Cookie Policy
Effective
We use a short list of first-party cookies — most of them are the ones that make signing in and checking out work at all. On an event organizer’s own pages, the Meta and Google advertising tags that organizer has connected set cookies too, unless you opt out.
This Cookie Policy explains the cookies and similar technologies used on the Service, and how to control them. It supplements our Privacy Policy.
1.What cookies are
A cookie is a small text file a website asks your browser to store, and hands back to the site on your next request. Cookies are how a website remembers that you are signed in between one page and the next.
- First-party cookies are set by the site you are visiting. Every cookie we set is first-party. The advertising tags an Event Organizer connects also keep their cookies on our domain — see Advertising cookies.
- Session cookies are erased when you close your browser. Persistent cookies last for a stated period.
- Strictly necessary cookies are required for the site to function — you cannot turn them off and still buy a ticket.
We also use local storage on the check-in application, so that staff can keep scanning tickets when venue signal drops. That is not a cookie and is never used for tracking — see Offline check-in.
2.Strictly necessary cookies
These make the Service work. Blocking them will break sign-in, checkout, or ticket scanning.
| Cookie | Purpose | Lifetime |
|---|---|---|
| authjs.session-token (__Secure- prefixed over HTTPS) | Keeps you signed in. Contains a signed token identifying your account and role. HTTP-only, so page scripts cannot read it | Session, up to 30 days |
| authjs.csrf-token (__Host- prefixed over HTTPS) | Protects sign-in and account forms against cross-site request forgery | Session |
| authjs.callback-url | Remembers where to send you after you sign in | Session |
| tbf_flash | Carries a one-off confirmation message across a redirect, so you see “Saved” after an action completes. Cleared as soon as it is shown | 60 seconds |
| tbf_gate_device | Identifies a phone or tablet that event staff enrolled as a ticket scanner. HTTP-only. Only set on staff devices, never on a buyer’s browser | Until the event access code expires |
| tbf_oauth_state | Protects the administrator flow that connects a payment processor. Only set for administrators, and deleted the moment the connection completes | A few minutes |
3.Analytics and attribution cookies
These help us understand how the Service is used and which campaigns bring people to an event. They are not required for the Service to work, and you can switch them off — see Your choices.
| Cookie | Purpose | Lifetime |
|---|---|---|
| tbf_ft | First-touch attribution. Records the campaign parameters, referring site, and landing page of your first attributed visit, so a purchase can be credited to the right campaign. Set only when you arrive with campaign parameters or from an external site — a plain direct visit sets nothing | 30 days |
| ph_… _posthog | PostHog’s cookie, our product analytics provider. Holds a random identifier for your browser and basic session state so that a sequence of page views can be counted as one visit | Up to 12 months |
| datafast_visitor_id, datafast_visitor_first_seen_at, datafast_visitor_session_count | DataFast’s cookies, our traffic analytics provider. A random identifier for your browser, when it was first seen, and how many visits it has made, so that visitors and returning visitors can be counted | 12 months |
| datafast_session_id | DataFast’s visit cookie. Groups the page views of one visit together. Alongside it, a session-storage entry (datafast_pageview_state) stops a page reload being counted twice | 30 minutes after your last page view |
Session replay
PostHog records a reconstruction of some browsing sessions so we can see where the interface confuses or fails people. Every text input is masked — names, email addresses, phone numbers, and anything else you type into a field are not captured. Card details are entered on the payment processor’s own fields and never appear in a replay at all.
Turning off analytics, as described below, turns off session replay too.
4.Advertising cookies
Set only on an Event Organizer’s event pages, checkout, order confirmation, and organization page, only when that organizer has connected its Meta or Google advertising account, and never once you have opted out. They are not required for the Service to work. What the tags send, and what we send Meta from our servers when you buy, is in the Privacy Policy.
| Cookie | Purpose | Lifetime |
|---|---|---|
| _fbp | Meta’s browser identifier, set by the organizer’s Meta pixel so Meta can recognise this browser across visits and match a purchase to an ad | 90 days |
| _fbc | Meta’s click identifier, set when you arrive from one of the organizer’s Meta ads, so the purchase can be credited to that ad | 90 days |
| _ga, _ga_… | Google Analytics identifiers, set by the organizer’s Google tag to count your visits and purchase in its Google Analytics property | 2 years |
| _gcl_au and other _gcl_ cookies | Google Ads conversion cookies, set by the organizer’s Google tag so a purchase can be credited to one of its Google ads | 90 days |
| tbf_ad_optout | Ours. Remembers that you opted out of advertising tracking on Your Privacy Choices, so the tags stay off and your purchases are not sent to Meta | 12 months |
The organizer’s tags load from, and report to, Meta (connect.facebook.net, facebook.com) and Google (googletagmanager.com, google-analytics.com, google.com, doubleclick.net) directly. The order confirmation also keeps a local-storage note of each order it has reported, so a reload does not report the same purchase twice.
5.Third-party content
Our own analytics requests are proxied through our own domain rather than being sent directly to the provider, so they are not blocked by network filters and no additional third-party host is contacted for them. Event Organizers’ advertising tags are the exception — see Advertising cookies.
Where you pay by card, the payment fields are supplied by Square or Stripe and may set cookies of their own for fraud prevention and to keep the payment session alive. Those are governed by that processor’s own privacy and cookie policies. We cannot switch them off — they are part of taking a payment safely.
Where our ticket widget is embedded in an Event Organizer’s website, that site sets its own cookies. They are not ours and are covered by that site’s cookie policy.
6.Offline check-in storage
The check-in application used by event staff can download a manifest of an event’s tickets to the device, so scanning keeps working when venue signal drops. That manifest is held in browser storage on the staff device, contains only what is needed to validate a ticket at the door, and is reconciled with our servers as soon as the device reconnects.
This is staff-only. Nothing comparable is stored on a ticket buyer’s device.
7.Your choices
Global Privacy Control
If your browser or extension sends a Global Privacy Control signal, we treat it as an opt-out request: Event Organizers’ advertising tags do not load, we do not send your purchases to Meta, and we switch off analytics and session replay for that browser automatically. You do not need to do anything else.
Opting out of advertising tags
Without Global Privacy Control, use the switch on Your Privacy Choices. It sets the tbf_ad_optout cookie, so it applies to that browser until you clear your cookies — set it on each device you buy from.
Browser settings
Every major browser lets you see the cookies a site has set, delete them, and block future ones. Look under Privacy or Site settings. Blocking all cookies will prevent you from signing in or completing a purchase.
Do Not Track
There is no agreed industry standard for how a site should respond to a Do Not Track header, so we do not act on it. We do act on Global Privacy Control, as described above.
8.Changes and contact
We update this policy when the cookies we use change. The effective date at the top reflects the current version.
Questions about cookies: support@fomotickets.com.