Privacy policy

This page is available in English only. The English version prevails.

Last updated 19 September 2026 · Effective 1 October 2026
1. What we collect 2. How we use it 3. Sharing and third parties 4. Cookies and similar technologies 5. How long we keep it 6. Your rights 7. Security 8. Children 9. International transfers 10. Changes and contact

1. What we collect

We collect only what is needed to sell you a ticket and get you through the door. It comes from three places:

SourceDataWhy
You give it to usDisplay name, email, mobile number, attendee names Account creation, ticketing and entry checks
Created by a purchaseOrders, ticket tier, amount, payment method, refunds Fulfilling the sale and handling support
Collected automaticallyDevice model, OS, browser, IP address, page logs Fraud prevention, debugging, stopping bulk bots

We do not collect full card numbers or CVV codes — those go straight to the payment provider, and we only ever see the last four digits and the result. We also do not collect biometrics, your contacts, or precise location.

2. How we use it

We do not sell your personal data, and we do not use it for third-party ad targeting.

3. Sharing and third parties

We share only where it is necessary, and only on terms at least as strict as this policy:

RecipientWhat they getPurpose
Payment providers
(card acquirer, PayPal)
Order reference, amount, currency Taking payment and issuing refunds
Promoters and venuesAttendee name, ticket tier, entry pass Issuing tickets and checking entry
Cloud, SMS and email providersWhatever the message requires Running the platform and delivering notifications
Courts and regulatorsWhat the law requires Meeting legal obligations

4. Cookies and similar technologies

Three kinds. The first two are required for the site to work and cannot be switched off:

You can clear this site's data at any time. Doing so also removes your session and any locally stored order history.

5. How long we keep it

6. Your rights

You can exercise any of these at any time. We respond within 15 working days.

7. Security

HTTPS across the whole site. Passwords are salted and hashed, never reversible. Payment data is handled by a PCI DSS certified provider; full card numbers never land on our servers. Internal access follows least privilege and is audited. In the event of a breach we will notify affected users and the relevant regulator within 72 hours.

8. Children

Accounts are not offered to children under 14. Users aged 14 to 18 should have a guardian's consent. If we discover we have collected a child's data without that consent, we delete it promptly.

9. International transfers

Shows are staged in Singapore, Hong Kong, Macau, South Korea and mainland China, so attendee names and similar details must be passed to the local promoter or ticketing system in order to issue a ticket. We say so on the checkout page and transfer only the minimum fields needed.

10. Changes and contact

If this policy changes materially — for instance if we start collecting more, or share with someone new — we will post a notice on the site and email you 7 days before it takes effect. Continuing to use Tickyo means accepting the updated policy.

Privacy questions: privacy@tickyo.com
Data protection contact: Tickyo Data Compliance

See also the refund and support policy.