TicketTuck

Subprocessors

Last updated: October 10, 2026

TicketTuck is in beta. We may update this page as we finalize it; we’ll tell you about material changes by email or in the app.

TicketTuck uses the service providers below to run the Service. We give at least 30 days’ notice before adding or replacing a subprocessor, by updating this page and emailing organizations’ admins. If your organization reasonably objects to a change on data-protection grounds and we can’t resolve it together, you may end the affected service and get a pro-rata refund of prepaid fees. Questions about this list: privacy@tickettuck.com.

TicketTuck’s subprocessors

These providers process personal data on TicketTuck’s behalf to provide the Service.

Subprocessor Purpose Personal data involved Location
Cloudflare, Inc. Hosting the app, organizations’ pages and the marketing site. Database and image storage. Bot check (Turnstile). Rate limiting. Security certificates and custom web addresses. Server logs. All Service data: organizations’ pages and settings, staff accounts, buyer orders and answers, check-ins, the activity log, uploaded images, IP addresses, browser signals for the bot check, and short-lived server logs United States company. Requests are handled by Cloudflare’s global network, in the data center nearest the visitor.
Resend Sending email: receipts, refund and cancellation notices, “payment not completed” notices, invitations, email confirmations, password resets, plan receipts and account security notices Recipient name and email, and what the message contains (event, items, amounts, order number, card brand and last four digits, ticket codes, or a sign-in link) United States
NMI Payment gateway for TicketTuck’s own plan billing, including card storage in its Customer Vault. (For organizations’ payments, see the next section.) The organization’s billing contact, and the card details typed into NMI’s hosted fields. TicketTuck never receives the full card number. United States
Paysafe Card processing for TicketTuck’s own plan billing Billing contact and transaction details, received from NMI United States
GitHub, Inc. Source-code hosting and automated build checks None. Code and fictional demo data only; customer data is never placed in the code repository. United States

Payment providers under each organization’s own agreement

Card payments on an organization’s pages are processed under that organization’s own merchant agreement. TicketTuck sends transaction details to the gateway using the organization’s credentials, on the organization’s instructions. These providers process the data as the organization’s own payment providers, so they aren’t TicketTuck’s subprocessors for this purpose. We list them here for transparency.

Provider Role Data involved Location
NMI Payment gateway for organizations’ card payments (hosted card fields, plus the transaction service) Card number, expiry date and security code, typed by the buyer directly into NMI’s fields. Sent by TicketTuck: amount, order number and description, buyer name, email, phone, billing address, IP address, and the organization’s accounting references (department, GL code, fund, designation). United States
Paysafe Processor and acquirer (with its sponsor bank) for organizations that use Paysafe. Also receives organizations’ merchant applications from TicketTuck. Transaction details from NMI. Application details: business information, the authorized signer’s contact details, expected sales. United States
Another processor If an organization uses another processor we support, or brings its own merchant account Transaction details from NMI As set out in the organization’s merchant agreement

Not subprocessors