TicketsByFomo
Sign inCreate account
TicketsByFomo
Browse eventsMy ticketsContact
TermsPurchase PolicyRefundsPrivacyCookiesYour Privacy ChoicesAccessibilityAll legal

© 2026 Vadelis Labs Inc. · TicketsByFomo · Payments secured by Square

All legal documents

Buying tickets

  • Terms of Use
  • Purchase Policy
  • Refunds

Privacy and data

  • Privacy Policy
  • Cookies
  • Your Privacy Choices

Using the platform

  • Acceptable Use
  • Copyright / DMCA
  • Organizer Agreement

Accessibility and security

  • Accessibility
  • Security

Privacy Policy

Effective August 25, 2026

A complete account of the personal information we handle — for ticket buyers, attendees, event organizers, and anyone browsing the site — written against what the platform actually does.

This Privacy Policy explains how Vadelis Labs Inc., the operator of TicketsByFomo and FOMOtickets, collects, uses, shares, and protects personal information, and what choices you have. It applies to our websites, our embedded ticket widgets, the tickets and emails we send, and the check-in applications used at events.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not run advertising on the Service, and we do not pass your details to advertising networks or data brokers.
The short version
What we collectYour name, contact details, what you bought, answers to questions the event organizer asked, and technical information about your visit.
WhyTo sell you a ticket, get you into the event, support you afterwards, keep the platform secure, and meet our legal obligations.
Who sees itThe organizer of the event you bought into, and the service providers listed in this policy. Nobody else, unless the law requires it.
Card detailsNever touch our systems. They go straight to Square or Stripe.
Your rightsAccess, correction, deletion, portability, and more — see Your rights and Your Privacy Choices.

Contents

  1. 1.Who this policy covers
  2. 2.Our role: controller and service provider
  3. 3.What we collect
  4. 4.Sensitive information
  5. 5.How we use information, and on what basis
  6. 6.Who we share information with
  7. 7.Cookies and tracking technologies
  8. 8.Email and your choices about it
  9. 9.How long we keep information
  10. 10.How we protect information
  11. 11.Your privacy rights
  12. 12.United States state privacy notices
  13. 13.Children
  14. 14.Where information is held, and international users
  15. 15.Other sites and embedded widgets
  16. 16.Changes to this policy
  17. 17.Contact us

1.Who this policy covers

This policy applies to four groups of people:

Ticket buyers
Anyone who buys a ticket, registers for an event, or joins a waitlist through the Service.
Attendees
Anyone whose name or details a buyer entered on a ticket, and anyone checked in at the door.
Event Organizers and their staff
People with an account that lets them create events, sell at the door, or scan tickets.
Visitors
Anyone browsing the site or an embedded ticket widget without buying anything.

It does not cover what an Event Organizer does with your information on its own systems once we have passed it to them, or the practices of any other website — including a site that embeds our ticket widget. Those are governed by their own privacy policies.

2.Our role: controller and service provider

Our role changes depending on whose information it is and why we hold it.

We are the controller
for your account, your login and security records, your transaction history with us, the technical records of your visit, our own analytics, and our fraud and abuse prevention. We decide why and how that information is used, and this policy governs it.
We act as a service provider (processor) for the Event Organizer
for information collected specifically for their event — attendee names, answers to the questions they configured, waivers they wrote, check-in records, and their attendee lists. They decide what to ask and what to do with the answers. We process it on their instructions to run the event, and we do not use it for our own purposes.

Where we act as a service provider, requests about that information may need to go to the Event Organizer. Send the request to us anyway — we will act on it where we can and route it where we cannot, and we will tell you which happened.

Whichever hat we are wearing, we never sell attendee information, never share it for advertising, and never use one Event Organizer’s attendee list to market another Event Organizer’s events.

3.What we collect

Information you give us

CategoryWhat it includesWhen
Identifiers and contact detailsFirst and last name, email address, phone number.Creating an account, checking out, joining a waitlist, contacting support.
Account credentialsA one-way hash of your password (never the password itself), email verification and password reset tokens.Registering, signing in, resetting a password.
Billing and address informationHome or billing address, where the event is configured to collect one.Checkout, for events that require it.
Order informationWhat you bought, quantities, ticket types, add-ons, discount codes used, amounts, fees and tax, and the payment processor’s reference for the payment.Every purchase.
Attendee detailsThe name — and sometimes email or phone — of each person a ticket is for.Checkout, where the event requires named tickets.
Answers to organizer questionsWhatever the Event Organizer chose to ask: dietary needs, accessibility requirements, affiliations, free text.Checkout, for events with custom questions.
Waivers and signaturesThe version of the waiver you accepted, the legal name you typed, and the time you accepted it.Checkout, for events with a waiver.
Support correspondenceThe content of your messages to us and our replies.When you contact us.

Information we collect automatically

  • Device and connection data — IP address, browser and operating system, and the user agent string. The IP address and user agent of a purchase are stored with the order as a fraud and dispute record.
  • Usage data — pages viewed, events viewed, checkout steps reached and abandoned, and other interactions with the Service.
  • Referral and campaign data — the site you arrived from, the page you landed on, and any campaign parameters in the link you followed. We store the first attributed visit in a cookie for 30 days so that we can credit the right campaign for a purchase. See the Cookie Policy.
  • Session replay — our analytics provider records a reconstruction of some browsing sessions so we can see where the interface fails people. Every text input is masked, so names, email addresses, phone numbers, and anything else typed into a field are not captured, and card entry happens on the payment processor’s own fields and never appears at all.
  • Security records — sign-in attempts, rate-limiting counters keyed to an IP address or account, and audit records of check-in scans (which device, which operator, and when).

Information we receive from others

  • From payment processors — whether a payment succeeded, failed, or was refunded, the processor’s payment identifier, and the payment method type. We do not receive your full card number, expiry date, or security code.
  • From our email provider — whether a message was delivered, bounced, or was reported as spam, so we can stop sending to addresses that reject our mail.
  • From Event Organizers — details of a sale made at the door, and any attendee information they add on your behalf.

What we deliberately do not collect

  • Full payment card numbers, expiry dates, or security codes.
  • Social security or other government identification numbers.
  • Precise geolocation. We never ask for device location.
  • Biometric identifiers. Scanning a ticket reads a QR code, not a face.
  • Information about your activity on other websites or apps.

4.Sensitive information

We do not ask for sensitive personal information for our own purposes, and we do not use or disclose it to infer characteristics about you.

An Event Organizer may configure a checkout question whose answer is sensitive — an accessibility requirement, a dietary restriction that implies a religious belief, a health condition relevant to a waiver. Where that happens:

  • you choose whether to answer, unless the Event Organizer has made the question required for entry;
  • the answer is used only to run that event, and is visible to that Event Organizer and to staff working that event; and
  • we hold it as a service provider, on the Event Organizer’s instructions, and use it for nothing else.

Please do not enter sensitive information into a free-text field where it is not being asked for.

5.How we use information, and on what basis

What we doWhyLegal basis (where GDPR applies)
Take your order, hold inventory, charge your card, issue tickets, email confirmations and tickets, admit you at the door, process refundsTo perform the contract you entered into when you bought a ticketPerformance of a contract
Give the Event Organizer the attendee list and answers for its eventSo the event can actually be runPerformance of a contract; legitimate interests
Answer support requests and handle complaints and disputesTo provide the service you asked for and defend claimsPerformance of a contract; legitimate interests
Detect and prevent fraud, bot purchasing, ticket-limit evasion, duplicate scans, and abuse; keep accounts secureTo protect buyers, Event Organizers, and the platformLegitimate interests; legal obligation
Understand how the Service is used, fix what is broken, and improve itTo make the product work betterLegitimate interests
Report aggregate sales, attendance, and campaign performance to Event OrganizersTo give organizers the numbers for their own eventsLegitimate interests
Send you marketing about events, where you have asked for itTo tell you about things you said you wanted to hear aboutConsent
Keep records for tax, accounting, and audit; respond to lawful requestsBecause we are required toLegal obligation

We do not use your information to make decisions about you with legal or similarly significant effects by automated means alone. Automated fraud checks may flag an order, but a person reviews before an order is cancelled on that basis.

6.Who we share information with

Event Organizers

When you buy a ticket, the Event Organizer for that event receives your name, email address, phone number if you gave one, what you bought, and your answers to their questions and waivers. They need it to run the event, admit you, and contact you about it.

Event Organizers are contractually required to use that information only for their event, to keep it secure, to comply with privacy law, and not to sell it. What they do with it on their own systems is governed by their privacy policy, not ours. See the Organizer Agreement.

Service providers

We use a small number of providers to run the Service. Each is bound by contract to process information only on our instructions and to protect it. All of them store data in the United States.

ProviderWhat they do for usLocation
Vercel Inc.Hosts and delivers the application; serves pages and API requests, and holds short-lived request logsUnited States
Supabase Inc.Hosts the database that holds accounts, orders, and tickets, and the storage bucket that holds event imagesUnited States
Square, Inc. or Stripe, Inc.Processes card payments and refunds; captures card details directly, so they never reach us. Only one processor is active at a timeUnited States
Twilio SendGridDelivers transactional email — order confirmations, tickets, verification, password resets, refund notices — and reports delivery outcomesUnited States
PostHog Inc.Product analytics and masked session replayUnited States
Upstash Inc.Rate limiting on sign-in and other sensitive endpoints, to blunt brute-force and abuseUnited States

Others

  • Legal and safety disclosures. We disclose information where we are legally required to — a subpoena, court order, or lawful request from a regulator or law enforcement — and where necessary to investigate fraud, enforce our terms, or protect the rights, property, or safety of any person. We review each request and disclose no more than is required.
  • Professional advisers. Our lawyers, accountants, insurers, and auditors, under duties of confidentiality.
  • Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will tell you before your information becomes subject to a different privacy policy.
  • With your direction. Where you ask us to share something with someone.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act and comparable state laws. We have not done so in the preceding 12 months, and we do not knowingly sell or share the personal information of anyone under 16.

7.Cookies and tracking technologies

We use a small set of first-party cookies for signing in, for security, and for analytics and campaign attribution. We do not use advertising cookies and we do not allow third-party ad networks to set cookies through the Service.

The full list, with purposes and lifetimes, and how to control them, is in the Cookie Policy.

8.Email and your choices about it

Service email
Order confirmations, tickets, verification and password reset messages, event change and refund notices. These are part of the service and you cannot unsubscribe from them while you hold an active order — without them you would not receive your tickets.
Marketing email
Sent only where you have opted in. Every marketing message carries an unsubscribe link that works immediately, and you can also ask us to remove you at any time.
Event Organizer email
An Event Organizer may email you about its own event. Marketing from an Event Organizer is their responsibility and their unsubscribe link; we require them to honour opt-outs.
Suppression
If mail to your address hard-bounces or is reported as spam, we add it to a suppression list and stop sending to it. This protects delivery for everyone. Contact us to have an address reinstated.

9.How long we keep information

We keep personal information only as long as we need it for the purpose it was collected, plus any period the law requires.

InformationHow long
Order, ticket, refund, and payment recordsAt least 7 years after the event, for tax, accounting, audit, and dispute purposes. These records cannot be deleted on request while that obligation runs.
Your account and profileUntil you ask us to delete it, or until it has been inactive for 7 years. Deletion is completed within 45 days of a verified request, except for records we must keep.
Attendee details and answers to organizer questionsFor the life of the event plus the retention period the Event Organizer instructs, and in any case no longer than our order records.
Waivers and signaturesFor as long as a claim relating to the event could be brought, and at least 7 years.
Check-in and scan audit records12 months after the event.
Waitlist entriesUntil the event has passed, or until you ask to be removed.
Email suppression recordsIndefinitely. Deleting a suppression record would cause us to start mailing an address that rejects our mail.
Analytics and session replayGoverned by our analytics provider’s retention settings; replays are kept for a short window and are not linked to an identified person before purchase.
Security logs, rate-limit records, and request logsShort-lived — typically 30 to 90 days — unless retained for an active investigation.

Where we no longer need information but cannot delete it immediately, we isolate it from further use until deletion is possible. Where we keep information for reporting, we aggregate or anonymize it so it no longer identifies anyone.

10.How we protect information

  • All traffic is encrypted in transit with TLS, and data at rest is encrypted by our hosting and database providers.
  • Passwords are stored only as salted one-way hashes. We cannot read your password, and neither can anyone who obtains our database.
  • Payment credentials belonging to an Event Organizer are encrypted with AES-256-GCM using a key held outside the database.
  • Access to production data is limited to the people who need it, by role, and staff and organizer accounts are created by invitation rather than open registration.
  • Sensitive endpoints are rate limited, and every ticket scan is written to an audit record identifying the device and operator.
  • Card data never enters our systems, which materially reduces what an attacker could obtain.

No system is perfectly secure, and we cannot guarantee absolute security. If you believe your account has been compromised, or you have found a vulnerability, see our Security page or write to support@fomotickets.com.

11.Your privacy rights

Depending on where you live, you may have some or all of the following rights. Where a right is available to you under applicable law, we honour it — and where it is not, we will still generally try to help.

Know and access
Ask what personal information we hold about you, where it came from, why we have it, and who we have disclosed it to, and get a copy.
Correct
Ask us to fix information that is wrong or out of date. You can change most of your own details in your account.
Delete
Ask us to delete your information, subject to the records we are required to keep (see Retention).
Portability
Get a copy of the information you gave us in a portable, machine-readable format.
Opt out of sale, sharing, or targeted advertising
We do not do any of these, so there is nothing to opt out of — but the right exists and we confirm our position on request.
Limit the use of sensitive personal information
We do not use sensitive personal information for any purpose beyond providing the service you asked for.
Non-discrimination
We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.
Withdraw consent
Where we rely on your consent, you can withdraw it at any time. That does not affect processing already carried out.
Appeal
If we decline a request, you may appeal by replying to our decision. We will review and respond in writing, and tell you how to contact your state Attorney General if you remain dissatisfied.
Complain to a regulator
You can lodge a complaint with your state Attorney General or, where the GDPR applies, your local supervisory authority.

How to exercise a right. Everything you need — what to send, how we verify you, how long we take, and how authorized agents work — is on Your Privacy Choices.

12.United States state privacy notices

This section supplements the rest of this policy for residents of U.S. states with comprehensive privacy laws, including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as those laws come into effect. It applies to you where the relevant law applies to us.

Categories of personal information

Using the categories defined in the California Consumer Privacy Act, in the preceding 12 months we have collected the following. For each we list the sources, the business purposes (set out in How we use information), and the categories of recipient it is disclosed to for a business purpose.

CCPA categoryDo we collect it?Disclosed for a business purpose to
Identifiers (name, email, phone, postal address, IP address, account ID)YesEvent Organizers; hosting, database, email, payment, and analytics providers
Personal information under Cal. Civ. Code § 1798.80 (name, address, payment record)YesEvent Organizers; payment and database providers
Commercial information (orders, tickets, refunds, purchase history)YesEvent Organizers; payment, database, and analytics providers
Internet or network activity (pages viewed, referral source, campaign parameters, session replay)YesAnalytics and hosting providers
Geolocation dataApproximate only, inferred from IP address for security and fraud prevention. No precise locationHosting and security providers
Audio, electronic, visual, or similar informationNo—
Biometric informationNo—
Professional or employment informationOnly where an Event Organizer asks for it at checkoutThat Event Organizer
Education informationOnly where an Event Organizer asks for it at checkoutThat Event Organizer
Sensitive personal informationOnly where an Event Organizer asks for it, and account credentials, which are held as hashesThat Event Organizer; database provider
Inferences drawn to create a profileNo. We do not build behavioural profiles—

Sale and sharing

We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding 12 months. We do not have actual knowledge of selling or sharing the personal information of consumers under 16.

Global Privacy Control

We recognize a Global Privacy Control (GPC) signal sent by your browser as a valid opt-out request. Because we do not sell or share personal information, there is nothing for the signal to stop on that front — but where we detect it we also switch off optional analytics and session replay for that browser.

Do Not Track

There is no common industry standard for responding to browser Do Not Track signals, so we do not respond to them. We do respond to Global Privacy Control, as described above.

California Shine the Light

California Civil Code § 1798.83 lets California residents ask about personal information disclosed to third parties for their direct marketing purposes. We do not make such disclosures.

Notice of financial incentive

We do not offer financial incentives in exchange for personal information.

13.Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. Accounts require you to be at least 13, and at least 18 unless a parent or guardian accepts the Terms of Use on your behalf.

Where a family attends an event together, a parent or guardian buys the tickets and may enter a child’s name as an attendee. That name is provided by the adult, is used only to admit the child to that event, and is held on the same basis as any other attendee detail.

If you believe a child under 13 has given us personal information, write to support@fomotickets.com and we will delete it.

14.Where information is held, and international users

The Service is operated from the United States, and all of the providers listed in this policy store data in the United States. Vadelis Labs Inc. is a Florida corporation.

If you access the Service from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those in your country. By using the Service you understand that this transfer takes place.

Where the GDPR or UK GDPR applies to a particular processing activity, we rely on appropriate safeguards for that transfer — the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Addendum — together with the technical and organizational measures described in How we protect information. Contact us for a copy of the relevant documentation.

15.Other sites and embedded widgets

Our ticket widget can be embedded in an Event Organizer’s own website. The purchase itself runs on our systems and is covered by this policy, but the surrounding page is not ours — its content, cookies, and analytics belong to whoever runs it, and their privacy policy applies to them.

Links from the Service to other websites are provided for convenience. We do not control those sites and are not responsible for their privacy practices.

16.Changes to this policy

We update this policy when our practices change or when the law requires it. The effective date at the top always reflects the current version.

Where a change is material — a new category of information, a new purpose, a new recipient — we will give you notice before it takes effect, by email or a prominent notice on the Service, and where the law requires it we will ask for your consent.

17.Contact us

Questions, requests, or complaints about privacy: support@fomotickets.com.

Vadelis Labs Inc.1784 NW Madrid WayBoca Raton, FL 33432United States

To exercise a privacy right, please use the instructions on Your Privacy Choices — it tells us what we need to verify you and gets your request handled faster.

This document is part of the TicketsByFomo legal collection. Each document links to the others where they overlap.

PreviousRefundsNextCookies