TicketTuck

Privacy Policy

Last updated: October 10, 2026 · Version: 2026-10-10

TicketTuck is in beta. We may update this policy as we finalize it; we’ll tell you about material changes by email or in the app.

The short version

1. Who we are

We’re TicketTuck (“TicketTuck”, “we”, “us”). This policy covers three places:

2. Our two roles

When TicketTuck decides how data is used (we are the “controller” or “business”), this policy applies. That covers:

When we handle data for an organization (we are its “processor” or “service provider”), the organization is in charge. That covers:

We follow the organization’s instructions under our contract with it (our Data Processing Addendum). We don’t use this data for our own purposes, except as that contract allows, for example to keep the Service secure. The organization’s privacy policy explains how it uses your information.

3. What we collect

3.1 Visitors to tickettuck.com

3.2 Organization staff (Studio and event-day app)

3.3 Organizations applying for payments and paying for a plan

3.4 Buyers, donors, registrants and attendees (on behalf of the organization)

When you use an organization’s page, we collect the following for that organization:

Card details. When you pay by card, you type your card number, expiry date and security code into fields hosted by NMI, the payment gateway. Those fields sit inside the page but are run by NMI, so your card details go directly to NMI. NMI gives our system a one-time token that we use to complete the charge through the organization’s own merchant account. Neither TicketTuck nor the organization receives or stores your card number.

3.5 Information about minors

Some organizations run events for minors, such as camps, youth programs and school events. In those cases, a parent, guardian or the organization usually enters the minor’s name and any details the organization asks for. See Section 10.

4. How we use information

Purpose Whose data Legal basis (only where EU/UK-style law applies; see Section 13)
Run organizations’ pages, checkout, tickets and receipts Buyers (for the organization) Performance of the organization’s contract with the buyer; we act on the organization’s instructions
Process payments through the organization’s own merchant account, and confirm uncertain payments Buyers (for the organization) Same as above
Send receipts, refund and cancellation notices, and “your payment didn’t go through” emails for the organization Buyers (for the organization) Same as above
Run check-in and door sales Buyers and attendees (for the organization) Same as above
Provide staff accounts, roles, two-step sign-in and invitations Staff Contract; legitimate interests in security
Keep the Service secure: prevent fraud, card testing and account takeover, and keep the activity log Everyone Legitimate interests; legal obligations
Respond to inquiries and support requests Visitors, staff Legitimate interests; steps before a contract
Help organizations apply for a merchant account Applicant contacts Contract and steps before a contract
Bill for plans Billing contacts Contract
Send TicketTuck news and tips Staff and visitors who opted in Consent
Improve the Service with aggregated statistics that don’t identify anyone Everyone Legitimate interests
Meet legal, tax and accounting obligations, and respond to lawful requests As needed Legal obligation

We don’t sell personal information. We don’t “share” it for cross-context behavioral advertising, as California law defines that term. We don’t use it for automated decisions with legal or similarly significant effects. We don’t use buyer data to train AI models.

5. How information is shared

6. How long we keep information

Information How long we keep it
Orders, payments, refunds and check-ins (organizations’ financial records) While the organization’s account is open, and 7 years after the transaction. An organization can remove a buyer’s name and contact details sooner; the amounts stay in its financial records.
Buyer IP addresses on orders 18 months after the order, then deleted automatically. This covers the card networks’ longest dispute window.
Answers to organizations’ questions, and attendee names 24 months after the event (or after the order, for pages without a date), then de-identified automatically
Organizations’ mailing-list opt-ins Until the buyer withdraws consent or the organization deletes the record
Staff accounts While active. When you ask us to delete your account, we do so within 90 days, and past activity-log entries then show “Deleted user” instead of your name.
Sessions, invitations, reset links and sign-in tickets Until they expire. Expired records are cleared automatically within a day.
Activity log 24 months (payment-security logs must be kept for at least 12). When an organization closes, its activity log is kept for 12 months after closing, then deleted automatically.
TicketTuck’s invoices for an organization’s plan As long as tax and accounting law requires (generally 7 years), including after the organization closes
Website inquiries (“Get started”) 24 months after the last contact, unless the person becomes a customer
Payment applications For the life of the merchant relationship, plus 3 years. Declined or abandoned applications: 12 months.
TicketTuck news opt-ins Until you unsubscribe. After that we keep only your email address, so we don’t email you again.
Pages, images and brand settings While the organization’s account is open. Deleted after it closes and the export window ends (see the Terms, Section 12.4).
Server logs Up to 7 days. These logs are designed to leave out card data, tokens, keys and buyer contact details.
Database backups (point-in-time recovery) Rolling 30 days. Deleted data leaves backups within 30 days.

We may keep information longer when the law requires it, for an open dispute or chargeback, or to protect against fraud.

7. How we protect information

Our security measures include:

Card data never reaches our servers. No system is perfectly secure. If a breach affects your information, we’ll notify the affected organization, or you, as the law requires. More on our Security page.

8. Your rights and choices

If you are a buyer, donor or attendee, contact the organization that ran the page. It controls your information and can access, correct, export or delete it. If you contact us instead, we’ll forward your request to the organization within 5 business days and help it respond.

For information we control (Sections 3.1 to 3.3), you can ask us to:

Email from organizations. If you asked an organization for news, use the unsubscribe link in its emails, or contact the organization. Receipts and refund notices are transactional, so they’re sent even if you didn’t opt in to news.

How to make a request: email privacy@tickettuck.com. We’ll verify your request, usually by confirming you control the email address on file. You can use an authorized agent where the law allows. If we deny your request, you can appeal by replying to our decision, and we’ll answer within the time the law requires (usually 45 to 60 days). We won’t treat you differently for using your rights.

State privacy laws. Residents of California and many other states (such as Colorado, Connecticut, Delaware, Maryland, Minnesota, New Jersey, Oregon, Texas and Virginia) have rights under their state’s privacy law, including those listed above. We offer these rights to everyone, wherever they live. We don’t sell personal information or share it for targeted advertising. We treat a Global Privacy Control signal as a request to opt out of sale and sharing; because we do neither, there’s nothing more you need to do. We don’t use sensitive personal information to infer characteristics about you.

9. Cookies and similar technology

We use only what the Service needs to work and to stay secure. We use no advertising or analytics cookies.

Name or type Where What it does How long
__Host-ft5_session (cookie) app.tickettuck.com Keeps staff signed in. HttpOnly and Secure, so scripts can never read it. 14 days; 1 day for TicketTuck administrators; deleted when you sign out
Cloudflare Turnstile Checkout, sign-up and the “Get started” form An invisible bot check. Cloudflare collects signals such as IP address and browser characteristics to tell people from bots, and says it doesn’t use them for advertising or to profile visitors. It may set strictly necessary security cookies. Set by Cloudflare
Cloudflare security cookies (for example, __cf_bm) All sites, if Cloudflare’s bot protection sets them Protect the site from automated attacks Short-lived (set by Cloudflare)
Browser session storage Organizations’ pages Remembers the tickets you picked and the details you typed during checkout, so a refresh doesn’t lose them. It stays on your device and is cleared when you close the tab. Until the tab closes
Browser storage (local storage and IndexedDB) Event-day app (staff phones) Keeps the event’s guest list and unsent scans on the phone, so check-in works without a signal. Also keeps a volunteer’s door link and a few display settings. Until cleared from the device

Because these are all strictly necessary, we don’t show a cookie banner.

10. Children and events for minors

The Service isn’t directed to children, and we don’t knowingly collect personal information directly from children under 13. Staff users must be adults. Buyers must be at least 18, or have a parent or guardian complete the purchase.

When an organization runs an event for minors, the minor’s information is usually entered by a parent or guardian, or by the organization. The organization is responsible for getting any consent it needs and for collecting only what the event requires. For a school or college, information may also be covered by the school’s own student-privacy obligations, such as FERPA; we handle it only as the school instructs, under our agreement with it. If you believe a child under 13 gave us information directly, contact privacy@tickettuck.com and we’ll work with the organization to delete it.

Organizations’ pages may link to the organization’s own website, policies and other sites. Pages may also show images hosted elsewhere, such as Unsplash. Those sites have their own privacy practices.

12. Where information is processed

We’re based in the United States, and our service providers are U.S. companies. Cloudflare’s network serves pages from data centers around the world, so a request may be handled in the data center nearest the visitor.

13. Visitors from outside the United States

The Service is designed for U.S. organizations. If you’re outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those where you live. If EU, UK or similar law applies to your information, the legal bases are listed in Section 4, and you may also have the rights to object, to restrict processing and to complain to your data protection authority.

14. Changes to this policy

When we make material changes, we’ll post the new version here with a new “Last updated” date, and tell organizations’ admins by email or in the app. Earlier versions are available on request.

15. Contact

TicketTuck. Privacy questions and requests: privacy@tickettuck.com. Security issues: security@tickettuck.com. Contact us at support@tickettuck.com for our mailing address.