Skip to content

Privacy Policy

Effective 18 September 2026 · Version 2026-09-18

Draft pending legal review. This document describes how the platform actually works today, but it has not yet been reviewed by counsel. It is published so that nothing in the product refers to a document that does not exist; the wording may change.

This policy explains what Backdoor Tickets collects when you browse events, buy a ticket, join the waitlist or use a staff account, why we collect it, who else sees it, and what you can ask us to do about it.

It describes what the platform actually does today, not what we intend it to do. Where something is missing, it is named as missing.

Who we are

Backdoor Tickets operates this ticketing platform and is the controller of the personal data described here. You can reach us about anything on this page at support@backdoor.tools.

Events are run by independent organizers. When you buy a ticket, the organizer of that event also receives your details and decides for themselves what to do with them — see who we share data with.

What we collect

When you buy a ticket — your name, email address, phone number if you give one, and the billing address attached to your card. Your order itself: what you bought, the amount, any discount or donation, the payment method, and its refund or dispute status. The tickets issued to you, including their barcodes. Which version of our terms and which refund policy you were shown when you agreed to them.

Your card details are never collected by us. Card number, expiry and security code are typed directly into Stripe’s payment form and go straight to Stripe. They do not reach our servers and are not in our database. We keep only Stripe’s reference numbers for the payment. That is equally true if you pay with Link, Stripe’s wallet — the saved card lives with Stripe, and what reaches our database is the same amount and reference as any other order.

When you attend an event — a record that your ticket was scanned at the door, when, and by which staff member.

When you join the waitlist — your email address, the name and role you give, what you type under “how did you hear about us”, and any campaign tags carried by the link you followed. We also record that you ticked the box agreeing to be emailed, when, and the exact wording you were shown — that record exists so we can prove we had your permission, and for no other purpose. We no longer record your IP address or browser details here, and the ones previously collected have been deleted.

If you have an account — your email, name, phone and role, held by our sign-in provider. For staff accounts we also keep an audit record of role and account changes. If you connect an AI assistant to your account, we record that you consented and what it was permitted to do.

When you simply use the site — our servers process your IP address to rate-limit abuse of public forms. It is held briefly as a counter and is not stored alongside anything else about you. We do not run analytics, advertising, tag-manager, session-replay or tracking software of any kind, and there are no tracking pixels anywhere on this site.

Why we use it, and on what basis

  • To perform our contract with you — taking your order, issuing and re-sending your tickets, admitting you to the event, handling refunds, and supporting you when something goes wrong.
  • Because the law requires it — keeping financial and tax records of sales, and records of what terms a buyer accepted.
  • For our legitimate interests — preventing fraud and ticket abuse, defending chargebacks with the record of what you were shown, keeping the platform secure and available, and understanding how many tickets an event sold.
  • With your consent — the waitlist, and connecting an AI assistant to your account. The waitlist box is unticked when you arrive and is the only thing it asks; we will not email you about the launch without it. Every marketing email we send carries an unsubscribe link, one press and no sign-in, and you can also withdraw by writing to support@backdoor.tools. Withdrawing stops the marketing immediately and does not affect anything done before you withdrew it. You will still get the emails we owe you about tickets you have bought — receipts, refunds, cancellations and transfers — because those are not marketing and carry no unsubscribe link.

We do not use your data to build advertising profiles, and we do not make automated decisions about you that produce legal or similarly significant effects.

Who else sees your data

The organizer of the event you bought from. They receive the name, email, phone and order details of their own buyers, so they can run the event, admit you and handle their own refunds. They may export that list. Each organizer decides for themselves how they use it afterwards, which makes them separately responsible for it under data-protection law — their own privacy practices are not ours, and this policy does not cover them. An organizer only ever sees buyers of their own events.

The service providers that run the platform for us. Each one processes data on our instructions and for no purpose of their own:

  • Supabase Database, file storage and sign-in. Everything the platform stores.
  • Railway Hosting the application. Request data passing through server logs.
  • Stripe Card payments, organizer payouts, and Link if you use it. Your name, email, billing details and card payment — entered directly into Stripe. If you pay with Link, Stripe also uses your email and phone number to create or recognise a Link wallet, which is Stripe's own account with you rather than ours (§4).
  • Resend Sending email — confirmations, tickets, receipts. Your email address, name and the contents of the message.
  • Upstash Rate limiting, to block abuse of public forms and endpoints. Your IP address, held briefly as a counter key and not stored with your other data.
  • Google Maps Platform The venue map shown on an event page. Loaded by your browser, so Google receives your IP address and browser details directly.
  • Google Wallet Adding a ticket to Google Wallet, if you choose to. The ticket's name, event and barcode.
  • Apple Wallet Adding a ticket to Apple Wallet, if you choose to. The pass is built by us and downloaded by your device.

An AI agent or other app, only if you connect one. You can let an app such as Claude act as you through our agent interface. Nothing is connected unless you approve it on a consent screen that names the app and lists what it will be able to do. While a grant is live, that app reads what your own account can read — your profile, your orders and your tickets — and sends it to a third party we do not run, under their privacy policy rather than ours. No agent can ever take a payment, see your card details, refund or cancel an order. You can see every app you have connected, and revoke any of them, under Connected apps in your account; revoking takes effect immediately.

Stripe, again, if you pay with Link. Link is Stripe’s own wallet, and it is the one place on this list where a provider is acting for itself rather than only for us. When you reach the payment step, Stripe’s script reads the email address and phone number you typed into our checkout and uses them to create or recognise your Link account; paying with Link can enrol you as part of paying. That account is with Stripe, under Stripe’s privacy policy rather than this one, and it works at every other business that offers Link — which is the point of it. We cannot see what you save there, and we cannot delete it for you. If you would rather not, enter a card instead: Link is one choice in the payment box, never the only one, and nothing about it reaches Stripe differently if you skip it.

Nobody else. We do not sell your personal information, and we do not disclose it to advertisers, data brokers or analytics companies. We may disclose data where the law compels us to, or to establish or defend a legal claim.

Cookies and your browser

We set only the cookies the site needs to work: the one that keeps you signed in, a staff-only one that remembers a light or dark theme, and a flag recording that you dismissed the notice at the foot of the page. Nothing else is stored in your browser.

Stripe sets its own cookies to detect payment fraud, and they are set on event pages as soon as Stripe’s script loads, not only when you reach the payment step. If you pay with Link, Stripe stores something further so that it recognises you next time — at any business that offers Link, not only this one.

Nothing third-party loads before you ask for it. Where an organizer has picked a venue from Google Maps, the event page offers a map — but it stays unloaded behind a “Show map” button, so Google receives nothing about you unless you press it. The venue address and the directions link work without it. Stripe is the one exception, because its fraud checks are part of taking a payment at all.

Our Cookie Policy lists every one of them — what sets it, why, and how long it lasts.

How long we keep it

Waitlist entries. Deleted 90 days after we email you about the launch. If we never get round to emailing you, deleted after two years — by then you did not consent to hearing from us, whatever you told us at the time.

Payment notifications from Stripe. The technical records of a payment event are deleted after 90 days.

The record that you unsubscribed. Kept indefinitely, and deliberately: it is your email address, the reason and the date, and it is the only thing that stops you being emailed again after the waitlist entry itself has been deleted. We remove it only if you ask us to start emailing you again.

Your account, and the details on it. Kept for as long as you have an account. Delete it from Your data and your name, email address, phone number and postal address go immediately.

Orders, tickets, attendance and payout records. Kept after your account is gone, without you attached to them. We have not yet fixed a final period for these, because how long a ticket sale must be retained is a tax and payments question we are taking advice on. We would rather tell you that than publish a number we made up. Our working assumption is seven years from the date of the order.

A deletion job runs daily and enforces the periods above. The full table — every kind of record we hold, its period and the reason — is in our retention schedule, and we will send it to you if you ask.

Your rights

Depending on where you live, you can ask us to:

  • tell you what personal data we hold about you, and give you a copy;
  • correct anything that is wrong;
  • delete it, where we are not required to keep it;
  • restrict or object to how we use it;
  • send a copy to another service in a portable format;
  • withdraw a consent you previously gave.

If you have an account, you can do the first and third of those yourself, right now. Sign in and open Your data. “Download my data” gives you a file containing your profile, your orders, your tickets and any record of your ticket being scanned. “Delete my account” erases your name, email address, phone number and postal address, and closes your sign-in.

Deleting your account does not delete your past orders. We keep the order itself — what was bought, for how much, and its payment and refund status — because tax law requires it and because a card payment can be disputed long after the event. What we remove is you from it: after a deletion there is no name, email address, phone number or address on the record, and no way for us to find it from yours.

For anything else — correcting something, objecting to a use, or a request about an order you placed as a guest without an account — email support@backdoor.tools and say what you want. We may need to confirm you control the email address on the order before acting, because tickets are tied to an email address rather than to an account. We aim to answer within 30 days. We will not treat you differently for exercising any of these rights.

If you are in the UK or EEA and you are unhappy with how we handled your request, you can complain to your local data-protection authority.

California residents (CCPA/CPRA)

If you live in California, this section is your notice at collection and your statement of rights. It adds detail; it does not replace anything above.

Categories we collect. Identifiers (name, email, phone, postal address, account ID); commercial information (what you bought, order amounts, refunds); internet activity in the narrow sense of an IP address used for rate limiting; and, if you attend, a record that your ticket was scanned. We collect no biometric, geolocation, health, precise-location, genetic or employment data, and we do not collect the categories the CPRA defines as sensitive personal information.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months, including for anyone we know to be under 16. There is no advertising technology, analytics or data broker in this product, so there is nothing to opt out of — which is why you will not find a “Your Privacy Choices” link. We disclose personal information for business purposes only: to the service providers listed above, to the organizer of the event you bought a ticket to, and — only if you connect one and for as long as you leave it connected — to an AI agent or other app you authorised to act as you.

Your rights. You may ask us to tell you what we have collected about you, where we got it, why we have it and who we disclosed it to; to give you a copy; to correct anything inaccurate; and to delete it, subject to the exceptions the law allows — we keep records of a completed sale for tax and accounting purposes even after a deletion request.

How to make a request. Email support@backdoor.tools. We will confirm receipt within 10 business days and respond within 45 days, extending once by a further 45 days if we need to, and telling you if we do. We may need to verify that you control the email address on the order before we act. An authorized agent may make a request for you with your written permission.

No retaliation. We will not deny you service, charge you a different price, or give you a worse experience because you exercised any of these rights.

How we protect it

The site is served over HTTPS only. Access to personal data in the admin tools is limited by role and scoped to a single organizer, so staff of one organizer cannot see another’s buyers. Payments run through Stripe’s own hosted card fields, which is what keeps card data out of our systems entirely.

No system is perfectly secure. If a breach affects your data and the law requires us to tell you, we will.

Children

The platform is not directed at children under 13, and we do not knowingly collect their personal data. A parent or guardian who believes we have it should write to support@backdoor.toolsand we will delete it. Whether a child may attend an event is the organizer’s rule, not ours.

Where your data is held

Our database and hosting are in the United States. Some of the providers listed above operate globally, so your data may be processed outside the country you live in. Where a transfer out of the UK or EEA is involved, we rely on the standard contractual clauses in our agreements with those providers.

Changes to this policy

We update this policy when what we do changes. Each version carries the date and version shown at the top of this page. If a change materially affects how we use data we already hold about you, we will tell you rather than relying on you re-reading this page.

Contact

Backdoor Ticketssupport@backdoor.tools. For a request about a specific order, include your order number.

Terms of Sale and Service · Back to events