TiketBurst
  • Events
  • Live
Sign In Create Event
Privacy Policy

Your privacy matters

This policy explains how TiketBurst collects, uses, and protects your personal data in compliance with Ivoirian data protection law and GDPR principles.

Effective: 17 March 2026 Questions? privacy@tiketburst.com
On this page
  1. 1. Who we are
  2. 2. Data we collect
  3. 3. How we use your data
  4. 4. When we share your data
  5. 5. Your rights
  6. 6. Data retention
  7. 7. Security
  8. 8. Cookies
  9. 9. Children
  10. 10. Changes to this policy

1. Who we are

TiketBurst ("we", "us", "our") is a digital ticketing and fundraising platform operated from Abidjan, Côte d'Ivoire. We are the data controller for personal information collected through our website, mobile app, and APIs.

Registered address: Plateau, Abidjan, Côte d'Ivoire. Data protection contact: privacy@tiketburst.com.

2. Data we collect

We collect information in the following ways:

Information you provide

  • Account data: full name, email address, phone number, password (hashed).
  • Identity verification (KYC): government-issued ID scans for organizers required to process withdrawals or run large-capacity events.
  • Payment data: mobile money numbers, card last-4 digits. We do not store full card numbers — these are handled by our PCI-compliant payment processors.
  • Event data: event title, description, images, venue, capacity, ticket tiers.

Data collected automatically

  • IP address, browser type, device identifiers, and OS version.
  • Pages visited, session duration, click events (via our first-party analytics).
  • QR scan logs (timestamp, scanner ID, result) for event check-in.

3. How we use your data

We use your data to:

  • Create and manage your account and ticket purchases.
  • Process payments and disburse payouts to organisers.
  • Verify event check-ins via QR code scanning.
  • Send transactional communications (booking confirmation, receipt, payout notification).
  • Detect fraud, abuse, and ensure platform security.
  • Comply with legal obligations (tax reporting, anti-money-laundering).
  • Improve our product through aggregate, anonymised analytics.

We will only send marketing emails where you have explicitly opted in, and you can unsubscribe at any time.

4. When we share your data

We do not sell your personal data. We share it only in the following circumstances:

  • Payment processors: Wave, Orange Money, MTN MoMo, Moov Money, and card network processors receive the minimum data required to complete a transaction.
  • Organizers: Buyers' names and ticket IDs are shared with the event organiser for check-in purposes. We do not share your phone number or email without your consent.
  • Service providers: cloud hosting (Supabase / AWS), email delivery, SMS OTP providers, acting as data processors under written agreements.
  • Legal obligation: where required by Ivoirian law, court order, or regulatory authority.
  • Business transfer: in the event of a merger or acquisition, data may transfer subject to the same privacy protections.

5. Your rights

You have the right to:

  • Access a copy of your personal data we hold.
  • Rectify inaccurate or incomplete data via your account settings.
  • Delete your account and associated data (subject to legal retention requirements).
  • Portability — export your data in machine-readable format.
  • Object to marketing communications at any time.
  • Restrict processing while a dispute is under review.

To exercise any right, email privacy@tiketburst.com. We will respond within 30 days.

6. Data retention

We retain personal data for as long as your account is active or as required by law:

  • Account data: held until account deletion + 30 days grace period.
  • Transaction records: 5 years (tax and accounting obligation).
  • KYC documents: 5 years post-relationship end (AML regulation).
  • Log data: 12 months rolling.

After retention periods expire, data is securely deleted or anonymised.

7. Security

We implement industry-standard security measures including:

  • TLS 1.3 encryption in transit; AES-256 encryption at rest.
  • HMAC-SHA256 rotating QR codes (30-second windows) to prevent ticket fraud.
  • Bcrypt-hashed passwords with salting.
  • Role-based access control and audit logs for all admin operations.
  • Regular penetration testing and vulnerability scanning.

No system is 100% secure. If you discover a security vulnerability, please disclose it responsibly to security@tiketburst.com.

8. Cookies

We use minimal cookies:

  • Strictly necessary: session token, CSRF token. These cannot be disabled.
  • Preferences: theme setting (dark/light), language. Stored in localStorage.
  • Analytics: two first-party cookies, set by us and readable only by us — tb_vid (a random identifier, 12 months) and tb_sid (a session identifier, 30 minutes). They let us count how many distinct people viewed an event, rather than how many times a page was reloaded, and tell organisers how many of those visitors went on to register or buy.

These identifiers are random values. They are never sold, never shared with ad networks, and are not used to build a profile of you across other websites — we set no third-party cookies and load no tracking pixels.

Analytics records are kept in raw form for 90 days, after which only aggregate daily totals remain. If you ask us to delete your data, we remove the link between your account and these identifiers, leaving only anonymous counts that can no longer be traced to you.

9. Children

TiketBurst is not directed at children under 16. We do not knowingly collect personal data from minors. If you believe a child has created an account, contact us immediately at privacy@tiketburst.com and we will delete the account.

10. Changes to this policy

We may update this policy periodically. Material changes will be communicated by email to registered users and by a prominent notice on the platform at least 14 days before taking effect.

Continued use of TiketBurst after the effective date constitutes acceptance of the updated policy.

HomeEventsTicketsAccount