Privacy Policy
Last updated: August 2, 2026
Sections marked “[TBD — legal review]” contain jurisdiction-specific details that must be confirmed by legal counsel before relying on this document.
1. Overview and roles
This policy explains how personal data is handled on Orbit Ticket. Because Orbit Ticket is a marketplace, two roles exist: for organizer and staff account data, Orbit Ticket is the data controller; for buyer and attendee data collected during an organizer's checkout, the organizer is the controller and Orbit Ticket processes that data on the organizer's behalf, plus limited processing for its own purposes (platform security, service-fee accounting, and legal compliance).
The controlling legal entity and, where required, its representative: [TBD — legal review].
2. Data we collect
Account data: name, email address, and a hashed password (or Google sign-in identifier) for organizers and staff. Buyer data: name, email address, optional phone number, and any answers to the organizer's checkout questions. Order and ticket data: purchased items, amounts, currency, payment status, ticket QR codes, and check-in records. Technical data: log and device information needed to run and secure the service.
Card payments are processed by Stripe. Orbit Ticket never receives or stores full card numbers.
3. How we use data
We use data to process orders and payments, deliver tickets by email, run door check-in, prevent fraud and abuse, provide organizer reporting, and send transactional email (order confirmations, payment instructions, ticket delivery). Marketing email from the organizer is sent only with your opt-in, and every message contains an unsubscribe link.
4. Sharing
Buyer data is shared with the organizer of the event you buy for — that is who you buy from. We also use service providers to run the platform: Stripe (payments), Resend (email delivery), and hosting and database infrastructure providers. We disclose data to authorities only where the law requires it. We do not sell personal data.
5. Cookies
Orbit Ticket uses only cookies that are necessary to operate the service: session and sign-in cookies for staff accounts and a cookie storing your language preference. We do not use advertising or cross-site tracking cookies.
6. Retention
We keep personal data only as long as needed for the purposes above. Order and accounting records are kept for the statutory retention periods that apply to the organizer and to us; the specific periods per jurisdiction: [TBD — legal review].
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or receive a copy of your personal data, and to object to certain processing. For data collected in an organizer's checkout, the organizer is your first point of contact; we support organizers in fulfilling these requests. You can also contact us at legal@orbit-ticket.example [TBD — legal review].
The competent supervisory authority you may complain to: [TBD — legal review].
8. International transfers
Hosting locations and, where applicable, the safeguards used for transfers of personal data outside your jurisdiction: [TBD — legal review].
9. Security
Data is encrypted in transit, access is restricted per organization and role, passwords are stored only as salted hashes, and ticket QR codes are cryptographically signed so they cannot be forged.
10. Changes
We may update this policy as the service or legal requirements evolve. The date above shows the latest revision.
11. Contact
Privacy questions: legal@orbit-ticket.example [TBD — legal review: replace with the registered privacy mailbox].