TicketsByFomo
Sign inCreate account
TicketsByFomo
Browse eventsMy ticketsContact
TermsPurchase PolicyRefundsPrivacyCookiesYour Privacy ChoicesAccessibilityAll legal

© 2026 Vadelis Labs Inc. · TicketsByFomo · Payments secured by Square

All legal documents

Buying tickets

  • Terms of Use
  • Purchase Policy
  • Refunds

Privacy and data

  • Privacy Policy
  • Cookies
  • Your Privacy Choices

Using the platform

  • Acceptable Use
  • Copyright / DMCA
  • Organizer Agreement

Accessibility and security

  • Accessibility
  • Security

Cookie Policy

Effective September 30, 2026

We use a short list of first-party cookies — most of them are the ones that make signing in and checking out work at all. On an event organizer’s own pages, the Meta and Google advertising tags that organizer has connected set cookies too, unless you opt out.

This Cookie Policy explains the cookies and similar technologies used on the Service, and how to control them. It supplements our Privacy Policy.

Advertising cookies appear only on Event Organizers’ pages, and only when an organizer connects them. An organizer can add its own Meta pixel and Google tag to its event pages, checkout, and order confirmation; those tags set advertising cookies and tell Meta and Google what you view and buy there. Opt out with one switch, or send Global Privacy Control. We run no advertising of our own, and no data broker sets a cookie through the Service.

Contents

  1. 1.What cookies are
  2. 2.Strictly necessary cookies
  3. 3.Analytics and attribution cookies
  4. 4.Advertising cookies
  5. 5.Third-party content
  6. 6.Offline check-in storage
  7. 7.Your choices
  8. 8.Changes and contact

1.What cookies are

A cookie is a small text file a website asks your browser to store, and hands back to the site on your next request. Cookies are how a website remembers that you are signed in between one page and the next.

  • First-party cookies are set by the site you are visiting. Every cookie we set is first-party. The advertising tags an Event Organizer connects also keep their cookies on our domain — see Advertising cookies.
  • Session cookies are erased when you close your browser. Persistent cookies last for a stated period.
  • Strictly necessary cookies are required for the site to function — you cannot turn them off and still buy a ticket.

We also use local storage on the check-in application, so that staff can keep scanning tickets when venue signal drops. That is not a cookie and is never used for tracking — see Offline check-in.

2.Strictly necessary cookies

These make the Service work. Blocking them will break sign-in, checkout, or ticket scanning.

CookiePurposeLifetime
authjs.session-token (__Secure- prefixed over HTTPS)Keeps you signed in. Contains a signed token identifying your account and role. HTTP-only, so page scripts cannot read itSession, up to 30 days
authjs.csrf-token (__Host- prefixed over HTTPS)Protects sign-in and account forms against cross-site request forgerySession
authjs.callback-urlRemembers where to send you after you sign inSession
tbf_flashCarries a one-off confirmation message across a redirect, so you see “Saved” after an action completes. Cleared as soon as it is shown60 seconds
tbf_gate_deviceIdentifies a phone or tablet that event staff enrolled as a ticket scanner. HTTP-only. Only set on staff devices, never on a buyer’s browserUntil the event access code expires
tbf_oauth_stateProtects the administrator flow that connects a payment processor. Only set for administrators, and deleted the moment the connection completesA few minutes

3.Analytics and attribution cookies

These help us understand how the Service is used and which campaigns bring people to an event. They are not required for the Service to work, and you can switch them off — see Your choices.

CookiePurposeLifetime
tbf_ftFirst-touch attribution. Records the campaign parameters, referring site, and landing page of your first attributed visit, so a purchase can be credited to the right campaign. Set only when you arrive with campaign parameters or from an external site — a plain direct visit sets nothing30 days
ph_… _posthogPostHog’s cookie, our product analytics provider. Holds a random identifier for your browser and basic session state so that a sequence of page views can be counted as one visitUp to 12 months
datafast_visitor_id, datafast_visitor_first_seen_at, datafast_visitor_session_countDataFast’s cookies, our traffic analytics provider. A random identifier for your browser, when it was first seen, and how many visits it has made, so that visitors and returning visitors can be counted12 months
datafast_session_idDataFast’s visit cookie. Groups the page views of one visit together. Alongside it, a session-storage entry (datafast_pageview_state) stops a page reload being counted twice30 minutes after your last page view

Session replay

PostHog records a reconstruction of some browsing sessions so we can see where the interface confuses or fails people. Every text input is masked — names, email addresses, phone numbers, and anything else you type into a field are not captured. Card details are entered on the payment processor’s own fields and never appear in a replay at all.

Turning off analytics, as described below, turns off session replay too.

4.Advertising cookies

Set only on an Event Organizer’s event pages, checkout, order confirmation, and organization page, only when that organizer has connected its Meta or Google advertising account, and never once you have opted out. They are not required for the Service to work. What the tags send, and what we send Meta from our servers when you buy, is in the Privacy Policy.

CookiePurposeLifetime
_fbpMeta’s browser identifier, set by the organizer’s Meta pixel so Meta can recognise this browser across visits and match a purchase to an ad90 days
_fbcMeta’s click identifier, set when you arrive from one of the organizer’s Meta ads, so the purchase can be credited to that ad90 days
_ga, _ga_…Google Analytics identifiers, set by the organizer’s Google tag to count your visits and purchase in its Google Analytics property2 years
_gcl_au and other _gcl_ cookiesGoogle Ads conversion cookies, set by the organizer’s Google tag so a purchase can be credited to one of its Google ads90 days
tbf_ad_optoutOurs. Remembers that you opted out of advertising tracking on Your Privacy Choices, so the tags stay off and your purchases are not sent to Meta12 months

The organizer’s tags load from, and report to, Meta (connect.facebook.net, facebook.com) and Google (googletagmanager.com, google-analytics.com, google.com, doubleclick.net) directly. The order confirmation also keeps a local-storage note of each order it has reported, so a reload does not report the same purchase twice.

5.Third-party content

Our own analytics requests are proxied through our own domain rather than being sent directly to the provider, so they are not blocked by network filters and no additional third-party host is contacted for them. Event Organizers’ advertising tags are the exception — see Advertising cookies.

Where you pay by card, the payment fields are supplied by Square or Stripe and may set cookies of their own for fraud prevention and to keep the payment session alive. Those are governed by that processor’s own privacy and cookie policies. We cannot switch them off — they are part of taking a payment safely.

Where our ticket widget is embedded in an Event Organizer’s website, that site sets its own cookies. They are not ours and are covered by that site’s cookie policy.

6.Offline check-in storage

The check-in application used by event staff can download a manifest of an event’s tickets to the device, so scanning keeps working when venue signal drops. That manifest is held in browser storage on the staff device, contains only what is needed to validate a ticket at the door, and is reconciled with our servers as soon as the device reconnects.

This is staff-only. Nothing comparable is stored on a ticket buyer’s device.

7.Your choices

Global Privacy Control

If your browser or extension sends a Global Privacy Control signal, we treat it as an opt-out request: Event Organizers’ advertising tags do not load, we do not send your purchases to Meta, and we switch off analytics and session replay for that browser automatically. You do not need to do anything else.

Opting out of advertising tags

Without Global Privacy Control, use the switch on Your Privacy Choices. It sets the tbf_ad_optout cookie, so it applies to that browser until you clear your cookies — set it on each device you buy from.

Browser settings

Every major browser lets you see the cookies a site has set, delete them, and block future ones. Look under Privacy or Site settings. Blocking all cookies will prevent you from signing in or completing a purchase.

Do Not Track

There is no agreed industry standard for how a site should respond to a Do Not Track header, so we do not act on it. We do act on Global Privacy Control, as described above.

8.Changes and contact

We update this policy when the cookies we use change. The effective date at the top reflects the current version.

Questions about cookies: support@fomotickets.com.

This document is part of the TicketsByFomo legal collection. Each document links to the others where they overlap.

PreviousPrivacy PolicyNextYour Privacy Choices