Draft — for internal review only

This page is a draft and has not been reviewed by counsel. It is illustrative marketing copy, not legal advice. Before accepting payments against it the operator must replace this text with the version signed off by qualified counsel.

Legal

Privacy Policy

This Privacy Policy explains what data TicketNexus collects, why we collect it, the third parties we share it with, and how you can reach us about your data. It supplements our Terms of Service — the agreement that governs your use of the service.

Effective:

Data we collect

We collect first-party data you provide directly to TicketNexus: the email address, name and account metadata you submit when creating an account with Better Auth; the messages and contact details you send through the public contact form; the email and context you provide when joining the waitlist for a future product surface; and the application fields you fill out when applying for the invitation-only Elite tier. Each piece of data is collected for a specific purpose tied to a feature — sign-up, contact, waitlisting, or membership application — and we do not collect data we have no use for.

Public marketplace listings (event metadata, seat or section, price, description, optional photos) are user-supplied content: sellers fill them in, buyers read them, and we surface them through the listings browser without separately profiling them. The same rule applies to Elite application submissions — we read what you sent, evaluate it for membership, and keep it for the period the application requires.

Auth via Better Auth

Better Auth is the framework handling every credential check on TicketNexus. When you sign up or sign in, Better Auth stores the information needed to verify you on subsequent visits: a hashed representation of your credential material, the session tokens that keep you signed in across requests, and the account identifiers that link those sessions back to your profile. We never retain raw passwords on our servers — credential material is processed by Better Auth and never reaches our application database in plaintext.

Better Auth is the only gate for surfaces that show your personal data (the dashboard, your watchlist, your purchase history, your application status, the concierge desk). Anonymous visitors can browse the public listings, read marketing pages, and load the legal copy without ever touching Better Auth; the moment a page needs to know whose account it is rendering, it consults Better Auth first.

Stripe Connect payment metadata

Payments on TicketNexus go through Stripe Connect payment links and the hosted Stripe checkout — we do not collect card numbers, expiration dates, CVV codes or any other card data on our servers. Card payment information is collected by Stripe on the hosted checkout page and never crosses into TicketNexus infrastructure.

What we do receive is the metadata Stripe returns to us: the payment status (succeeded, failed, refunded, disputed), the amount and currency that cleared, the platform fee Stripe collected on the transaction, the last4 / billing reference Stripe associates with the buyer, and the dispute lifecycle events Stripe sends as a charge moves through any review. We persist this metadata so we can reconcile every transaction, respond to disputes, and meet the tax-relevant retention requirements of the jurisdictions you transact in. The Stripe-billing module verify route is the canonical place this reconciliation reads from.

Listings and application data

Sellers in the Standard marketplace fill in the fields a listing needs to be browsable: event metadata (the artist, team or production; the date and venue), the seat or section being offered, the asking price, a written description, and any photos the seller chooses to upload. We surface those fields to buyers through the public listings browser and retain them for the lifetime of the listing plus the period required to back up dispute resolution for that transaction.

Applicants for the Elite tier submit a separate set of fields: full name, contact information, the references an applicant chooses to provide, and the journey use case the applicant describes. We treat Elite application data as first-party content you supplied for a specific decision; we do not profile it for marketing, and we delete it on request once the application is closed unless retention is required to defend a decision we made on its basis.

Cookies

TicketNexus sets a single cookie by default: a small locale cookie remembering whether you prefer a non-default display language. The site is otherwise single-locale static, so even this cookie is not always written — it exists to support a future i18n switch without retroactively changing behaviour for visitors who never set a preference. No first-party analytics cookies are set, no advertising cookies are set, and no third-party tracking pixels run on our pages.

When you sign in, Better Auth issues its own session cookies on our domain — these are required to keep you signed in across requests and to recognize you on the gated dashboard surfaces. When you reach the Stripe hosted checkout page, Stripe sets its own cookies in that context (we do not read or forward those cookies back to our domain). Stripes session is short-lived and confined to the checkout flow.

Retention

Account records are retained for the life of your account plus the period the jurisdiction in which you transact mandates for transaction history, dispute records and tax-relevant invoices. We do not retain data beyond the period we need it for — once the legal retention period closes on a record, it is deleted from active systems and any backups run their normal rotation.

Contact-form submissions and waitlist sign-ups follow separate, documented lifetimes that are shorter than account records, and either can be erased on request without affecting the rest of your account. Payment events (the Stripe metadata described above) are retained for the period required to support reconciliation and tax, then deleted on the same rotation. Deletion-on-request is available for every category of personal data we hold, subject to the legal-hold exception for records we are required to preserve (an open dispute, an active tax audit, a regulator-mandated freeze).

Contact

Send data-protection requests (access, correction, deletion, portability) and privacy questions to our privacy mailbox through the contact form on this site (it posts to POST /api/contact and reaches the privacy desk) or directly to our privacy email address. We respond to every verifiable request within the timeline the relevant law requires.

For non-privacy questions (a listing dispute, an account problem, a membership question) please use the standard support queue rather than the privacy mailbox — the privacy desk is set up to handle data-protection requests specifically, and routing the right question to the right team gets you a faster answer.

Changes to this policy

We may update this Privacy Policy as the service evolves; the effective date at the top of this page reflects the version in force. Material changes are announced by email at least fourteen days before they take effect, except where the change is in your favour or required by law on a shorter timeline. A version history of every prior effective date is preserved alongside the current text so a reviewer can trace what changed and when.

Your continued use of TicketNexus after the effective date of an updated policy signals acceptance of the new terms. If you do not agree to an update, you may close your account before the effective date and we will handle your existing records under the policy that applied at the time you collected them.