Data & security
Your data stays yours.
Equaticket is infrastructure. We process ticket sales and deliver transactional emails on your behalf. We don't monetize your attendee data, share it with advertisers, or use it to promote other events to your buyers.
Export anytime
Full attendee list as CSV, no restrictions, no expiry. Your data leaves with you.
No marketplace
Equaticket has no discovery platform. We don't cross-promote your attendees to other organizers.
Direct payments
Money flows straight to your Stripe account. Equaticket never holds organizer funds.
Audience ownership
Your attendees belong to you.
When a buyer purchases a ticket through Equaticket, their name and email become part of your audience, not a platform-wide audience. We do not:
You can export your full attendee list as a CSV at any time, with no restrictions. You can also connect your Mailchimp or Kit account to sync buyers to your own email list automatically. When you leave Equaticket, your data leaves with you.
Transparency
What we process and why.
When a buyer purchases a ticket, we collect only what's needed to deliver that ticket and operate the platform:
Name and email address
To deliver the ticket confirmation email and populate your audience dashboard
Payment details
Processed by Stripe directly. Equaticket never sees or stores raw card data.
Order and ticket records
Retained for the validity of the purchase, refunds, and organizer reporting
We do not build advertising profiles on buyers. We do not share buyer data with third parties for marketing purposes.
Payments
Money flows directly to you.
Equaticket uses Stripe Connect Standard. When a buyer checks out, payment goes directly to your connected Stripe account. Equaticket is not an intermediary in the money flow. We never hold organizer funds.
Your Stripe account is yours. Equaticket's access is limited to initiating charges on your behalf during checkout. You can disconnect at any time from your Stripe dashboard.
Buyer
pays at checkout
Stripe
processes the card
Your account
funds arrive directly
Equaticket is never in the money flow: no holding, no payouts.
Security
How we protect your account.
API keys hashed
Stored as SHA-256 hashes. The raw key is shown once at creation and never stored in recoverable form.
Webhook secrets encrypted
Signing secrets stored encrypted at rest using AES-256-GCM.
Scope-limited access
API keys are scoped to specific permissions (events:read, orders:read, etc.) and cannot exceed grants at creation.
Row-level security
Database hosted on Supabase PostgreSQL with RLS policies on all tables. Each organizer's data is isolated at the row level.
Edge hosting
Vercel edge network with serverless functions. Cloudflare for DNS and DDoS protection.
PCI by delegation
Payment data handled entirely by Stripe. Equaticket never sees raw card data; Stripe absorbs the PCI scope.
GDPR
Data erasure on request.
If one of your buyers requests deletion of their personal data under GDPR or a similar regulation, you can process the request directly from your audience dashboard. Erasure anonymizes the buyer's record across all their orders and tickets, permanently and immediately.
You are the data controller for your attendees. Equaticket does not accept data erasure requests directly from buyers.
For step-by-step instructions, see the GDPR Data Erasure guide →
Incidents
We communicate openly.
If there is a platform incident affecting service, we publish updates at equaticket.com/status. Organizers on paid plans receive email notifications for incidents that affect their account.
Infrastructure you can trust.
Flat subscription. No data monetization. Your audience stays yours.
