TixEveryLegal centre

Privacy Policy

TixEvery Privacy Policy Effective date: 24 February 2026 Version: 1.0

This Privacy Policy explains how TixEvery collects, uses, shares and protects personal data when you use our Platform (including purchasing tickets/products/add-ons or browsing our sites).

This policy should be read alongside the Customer Terms & Conditions, Cookie Policy, and Refunds & Cancellations Policy.

Roles: who controls your data 1.1 Organisers as Data Controllers. For Events, Tickets, Products and Add-ons listed by an Organiser, the Organiser is typically a Data Controller for customer data used to sell and administer the Event/Order and fulfil organiser items. 1.2 TixEvery as Controller and/or Processor. Depending on context, TixEvery acts as a Data Controller for platform-level operations such as security, fraud prevention, service improvement, analytics, account administration and enforcing policies, and/or as a Data Processor when processing personal data on behalf of an Organiser to facilitate Orders and administer Events.

What data we collect We may collect identity/contact data (name, email, phone if provided, billing address if required), Order data (items purchased, quantities, prices, booking fee, event details, delivery status), payment-related data (payment status, payment provider identifiers; we do not store full card details), support data (messages to support, complaint/dispute details), technical data (IP address, device/browser info, event logs, cookies and similar identifiers), and preferences (marketing opt-in/opt-out where applicable).

How we use personal data (purposes) We use personal data to process and administer Orders, deliver tickets, provide customer support, prevent fraud and secure the Platform, enforce policies, operate and improve the Platform, enable Organisers to administer Events and fulfil Products/Add-ons, send essential operational communications, and send marketing communications where permitted by law and in line with your preferences.

Lawful bases Depending on context, we rely on contract, legal obligation, legitimate interests, and consent. Legitimate interests may include operating and protecting the Platform, preventing fraud, enforcing policies, improving performance and reliability, and supporting Organisers in administering Events and promoting reasonably related future events where permitted by law, including where consent has been obtained or PECR soft opt-in conditions are met, subject to your rights and freedoms.

Sharing and disclosures We may share personal data with Organisers, payment providers and fraud/risk tools, email/communications providers, hosting and infrastructure providers, analytics providers (where enabled), authorities where required by law or to respond to lawful requests, and professional advisers. We do not sell personal data.

Marketing, legitimate interests and opt-out 6.1 Transactional communications. We and/or Organisers may send essential transactional communications to administer Orders and Events. 6.2 Marketing communications. Where permitted by law, including where consent has been obtained or PECR soft opt-in conditions are met, you may receive marketing communications from the Organiser about the Event and reasonably related future events, and/or from TixEvery about platform updates and reasonably relevant offers. Where required, customers must have an opt-out at the point of data collection and in every marketing message. These communications may rely on legitimate interests or consent depending on the situation and applicable law. 6.3 Opt-out and objections. You can unsubscribe/opt out at any time using links in emails or by contacting us. Opt-outs and objections will be honoured promptly and in any event within legally required timeframes. Organisers are required to honour opt-outs and are responsible for their compliance.

Data security We store customer data on secure servers and apply appropriate technical and organisational measures designed to protect data against unauthorised access, loss, misuse, alteration or disclosure, including access controls, encryption in transit, monitoring and secure backups.

Data retention We retain data only as long as necessary for fulfilling Orders and providing the Platform, resolving disputes and chargebacks, meeting legal/accounting obligations, and preventing fraud and abuse. Retention periods vary by data type and may be longer where required by law.

International transfers Where service providers are located outside the UK, we use appropriate safeguards as required by applicable law.

Your rights You may have rights to access, correct, delete, restrict processing, object to processing, portability where applicable, and withdraw consent. To exercise rights, contact privacy@tixevery.com.

Children The Platform is not intended for children under 13. For age-restricted events, Organisers/venues may set minimum ages and entry requirements.

Changes to this policy We may update this policy from time to time and will post the latest version on the Platform.

Contact Privacy: privacy@tixevery.com

Support: support@tixevery.com

Additional data-use detail

Depending on the data flow, TixEvery may act as an independent controller, joint participant in a payment or platform flow, or processor for an organiser. Organisers may act as controllers for their own event administration and marketing use of customer data. Where a request relates to organiser-controlled processing, we may refer or assist the organiser as appropriate.

We may use customer accounts, saved shows, order history, preferences, location signals, analytics and engagement data for service operation, recommendations, personalisation, fraud prevention and product improvement where we have a lawful basis. Some marketing may rely on consent; some organiser or platform communications may rely on legitimate interests or PECR soft opt-in rules, only where the relevant legal conditions are met and always subject to opt-outs at collection where required and in every marketing message.

Organisers may export customer data for permitted event, accounting, support and compliant marketing purposes, provided they satisfy UK GDPR and PECR requirements before using it for marketing. We may use analytics, monitoring and AI-assisted insights to understand platform performance, improve recommendations and support organisers, without permitting organisers to use personal data unlawfully. Current sub-processor information is available at /terms/sub-processors.

TixEvery legal information for event organisers, customers and platform users.