Privacy Policy
Last updated: July 6, 20261. Introduction
Jurasco Inc. ("we," "us," or "our") operates the ticketcosmo.com website, the TicketCosmo mobile application, and all related APIs, tools, and services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
This policy applies to all current and future features, functionality, and services we offer. By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Who We Are
TicketCosmo is an event ticketing platform that enables event organizers to sell tickets to their events. We act as a technology platform connecting event organizers and ticket buyers. We are not the organizer of any event listed on the platform, and we do not control the content or conduct of events.
For questions about this Privacy Policy, contact us at: [email protected]
3. Information We Collect
3.1 Information You Provide
Ticket buyers:
- Full name
- Email address (verified via one-time code)
- Payment information (processed by Stripe — we do not store card numbers, CVV codes, or bank account details)
Event organizers (app users):
- Full name
- Email address
- Google account information (if signing in with Google)
- Stripe account connection (we store a Stripe account ID and connected account details, not your underlying financial details)
- Event details you create (names, dates, locations, descriptions, images, seating configurations, and pricing)
Scanner users:
- Full name
- Email address
3.2 Information Collected Automatically
When you use the Service, we may collect:
- IP address
- Browser type and version
- Device type, operating system, and mobile network information
- Device identifiers (such as advertising IDs or device tokens, where applicable)
- Pages visited, features used, and time spent
- Referring URLs
- Error logs and performance data from Cloud Functions
- Crash reporting and diagnostics data via Firebase
We use Cloudflare as our DNS and security provider. Cloudflare may collect additional technical data as part of its security and performance services. See cloudflare.com/privacypolicy for details.
3.3 Information from Third Parties
- Google Sign-In: If you sign in with Google, we receive your name, email address, and Google account ID.
- Stripe: We receive confirmation of payment status and a Stripe account identifier. We do not receive or store your full card number, CVV, or bank account details.
- Apple/Google (subscriptions): If you purchase a premium subscription through the mobile app, we receive a transaction ID and subscription status from Apple or Google. We do not receive your payment method details.
3.4 Information You Provide About Others
If you purchase tickets on behalf of another person, or if you are an organizer who uploads attendee lists or imports contact data, you represent that you have the right to provide us with that person's information. We will process such information in accordance with this policy.
4. How We Use Your Information
We use the information we collect to:
- Process ticket purchases — create ticket records, send confirmation emails with ticket links
- Verify email addresses — send one-time verification codes before purchases
- Send tickets — email ticket links and QR codes to buyers
- Enable event management — allow organizers to create events, manage venues, issue and scan tickets
- Process payments — pass payment information to Stripe for processing on the event organizer's behalf
- Send Stripe receipts — provide your email to Stripe so they can send a payment receipt
- Manage subscriptions — track premium subscription status for app users
- Communicate with you — respond to inquiries, provide customer support, and send service-related notices
- Security and fraud prevention — verify purchase tokens, validate QR codes, detect abuse
- Operate and improve the Service — monitor performance, fix errors, improve features, and develop new functionality
- Comply with legal obligations — respond to lawful requests from authorities where required
We do not use your information for advertising, and we do not sell your personal information to third parties.
5. Legal Basis for Processing (GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, our legal basis for processing your personal data is:
- Contract performance — processing necessary to fulfill a ticket purchase or provide the Service
- Legitimate interests — security, fraud prevention, service improvement, and customer support
- Legal obligation — compliance with applicable laws, tax regulations, and record-keeping requirements
- Consent — where we have asked for and received your explicit consent (for example, for optional communications or certain device permissions)
6. How We Share Your Information
6.1 With Event Organizers
When you purchase a ticket, the event organizer receives your name and email address. This is necessary for the organizer to manage attendance and contact you about the event. Organizers may also be able to export attendee lists containing this information. Event organizers are independent parties, and their use of your information is governed by their own privacy practices.
6.2 With Service Providers
We share information with third-party service providers who help us operate the Service:
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Google Firebase / Firestore | Database, authentication, hosting, crash reporting | policies.google.com/privacy |
| Stripe | Payment processing and connected account management | stripe.com/privacy |
| SMTP2GO | Email delivery | smtp2go.com/privacy |
| Cloudflare | Security, DNS, CDN, DDoS protection | cloudflare.com/privacypolicy |
| Google Wallet | Wallet pass generation | policies.google.com/privacy |
| Apple Wallet | Wallet pass generation | apple.com/legal/privacy |
These providers are contractually obligated to use your data only to provide services to us.
6.3 Legal Requirements
We may disclose your information if required to do so by law, regulation, or valid legal process (such as a subpoena or court order), or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
6.4 Business Transfers
If TicketCosmo is acquired, merged, or sold, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Service before your information is transferred and becomes subject to a different privacy policy.
7. Payments
All payment processing is handled by Stripe. When you make a purchase, your payment information is transmitted directly to Stripe and is subject to Stripe's Privacy Policy at stripe.com/privacy.
Payments for ticket purchases are made directly to the event organizer's Stripe account. TicketCosmo does not hold or control the funds from ticket sales.
We store the following payment-related information:
- Whether a payment was successful
- The Stripe Payment Intent ID (for support and recovery purposes)
- The amount and currency paid
- The buyer's name and email address
We do not store card numbers, CVV codes, expiration dates, or bank account information.
8. Ticket Data and QR Codes
Ticket URLs contain a cryptographically signed token that authenticates the ticket. This token is generated using HMAC-SHA256 and cannot be forged without access to our private key. Ticket links should be treated as confidential — sharing your ticket link may allow another person to use your ticket.
QR codes on wallet passes encode the same ticket URL. Whoever presents the QR code at the event will be admitted.
9. Communications
We send emails and notifications that are strictly necessary to provide the Service — for example, ticket confirmations, verification codes, payment receipts, and security alerts. We do not send marketing or promotional communications unless you have explicitly opted in. You may not opt out of transactional messages while using the Service, as they are required for operation.
10. Device Permissions
The TicketCosmo mobile application may request access to:
- Camera: To scan QR codes for ticket validation. You can deny this permission and still use most features, but you will not be able to scan tickets.
- Storage / Photos: To save wallet passes or event images to your device. This is optional.
- Notifications: To send you transactional alerts about tickets or events you are attending. You can manage notification preferences in your device settings.
You can revoke any of these permissions at any time through your device settings, though doing so may limit certain features.
11. Data Retention
| Data Type | Retention Period |
|---|---|
| Ticket purchase records | 7 years (financial and tax records) |
| Buyer name and email | 7 years (associated with ticket records) |
| Event organizer account data | Duration of account + 2 years after deletion |
| Scanner user accounts | Duration of account + 1 year after deletion |
| One-time verification codes (OTPs) | Deleted after use or after 10 minutes |
| Stripe OAuth state tokens | Deleted after use or after 10 minutes |
| Processed webhook event IDs | 30 days |
| Server and Cloud Functions logs | 30 days |
| Backups | Up to 90 days from creation, then securely deleted |
You may request earlier deletion of your personal data (see Section 13). We will retain information only as long as necessary for the purposes set out in this policy, or as required by law.
12. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- All data is transmitted over HTTPS/TLS
- Firestore data is encrypted at rest by Google
- Ticket tokens are cryptographically signed (HMAC-SHA256) and cannot be forged
- Stripe account IDs and webhook secrets are stored in server-side environment variables, never in client-side code
- One-time verification codes are deleted immediately after use
- Cloudflare provides DDoS protection and Web Application Firewall
- Access to production systems is restricted to authorized personnel on a need-to-know basis
- We review our information collection, storage, and processing practices regularly
No method of transmission over the internet is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security. In the event of a data breach affecting your personal data, we will notify you and the relevant authorities as required by applicable law.
13. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
13.1 General Rights
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Deletion — request deletion of your personal data, subject to legal retention requirements
- Portability — request your data in a structured, commonly used, machine-readable format
- Objection — object to certain types of processing, such as processing based on legitimate interests
- Restriction — request that we restrict processing of your data
- Withdraw consent — where processing is based on consent, you may withdraw it at any time
13.2 GDPR — Right to Lodge a Complaint
If you are in the European Economic Area, United Kingdom, or Switzerland, you have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates applicable data protection laws.
13.3 California and US State Privacy Rights
If you are a resident of California or another US state with a comprehensive privacy law, you have the right to:
- Know what personal information we collect, use, disclose, and sell (we do not sell personal information)
- Request deletion of your personal information, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information for cross-context behavioral advertising (we do not engage in these practices)
- Non-discrimination for exercising your privacy rights
To exercise your rights under California or other US state laws, contact us at [email protected]. We will verify your identity before processing your request. Only you, or someone legally authorized to act on your behalf, may make a request.
13.4 Account Deletion
Event organizers may request deletion of their account and associated data by contacting us at [email protected]. We will process deletion requests within 30 days, subject to legal retention requirements (for example, financial records must be retained for tax purposes).
Note for ticket buyers: We do not create user accounts for ticket buyers. Your data is associated with your ticket records. To request deletion, provide your name, email address, and the event you attended.
13.5 How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request. If we cannot verify your identity, we may deny the request.
14. Aggregated and De-Identified Data
We may aggregate or de-identify personal data so that it no longer identifies you. We may use and share such data for any lawful purpose, including research, analytics, and service improvement, without restriction.
15. Children's Privacy
The Service is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at [email protected] and we will delete it promptly.
16. International Data Transfers
Our Service is operated using infrastructure hosted primarily in the United States (Google Cloud us-central1). If you are located outside the United States, your personal data will be transferred to and processed in the United States.
We rely on appropriate safeguards for international transfers, including Standard Contractual Clauses approved by the European Commission where required by applicable law.
17. Cookies and Tracking
The Service does not use advertising cookies or tracking cookies for behavioral advertising. Cloudflare may set security-related cookies as part of its bot detection and DDoS protection services. Cloudflare Turnstile (our CAPTCHA replacement) uses a privacy-preserving challenge mechanism that does not track users across sites.
Firebase Authentication may use session cookies or similar technologies to maintain your sign-in state. These are necessary for the operation of the Service.
18. Third-Party Links
The Service may contain links to third-party websites or services (for example, event organizer websites or social media pages). We are not responsible for the privacy practices or content of those third parties. We encourage you to read their privacy policies before providing them with your information.
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or Service functionality. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we will provide additional notice (such as an email to event organizers or a prominent banner on the Service).
Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy. If you do not agree to the updated policy, you should stop using the Service and contact us to delete your data where applicable.
20. Contact Us
For privacy-related questions, requests, or complaints:
- Email: [email protected]
- Website: https://ticketcosmo.com
If you need this policy in an alternative format, please contact us and we will endeavor to provide it.