Privacy policy
This Privacy Policy explains how Ticket Monkey Ltd (“Ticket Monkey”, “we”, “us”, “our”) collects, uses, shares and protects your personal data when you use our website, mobile apps, ticketing platform and related services (together, the “Platform”).
It applies to ticket buyers, event organisers, and visitors to our websites. Please read it alongside our Cookie Policy and, where relevant, our Website Terms of Use and the applicable Customer Purchase Policy.
Contents
- Who we are and how to contact us
- Our role: when we are controller and when we are processor
- The personal data we collect
- How we use your data and our lawful bases
- Cookies and similar technologies
- Marketing
- Who we share your data with
- International data transfers
- How long we keep your data
- Your rights
- Children’s data
- How we keep your data secure
- Changes to this policy
- How to complain
1. Who we are and how to contact us
Ticket Monkey Ltd is a private limited company registered in England & Wales (Company No. 16420115), with its registered office at Unit 1 Mill Rd Trading Estate, Barnstaple, Devon, EX31 1JH, United Kingdom. Our VAT registration number is GB4959360.
For any question about this policy or to exercise your data protection rights, contact us at support@ticketmonkey.co.uk or 0333 772 0726. We are the “controller” of your personal data except where this policy says otherwise (see section 2).
2. Our role: when we are controller and when we are processor
Because of how our Platform works, our data protection role changes depending on the activity:
- We are the controller for: operating and securing the Platform; your account; payments and booking fees we charge; fraud prevention; customer support we provide; our own direct marketing; and analytics about how our websites are used.
- We act as a processor for the event organiser in respect of personal data relating to ticket sales for their events — for example where an organiser uses our tools to manage attendees, send their own communications, or apply their own tracking pixels to an event page. In those cases the organiser is the controller and decides how that data is used. Our processing for organisers is governed by our Data Processing Agreement.
If you have a question about an organiser’s use of your data, you can contact them directly, or contact us and we will help direct your request.
3. The personal data we collect
Depending on how you use the Platform, we may collect:
- Identity data — name, title, and date of birth where an event requires age verification.
- Contact data — email address, postal address and telephone number.
- Account data — login credentials and settings (organisers authenticate through our secure identity service).
- Transaction data — tickets purchased, order history, booking fees, and payment confirmation details. Card details are handled by our payment processor; we do not store full card numbers.
- Usage and device data — IP address, browser and device information, and how you interact with our sites and apps.
- Communications data — messages you send us and our support correspondence.
- Marketing data — your preferences and opt-in / opt-out choices.
- Additional data you choose to provide — for example accessibility or dietary requirements for a specific event.
4. How we use your data and our lawful bases
We only use your personal data where the law allows. The main purposes and the lawful bases we rely on under the UK GDPR are:
| What we do | Lawful basis |
|---|---|
| Process your order, deliver tickets, and handle refunds, exchanges and cancellations | Performance of a contract with you |
| Provide customer support and respond to your enquiries | Contract; and our legitimate interest in helping our users |
| Take payment and charge booking fees | Contract; legal obligation (tax and accounting records) |
| Prevent, detect and investigate fraud and misuse | Legitimate interests (protecting the Platform, organisers and customers); legal obligation |
| Operate, secure, maintain and improve the Platform and understand how it is used | Legitimate interests (running and improving our service) |
| Send you marketing about our own services | Consent, or our legitimate interest under the “soft opt-in” for existing customers (see section 6) |
| Comply with our legal and regulatory obligations | Legal obligation |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you can object at any time (see section 10).
5. Cookies and similar technologies
We and our partners use cookies and similar technologies on our websites and apps. Some are essential to make the Platform work and to keep it secure; others (such as analytics or organiser-applied marketing pixels) are only used where you have given consent through our cookie banner. Full details, and how to change your choices, are in our Cookie Policy.
6. Marketing
We will only send you marketing where we are allowed to. If you have bought from us, or asked about our services, we may send you information about similar Ticket Monkey services under the “soft opt-in” permitted by the Privacy and Electronic Communications Regulations (PECR), unless you tell us not to. Otherwise we will ask for your consent.
You can opt out of our marketing at any time using the unsubscribe link in any message or by emailing support@ticketmonkey.co.uk. Marketing sent by an event organiser using their own tools is the organiser’s responsibility — opt out with them directly.
7. Who we share your data with
We share personal data only where necessary, with:
- Event organisers and venues — so they can admit you, manage their event, and handle refunds.
- Our service providers (sub-processors) who help us run the Platform. Our current key providers are set out below.
- Professional advisers, regulators, and law enforcement where we are required to share data by law, or to establish, exercise or defend legal claims.
- A buyer or successor if we restructure, sell or transfer part of our business.
Our current key sub-processors include:
| Provider | Purpose |
|---|---|
| Stripe | Payment processing and fraud prevention |
| Amazon Web Services (AWS) | Hosting and infrastructure |
| Cloudflare | Security, content delivery and bot protection |
| Our identity provider (Keycloak, self-hosted) | Secure account log-in for organisers |
This list is not exhaustive and may change as our services evolve; we keep an up-to-date list and will provide it on request. We require all sub-processors to protect personal data and to use it only as instructed.
8. International data transfers
We aim to keep personal data within the UK and the European Economic Area (EEA). Where a provider processes data outside the UK or EEA, we put appropriate safeguards in place — such as a UK “adequacy” decision, the International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses. You can ask us for a copy of the safeguards we use.
9. How long we keep your data
We keep personal data only for as long as we need it for the purposes set out in this policy, then delete or anonymise it. In particular, we keep transaction and order records for up to six years to meet tax, accounting and legal requirements. Account data is kept while your account is active and for a reasonable period afterwards to handle disputes and chargebacks.
10. Your rights
Under data protection law you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased, where the law requires;
- object to, or ask us to restrict, certain processing — including direct marketing, which you can stop at any time;
- ask us to transfer your data to another provider (data portability); and
- withdraw consent at any time, where we rely on consent.
To exercise any of these, contact support@ticketmonkey.co.uk. We may need to verify your identity first. We will respond within one month. There is normally no charge.
11. Children’s data
The Platform is intended for adults. We do not knowingly collect data from children under 16 without parental involvement. Some events are age-restricted, and an organiser may require proof of age. If you believe a child has provided us with personal data, contact us and we will take appropriate steps.
12. How we keep your data secure
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration — including encryption in transit, access controls, and secure development practices. Payment card data is handled by our PCI-compliant payment processor.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version on our website with a new effective date and, where changes are significant, we will tell you by email or through your account.
14. How to complain
If you have a concern about how we handle your data, please contact us first so we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, at https://ico.org.uk or on 0303 123 1113.
