TicketsByFomo
Sign inCreate account
TicketsByFomo
Browse eventsMy ticketsContact
TermsPurchase PolicyRefundsPrivacyCookiesYour Privacy ChoicesAccessibilityAll legal

© 2026 Vadelis Labs Inc. · TicketsByFomo · Payments secured by Square

All legal documents

Buying tickets

  • Terms of Use
  • Purchase Policy
  • Refunds

Privacy and data

  • Privacy Policy
  • Cookies
  • Your Privacy Choices

Using the platform

  • Acceptable Use
  • Copyright / DMCA
  • Organizer Agreement

Accessibility and security

  • Accessibility
  • Security

Cookie Policy

Effective August 25, 2026

We use a short list of first-party cookies — most of them are the ones that make signing in and checking out work at all. No advertising cookies, and no third-party ad networks.

This Cookie Policy explains the cookies and similar technologies used on the Service, and how to control them. It supplements our Privacy Policy.

We do not use advertising cookies. No ad network, data broker, or social platform sets a cookie through the Service, and we do not build advertising profiles or share cookie data for cross-context behavioural advertising.

Contents

  1. 1.What cookies are
  2. 2.Strictly necessary cookies
  3. 3.Analytics and attribution cookies
  4. 4.Third-party content
  5. 5.Offline check-in storage
  6. 6.Your choices
  7. 7.Changes and contact

1.What cookies are

A cookie is a small text file a website asks your browser to store, and hands back to the site on your next request. Cookies are how a website remembers that you are signed in between one page and the next.

  • First-party cookies are set by the site you are visiting. Every cookie we set is first-party.
  • Session cookies are erased when you close your browser. Persistent cookies last for a stated period.
  • Strictly necessary cookies are required for the site to function — you cannot turn them off and still buy a ticket.

We also use local storage on the check-in application, so that staff can keep scanning tickets when venue signal drops. That is not a cookie and is never used for tracking — see Offline check-in.

2.Strictly necessary cookies

These make the Service work. Blocking them will break sign-in, checkout, or ticket scanning.

CookiePurposeLifetime
authjs.session-token (__Secure- prefixed over HTTPS)Keeps you signed in. Contains a signed token identifying your account and role. HTTP-only, so page scripts cannot read itSession, up to 30 days
authjs.csrf-token (__Host- prefixed over HTTPS)Protects sign-in and account forms against cross-site request forgerySession
authjs.callback-urlRemembers where to send you after you sign inSession
tbf_flashCarries a one-off confirmation message across a redirect, so you see “Saved” after an action completes. Cleared as soon as it is shown60 seconds
tbf_gate_deviceIdentifies a phone or tablet that event staff enrolled as a ticket scanner. HTTP-only. Only set on staff devices, never on a buyer’s browserUntil the event access code expires
tbf_oauth_stateProtects the administrator flow that connects a payment processor. Only set for administrators, and deleted the moment the connection completesA few minutes

3.Analytics and attribution cookies

These help us understand how the Service is used and which campaigns bring people to an event. They are not required for the Service to work, and you can switch them off — see Your choices.

CookiePurposeLifetime
tbf_ftFirst-touch attribution. Records the campaign parameters, referring site, and landing page of your first attributed visit, so a purchase can be credited to the right campaign. Set only when you arrive with campaign parameters or from an external site — a plain direct visit sets nothing30 days
ph_… _posthogOur analytics provider’s cookie. Holds a random identifier for your browser and basic session state so that a sequence of page views can be counted as one visitUp to 12 months

Session replay

Our analytics provider records a reconstruction of some browsing sessions so we can see where the interface confuses or fails people. Every text input is masked — names, email addresses, phone numbers, and anything else you type into a field are not captured. Card details are entered on the payment processor’s own fields and never appear in a replay at all.

Turning off analytics, as described below, turns off session replay too.

4.Third-party content

Analytics requests are proxied through our own domain rather than being sent directly to the provider, so they are not blocked by network filters and no additional third-party host is contacted from your browser.

Where you pay by card, the payment fields are supplied by Square or Stripe and may set cookies of their own for fraud prevention and to keep the payment session alive. Those are governed by that processor’s own privacy and cookie policies. We cannot switch them off — they are part of taking a payment safely.

Where our ticket widget is embedded in an Event Organizer’s website, that site sets its own cookies. They are not ours and are covered by that site’s cookie policy.

5.Offline check-in storage

The check-in application used by event staff can download a manifest of an event’s tickets to the device, so scanning keeps working when venue signal drops. That manifest is held in browser storage on the staff device, contains only what is needed to validate a ticket at the door, and is reconciled with our servers as soon as the device reconnects.

This is staff-only. Nothing comparable is stored on a ticket buyer’s device.

6.Your choices

Global Privacy Control

If your browser or extension sends a Global Privacy Control signal, we treat it as an opt-out request. We do not sell or share personal information, so there is nothing to stop on that front — but where we detect the signal we also switch off analytics and session replay for that browser automatically. You do not need to do anything else.

Browser settings

Every major browser lets you see the cookies a site has set, delete them, and block future ones. Look under Privacy or Site settings. Blocking all cookies will prevent you from signing in or completing a purchase.

Do Not Track

There is no agreed industry standard for how a site should respond to a Do Not Track header, so we do not act on it. We do act on Global Privacy Control, as described above.

7.Changes and contact

We update this policy when the cookies we use change. The effective date at the top reflects the current version.

Questions about cookies: support@fomotickets.com.

This document is part of the TicketsByFomo legal collection. Each document links to the others where they overlap.

PreviousPrivacy PolicyNextYour Privacy Choices