Privacy Policy
Last updated: 17 July 2026 · Draft pending legal review
1. What we collect
Account details (email, display name), profile content you add, transaction records for tickets and bookings, messages you send on-platform, device push subscriptions you opt into, and product analytics events (page views, searches) tied to your account or an anonymous session.
2. How we use it
To run the marketplace: process orders, deliver tickets and QR check-in, power bookings and messaging, send the notifications you have enabled, prevent fraud and abuse, and improve the product through aggregated analytics. We do not sell personal data and we do not run third-party advertising trackers.
3. Sharing
Payment details go directly to our payment processors. Organizers see attendee names for their own events (check-in lists). Public profiles show what you choose to publish. We disclose data to authorities only where legally required.
4. Retention
Transaction records are kept as required by tax and accounting law. Messages are retained for the life of your account plus 90 days. Raw analytics events are kept for 13 months; only aggregated rollups persist beyond that. Deleting your account soft-deletes your content and removes it from public surfaces immediately.
5. Your rights
You can access, correct, export, or delete your data from account settings, and disable each notification channel per category. For anything not self-serve, contact privacy@spotlive.example (placeholder — replace before launch).
6. Security
Passwords are hashed with Argon2, sessions are revocable per device, payment card data never touches our servers, and staff actions on user data are audit-logged. Report vulnerabilities to security@spotlive.example.