Privacy Policy
Effective
A complete account of the personal information we handle — for ticket buyers, attendees, event organizers, and anyone browsing the site — written against what the platform actually does.
This Privacy Policy explains how Vadelis Labs Inc., the operator of TicketsByFomo and FOMOtickets, collects, uses, shares, and protects personal information, and what choices you have. It applies to our websites, our embedded ticket widgets, the tickets and emails we send, and the check-in applications used at events.
| The short version | |
|---|---|
| What we collect | Your name, contact details, what you bought, answers to questions the event organizer asked, and technical information about your visit. |
| Why | To sell you a ticket, get you into the event, support you afterwards, keep the platform secure, and meet our legal obligations. |
| Who sees it | The organizer of the event you bought into, and the service providers listed in this policy. Nobody else, unless the law requires it. |
| Card details | Never touch our systems. They go straight to Square or Stripe. |
| Your rights | Access, correction, deletion, portability, and more — see Your rights and Your Privacy Choices. |
1.Who this policy covers
This policy applies to four groups of people:
- Ticket buyers
- Anyone who buys a ticket, registers for an event, or joins a waitlist through the Service.
- Attendees
- Anyone whose name or details a buyer entered on a ticket, and anyone checked in at the door.
- Event Organizers and their staff
- People with an account that lets them create events, sell at the door, or scan tickets.
- Visitors
- Anyone browsing the site or an embedded ticket widget without buying anything.
It does not cover what an Event Organizer does with your information on its own systems once we have passed it to them, or the practices of any other website — including a site that embeds our ticket widget. Those are governed by their own privacy policies.
2.Our role: controller and service provider
Our role changes depending on whose information it is and why we hold it.
- We are the controller
- for your account, your login and security records, your transaction history with us, the technical records of your visit, our own analytics, and our fraud and abuse prevention. We decide why and how that information is used, and this policy governs it.
- We act as a service provider (processor) for the Event Organizer
- for information collected specifically for their event — attendee names, answers to the questions they configured, waivers they wrote, check-in records, and their attendee lists. They decide what to ask and what to do with the answers. We process it on their instructions to run the event, and we do not use it for our own purposes.
Where we act as a service provider, requests about that information may need to go to the Event Organizer. Send the request to us anyway — we will act on it where we can and route it where we cannot, and we will tell you which happened.
3.What we collect
Information you give us
| Category | What it includes | When |
|---|---|---|
| Identifiers and contact details | First and last name, email address, phone number. | Creating an account, checking out, joining a waitlist, contacting support. |
| Account credentials | A one-way hash of your password (never the password itself), email verification and password reset tokens. | Registering, signing in, resetting a password. |
| Billing and address information | Home or billing address, where the event is configured to collect one. | Checkout, for events that require it. |
| Order information | What you bought, quantities, ticket types, add-ons, discount codes used, amounts, fees and tax, and the payment processor’s reference for the payment. | Every purchase. |
| Attendee details | The name — and sometimes email or phone — of each person a ticket is for. | Checkout, where the event requires named tickets. |
| Answers to organizer questions | Whatever the Event Organizer chose to ask: dietary needs, accessibility requirements, affiliations, free text. | Checkout, for events with custom questions. |
| Waivers and signatures | The version of the waiver you accepted, the legal name you typed, and the time you accepted it. | Checkout, for events with a waiver. |
| Support correspondence | The content of your messages to us and our replies. | When you contact us. |
Information we collect automatically
- Device and connection data — IP address, browser and operating system, and the user agent string. The IP address and user agent of a purchase are stored with the order as a fraud and dispute record.
- Usage data — pages viewed, events viewed, checkout steps reached and abandoned, and other interactions with the Service.
- Referral and campaign data — the site you arrived from, the page you landed on, and any campaign parameters in the link you followed. We store the first attributed visit in a cookie for 30 days so that we can credit the right campaign for a purchase. See the Cookie Policy.
- Session replay — our analytics provider records a reconstruction of some browsing sessions so we can see where the interface fails people. Every text input is masked, so names, email addresses, phone numbers, and anything else typed into a field are not captured, and card entry happens on the payment processor’s own fields and never appears at all.
- Security records — sign-in attempts, rate-limiting counters keyed to an IP address or account, and audit records of check-in scans (which device, which operator, and when).
Information we receive from others
- From payment processors — whether a payment succeeded, failed, or was refunded, the processor’s payment identifier, and the payment method type. We do not receive your full card number, expiry date, or security code.
- From our email provider — whether a message was delivered, bounced, or was reported as spam, so we can stop sending to addresses that reject our mail.
- From Event Organizers — details of a sale made at the door, and any attendee information they add on your behalf.
What we deliberately do not collect
- Full payment card numbers, expiry dates, or security codes.
- Social security or other government identification numbers.
- Precise geolocation. We never ask for device location.
- Biometric identifiers. Scanning a ticket reads a QR code, not a face.
- Information about your activity on other websites or apps.
4.Sensitive information
We do not ask for sensitive personal information for our own purposes, and we do not use or disclose it to infer characteristics about you.
An Event Organizer may configure a checkout question whose answer is sensitive — an accessibility requirement, a dietary restriction that implies a religious belief, a health condition relevant to a waiver. Where that happens:
- you choose whether to answer, unless the Event Organizer has made the question required for entry;
- the answer is used only to run that event, and is visible to that Event Organizer and to staff working that event; and
- we hold it as a service provider, on the Event Organizer’s instructions, and use it for nothing else.
Please do not enter sensitive information into a free-text field where it is not being asked for.
5.How we use information, and on what basis
| What we do | Why | Legal basis (where GDPR applies) |
|---|---|---|
| Take your order, hold inventory, charge your card, issue tickets, email confirmations and tickets, admit you at the door, process refunds | To perform the contract you entered into when you bought a ticket | Performance of a contract |
| Give the Event Organizer the attendee list and answers for its event | So the event can actually be run | Performance of a contract; legitimate interests |
| Answer support requests and handle complaints and disputes | To provide the service you asked for and defend claims | Performance of a contract; legitimate interests |
| Detect and prevent fraud, bot purchasing, ticket-limit evasion, duplicate scans, and abuse; keep accounts secure | To protect buyers, Event Organizers, and the platform | Legitimate interests; legal obligation |
| Understand how the Service is used, fix what is broken, and improve it | To make the product work better | Legitimate interests |
| Report aggregate sales, attendance, and campaign performance to Event Organizers | To give organizers the numbers for their own events | Legitimate interests |
| Send you marketing about events, where you have asked for it | To tell you about things you said you wanted to hear about | Consent |
| Keep records for tax, accounting, and audit; respond to lawful requests | Because we are required to | Legal obligation |
We do not use your information to make decisions about you with legal or similarly significant effects by automated means alone. Automated fraud checks may flag an order, but a person reviews before an order is cancelled on that basis.
8.Email and your choices about it
- Service email
- Order confirmations, tickets, verification and password reset messages, event change and refund notices. These are part of the service and you cannot unsubscribe from them while you hold an active order — without them you would not receive your tickets.
- Marketing email
- Sent only where you have opted in. Every marketing message carries an unsubscribe link that works immediately, and you can also ask us to remove you at any time.
- Event Organizer email
- An Event Organizer may email you about its own event. Marketing from an Event Organizer is their responsibility and their unsubscribe link; we require them to honour opt-outs.
- Suppression
- If mail to your address hard-bounces or is reported as spam, we add it to a suppression list and stop sending to it. This protects delivery for everyone. Contact us to have an address reinstated.
9.How long we keep information
We keep personal information only as long as we need it for the purpose it was collected, plus any period the law requires.
| Information | How long |
|---|---|
| Order, ticket, refund, and payment records | At least 7 years after the event, for tax, accounting, audit, and dispute purposes. These records cannot be deleted on request while that obligation runs. |
| Your account and profile | Until you ask us to delete it, or until it has been inactive for 7 years. Deletion is completed within 45 days of a verified request, except for records we must keep. |
| Attendee details and answers to organizer questions | For the life of the event plus the retention period the Event Organizer instructs, and in any case no longer than our order records. |
| Waivers and signatures | For as long as a claim relating to the event could be brought, and at least 7 years. |
| Check-in and scan audit records | 12 months after the event. |
| Waitlist entries | Until the event has passed, or until you ask to be removed. |
| Email suppression records | Indefinitely. Deleting a suppression record would cause us to start mailing an address that rejects our mail. |
| Analytics and session replay | Governed by our analytics provider’s retention settings; replays are kept for a short window and are not linked to an identified person before purchase. |
| Security logs, rate-limit records, and request logs | Short-lived — typically 30 to 90 days — unless retained for an active investigation. |
Where we no longer need information but cannot delete it immediately, we isolate it from further use until deletion is possible. Where we keep information for reporting, we aggregate or anonymize it so it no longer identifies anyone.
10.How we protect information
- All traffic is encrypted in transit with TLS, and data at rest is encrypted by our hosting and database providers.
- Passwords are stored only as salted one-way hashes. We cannot read your password, and neither can anyone who obtains our database.
- Payment credentials belonging to an Event Organizer are encrypted with AES-256-GCM using a key held outside the database.
- Access to production data is limited to the people who need it, by role, and staff and organizer accounts are created by invitation rather than open registration.
- Sensitive endpoints are rate limited, and every ticket scan is written to an audit record identifying the device and operator.
- Card data never enters our systems, which materially reduces what an attacker could obtain.
No system is perfectly secure, and we cannot guarantee absolute security. If you believe your account has been compromised, or you have found a vulnerability, see our Security page or write to support@fomotickets.com.
11.Your privacy rights
Depending on where you live, you may have some or all of the following rights. Where a right is available to you under applicable law, we honour it — and where it is not, we will still generally try to help.
- Know and access
- Ask what personal information we hold about you, where it came from, why we have it, and who we have disclosed it to, and get a copy.
- Correct
- Ask us to fix information that is wrong or out of date. You can change most of your own details in your account.
- Delete
- Ask us to delete your information, subject to the records we are required to keep (see Retention).
- Portability
- Get a copy of the information you gave us in a portable, machine-readable format.
- Opt out of sale, sharing, or targeted advertising
- We do not do any of these, so there is nothing to opt out of — but the right exists and we confirm our position on request.
- Limit the use of sensitive personal information
- We do not use sensitive personal information for any purpose beyond providing the service you asked for.
- Non-discrimination
- We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.
- Withdraw consent
- Where we rely on your consent, you can withdraw it at any time. That does not affect processing already carried out.
- Appeal
- If we decline a request, you may appeal by replying to our decision. We will review and respond in writing, and tell you how to contact your state Attorney General if you remain dissatisfied.
- Complain to a regulator
- You can lodge a complaint with your state Attorney General or, where the GDPR applies, your local supervisory authority.
How to exercise a right. Everything you need — what to send, how we verify you, how long we take, and how authorized agents work — is on Your Privacy Choices.
12.United States state privacy notices
This section supplements the rest of this policy for residents of U.S. states with comprehensive privacy laws, including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as those laws come into effect. It applies to you where the relevant law applies to us.
Categories of personal information
Using the categories defined in the California Consumer Privacy Act, in the preceding 12 months we have collected the following. For each we list the sources, the business purposes (set out in How we use information), and the categories of recipient it is disclosed to for a business purpose.
| CCPA category | Do we collect it? | Disclosed for a business purpose to |
|---|---|---|
| Identifiers (name, email, phone, postal address, IP address, account ID) | Yes | Event Organizers; hosting, database, email, payment, and analytics providers |
| Personal information under Cal. Civ. Code § 1798.80 (name, address, payment record) | Yes | Event Organizers; payment and database providers |
| Commercial information (orders, tickets, refunds, purchase history) | Yes | Event Organizers; payment, database, and analytics providers |
| Internet or network activity (pages viewed, referral source, campaign parameters, session replay) | Yes | Analytics and hosting providers |
| Geolocation data | Approximate only, inferred from IP address for security and fraud prevention. No precise location | Hosting and security providers |
| Audio, electronic, visual, or similar information | No | — |
| Biometric information | No | — |
| Professional or employment information | Only where an Event Organizer asks for it at checkout | That Event Organizer |
| Education information | Only where an Event Organizer asks for it at checkout | That Event Organizer |
| Sensitive personal information | Only where an Event Organizer asks for it, and account credentials, which are held as hashes | That Event Organizer; database provider |
| Inferences drawn to create a profile | No. We do not build behavioural profiles | — |
Sale and sharing
We have not sold personal information, and have not shared it for cross-context behavioural advertising, in the preceding 12 months. We do not have actual knowledge of selling or sharing the personal information of consumers under 16.
Global Privacy Control
We recognize a Global Privacy Control (GPC) signal sent by your browser as a valid opt-out request. Because we do not sell or share personal information, there is nothing for the signal to stop on that front — but where we detect it we also switch off optional analytics and session replay for that browser.
Do Not Track
There is no common industry standard for responding to browser Do Not Track signals, so we do not respond to them. We do respond to Global Privacy Control, as described above.
California Shine the Light
California Civil Code § 1798.83 lets California residents ask about personal information disclosed to third parties for their direct marketing purposes. We do not make such disclosures.
Notice of financial incentive
We do not offer financial incentives in exchange for personal information.
13.Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. Accounts require you to be at least 13, and at least 18 unless a parent or guardian accepts the Terms of Use on your behalf.
Where a family attends an event together, a parent or guardian buys the tickets and may enter a child’s name as an attendee. That name is provided by the adult, is used only to admit the child to that event, and is held on the same basis as any other attendee detail.
If you believe a child under 13 has given us personal information, write to support@fomotickets.com and we will delete it.
14.Where information is held, and international users
The Service is operated from the United States, and all of the providers listed in this policy store data in the United States. Vadelis Labs Inc. is a Florida corporation.
If you access the Service from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those in your country. By using the Service you understand that this transfer takes place.
Where the GDPR or UK GDPR applies to a particular processing activity, we rely on appropriate safeguards for that transfer — the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Addendum — together with the technical and organizational measures described in How we protect information. Contact us for a copy of the relevant documentation.
15.Other sites and embedded widgets
Our ticket widget can be embedded in an Event Organizer’s own website. The purchase itself runs on our systems and is covered by this policy, but the surrounding page is not ours — its content, cookies, and analytics belong to whoever runs it, and their privacy policy applies to them.
Links from the Service to other websites are provided for convenience. We do not control those sites and are not responsible for their privacy practices.
16.Changes to this policy
We update this policy when our practices change or when the law requires it. The effective date at the top always reflects the current version.
Where a change is material — a new category of information, a new purpose, a new recipient — we will give you notice before it takes effect, by email or a prominent notice on the Service, and where the law requires it we will ask for your consent.
17.Contact us
Questions, requests, or complaints about privacy: support@fomotickets.com.
Vadelis Labs Inc.1784 NW Madrid WayBoca Raton, FL 33432United StatesTo exercise a privacy right, please use the instructions on Your Privacy Choices — it tells us what we need to verify you and gets your request handled faster.