Privacy
Last updated 5 September 2026. Operated by Needs your details — set entity in src/lib/legal.ts.
What Tikit stores
Tikit is a ticketing platform. It stores what it needs to sell a ticket and let someone through a door, in its own database:
- Buyers: your name, mobile number and email from checkout; your orders and tickets, including the seat on each ticket for a seated event; which tracking link, if any, you arrived from; and whether and when each ticket was scanned at the door. If you use Find my tickets, an account is created under your email with no password. If you pass a ticket to someone else, the name, email address and mobile number you give for them are stored with that ticket, together with the email address it came from.
- Promo codes: if you use one at checkout, the code is kept on your order so the organiser can see which codes were used and what they took off.
- Organisers: your name, email, mobile number and a password hash; your organiser profile and logo; your events, ticket tiers and cover images; your bank details (account number, holder and bank) for payouts; your entity type and company registration number; the name of the director signing and the last four digits of their ID number (never the full number); and the results of verification checks.
- Everyone with an account: a session cookie so you stay signed in, the device and IP address of each session (shown to you under Settings → Security), notification preferences, and an activity log of things you did.
- Door staff: a name, a hashed PIN, and a log of every scan they made.
- Team members: the email address an organiser invites, the role they were given, who invited them, and when they joined.
- Connected apps: which AI assistants you authorised, and a log of every call they made as you, reads included.
- Signing in with Google: if you choose Continue with Google, Tikit stores the name, email address and profile picture Google shares, together with the sign-in token Google issues for that link, and nothing else from your Google account. Google sees that you signed in to Tikit. You can disconnect Google under Settings → Security once you have a password.
What it does not store
Tikit never sees or stores your card number; payment happens on the payment provider's pages. The full ID number submitted for verification is passed to the verification partner and not kept.
Who else sees it
- The organiser of an event you buy tickets for sees your name, email and mobile number, so they can run the event and contact you about it.
- People an organiser adds to their team can see that organiser's events, orders and buyers' contact details according to their role: a manager sees orders and can refund them; door staff see only the attendee list and the scans.
- The person you pass a ticket to sees your first name in the email that brings them the ticket, and the organiser sees their name and contact details on the attendee list. If they pass it on again, the next person sees their name, not yours.
- Paystack processes payments, refunds, organiser payouts and bank account verification. Resend delivers email. Meta (WhatsApp) and Clickatell (SMS) deliver tickets to your phone. Inngest runs background work such as sending tickets and scheduling payouts. Verification partners check company registrations, ID numbers and bank accounts. Each receives only what that job needs. Until a partner is connected, a built-in stand-in records the message or check instead of sending it anywhere.
- An AI assistant you connect (such as Claude) can read your organiser data and add ticket tiers on your behalf, within the permissions you approved. You can see and revoke this under Settings → Connected apps.
- Hosting: the database and uploaded images live with the hosting provider the operator has chosen.
Tikit does not sell personal information and does not run advertising.
Cookies
Tikit sets a session cookie when you sign in or use Find my tickets. Your light or dark mode choice is kept in your browser's own storage, not in a cookie. It loads no analytics, no tracking pixels and no third-party embeds, which is why there is no cookie banner.
Emails and messages
Tickets, receipts, refund notices, sign-in codes, password emails and account confirmations are sent because you asked for something; they are not marketing and carry no unsubscribe link. Organisers can turn sale alerts, the daily digest and payout updates on or off under Settings → Notifications.
Your data
- Download it: Settings → Account → Download my data returns everything you created as a file.
- Correct it: your name, phone and photo under Settings → Profile; your organiser profile and bank details under Organiser profile; your email under Settings → Account.
- Delete it: Settings → Account → Delete account. Deletion is immediate and permanent once you confirm the emailed link. It removes your sign-in, sessions and connected apps and, for an organiser, the draft events, every uploaded image, and the contact, bank, verification and ID details. Tickets already sold or bought are kept, with the organiser name on them and the event they are for, because the other party to those tickets still needs them; the activity log keeps an anonymised line so that "who cancelled this event" still has an answer. An organiser cannot delete while buyers hold tickets for an event that hasn't happened yet, while money is owed either way, or while team members are still attached.
Tikit does not apply a fixed retention period to logs; they are kept until the operator prunes them.
Security
Everything travels over HTTPS. Passwords are stored as hashes. Door-staff PINs are stored as hashes. Ticket QR codes are signed so they cannot be forged.
Contact
Questions or requests about your data: Needs your details — set contactEmail in src/lib/legal.ts.