Privacy Notice
Effective
1. Who we are, and how to reach us
ticket.watch is the service described in this notice. The controller for the personal data it holds is [to be confirmed], at [to be confirmed]. Write to us at support@ticket.watch, or through support.
We cannot yet name the controller. The company that will operate ticket.watch is being incorporated, and we will not print a name, a company number or a registered address before there is one to print. Rather than leave the gap invisible, this notice marks it. Until it is filled, the person answerable for your data is whoever answers support@ticket.watch, and every right in section 12 can be exercised at that address today.
2. What this service does, and what it never does
You tell us which event you want. On a schedule we ask the seller's own public pages whether tickets are there, and when the answer changes in your favour we email, text or push you a link to the seller. That is the whole product.
ticket.watch never adds a ticket to a basket, and never buys, reserves or resells a ticket. We are not a seller, an agent, a broker or a marketplace. We hold no tickets and take no payment for one. That is why this notice has no section about payment data: there is none to write about. Every purchase happens on the seller's own site, in your own browser.
It also means the checks we make carry nothing about you. When we ask a seller whether tickets exist, the request contains no name, no email address and no account id. A seller can of course see that one of its own pages was fetched; what it cannot learn from us is who asked, or that any particular person is interested in that event.
3. What we store
Your account
- Your email address, and whether you have confirmed it.
- Your name, if you gave one or Google gave us one.
- Your profile picture's address at Google, if you signed in with Google.
- Your password, stored as a one-way hash we cannot reverse.
- Your phone number and whether it is verified, if you opt in to SMS.
- The date you switched SMS on, which is the record of your consent.
- A short-lived code we texted you, stored as a hash, with its attempt count.
- Which channels you want alerts on: email, SMS, push, or a combination.
What you asked us to watch
- The events and productions you follow, and their date, time, quantity, price, ticket-type, section and resale filters.
- The performers you follow.
- Whether a watch is active, paused or finished, and how many times we have checked it.
- If you asked us to add an event we do not yet cover: the email address you gave and the words you typed, including any link.
Alerts we sent you
- Every alert: its channel, kind, subject, body, send and delivery times, and the message id our provider gave it.
- Whether you clicked the link in an alert, how often, and when.
- A one-off token in every alert email, so one-click unsubscribe works.
Signing in, and devices
- Your sign-in sessions, including their IP address, browser user-agent and expiry.
- Sign-in, email-confirmation and password-reset tokens, until they expire.
- For each device you turned push alerts on for: the push address its browser gave us, the keys that encrypt the alert to that device, its user-agent, and when we last used it.
- If you signed in with Google, the link between your account here and your Google account. Section 4 sets out exactly what that is.
If you use the developer API
- For each API key: the name you gave it, its first few characters, a one-way hash of the key itself, its permissions, when it was last used, and whether you revoked it. The key is shown once and never stored in a form we can read back.
Keeping the service up
- Rate-limit counters against your account id and your IP address. They live in memory at our Redis provider for minutes, and are never written to the database.
- A record of any action an administrator took on your account.
We do not store card or payment details, a billing address, a marketing profile, an advertising identifier, precise location, or anything about what you went on to buy.
Everything we hold about events, venues, performers, prices and availability is public information about the ticket market. It is not about you, it is not linked to you, and this notice does not cover it.
4. Signing in with Google
Signing in with Google is optional. Email and password works just as well, and nothing in the product is reserved for Google accounts.
When you choose it, we ask Google for three permissions and no others: openid, which lets Google tell us you signed in; email, which gives us your email address and whether Google has verified it; and profile, which gives us your name and profile picture. Google sends us your email address, your name and profile picture, and the permanent account identifier Google uses for you. We ask for nothing else — not your contacts, not your calendar, not your Google Drive, and no permission to act on your behalf anywhere.
We never receive your Google password, and you never type it into this site. You sign in at Google, and Google tells us the result.
What we keep. We store the link between your account and your Google account: Google's identifier for you, that the provider was Google, and the sign-in tokens Google issued for that connection. Your email address, name and picture are saved to your account in the ordinary way, as section 3 describes.
Two ways in, one account. If you already have an account here under the same email address, signing in with Google joins that Google account to it rather than making a second one, because we treat Google as a trusted way of proving that address is yours. Google will not be joined to an account under a different address. The practical effect is that you can sign in either way and land in the same place, with the same watches.
You can stop using Google at any time by setting a password and signing in with that instead, and you can withdraw our access from your Google account's own permissions page. Doing so does not delete your ticket.watch account; section 12 explains how to do that.
5. Why we are allowed to store it
- Because you asked for the service (UK GDPR Article 6(1)(b), contract). Your account, your watches, the checks we run for them, and the alerts we send you. Sign-in with Google, if you choose it, is part of running your account. Without this data there is no service to give you.
- Because you consented (Article 6(1)(a), and PECR for the messages). Text messages, after you have verified your number and switched them on. Push alerts, after you allow them in your browser. You can withdraw either at any moment in settings, in one click — no harder than switching it on — and withdrawal affects nothing else about your account. Analytics cookies are used only with your acceptance (see section 10).
- Because we have a legitimate interest (Article 6(1)(f)). Rate-limit counters, the IP address and user-agent on a session, delivery records, and administrator action records — the minimum needed to keep the service available, to show you what we sent, and to stop abuse. We think you would expect all of it; if you disagree, section 12 gives you the right to object and we will hear it.
We hold no special-category data. We build no profile of you, and we make no automated decision that has a legal or similarly significant effect on you.
6. What we do with it
We run your account, check the sellers you asked us to check, send you the alerts you asked for, answer your support email, and keep the service working and unabused. We also use Google Analytics to understand visits to public pages, as section 10 explains.
We do not sell your personal data, share it for advertising, rent it, trade it, or use it to build a profile of you. Nobody outside the suppliers in section 8 gets it, and they get only what their job needs.
7. How long we keep it
| What | How long |
|---|---|
| Your account, your watches and your settings | Until you delete your account |
| The text of an alert we sent you (subject and body) | 30 days, then blanked; the record that we sent it survives |
| The record that we sent you an alert | 180 days |
| An expired sign-in session, with its IP address and user-agent | 7 days after it expires |
| A sign-in or password-reset token | 1 day after it expires |
| A phone-verification record | 30 days |
| A device you turned push alerts on for, after its push address stops working | 30 days from the first failure |
| A device you turned push alerts on for, that we have not sent to | 180 days from its last use |
| The email address and wording of an event request you sent us | 365 days from the request, once it has been answered, declined or found to be a duplicate; then both are blanked and only the anonymous record of the demand remains |
| A record of an action an administrator took on your account | 90 days |
| Rate-limit counters | Minutes to an hour; they expire automatically and are never written to the database |
| Everything attached to your account, when you delete the account | Immediately, by database cascade |
These are not aspirations. Each row is enforced by a scheduled job that runs every night, and each is set in code next to the rule that makes it true.
Two honest exceptions. A backup taken before you deleted your account may still contain your data until that backup is rotated. And if you sent us a request to add an event we do not yet cover, deleting your account unlinks that request from you but does not immediately blank the email address you gave with it; that happens on the schedule in the table above, a year after the request is closed. If you want it gone sooner, ask us and we will do it by hand.
8. Who else sees it
We use these suppliers to run the service. Each acts on our instructions, for the purpose named and no other.
Suppliers that handle your personal data
- Vercel — Hosts the website and scheduled jobs in Stockholm.
- Our own PostgreSQL database — Stores account and service data in Helsinki.
- Upstash — Stores temporary rate-limit counters in its EU Redis region.
- Twilio — Sends opted-in SMS alerts.
- Forward Email — Sends alert email over SMTP.
- Google — Provides optional Google sign-in and Google Analytics for public-page measurement, with analytics cookies only after acceptance.
- Browser push services — Deliver a push alert to a device you turned push on for. Google, Mozilla, Microsoft or Apple runs the one your browser chose. It sees the subscription address for that device; the alert text is encrypted so that only your device can read it.
Suppliers that never receive your personal data
- Browserbase — Obtains sessions from public ticket-seller pages. It never learns your user id, your email, your phone number or what you are watching.
- IPRoyal — Carries checks to sellers over a UK residential network. It never learns your user id, your email, your phone number or what you are watching.
Those last two carry the anonymous checks described in section 2, not your data. Beyond this list, we disclose personal data only where the law requires it of us — a court order, or a statutory request we are obliged to answer — and we will tell you if that happens unless we are forbidden to.
9. Where your data lives, and when it leaves the UK
Your account and everything attached to it sit in a PostgreSQL database in Helsinki, Finland. The website and its scheduled jobs run in Stockholm, Sweden. Rate-limit counters sit in our Redis provider's EU region. Finland and Sweden are covered by the UK's adequacy regulations for the European Economic Area, so data resting there needs no further safeguard.
Some suppliers are United States companies and personal data reaches them there or in transit. Twilio, when we text you. Google, for optional sign-in and public-page Analytics. Your browser's push service, when we push an alert to your device. For each of these we rely on the UK Extension to the EU–US Data Privacy Framework where the supplier is certified under it, and on the Information Commissioner's International Data Transfer Agreement where it is not. Email support@ticket.watch naming a supplier and we will tell you which of the two applies to it and send you a copy of the terms.
10. Cookies and browser storage
We use Google Analytics on public pages while you are signed out. Consent Mode starts with analytics storage and all advertising permissions denied. Before you accept, or if you decline, Google can receive cookieless measurement pings, including the public page address and browser information; your IP address is visible to Google when your browser connects. Neither analytics cookie below is written until you accept. We do not attach your account details to Analytics, and do not enable advertising signals. The small choice control lets you accept or decline without interrupting reading.
The session, appearance, sign-in and push-snooze entries above support services or settings you asked for. Analytics cookies are optional and require acceptance. Blocking essential cookies can sign you out or lose your appearance choice. If your browser blocks local storage, we cannot remember an analytics decision across visits.
To change your analytics choice, clear this site's local storage and its analytics cookies in your browser settings, then reload a public page. Analytics storage starts denied again and the control returns. A refusal otherwise has no expiry.
11. Email, SMS and push, and how to stop them
Every alert email has a one-click unsubscribe link and the standard unsubscribe headers, so your mail client's own unsubscribe button works. You can also switch email off in settings. We will still send you the occasional message your account needs — a password reset you asked for, or a notice that your password changed — because those are not marketing and you cannot be left unable to recover your account.
You receive SMS only after verifying your number and switching SMS on. Switch SMS off in your settings to stop them; it takes effect at once.
Standard network rates apply. We never charge for a message and never send marketing by SMS; every text is an alert you asked for.
Push alerts go only to a device where you allowed notifications. Turn push off in settings, or revoke notification permission in the browser, and we stop; a device that rejects our alerts is dropped automatically on the schedule in section 7.
12. Your rights
Under UK GDPR you may ask us to:
- Give you a copy of the personal data we hold about you, and tell you what we do with it (Article 15).
- Correct anything wrong or incomplete (Article 16).
- Erase it (Article 17).
- Restrict what we do with it while a dispute is resolved (Article 18).
- Send it on to you or to someone else in a machine-readable form (Article 20).
- Stop processing you object to, where we rely on legitimate interests (Article 21).
- Withdraw consent to SMS, push or analytics cookies (see section 10), at any time, without giving a reason (Article 7(3)).
Two of these you can do yourself, immediately, in settings: withdraw SMS or push consent, and delete your account. Deleting removes:
- Your watches, and any alerts still pending on them
- Your performer follows
- Your saved music genres
- Your notification history
- Your phone number and its verification
- Any devices you've turned push alerts on for
- Your sign-in credentials and sessions
- Your API keys
- This is permanent and cannot be undone.
- Public event and platform data we collected is not personal to you and stays.
For anything else, email support@ticket.watch. We respond within one month, as the law requires, and we charge no fee. If a request is unusually complex we may take up to two further months, and we will tell you within the first month if that happens and why.
If we get it wrong, tell us first and we will try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at any time and without asking us first. Our ICO registration number is [to be confirmed].
13. Security, and what we do if something goes wrong
Every page and every API call is served over HTTPS. Passwords are one-way scrypt hashes. Verification codes and API keys are stored hashed, and the tokens in alert links are random opaque values that reveal nothing. Session cookies are HTTP-only and same-site. Database access is limited to the service and to us.
No system is perfect. If personal data is ever breached in a way that risks your rights, we will report it to the ICO within 72 hours as Article 33 requires, and we will tell you directly, without delay, whenever the risk to you is high.
14. Age
This service is for adults. Our terms require you to be 18 or over, we do not aim the service at children, and we do not knowingly hold data about one. If you believe a child has an account here, tell us and we will delete it.
15. Changes to this notice
When we change this notice we change the effective date at the top. If a change is material — a new purpose, a new supplier that handles your data, a shorter answer to one of your rights — we will email the address on your account and tell you before it takes effect. We will not treat your silence as agreement to anything.