Privacy Policy
TixEvery Privacy Policy Effective date: 11 September 2026 Version: 1.1
This Privacy Policy explains how TixEvery collects, uses, shares and protects personal data when you use our Platform (including purchasing tickets/products/add-ons or browsing our sites).
This policy should be read alongside the Customer Terms & Conditions, Cookie Policy, and Refunds & Cancellations Policy.
Roles: who controls your data 1.1 Organisers as Data Controllers. For Events, Tickets, Products and Add-ons listed by an Organiser, the Organiser is typically a Data Controller for customer data used to sell and administer the Event/Order and fulfil organiser items. 1.2 TixEvery as Controller and/or Processor. Depending on context, TixEvery acts as a Data Controller for platform-level operations such as professional accounts and Network profiles, recommendations, security, fraud prevention, service improvement, analytics, account administration, reports, moderation, appeals and enforcing policies, and/or as a Data Processor when processing personal data on behalf of an Organiser to facilitate Orders and administer Events.
What data we collect We may collect identity/contact data (name, email, phone if provided, billing address if required), professional account and Network profile data (professional type, organisation or trading name, biography, location, images, appearances, listings and profile claims), Network Content and interaction data (opportunities, posts, comments, reactions, reviews, endorsements, connections, direct or group messages and attachments), safety and moderation data (reports, relevant evidence, outcomes and appeals), Order data (items purchased, quantities, prices, booking fee, event details, delivery status), payment-related data (payment status and payment-provider identifiers; we do not store full card details), support data (messages to support, complaint/dispute details), technical data (IP address, device/browser information, event logs, cookies and similar identifiers), and preferences (marketing opt-in/opt-out where applicable).
How we use personal data (purposes) We use personal data to create, link and maintain eligible professional Network profiles; make profiles and submitted content available to their intended audience; provide discovery, opportunities, connections, recommendations, posts, comments and messaging; investigate reports, moderate content, protect users and handle appeals; process and administer Orders; deliver tickets; provide support; prevent fraud and secure the Platform; enforce policies; operate and improve the Platform; enable Organisers to administer Events and fulfil Products/Add-ons; send essential service communications; and send marketing where permitted by law and in line with your preferences.
Lawful bases Depending on context, we rely on contract, legal obligation, legitimate interests, and consent. Legitimate interests may include operating and protecting the Platform, preventing fraud, enforcing policies, improving performance and reliability, and supporting Organisers in administering Events and promoting reasonably related future events where permitted by law, including where consent has been obtained or PECR soft opt-in conditions are met, subject to your rights and freedoms.
Sharing and disclosures We may share personal data with Organisers, intended recipients of Network content or messages, payment providers and fraud/risk tools, email/communications providers, hosting and infrastructure providers, analytics providers (where enabled), authorities where required by law or to respond to lawful requests, and professional advisers. Public profile information and other content a user chooses to publish may be visible publicly. We do not sell or rent personal data, or disclose it to external partners for their own independent marketing. This does not prevent necessary disclosure to service providers acting on our instructions or other operational disclosures described in this policy.
Marketing, legitimate interests and opt-out 6.1 Essential service communications. We and/or Organisers may send genuinely non-promotional messages needed to operate an account, service or transaction. These include ticket or order confirmations and delivery, event and safety updates, application or registration information, ticket and sales reports, payout or remittance summaries, settlements, refunds, chargebacks, failed payments, Stripe or identity checks, account security, support, moderation and appeal decisions, and material legal notices. 6.2 TixEvery marketing. Subject to applicable law, TixEvery may use professional account contact details for its own newsletters, promotional product and feature announcements, Network opportunities and recommendations, offers, surveys and invitations. Depending on the recipient and channel, we may rely on legitimate interests, a valid PECR soft opt-in or consent. Acceptance of professional terms acknowledges this processing but is not treated as consent where separate consent is required. 6.3 Opt-out and objections. You have an absolute right to object to direct marketing and may unsubscribe from TixEvery marketing emails at any time using the link in the message or by contacting privacy@tixevery.com. Where offered, you may also opt out of marketing texts, optional marketing push notifications and other marketing channels. An existing opt-out is not reversed by accepting updated terms. Marketing opt-out does not stop the essential service messages in clause 6.1. Organiser-controlled marketing preferences may need to be changed separately where the Organiser is a separate controller.
Data security We store customer data on secure servers and apply appropriate technical and organisational measures designed to protect data against unauthorised access, loss, misuse, alteration or disclosure, including access controls, encryption in transit, monitoring and secure backups.
Data retention We retain data only as long as necessary for fulfilling Orders and providing the Platform and Network, resolving disputes, reports, appeals and chargebacks, meeting legal/accounting obligations, preserving safety and moderation records, and preventing fraud and abuse. We may retain the minimum information required to honour a marketing suppression. Retention periods vary by data type and may be longer where required by law.
International transfers Where service providers are located outside the UK, we use appropriate safeguards as required by applicable law.
Your rights You may have rights to access, correct, delete, restrict processing, object to processing, portability where applicable, and withdraw consent. To exercise rights, contact privacy@tixevery.com.
Children The Platform is not intended for children under 13. For age-restricted events, Organisers/venues may set minimum ages and entry requirements.
Changes to this policy We may update this policy from time to time and will post the latest version on the Platform.
Contact Privacy: privacy@tixevery.com
Support: support@tixevery.com
Additional data-use detail
Depending on the data flow, TixEvery may act as an independent controller, joint participant in a payment or platform flow, or processor for an organiser. Organisers may act as controllers for their own event administration and marketing use of customer data. Where a request relates to organiser-controlled processing, we may refer or assist the organiser as appropriate.
We may use customer accounts, saved shows, order history, preferences, location signals, analytics and engagement data for service operation, recommendations, personalisation, fraud prevention and product improvement where we have a lawful basis. Some marketing may rely on consent; some organiser or platform communications may rely on legitimate interests or PECR soft opt-in rules, only where the relevant legal conditions are met and always subject to opt-outs at collection where required and in every marketing message.
Organisers may export customer data for permitted event, accounting, support and compliant marketing purposes, provided they satisfy UK GDPR and PECR requirements before using it for marketing. We may use analytics, monitoring and AI-assisted insights to understand platform performance, improve recommendations and support organisers, without permitting organisers to use personal data unlawfully. Current sub-processor information is available at /terms/sub-processors.
Legal centre