Privacy policy
Last updated: 18 July 2026
1. Controller
The controller responsible for data processing on this website within the meaning of the EU General Data Protection Regulation (GDPR) is:
Koriba
Dürener Str. 1
53947 Nettersheim
Email: impressum@ticketente.com
2. What this website does
ticketente sells event tickets on behalf of event organizers. When you buy a ticket, the purchase contract is concluded with the organizer named on the event page. We process your data to sell, deliver, and validate tickets — nothing more. We do not run advertising, we do not use tracking or analytics cookies, and we never sell your data.
3. Data we process
Orders and tickets
When you buy a ticket we store your email address, your name, the tickets you bought, the amounts paid, and payment references issued by our payment provider. We use this data to issue your tickets, send your order confirmation, give you access to your ticket page, and handle refunds. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR) and our statutory bookkeeping obligations (Art. 6 (1) (c) GDPR).
Attendee names
Each ticket carries the name of the person attending (by default the buyer). If the buyer assigns a ticket to someone else, we store that person's name and, optionally, their email address in order to deliver the ticket to them and to admit them at the door. The attendee list is visible to the event's organizer. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR).
Payment data
Payments are processed by Stripe (Stripe Payments Europe, Ltd., Ireland). Your card or payment details are entered directly on Stripe's payment page and never reach our servers. Depending on the event, the payment is processed for the organizer's Stripe account, with Stripe acting under its own privacy policy (stripe.com/privacy). Legal basis: performance of a contract (Art. 6 (1) (b) GDPR).
Emails
We send transactional email only: order confirmations, ticket deliveries, and refund notices. Delivery is handled by Resend (Resend, Inc., USA); transfers are safeguarded by the EU standard contractual clauses. We do not send marketing email.
Server logs and abuse protection
Like every website, our servers process your IP address to deliver pages and to protect checkout and ticket scanning against abuse (rate limiting). Rate-limiting state is held briefly in memory and not written to a database. Legal basis: legitimate interest in a secure, functioning service (Art. 6 (1) (f) GDPR).
Error monitoring
When something breaks we capture a technical error report via Sentry (Functional Software, Inc., USA), which may include your IP address and the request that failed; transfers are safeguarded by the EU–US Data Privacy Framework and standard contractual clauses. Legal basis: legitimate interest in finding and fixing faults (Art. 6 (1) (f) GDPR).
Organizer accounts
Event organizers and their check-in staff sign in with an email address and password. We set a strictly necessary session cookie for signed-in staff only — ticket buyers never need an account and receive no such cookie. Legal basis: performance of a contract (Art. 6 (1) (b) GDPR).
4. Recipients
Your order data is shared with the organizer of the event you bought tickets for, who needs it to run the event and is independently responsible for their own processing. Our technical service providers are Stripe (payments), Resend (email delivery), Render (hosting — our servers and database run in Frankfurt, Germany, EU), and Sentry (error monitoring). These providers process data on our behalf under data processing agreements; where a provider is located outside the EU, transfers rest on the EU standard contractual clauses or an adequacy decision. We disclose data to authorities only where the law requires it.
5. Retention
Order and payment records are kept for the duration of statutory commercial and tax retention periods (up to ten years, § 147 AO, § 257 HGB). Reservation data for purchases that were never completed, server logs, and error reports are kept only briefly. Attendee and ticket data is kept as long as the order it belongs to.
6. Your rights
You have the right to access the personal data we hold about you (Art. 15 GDPR), to have it rectified (Art. 16) or erased (Art. 17), to restrict its processing (Art. 18), to receive it in a portable format (Art. 20), and to object to processing based on legitimate interest (Art. 21). To exercise any of these rights, email impressum@ticketente.com. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular the authority of your habitual residence.
7. No profiling
We do not use your data for automated decision-making or profiling, and we do not build advertising profiles.
8. Changes
We update this policy when the service changes. The current version is always available on this page.
ticketente