Privacy Policy
Privacy Policy
Last updated 28 August 2026
Who we are
This site is operated by Jarboom Ltd (“we”, “us”), trading as WTF Tickets, the data controller for the personal information described below.
[Registered company number, registered office address, and ICO registration number to be added here.]
What we collect
When you buy a ticket or contact us, we collect:
- Your name, email address, phone number and postcode.
- For group bookings, the same details for each person attending under your order, plus their age where an event requires it (e.g. an 18+ event).
- Order and payment records — what you bought, when, and for how much.
- If you request accessible or carer ticket pricing: the evidence document you upload, and the outcome of our review of it. See “Carer and Access evidence” below — we treat this category of data with extra care.
- Ordinary technical data any website collects to run properly: IP address, browser type, and pages visited.
We do not currently use advertising or analytics cookies (Google Analytics, Meta Pixel, TikTok Pixel). If we turn any of these on in future, we’ll ask for your consent first via a cookie banner, and update this policy before we do.
Why we use it, and our legal basis
- To fulfil your order — process payment, issue your ticket, and email your confirmation. Legal basis: performance of a contract with you.
- To run the event safely — entry checks, age verification, capacity management. Legal basis: performance of a contract, and our legitimate interest in running a safe event.
- To review accessible/carer ticket requests — legal basis: your explicit consent, given when you tick the declaration and upload your evidence.
- To prevent fraud and keep our records straight — legal basis: legitimate interest, and legal obligation (financial and tax records).
- To email you about your order (confirmations, reminders, replacement links) — legal basis: performance of a contract. We do not send you marketing email unless you separately opt in.
- To keep one operational record of ticket buyers (Mailchimp) — legal basis: legitimate interest. You’re only ever sent a Mailchimp marketing campaign if you ticked the marketing box at checkout; see “Who we share it with” below.
Carer and Access evidence
If you request a Carer or Access ticket, we ask you to upload evidence (for example a PIP/DLA/ADP award letter, a medical letter, or an access card) so we can verify eligibility for that pricing. This is “special category” data under UK GDPR, and we handle it accordingly:
- We only ever ask for evidence of eligibility — never a diagnosis, medication, or your NI number.
- Your file is stored privately and is never publicly accessible by a direct link.
- Only staff with a specific permission for this review queue can open it — not everyone who can see your order.
- Every time a member of our team views your file, that access is logged.
- We automatically delete the file after a set retention period (90 days by default, shown to you at the point of upload, and confirmed per event) — we don’t keep it indefinitely “just in case”.
- Approving or rejecting your evidence never automatically cancels or changes your ticket — that stays a separate decision, and we’ll always contact you directly first.
How long we keep your data
- Orders, tickets, payments and refunds are never deleted — we’re legally required to keep financial records, typically for at least six years.
- Carer/Access evidence files are automatically and permanently deleted after the retention window shown to you at upload (90 days by default).
- Your account/contact details are kept while you have an active order history with us, or until you ask us to remove them (see “Your rights” below) — subject to what we need to keep for the financial records above.
Who we share it with
We do not sell your personal data, and we do not share it with other companies for their own marketing purposes. We do use a small number of specialist companies to actually run the service, each acting under contract as our processor, only for the purpose of providing that service to us:
- Stripe — processes your payment. We never see or store your full card details.
- Supabase — hosts our database and the private storage used for Carer/Access evidence files.
- Vercel — hosts this website.
- Resend — sends your order confirmation and other account-related emails on our behalf.
- Mailchimp — holds our operational record of ticket buyers. Everyone is added in a “transactional” status that Mailchimp itself blocks from ever receiving a marketing campaign; you’re only moved into marketing status if you separately ticked the marketing box at checkout, and you can unsubscribe at any time from any marketing email you do receive.
[List each processor’s data processing agreement / location of data storage here once confirmed.]
We may also disclose information where we’re legally required to (for example, to law enforcement or a regulator), or to protect our rights, safety, or the safety of others.
Cookies
We use a small number of strictly necessary cookies — to remember your basket while you check out, and to keep you securely signed in to manage your booking. These don’t require your consent under UK law, and can’t be switched off, because the site can’t function without them. We do not currently set any analytics, advertising, or tracking cookies.
Your rights
Under UK GDPR, you have the right to:
- Ask us what personal data we hold about you, and get a copy of it.
- Ask us to correct anything that’s inaccurate.
- Ask us to delete your data, where we’re not required to keep it (see above).
- Object to, or ask us to restrict, certain processing.
- Ask for your data in a portable format.
- Complain to the Information Commissioner’s Office (ICO) if you think we’ve got something wrong.
To exercise any of these, email us at [privacy contact email]. We’ll respond within one month.
Security
We use industry-standard measures to protect your data: encrypted connections, access controls that restrict staff to only what their role needs, and an audit trail of sensitive actions like viewing Carer/Access evidence. No system is 100% secure, but we take this seriously and review it regularly.
Children
This site isn’t aimed at children. Where an event has a minimum age, we ask for a date of birth or age confirmation only to enforce that entry requirement — not for any other purpose.
Changes to this policy
We’ll update this page if how we handle your data changes, and update the “last updated” date at the top. For anything material — like starting to use tracking cookies — we’ll be clearer about it than just editing this page quietly.
Contact us
Questions about this policy or your data: [privacy contact email]
