Draft, not yet reviewed by a lawyer. This accurately describes what happens today but has not been checked for legal sufficiency. Do not publish it as final.
Last updated: 2 October 2026.
The short version
You bought a ticket to an event. Two organisations are involved: the event organiser who is putting the show on, and Stickets.live, the ticketing platform they use. You bought the ticket from the organiser (the payment went to their account, not ours), and they get your name and email so they know who is coming. We provide the ticket, the checkout and the door scanning. Your card details go straight to Stripe and neither of us ever sees them.
If you did not tick either mailing-list box at checkout, nobody added you to any list. That is not a setting we default on.
Who we are
Stickets.live is operated by Adam Zonnis, a sole proprietor, of 914 Dunn Ave, Victoria, British Columbia V8X 2Z4, Canada. Questions about this policy: adamzonnis@gmail.com.
The event organiser is a separate business. We do not control what they do with your details once they have them; if you want them to delete you from their records, ask them. If you are not sure who they are, the event page and your ticket email both name them.
What we collect when you buy a ticket
- Your name and email address.
- What you bought, for which event, and when.
- Payment confirmation from Stripe. We never receive your full card number.
- Whether your ticket has been scanned at the door, and when.
- If the event uses coat check or item collection, a record of what you handed over and whether you collected it.
- If you bought merchandise that has to be posted to you: a delivery name, address, phone number and email address. We ask for these only when something in your order needs shipping.
If you buy merchandise
Some merchandise is printed to order by an outside company rather than held in a box by the organiser. When that is how an item is made, your delivery name, address, phone number and email address are sent to that printer so they can make it and post it: today that is Printful, Gelato or Printify, depending on which one the organiser uses, and a shipping carrier chosen through Shippo. They receive what is needed to deliver your order and nothing about the rest of your account.
Your delivery address is kept with your order. It is not added to any mailing list, it is not used to work out where you live for marketing, and ticking a mailing-list box does not send it anywhere.
Mailing lists: two separate boxes
At checkout, and again if you fill in a post-show survey, you may be offered two entirely independent choices: join the organiser's mailing list, and join ours. They are separate on purpose. You can take one, both, or neither.
If you decline one, no record of you is created for that purpose at all; there is no hidden "on the list but not emailed" state. If you decline both, the organiser's management system holds no marketing record of you whatsoever. We still keep what we need for your order and your ticket.
If you do tick a box, we keep a record of when you ticked it, along with the IP address and browser your checkout reported at the time. That is evidence that you agreed, and it is the only thing we use it for.
If you tick a box, the record we create also carries where the event was (its city, state and country), and a label for the show and the venue you bought for. That is how an organiser can email the people who came to one show, or the people near a city they are playing next. It is taken from the event, not from you: it is where the show was, not where you are, and we do not work it out from your card. If you also bought merchandise we asked for a delivery address; that is used to post your order and is not what this record is made from.
Every marketing email we send has an unsubscribe link, and it works immediately.
Who your information reaches
- The event organiser: your name, email and what you bought. They need it to run the door and to contact you if the event changes.
- Stripe: payment processing. The charge is made on the organiser's own Stripe account, so Stripe holds your payment details under their arrangement as well as ours.
- ZeptoMail, an email service run by Zoho, sends your ticket and the other emails about your order: updates about the event, merchandise order emails, waitlist and resale messages, and, if you tick the organiser's mailing-list box, the confirmation email asking you to confirm. It gets your email address and what each email says. We use its data centre in Canada.
- Amazon Web Services (SES): sends marketing email from the organiser's mailing list, if you chose to join it. It is sent from the organiser's own email address, and gets your email address and what each email says. The email asking you to confirm no longer goes through SES; see ZeptoMail above.
- Cloudflare. Our public website passes through Cloudflare on its way to you. Cloudflare also holds the nightly encrypted backup of the database your order sits in, as ciphertext it cannot read. See "Where your data is held" below.
- Sentry: error tracking. If something breaks while you are buying a ticket, Sentry is told what broke: the technical description of the error, the line of our own code it happened on, the address of the page you were on, and the short reference code the error page shows you. It is not sent your cookies, your card details, or anything you had typed into a form. We cannot promise that a technical error message never repeats a value inside its own text, which is why Sentry is named here rather than left unsaid. Sentry's servers are in the United States.
- A print-to-order company and a shipping carrier, if your order contains merchandise that is made and posted for you. See If you buy merchandise above. They receive your delivery details only.
- Door staff at the event: the scanning app can show the name on the ticket so they can check you in. The organiser chooses which of their staff are allowed to see names; someone who has not been given that permission scans your ticket without seeing whose it is.
- The people who run Stickets.live. We built and run the system your order and ticket are stored in, so we can see them, including your name and email. We use that to keep the ticketing working, not to look at people.
- Nobody here can log in to the organiser's account and browse their ticket buyers whenever they feel like it. If the organiser needs help with something we cannot see from the outside, they have to give us a temporary code themselves. It runs out on its own, they can cancel it at any moment, and their own records show who came in and what was done.
We do not sell your information. We do not pass it to advertisers.
How your information is protected
The plain version, because a vague answer here is worse than an honest one.
- Your card details never reach us. The payment box on the checkout page is put there by Stripe, and your card number goes from your browser straight to Stripe. It does not pass through our systems and it is not stored on them. Neither we nor the organiser ever sees it. What comes back to us is confirmation that the payment worked.
- Your name and email are stored so that they can be read. They sit in an ordinary database, not scrambled into something unreadable. The organiser can read them, because they have to: that is how they know who is coming, send you your ticket and check you in on the night. The people who run Stickets.live can read them as well, as part of administering the system, and anyone who obtained a copy of that database or a backup of it would be able to read them too.
- We are not going to call that encryption, because it would not be. Any lock we put on your name and email would need a key sitting inside the same software that has to show them to the organiser at the door. It would protect you from very little and break the things you need to work. Not scrambling ticket-buyer details field by field is the ordinary choice across ticketing, and it is a choice we have made deliberately rather than one we have overlooked. Card details are the one part that genuinely never needs to be readable by anybody here, and that is exactly the part we never hold.
- Nothing here is locked away from us, and your order is no exception. We do not describe any part of this platform as encrypted in a way that stops us reading it. We say this so that nothing above sounds like a bigger promise than it is.
Cookies
The site sets no cookies at all. Your ticket selections are held on the page while you are buying and are lost if you reload it. If you buy merchandise, your basket is kept in your own browser's storage, on your device, not in a cookie, and it never leaves your device until you check out.
There are no analytics cookies, no advertising cookies, and nothing that follows you to other sites. The pages where you buy a ticket load no fonts and no trackers from Google or anyone else. Two outside companies can still tell that your browser visited: Stripe, because the payment box on the checkout page is loaded from Stripe; and YouTube (Google), if the event page shows a performer's video. That video loads from youtube-nocookie.com, YouTube's privacy-enhanced version, when you scroll to it.
How long we keep it
Order and ticket records are kept for six years, which is what the Canada Revenue Agency requires, partly because tax rules require it. If you are on a mailing list, we keep you on it until you unsubscribe.
Backups are separate from the live order above. The encrypted copy described under "Where your data is held" is kept for up to 30 days daily, or up to 365 days for the first good copy of each month, then removed automatically. If your order is deleted from the live database, it can still exist inside one of these backups until it ages out on that schedule.
We also keep plain copies of this same database on the same server. Before we release new code, and before we undo a release, we take a compressed copy of the whole database so a bad change can be reversed. These copies live on the same server as everything else, not somewhere separate, and they are not encrypted the way the nightly backup above is. We delete each one 30 days after it was taken, except we always keep the three most recent copies regardless of age, so a rollback always has something recent to restore from.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to adamzonnis@gmail.com. Remember that the organiser holds their own copy; ask them separately.
When you write to us, we look up what we hold under your email address and send it back, or delete it, but only for someone who has actually asked. Our staff cannot pull up your record on a whim: if there is no request from you, there is nothing for them to act on.
Refunds are the organiser's, not ours. Because you bought from them, they decide, and it is their money that comes back. If the event is cancelled, moved, or was not what you expected, they are who to contact.
You can also complain to a data protection regulator. In Canada that is the Office of the Privacy Commissioner of Canada, and in British Columbia the Office of the Information and Privacy Commissioner for BC. If you are in the UK or the EU you can complain to your own regulator instead.
Where your data is held
Your data is stored and processed in Canada. The application and the database that your order sits in run on a server in Beauharnois, Quebec, rented from OVHcloud. We are based in British Columbia, so the part of the service that holds your information keeps it in Canada. This corrects an earlier version of this policy, which wrongly described the server as being in Amazon Web Services' Oregon region; it never was.
Some of the companies we rely on to run the service are outside Canada. Where a company is outside Canada, the information it receives is subject to the laws where it operates, and in principle the authorities there can compel access to it under their own legal processes.
One exception runs the other way: your ticket and the other emails about your order, and (if you joined one) the confirmation email for an organiser's mailing list, go out through ZeptoMail's data centre in Canada, including your email address and what each email says.
A second exception leaves Canada: the nightly encrypted backup of the database your order sits in is kept with Cloudflare, whose network is worldwide, so this copy is not pinned to Canada the way the live application is. It is encrypted before it ever leaves our server, so Cloudflare holds a file it cannot read, not your information in the clear. A daily backup is kept for up to 30 days; the first good backup of each month is kept for up to 365 days, then removed automatically.
The companies that help us run this: Stripe (payments), ZeptoMail, run by Zoho (your ticket and order emails and mailing-list confirmation, through its Canadian data centre), Amazon Web Services (marketing email from an organiser's mailing list), Cloudflare (our public website and the encrypted backup above), Sentry (error tracking) and, if your order needed one, a print-on-demand company and a shipping carrier (see "If you buy merchandise" above). Any of them may handle your information in the United States and elsewhere.
Changes
If we change this, the date at the top changes. The version here is always the current one.
Your data
You can ask for a copy of what we hold about you, or ask us to delete it, from the data request page.