Privacy Policy
1. Controller
The controller responsible for data processing on this platform within the meaning of the General Data Protection Regulation (GDPR) is:
[COMPANY NAME OR FULL NAME OF THE OPERATOR]
[STREET AND NUMBER]
[POSTAL CODE AND CITY], [COUNTRY]
Email: [PRIVACY CONTACT EMAIL]
[IF A DATA PROTECTION OFFICER HAS BEEN APPOINTED: You can reach our data protection officer at: NAME, EMAIL. OTHERWISE REMOVE THIS SECTION.]
2. Overview
Ticketjumper is a platform through which organizers manage events and sell tickets. We process personal data only to the extent necessary to provide the platform, process ticket orders and comply with statutory obligations. No data is sold to third parties for advertising purposes. Analytics or marketing trackers are only used with your consent (Meta pixel on event pages, see section 9).
3. Allocation of roles: platform and organizers
The following applies when you purchase tickets:
- For the operation of the platform (e.g. user accounts, server logs, platform security), we ourselves are the controller within the meaning of Art. 4 No. 7 GDPR.
- For the processing of order and attendee data of a specific event, the respective organizer is the controller. We process this data on the organizer's behalf as a processor pursuant to Art. 28 GDPR. The organizer has access to the order and attendee data of their events (e.g. name, email address, booked tickets, answers to questions asked by the organizer, check-in status) and uses it under their own responsibility, for instance to stage the event and control admission.
- The organizer's own privacy policy applies to any data processing carried out by the organizer outside the platform.
4. Hosting and server log files
The platform is hosted by [HOSTING PROVIDER, LOCATION/COUNTRY]. When you access the platform, the web server automatically processes data transmitted by your browser (server log files): IP address, date and time of the request, requested URL, referrer URL, browser and operating system used, and the HTTP status code.
This data is technically required to deliver the platform, to ensure its stability and security and to defend against attacks (e.g. automated access attempts). The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure and stable operation). Log data is retained for [RETENTION PERIOD, E.G. 14 DAYS] and subsequently deleted unless it is needed to investigate specific security incidents.
5. Cookies and local storage
We use technically necessary cookies only. These are required for the operation of the platform and do not require consent (Section 25 (2) No. 2 of the German TDDDG):
- access_token / refresh_token: session cookies for signing in to your user account (HttpOnly). Storage period: up to 7 days or until you sign out.
- i18n_locale: stores the selected language. Storage period: up to 1 year.
- color scheme preference: stores your light/dark mode setting.
In addition, marketing cookies are used only with your consent: the tj_consent cookie stores your decision regarding the Meta pixel (storage period 180 days, see section 9); once consent is granted, Meta sets the _fbp and _fbc cookies. On event pages whose organizer uses a Meta pixel, we display a cookie notice for this purpose.
The legal basis for technically necessary cookies is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (f) GDPR respectively; for marketing cookies it is your consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG).
6. Registration and user account
When you register, we process the data you provide (name, email address, password stored in encrypted form as a hash) to set up and manage your user account. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). We send a verification email to confirm your email address. The account exists until you delete it or have it deleted; thereafter, the account data is deleted unless statutory retention obligations prevent this.
7. Ticket purchase and order processing
To process ticket orders, we process the data provided during checkout: first and last name, email address, selected tickets, answers to questions asked by the organizer (if any), and order and payment status. The processing serves to handle the ticket purchase between you and the organizer, to deliver the tickets by email (including the QR code for admission) and to enable admission control by the organizer.
The legal bases are Art. 6 (1) (b) GDPR (performance of the ticket contract with the organizer and of the platform usage relationship) and Art. 6 (1) (c) GDPR (statutory retention obligations). The order data is transmitted to the respective organizer (see Section 3).
8. Payment processing via Stripe
Payments are processed by the payment service provider Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland ("Stripe"). Payments flow through the Stripe accounts of the respective organizers (Stripe Connect). When you pay, the payment data you enter (e.g. card details) is collected and processed directly by Stripe; we never have access to complete payment card data. We only receive information from Stripe about the payment status and technical references for allocating the payment.
Stripe also processes data in the USA. Stripe is certified under the EU-US Data Privacy Framework; in addition, EU Commission standard contractual clauses are used. Further information: Stripe Privacy Policy.
The legal basis is Art. 6 (1) (b) GDPR. Stripe may act as an independent controller in order to comply with statutory obligations (e.g. anti-money-laundering).
9. Meta pixel and Conversions API (organizer marketing)
Organizers may use the Meta pixel of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland ("Meta") on their event pages to measure the performance of their Facebook and Instagram ads and to optimize ads for ticket sales.
The pixel is loaded only after your consent via the cookie notice (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG). Without consent, no data whatsoever is transmitted to Meta — neither in the browser nor server-side. With consent, we and Meta process: event data on page views, checkout starts and ticket purchases (including order value and currency), online identifiers (Meta cookies _fbp/_fbc), IP address and browser information, and — exclusively in hashed form — the buyer's email address and name. Purchase events are additionally transmitted server-side via the Meta Conversions API; duplicate events are merged via an event ID.
Your consent applies platform-wide to event pages with an active pixel and is stored for 180 days. You can withdraw it at any time with effect for the future via "Cookie settings" in the footer of the event pages.
For the collection and transmission of event data to Meta, we and Meta are joint controllers (Art. 26 GDPR) on the basis of Meta's "Controller Addendum"; subsequent processing by Meta takes place under Meta's own responsibility. The pixel is used for the benefit of the respective organizer, who receives the measurement data in aggregated form for their ad campaigns. Meta also processes data in the USA; Meta is certified under the EU-US Data Privacy Framework. Further information: Meta Privacy Policy.
Note: organizers who run ads via the platform are disclosed as the beneficiary/payer of the ad in the public Meta Ad Library for one year, as required by the Digital Services Act.
10. Email communication
We send transactional emails that are necessary for using the platform: order and payment confirmations, tickets, information from the organizer regarding your order (e.g. in the event of cancellation or rescheduling), verification and password emails, and invitations to organizations. Emails are sent via [EMAIL DELIVERY PROVIDER]. The legal basis is Art. 6 (1) (b) GDPR.
We only send promotional emails with your consent (Art. 6 (1) (a) GDPR); you may revoke consent at any time via the unsubscribe link or by informal notice to us. Unsubscribes are stored in a suppression list so that no further messages are sent to you (Art. 6 (1) (c) and (f) GDPR).
11. On-site check-in
At admission, the organizer scans the QR code of your ticket. In doing so, the ticket status and check-in time are processed in order to prevent multiple use. This processing is carried out on behalf of or under the responsibility of the organizer (see Section 3).
12. Recipients and processors
We only share personal data where this is necessary for the performance of the contract, where a statutory obligation exists, or where you have consented. Recipients include in particular:
- the respective organizer of your event (order and attendee data),
- Stripe (payment processing, see Section 8),
- [HOSTING PROVIDER] (hosting/infrastructure, data processing on our behalf),
- [EMAIL DELIVERY PROVIDER] (email delivery, data processing on our behalf),
- [STORAGE/CDN PROVIDER, IF USED] (storage of images, e.g. event and logo graphics).
Contracts pursuant to Art. 28 GDPR are in place with our processors. Data is only transferred to third countries where the requirements of Art. 44 et seq. GDPR are met (in particular adequacy decisions such as the EU-US Data Privacy Framework, or standard contractual clauses).
13. Storage periods
We store personal data only for as long as necessary for the purposes stated:
- User account: until the account is deleted.
- Order and invoice data: in accordance with retention periods under German commercial and tax law, up to 10 years (Section 257 of the German Commercial Code, Section 147 of the German Fiscal Code).
- Server log files: see Section 4.
- Email suppression list: for as long as necessary to permanently respect your unsubscribe request.
14. Your rights
You have the following rights vis-à-vis the respective controller with regard to your personal data:
- right of access (Art. 15 GDPR),
- right to rectification (Art. 16 GDPR),
- right to erasure (Art. 17 GDPR),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR),
- right to withdraw consent with effect for the future (Art. 7 (3) GDPR).
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6 (1) (f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation.
An informal message to [PRIVACY CONTACT EMAIL] is sufficient to exercise your rights. If your request concerns the data of a specific event, we may forward your request to the organizer responsible. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence or the place of the alleged infringement.
15. Data security
The platform is accessible via TLS encryption. Passwords are stored exclusively as cryptographic hashes. Access to personal data is restricted to what is necessary (role and permission model).
16. Obligation to provide data
Providing the data marked as mandatory during checkout is required to conclude the ticket purchase; without this data, the order cannot be processed. Apart from that, you are not obliged to provide data.
17. Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place on the platform. Note: the payment service provider Stripe may carry out its own automated checks for fraud prevention (see Section 8).
18. Mobile apps (iOS/Android)
We also offer the platform as a mobile app. In addition to the data described above, we process the following:
- Device permissions: The app accesses your camera (scanning ticket QR codes and taking photos/videos for the event gallery), microphone (recording voice messages in the chat) and photo library (selecting images for chat and gallery) only after your explicit consent. You can revoke these permissions at any time in your device settings.
- Push notifications: With your consent we register a device token (Apple Push Notification service or Firebase Cloud Messaging) to deliver notifications to you (e.g. about new chat messages). Content is not shown in plain text on the lock screen. You can disable push at any time in your device settings. The legal basis is Art. 6(1)(b) and (f) GDPR.
- Chat and user-generated content: In the organizer-bound chat we process messages, voice messages and images that you exchange with other members. Text messages are stored encrypted on our servers. Functions to report and block content and users are available. Chat content is automatically deleted after 14 days. The legal basis is Art. 6(1)(b) GDPR.
- Local storage on the device: Sign-in tokens are stored securely in your device's keychain (iOS) or keystore (Android) and can optionally be additionally protected by Face ID/Touch ID.
- No tracking: The app uses no advertising identifiers (e.g. IDFA) and no app tracking. The Meta Pixel described above (section 9) applies only to event pages on the web, not to the app.
19. Changes to this privacy policy
We will update this privacy policy if the legal situation, the platform or the data processing changes. The current version published here applies.
This English version is provided for convenience. In case of discrepancies, the German version of this privacy policy prevails.
