TicketTuck

Security

Last updated: October 10, 2026

How to tell us about a security problem, and how TicketTuck protects the people who buy tickets and give through our pages.

Report a vulnerability

If you think you’ve found a security issue in TicketTuck, please tell us privately first.

Email security@tickettuck.com

Helpful things to include:

Please don’t put real card numbers or anyone else’s personal details in your report. We’ll confirm we’ve received it within 3 business days, keep you updated while we fix it, and let you know when it’s resolved. We ask that you give us 90 days to fix an issue before you talk about it publicly.

What’s in scope

Out of scope

Ground rules

Safe harbor

If you make a good-faith effort to follow this policy while researching TicketTuck, we will consider your research authorized. We will not pursue or support legal action against you for it, including under anti-hacking or anti-circumvention laws, and we will work with you to understand and fix the issue quickly. If a third party brings legal action against you for research done under this policy, we will make it known that your activity was authorized by us.

This safe harbor covers only TicketTuck’s own systems listed above. It doesn’t cover services run by others, and it can’t authorize access to an organization’s or a buyer’s data. If you’re unsure whether something is allowed, ask us at security@tickettuck.com before you go further.

How we protect card data

Contact

Questions about security, or a customer security review? Email security@tickettuck.com. Our security.txt file lists the same contact.