DEMO · test data only · payments are simulated, no card is charged
Tik ChikTicketing

Privacy

What we collect, why, and who sees it.

Last updated September 26, 2026.

The short version

We collect what it takes to sell a ticket and admit its holder, and nothing else. Attendees are often children; their details are used to run the door and are never sent to any marketing or CRM system. The person paying is an adult; their details may be shared with the organizer's donor CRM, because they are the organizer's donor.

What we collect

From buyers: your name, email, mobile number, and what you bought. Payment card details go to Stripe and never touch our servers. If you tick the box, your consent to receive your tickets by text.

About attendees: name, mobile number, and school, as entered by the buyer, plus anything the organizer asks for at checkout. Whether and when each ticket was scanned at the door.

From organizers and their staff: email address, which organizations you belong to and in what role, sign-in times, and the tax details an organization enters for receipting (legal name, EIN, address).

Automatically: server logs with IP address and browser, kept for 30 days. We do not use analytics or advertising trackers, and there are no third-party cookies. The one cookie we set holds your sign-in session.

Who sees it

The organizer sees the orders and attendees for their event. A partner group selling into someone else's event sees only its own buyers and attendees, never another group's.

Stripe processes payments and receives what any card processor needs: the amount, and the buyer's name and email for the receipt.

The organizer's CRM (HubSpot, or a spreadsheet export), if they connect one, receives the purchaser's name, email, order and gift amounts, and receipt details. It does not receive attendee names, phone numbers, or schools. This boundary is enforced in code and tested.

Apple and Google receive the ticket details you choose to save to a wallet, if the organizer has enabled wallet passes. Google Wallet receives the attendee name only where the organizer has opted in to that.

Nobody else. We do not sell data, share it with advertisers, or use it to train anything.

Security

Sign-in is by a one-time emailed link; there are no passwords to leak. Session and sign-in tokens are stored hashed, so a copy of our database grants access to nothing. Ticket codes are signed per ticket and rotate every 30 seconds. Everything is served over HTTPS.

Retention and your rights

Orders, refunds, and receipts are financial records and are kept for seven years. Attendee details are kept for the organizer's use until they delete the event or ask us to remove them. You may ask us for a copy of your data, or for it to be corrected or deleted where we are not required to keep it, at privacy@tik-chik.com. If your request concerns an organizer's records, we will pass it to them and help them respond.

Texts: reply STOP to any message to opt out. We keep the opt-out so you are not texted again.

Children

Attendees at many events here are under 18. We do not knowingly collect information directly from anyone under 13; attendee details are entered by an adult buyer. If you believe a child has provided information to us directly, contact us and we will remove it.

Terms · Privacy · Refunds