safety and property of people and of the Service, and to investigate fraud. Where the law allows, we’ll tell the affected organization first.
In a business transfer, such as a merger or acquisition, information may transfer under this policy. We’ll tell you as required.
With your consent or at your direction.
6. How long we keep information
| Information | How long we keep it |
|---|---|
| Orders, payments, refunds and check-ins (organizations’ financial records) | While the organization’s account is open, and 7 years after the transaction. An organization can remove a buyer’s name and contact details sooner; the amounts stay in its financial records. |
| Buyer IP addresses on orders | 18 months after the order, then deleted automatically. This covers the card networks’ longest dispute window. |
| Answers to organizations’ questions, and attendee names | 24 months after the event (or after the order, for pages without a date), then de-identified automatically |
| Organizations’ mailing-list opt-ins | Until the buyer withdraws consent or the organization deletes the record |
| Staff accounts | While active. When you ask us to delete your account, we do so within 90 days, and past activity-log entries then show “Deleted user” instead of your name. |
| Sessions, invitations, reset links and sign-in tickets | Until they expire. Expired records are cleared automatically within a day. |
| Activity log | 24 months (payment-security logs must be kept for at least 12). When an organization closes, its activity log is kept for 12 months after closing, then deleted automatically. |
| TicketTuck’s invoices for an organization’s plan | As long as tax and accounting law requires (generally 7 years), including after the organization closes |
| Website inquiries (“Get started”) | 24 months after the last contact, unless the person becomes a customer |
| Payment applications | For the life of the merchant relationship, plus 3 years. Declined or abandoned applications: 12 months. |
| TicketTuck news opt-ins | Until you unsubscribe. After that we keep only your email address, so we don’t email you again. |
| Pages, images and brand settings | While the organization’s account is open. Deleted after it closes and the export window ends (see the Terms, Section 12.4). |
| Server logs | Up to 7 days. These logs are designed to leave out card data, tokens, keys and buyer contact details. |
| Database backups (point-in-time recovery) | Rolling 30 days. Deleted data leaves backups within 30 days. |
We may keep information longer when the law requires it, for an open dispute or chargeback, or to protect against fraud.
7. How we protect information
Our security measures include:
- encryption in transit (HTTPS everywhere, with HSTS);
- encryption at rest by our hosting provider;
- separate application-level encryption of payment gateway keys and two-step secrets;
- hashed passwords, sessions and links;
- optional two-step sign-in, required for TicketTuck administrators;
- account lockout and rate limits;
- bot checks on checkout and forms;
- strict browser security policies that limit which scripts can run on payment pages;
- role-based access checked on every request;
- strict separation between organizations’ data;
- an activity log of sensitive actions.
Card data never reaches our servers. No system is perfectly secure. If a breach affects your information, we’ll notify the affected organization, or you, as the law requires. More on our Security page.
8. Your rights and choices
If you are a buyer, donor or attendee, contact the organization that ran the page. It controls your information and can access, correct, export or delete it. If you contact us instead, we’ll forward your request to the organization within 5 business days and help it respond.
For information we control (Sections 3.1 to 3.3), you can ask us to:
- tell you what personal information we have about you, and give you a copy;
- correct it;
- delete it, subject to legal and security exceptions;
- stop sending you TicketTuck news. Use the unsubscribe link in any newsletter, turn it off under Your account, or email us.
Email from organizations. If you asked an organization for news, use the unsubscribe link in its emails, or contact the organization. Receipts and refund notices are transactional, so they’re sent even if you didn’t opt in to news.
How to make a request: email privacy@tickettuck.com. We’ll verify your request, usually by confirming you control the email address on file. You can use an authorized agent where the law allows. If we deny your request, you can appeal by replying to our decision, and we’ll answer within the time the law requires (usually 45 to 60 days). We won’t treat you differently for using your rights.
State privacy laws. Residents of California and many other states (such as Colorado, Connecticut, Delaware, Maryland, Minnesota, New Jersey, Oregon, Texas and Virginia) have rights under their state’s privacy law, including those listed above. We offer these rights to everyone, wherever they live. We don’t sell personal information or share it for targeted advertising. We treat a Global Privacy Control signal as a request to opt out of sale and sharing; because we do neither, there’s nothing more you need to do. We don’t use sensitive personal information to infer characteristics about you.
9. Cookies and similar technology
We use only what the Service needs to work and to stay secure. We use no advertising or analytics cookies.
| Name or type | Where | What it does | How long |
|---|---|---|---|
__Host-ft5_session (cookie) |
app.tickettuck.com | Keeps staff signed in. HttpOnly and Secure, so scripts can never read it. | 14 days; 1 day for TicketTuck administrators; deleted when you sign out |
| Cloudflare Turnstile | Checkout, sign-up and the “Get started” form | An invisible bot check. Cloudflare collects signals such as IP address and browser characteristics to tell people from bots, and says it doesn’t use them for advertising or to profile visitors. It may set strictly necessary security cookies. | Set by Cloudflare |
Cloudflare security cookies (for example, __cf_bm) |
All sites, if Cloudflare’s bot protection sets them | Protect the site from automated attacks | Short-lived (set by Cloudflare) |
| Browser session storage | Organizations’ pages | Remembers the tickets you picked and the details you typed during checkout, so a refresh doesn’t lose them. It stays on your device and is cleared when you close the tab. | Until the tab closes |
| Browser storage (local storage and IndexedDB) | Event-day app (staff phones) | Keeps the event’s guest list and unsent scans on the phone, so check-in works without a signal. Also keeps a volunteer’s door link and a few display settings. | Until cleared from the device |
Because these are all strictly necessary, we don’t show a cookie banner.
10. Children and events for minors
The Service isn’t directed to children, and we don’t knowingly collect personal information directly from children under 13. Staff users must be adults. Buyers must be at least 18, or have a parent or guardian complete the purchase.
When an organization runs an event for minors, the minor’s information is usually entered by a parent or guardian, or by the organization. The organization is responsible for getting any consent it needs and for collecting only what the event requires. For a school or college, information may also be covered by the school’s own student-privacy obligations, such as FERPA; we handle it only as the school instructs, under our agreement with it. If you believe a child under 13 gave us information directly, contact privacy@tickettuck.com and we’ll work with the organization to delete it.
11. Links and third-party content
Organizations’ pages may link to the organization’s own website, policies and other sites. Pages may also show images hosted elsewhere, such as Unsplash. Those sites have their own privacy practices.
12. Where information is processed
We’re based in the United States, and our service providers are U.S. companies. Cloudflare’s network serves pages from data centers around the world, so a request may be handled in the data center nearest the visitor.
13. Visitors from outside the United States
The Service is designed for U.S. organizations. If you’re outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those where you live. If EU, UK or similar law applies to your information, the legal bases are listed in Section 4, and you may also have the rights to object, to restrict processing and to complain to your data protection authority.
14. Changes to this policy
When we make material changes, we’ll post the new version here with a new “Last updated” date, and tell organizations’ admins by email or in the app. Earlier versions are available on request.
15. Contact
TicketTuck. Privacy questions and requests: privacy@tickettuck.com. Security issues: security@tickettuck.com. Contact us at support@tickettuck.com for our mailing address.