Privacy

Draft. The committee must add controller contact details and confirm the retention period before tickets go on sale.

Who is responsible

[Committee name and a contact email address for privacy questions.]

What we store

  • The email address you enter at checkout, so we can send your tickets.
  • A name for each ticket, printed on it and checked at the door.
  • Your order and whether each ticket has been used.
  • Your language preference, and a one-way hash of your IP address used only to limit abuse. The address itself is not kept.

What we never store

No card or bank details. Payment happens entirely on Stripe's pages. No passwords, because there are none — signing in uses a one-time link sent to your email address.

Who else sees it

Stripe (payment processing), Resend (sending your ticket email) and Google Cloud (hosting, in Finland). Nobody else, and we do not sell or share it.

How long we keep it

[Confirm the period. Names and email addresses are removed after the event; the financial record is kept as long as bookkeeping rules require.]

Your rights

You can ask what we hold about you, have it corrected, or have it deleted once it is no longer needed for the event or for bookkeeping. Contact the address above.