We collect what we need to sell you a ticket, get you through the door and keep the marketplace honest. Nothing more, and never for sale to anyone.
1. Controller
The controller of your personal data is MERCHBANDIT OÜ, registry code 16804278, Kütise tn 5-4, 76505 Saue, Saue vald, Harju maakond, Estonia. Privacy questions: privacy@wristbandit.online.
We have not appointed a data protection officer because our processing does not meet the thresholds of Article 37 GDPR.
2. What we collect
- Identity and contact data: first name, last name, email address, phone number.
- Account data: hashed password (we never see the password itself), two-factor authentication secrets (encrypted), sessions (IP address, browser identifier, expiry).
- Order data: event, ticket type, quantity, price, promo code used, order and ticket IDs, payment status and the payment reference returned by our payment provider. We do not receive or store your full card number.
- Ticket files delivered to you and the access log for them.
- Support data: messages you send us, the order they relate to, and internal notes our staff write about the case.
- Partner application data: name, contact details, country, seller type, experience and ticket information, and any proof documents you later send us.
- Technical and security data: IP address, request timestamps, rate-limit counters, audit records of actions on your account and orders, error logs.
- Email records: which emails we sent you, when, and their content, so we can prove what you were told.
3. Why we use it and on what legal basis
- Performing our contract with you (Art. 6(1)(b) GDPR): taking and fulfilling Orders, delivering tickets, running your account, answering support requests, sending order and ticket emails.
- Legal obligations (Art. 6(1)(c)): accounting and tax records, responding to lawful requests from authorities, consumer-law duties.
- Legitimate interests (Art. 6(1)(f)): preventing fraud, duplicate tickets and abuse (verification of Partners and tickets, rate limits, audit logs); securing the Platform; improving it based on how it is used; establishing and defending legal claims. You may object to processing based on legitimate interests.
- Consent (Art. 6(1)(a)): marketing emails such as new-event alerts, only if you opt in. You can withdraw consent at any time from the email or your account.
4. Who receives your data
We do not sell personal data and we do not use advertising trackers.
- Our payment service provider [Stripe Payments Europe, Ltd., Ireland] receives the data needed to process your payment and detect fraud.
- Our email service provider Resend, Inc. (servers in the EU, Ireland region) sends our transactional emails and receives your email address and the email content.
- Our hosting provider runs the servers on which the Platform and its database operate.
- Meta Platforms Ireland Ltd. receives pixel data about your visit to measure our advertising, unless you opt out of marketing cookies in our cookie banner or Cookie settings.
- Partners: when you buy a ticket, the Partner learns that their ticket was sold and, only where the organiser requires a named ticket, your name. Partners never receive your email, phone or payment details from us.
- Event organisers or venues, only where required to validate a ticket or by law.
- Professional advisers, auditors and authorities where legally required.
5. International transfers
We store data in the EU. Where a provider processes data outside the EU/EEA (for example a US-based company), we rely on the European Commission's Standard Contractual Clauses or an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified).
6. How long we keep it
- Orders, tickets, payments and related emails: 7 years after the end of the financial year of the order, as required by the Estonian Accounting Act (raamatupidamise seadus § 12) and to handle claims.
- Account data: for as long as the account exists; after deletion, order records are retained as above but detached from the login.
- Support conversations: 3 years after the last message.
- Partner applications: 2 years after the decision; approved Partners' data for the duration of the partnership plus the accounting period.
- Security and audit logs: 12 months, longer where needed for an investigation.
- Unfinished checkouts (ticket holds): the hold itself expires within minutes; no personal data is kept from an abandoned checkout except what you typed into a support request.
7. Your rights
You have the right to access your data, to have inaccurate data corrected, to erasure where the law allows it, to restriction of processing, to data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time.
To exercise your rights, write to privacy@wristbandit.online from the email address on your account, or use the contact form. We reply within one month.
You may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, info@aki.ee, www.aki.ee) or with the supervisory authority of the EU country where you live.
8. Cookies
Strictly necessary cookies keep the site working and need no consent: a session cookie to keep you signed in, a short-lived checkout cookie that ties your ticket hold to your browser, a two-factor cookie during sign-in, and a cookie that remembers a trusted device if you ask us to.
We use the Meta Pixel (Meta Platforms Ireland Ltd.) to measure the performance of our advertising; it sets its own cookie (for example _fbp) and sends Meta information about your visit and actions on the site. You can opt out at any time in our cookie banner or via “Cookie settings” in the footer: if you choose “Necessary only”, we instruct the pixel to stop and no further marketing data is sent to Meta.
9. Security
Passwords are stored as salted hashes. Ticket files are stored outside the web root and served only through short-lived signed links to the signed-in owner. Connections use TLS. Access to customer data by our staff is limited to what their role needs and is recorded in an audit log.
10. Children
The Platform is not directed at children under 16 and we do not knowingly collect their data. Age limits for events are set by organisers.
11. Changes
We will post changes on this page with a new date. Material changes are announced to account holders by email.