🎟 TicketFlow
Privacy Policy
Last updated: August 2, 2026
1. Who we are
TicketFlow ("we", "us") operates the ticket-flow.net website and dashboard. This policy explains what personal data we handle, why, and what your rights are. We are the controller for the data described here.
2. What we collect
Account
- Discord username, user id, email address and avatar, through Discord sign-in.
- Subscription status, received from Whop.
Email access
- Google account email address, and read-only Gmail access through Google OAuth, or IMAP credentials if you connect a mailbox directly.
- We read messages that match known ticket-platform senders in order to import order confirmations and sale notifications. Other mail is not read.
- Where you use a shared inbox for verification codes, we read the codes needed to complete a login you started.
Connected platform sessions
- Session cookies for platforms you connect, such as the Viagogo
wsu.2 cookie and TicketSwap session data. These act as login credentials for those accounts.
- They are stored encrypted, used only to act on your behalf on that platform, and never shared with other customers.
Browser extension
- The optional TicketFlow Helper extension reads cookies for ticketswap.* and viagogo.com and sends them to your own TicketFlow account, so the dashboard can act on those platforms.
- It does not read other websites, page content, keystrokes or browsing history.
- It is optional. You can connect Viagogo by pasting the session cookie yourself instead.
Inventory and financial data
- Order and sale data: events, dates, venues, seat details, quantities, purchase prices, sale prices and payouts.
- Where you use payout features: bank account details such as IBAN, and the addresses used for platform verification.
Account generator add-on
If you use this add-on, we additionally handle the email addresses, names, addresses and phone numbers used to set up accounts, and route the setup through a residential proxy and an external SMS verification provider.
Technical
- Server logs, IP address, and error diagnostics.
- An audit log of actions taken by team members on an owner's account.
3. Why we use it, and on what basis
| Purpose | Legal basis |
| Providing the dashboard you subscribed to | Performance of a contract |
| Signing you in and keeping your account secure | Performance of a contract |
| Reading order and sale emails to build your inventory | Performance of a contract |
| Acting on connected platforms on your instruction | Performance of a contract |
| Fraud prevention, abuse detection and audit logging | Legitimate interest |
| Diagnostics and error reporting | Legitimate interest |
| Billing | Legal obligation, performance of a contract |
4. Who we share with
We do not sell personal data. We share only what is needed with:
- Google, for Gmail and Sheets access you authorise.
- Whop, our payment and subscription provider.
- Discord, for sign-in and for notifications you enable.
- Ticket platforms you connect, such as TicketSwap and Viagogo, when acting on your instruction.
- Proxy providers, when platform traffic is routed through a residential proxy to keep your session stable.
- An SMS verification provider, only when you use the account generator add-on.
- Our hosting provider, Netcup GmbH in Germany.
5. Storage and security
- Data is stored on a server in Germany.
- Sensitive values, including platform session cookies, mailbox passwords and OAuth tokens, are encrypted at rest.
- Each customer's data is isolated in its own directory. Access is scoped per account in code, and that isolation is covered by automated tests that block a release if it regresses.
- All connections use HTTPS.
- Backups are kept for 7 days.
No system is perfectly secure. We cannot guarantee absolute security, and you share credentials with us at your own risk.
6. How long we keep it
- Account and inventory data: while your account is active, and up to 90 days after it closes.
- Platform session cookies and credentials: until you disconnect the integration or your account closes.
- Backups: 7 days.
- Billing records: as long as tax law requires.
7. Your rights
Under the GDPR you can request access to your data, correction, deletion, restriction, a copy in portable form, and you can object to processing based on legitimate interest. You can also withdraw consent for an integration at any time by disconnecting it.
To exercise any of this, contact us through Discord or the email address on ticket-flow.net. You also have the right to complain to your national data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens.
8. Your own responsibility
Some data you put into TicketFlow concerns other people, for example buyer names and contact details supplied by a ticket platform. You remain responsible for handling that data lawfully.
9. Changes
We may update this policy. Material changes will be announced in the dashboard or through our Discord.
10. Contact
Questions about this policy? Reach us through our Discord, or by email at the address listed on ticket-flow.net.