Skip to content

Privacy Policy

How we collect, use, share and protect your personal data, and the rights you have under the GDPR.

Last updated: 16 June 2026

Introduction

This Privacy Policy explains how Ticket Capital collects, uses, and protects your personal data when you visit ticket-capital.com and buy tickets from us. We are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and applicable national data protection law.

1. Who we are (the data controller)

The data controller responsible for your personal data is:

  • TICKET CAPITAL - FZCO
  • A Free Zone Company (FZCO) registered in the United Arab Emirates.
  • Trade Licence No. 49666, issued by the Dubai Integrated Economic Zones Authority (DIEZA), IFZA.
  • Registered address: IFZA Properties, Dubai Silicon Oasis (DSO-IFZA), Dubai, United Arab Emirates.
  • Company Manager: Jack Andrew Sewter.

For any data protection matter, contact us at privacy@ticket-capital.com.

2. Our EU Representative (GDPR Article 27)

Because we are established outside the European Union but offer tickets to buyers located in the EU and Ireland, the GDPR applies to our processing of your personal data, and we are required to appoint a representative within the EU under Article 27 of the GDPR. Our EU Representative can be contacted on all matters relating to the processing of your personal data, in addition to or instead of contacting us directly.

Our appointed EU representative under Article 27 GDPR will be named here.

3. What personal data we collect

We collect and process the following categories of personal data:

  • Account and contact data — your email address and, where you provide it, your name and phone number.
  • Order data — the tickets you buy, order references, order history, and delivery details.
  • Payment data — card and payment information is collected and processed directly by our payment provider, Stripe. We do not store your full card number on our systems; we receive confirmation of payment and limited transaction details.
  • Technical and usage data — your IP address, device and browser information, and data collected through cookies and similar technologies when you use our website (see our Cookie Policy).
  • Communications — the content of any messages you send us at support@ticket-capital.com or privacy@ticket-capital.com.
  • Fraud-prevention data — signals we or Stripe use to detect and prevent fraudulent transactions and chargeback abuse (e.g. device, payment and order-pattern data).

4. Why we use your data and our lawful basis

We process your personal data on the following lawful bases under Article 6 of the GDPR:

  • To create and manage your account and process your ticket orders — performance of a contract (Art. 6(1)(b)).
  • To take payment and prevent fraudulent transactions and chargeback abuse — performance of a contract (Art. 6(1)(b)) and our legitimate interests in preventing fraud (Art. 6(1)(f)).
  • To deliver your tickets and provide customer support — performance of a contract (Art. 6(1)(b)).
  • To send you service and transactional emails about your orders — performance of a contract (Art. 6(1)(b)).
  • To send you marketing emails about events and offers — your consent (Art. 6(1)(a)).
  • To improve and secure our website and analyse how it is used — your consent for analytics/marketing cookies (Art. 6(1)(a)) and our legitimate interests (Art. 6(1)(f)).
  • To comply with our legal and accounting obligations — compliance with a legal obligation (Art. 6(1)(c)).

Where we rely on your consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

5. Who we share your data with

  • Stripe (payment processing) — acts as a processor / independent service provider to take your card payment securely and to help detect and prevent fraud.
  • Resend (transactional email delivery) — sends order confirmations and service emails from ticket-capital.com on our behalf.
  • Our website and hosting providers — who host the site and process data on our instructions.
  • Authorities and advisers — where we are legally required to disclose data, or to establish, exercise or defend legal claims.

We require our processors to handle your data only on our instructions and to keep it secure.

6. International transfers of your data

We are based in the United Arab Emirates, which is a country outside the EU/EEA (“third country”) and which the European Commission has not recognised as providing an adequate level of data protection. This means that when your personal data is transferred to us in the UAE, it leaves the protection of EU law.

To protect your data on such transfers, we rely on appropriate safeguards as required by Chapter V of the GDPR — in particular the European Commission’s Standard Contractual Clauses (SCCs) under Article 46. You can request a copy of the safeguards we use by contacting privacy@ticket-capital.com.

7. How long we keep your data

We keep your personal data only for as long as necessary for the purposes set out above:

  • Order and payment records — retained for 7 years to meet accounting, tax, and legal-claim obligations.
  • Account data — retained while your account is active and for 2 years after your last activity, then deleted or anonymised.
  • Marketing consent data — retained until you unsubscribe or withdraw consent.

8. Your rights

Under the GDPR (Articles 15 to 21) you have the right to:

  • Access the personal data we hold about you (Art. 15);
  • Rectify inaccurate or incomplete data (Art. 16);
  • Erase your data (“right to be forgotten”) in certain circumstances (Art. 17);
  • Restrict our processing of your data in certain circumstances (Art. 18);
  • Data portability — receive your data in a structured, commonly used, machine-readable format (Art. 20);
  • Object to processing based on legitimate interests, and to direct marketing at any time (Art. 21);
  • Withdraw consent at any time where we rely on consent.

To exercise any of these rights, email privacy@ticket-capital.com or our EU Representative. We will respond within one month.

9. Complaints

If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with a supervisory authority. Buyers in Ireland may complain to the Irish Data Protection Commission (DPC):

Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland — www.dataprotection.ie.

You may also complain to the supervisory authority in your own EU member state.

10. Changes to this policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top shows when it was last changed.