Privacy policy
Last updated: [DATE]
Draft pending legal review. This text describes accurately how the platform works and is the brief for the solicitor, but an Irish lawyer must review it before launch. Tags like [THIS] mark what is still missing.
Who we are
[COMPANY NAME], a company registered in Ireland under number [CRO] with its registered office at [ADDRESS] ("sinfiesta", "we"), operates the ticketing platform at sinfiesta.ie.
For data protection matters: privacy@sinfiesta.ie.
Our role: when we are controller and when we are processor
This distinction matters because it determines who you go to in order to exercise your rights.
We are the controller when we…
- manage organiser accounts and their access to the platform;
- prevent fraud and abuse in ticket purchasing;
- measure product usage in order to improve it;
- meet legal, accounting and tax obligations.
We are the processor when we…
- handle attendee data on behalf of, and under the instructions of, the event organiser: guest lists, door control and communications about that event.
In that second case the organiser is the controller and their own policies apply alongside this one. If you write to us exercising a right over data we only process, we'll tell you and point you to the right party.
What data we handle
- Buyers: name, email address, order and ticket details, and entry records when a ticket is scanned. We do not store your card details -- payment is processed directly by Stripe.
- Organisers: contact and company details, login credentials, and Stripe account identifiers.
- Technical: IP address, browser type and request logs, for security and fraud prevention.
You do not need an account to buy a ticket. You buy as a guest and retrieve tickets through a single-use link sent to the order email.
Legal bases
- Performance of a contract: issuing and delivering your ticket, and handling refunds.
- Legitimate interests: preventing fraud, keeping the service secure, improving the product.
- Legal obligation: retention of accounting and tax records.
- Consent: marketing communications. Withdrawable at any time, with an unsubscribe link in every message.
Where your data lives
All infrastructure runs in Amazon Web Services, Ireland region (eu-west-1). Data is stored encrypted.
Some of our providers process data outside the European Economic Area. Where that happens we rely on the European Commission's Standard Contractual Clauses together with the corresponding supplementary measures.
Who we share it with
- Stripe -- payment processing. Stripe is an independent controller for payment data; see their own policy.
- Amazon Web Services -- hosting and transactional email (Ireland).
- Your event's organiser -- receives the data needed to manage entry.
- [TO COMPLETE with the remaining processors before launch: monitoring, support, analytics.]
We do not sell personal data and we do not share it with third parties for advertising.
How long we keep it
- Orders and tickets: [PERIOD], under Irish accounting obligations.
- Access and security logs: [PERIOD].
- Marketing consent: until you withdraw it.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, portability and objection. Email privacy@sinfiesta.ie and we will respond within one month.
You can also complain to Ireland's Data Protection Commission at dataprotection.ie.
Cookies
This site uses only strictly necessary cookies. There is no analytics or advertising tracking. If that changes, we will ask for your consent before setting any non-essential cookie.