TicketsByFomo
Sign inCreate account
TicketsByFomo
Browse eventsMy ticketsContact
TermsPurchase PolicyRefundsPrivacyCookiesYour Privacy ChoicesAccessibilityAll legal

© 2026 Vadelis Labs Inc. · TicketsByFomo · Payments secured by Square

All legal documents

Buying tickets

  • Terms of Use
  • Purchase Policy
  • Refunds

Privacy and data

  • Privacy Policy
  • Cookies
  • Your Privacy Choices

Using the platform

  • Acceptable Use
  • Copyright / DMCA
  • Organizer Agreement

Accessibility and security

  • Accessibility
  • Security

Privacy Policy

Effective September 30, 2026

A complete account of the personal information we handle — for ticket buyers, attendees, event organizers, and anyone browsing the site — written against what the platform actually does.

This Privacy Policy explains how Vadelis Labs Inc., the operator of TicketsByFomo and FOMOtickets, collects, uses, shares, and protects personal information, and what choices you have. It applies to our websites, our embedded ticket widgets, the tickets and emails we send, and the check-in applications used at events.

We do not sell your personal information, and we run no advertising of our own. An Event Organizer can connect its own Meta and Google advertising accounts to its event pages. Where it has, what you view and buy there is shared with Meta and Google so the organizer can measure and target its ads — see Event Organizers’ advertising tags. You can opt out with one switch, and a Global Privacy Control signal opts you out automatically. We never pass your details to data brokers.
The short version
What we collectYour name, contact details, what you bought, answers to questions the event organizer asked, and technical information about your visit.
WhyTo sell you a ticket, get you into the event, support you afterwards, keep the platform secure, and meet our legal obligations.
Who sees itThe organizer of the event you bought into, the service providers listed in this policy, and — where that organizer has connected them and you have not opted out — its Meta and Google advertising accounts. Nobody else, unless the law requires it.
Card detailsNever touch our systems. They go straight to Square or Stripe.
Your rightsAccess, correction, deletion, portability, and more — see Your rights and Your Privacy Choices.

Contents

  1. 1.Who this policy covers
  2. 2.Our role: controller and service provider
  3. 3.What we collect
  4. 4.Sensitive information
  5. 5.How we use information, and on what basis
  6. 6.Who we share information with
  7. 7.Cookies and tracking technologies
  8. 8.Event Organizers’ advertising tags
  9. 9.Email and your choices about it
  10. 10.How long we keep information
  11. 11.How we protect information
  12. 12.Your privacy rights
  13. 13.United States state privacy notices
  14. 14.Children
  15. 15.Where information is held, and international users
  16. 16.Other sites and embedded widgets
  17. 17.Changes to this policy
  18. 18.Contact us

1.Who this policy covers

This policy applies to four groups of people:

Ticket buyers
Anyone who buys a ticket, registers for an event, or joins a waitlist through the Service.
Attendees
Anyone whose name or details a buyer entered on a ticket, and anyone checked in at the door.
Event Organizers and their staff
People with an account that lets them create events, sell at the door, or scan tickets.
Visitors
Anyone browsing the site or an embedded ticket widget without buying anything.

It does not cover what an Event Organizer does with your information on its own systems once we have passed it to them, or the practices of any other website — including a site that embeds our ticket widget. Those are governed by their own privacy policies.

2.Our role: controller and service provider

Our role changes depending on whose information it is and why we hold it.

We are the controller
for your account, your login and security records, your transaction history with us, the technical records of your visit, our own analytics, and our fraud and abuse prevention. We decide why and how that information is used, and this policy governs it.
We act as a service provider (processor) for the Event Organizer
for information collected specifically for their event — attendee names, answers to the questions they configured, waivers they wrote, check-in records, and their attendee lists. They decide what to ask and what to do with the answers. We process it on their instructions to run the event, and we do not use it for our own purposes.

Where we act as a service provider, requests about that information may need to go to the Event Organizer. Send the request to us anyway — we will act on it where we can and route it where we cannot, and we will tell you which happened.

Whichever hat we are wearing, we never sell attendee information and never use one Event Organizer’s attendee list to market another Event Organizer’s events. The only advertising use is an Event Organizer’s own tags on its own event pages, described in Event Organizers’ advertising tags, which you can opt out of.

3.What we collect

Information you give us

CategoryWhat it includesWhen
Identifiers and contact detailsFirst and last name, email address, phone number.Creating an account, checking out, joining a waitlist, contacting support.
Account credentialsA one-way hash of your password (never the password itself), email verification and password reset tokens.Registering, signing in, resetting a password.
Billing and address informationHome or billing address, where the event is configured to collect one.Checkout, for events that require it.
Order informationWhat you bought, quantities, ticket types, add-ons, discount codes used, amounts, fees and tax, and the payment processor’s reference for the payment.Every purchase.
Attendee detailsThe name — and sometimes email or phone — of each person a ticket is for.Checkout, where the event requires named tickets.
Answers to organizer questionsWhatever the Event Organizer chose to ask: dietary needs, accessibility requirements, affiliations, free text.Checkout, for events with custom questions.
Waivers and signaturesThe version of the waiver you accepted, the legal name you typed, and the time you accepted it.Checkout, for events with a waiver.
Support correspondenceThe content of your messages to us and our replies.When you contact us.

Information we collect automatically

  • Device and connection data — IP address, browser and operating system, and the user agent string. The IP address and user agent of a purchase are stored with the order as a fraud and dispute record.
  • Usage data — pages viewed, events viewed, checkout steps reached and abandoned, and other interactions with the Service.
  • Referral and campaign data — the site you arrived from, the page you landed on, and any campaign parameters in the link you followed. We store the first attributed visit in a cookie for 30 days so that we can credit the right campaign for a purchase. See the Cookie Policy.
  • Session replay — PostHog, our product analytics provider, records a reconstruction of some browsing sessions so we can see where the interface fails people. Every text input is masked, so names, email addresses, phone numbers, and anything else typed into a field are not captured, and card entry happens on the payment processor’s own fields and never appears at all.
  • Security records — sign-in attempts, rate-limiting counters keyed to an IP address or account, and audit records of check-in scans (which device, which operator, and when).
  • Advertising identifiers — where an Event Organizer has connected Meta or Google advertising tags and you have not opted out: the identifiers those tags keep in cookies on our domain, and a click identifier if you arrived from one of their ads. See Event Organizers’ advertising tags.

Information we receive from others

  • From payment processors — whether a payment succeeded, failed, or was refunded, the processor’s payment identifier, and the payment method type. We do not receive your full card number, expiry date, or security code.
  • From our email provider — whether a message was delivered, bounced, or was reported as spam, so we can stop sending to addresses that reject our mail.
  • From Event Organizers — details of a sale made at the door, and any attendee information they add on your behalf.

What we deliberately do not collect

  • Full payment card numbers, expiry dates, or security codes.
  • Social security or other government identification numbers.
  • Precise geolocation. We never ask for device location.
  • Biometric identifiers. Scanning a ticket reads a QR code, not a face.
  • Information about your activity on other websites or apps.

4.Sensitive information

We do not ask for sensitive personal information for our own purposes, and we do not use or disclose it to infer characteristics about you.

An Event Organizer may configure a checkout question whose answer is sensitive — an accessibility requirement, a dietary restriction that implies a religious belief, a health condition relevant to a waiver. Where that happens:

  • you choose whether to answer, unless the Event Organizer has made the question required for entry;
  • the answer is used only to run that event, and is visible to that Event Organizer and to staff working that event; and
  • we hold it as a service provider, on the Event Organizer’s instructions, and use it for nothing else.

Please do not enter sensitive information into a free-text field where it is not being asked for.

5.How we use information, and on what basis

What we doWhyLegal basis (where GDPR applies)
Take your order, hold inventory, charge your card, issue tickets, email confirmations and tickets, admit you at the door, process refundsTo perform the contract you entered into when you bought a ticketPerformance of a contract
Give the Event Organizer the attendee list and answers for its eventSo the event can actually be runPerformance of a contract; legitimate interests
Answer support requests and handle complaints and disputesTo provide the service you asked for and defend claimsPerformance of a contract; legitimate interests
Detect and prevent fraud, bot purchasing, ticket-limit evasion, duplicate scans, and abuse; keep accounts secureTo protect buyers, Event Organizers, and the platformLegitimate interests; legal obligation
Understand how the Service is used, fix what is broken, and improve itTo make the product work betterLegitimate interests
Report aggregate sales, attendance, and campaign performance to Event OrganizersTo give organizers the numbers for their own eventsLegitimate interests
Send you marketing about events, where you have asked for itTo tell you about things you said you wanted to hear aboutConsent
Keep records for tax, accounting, and audit; respond to lawful requestsBecause we are required toLegal obligation

We do not use your information to make decisions about you with legal or similarly significant effects by automated means alone. Automated fraud checks may flag an order, but a person reviews before an order is cancelled on that basis.

6.Who we share information with

Event Organizers

When you buy a ticket, the Event Organizer for that event receives your name, email address, phone number if you gave one, what you bought, and your answers to their questions and waivers. They need it to run the event, admit you, and contact you about it.

Event Organizers are contractually required to use that information only for their event, to keep it secure, to comply with privacy law, and not to sell it. What they do with it on their own systems is governed by their privacy policy, not ours. See the Organizer Agreement.

Service providers

We use a small number of providers to run the Service. Each is bound by contract to process information only on our instructions and to protect it. All of them store data in the United States.

ProviderWhat they do for usLocation
Vercel Inc.Hosts and delivers the application; serves pages and API requests, and holds short-lived request logsUnited States
Supabase Inc.Hosts the database that holds accounts, orders, and tickets, and the storage bucket that holds event imagesUnited States
Square, Inc. or Stripe, Inc.Processes card payments and refunds; captures card details directly, so they never reach us. Only one processor is active at a timeUnited States
Twilio SendGridDelivers transactional email — order confirmations, tickets, verification, password resets, refund notices — and reports delivery outcomesUnited States
PostHog Inc.Product analytics and masked session replayUnited States
JustShipIt Pte. Ltd. (DataFast)Website traffic analytics — page views, referring sites, and approximate location derived from your IP address, counted against a random browser identifierSingapore; infrastructure mainly in the United States
Upstash Inc.Rate limiting on sign-in and other sensitive endpoints, to blunt brute-force and abuseUnited States

Others

  • Legal and safety disclosures. We disclose information where we are legally required to — a subpoena, court order, or lawful request from a regulator or law enforcement — and where necessary to investigate fraud, enforce our terms, or protect the rights, property, or safety of any person. We review each request and disclose no more than is required.
  • Professional advisers. Our lawyers, accountants, insurers, and auditors, under duties of confidentiality.
  • Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will tell you before your information becomes subject to a different privacy policy.
  • With your direction. Where you ask us to share something with someone.

Event Organizers’ advertising partners

Where an Event Organizer has connected its Meta or Google advertising account, information about your visit to its event pages and your purchase goes to Meta Platforms, Inc. and Google LLC at that organizer’s direction. What is sent, and how to stop it, is in Event Organizers’ advertising tags.

We do not sell personal information, as that term is used in the California Consumer Privacy Act and comparable state laws, and have not done so in the preceding 12 months. The disclosures to Meta and Google described in Event Organizers’ advertising tags are “sharing” for cross-context behavioural advertising under those laws, and you can opt out of them at any time. We do not have actual knowledge of selling or sharing the personal information of anyone under 16.

7.Cookies and tracking technologies

We use a small set of first-party cookies for signing in, for security, and for analytics and campaign attribution. On an Event Organizer’s event pages, the Meta and Google advertising tags that organizer has connected set advertising cookies too, unless you have opted out. No other ad network sets cookies through the Service.

The full list, with purposes and lifetimes, and how to control them, is in the Cookie Policy.

8.Event Organizers’ advertising tags

We run no advertising of our own. An Event Organizer can connect its own Meta pixel and Google tag so it can measure, and target, the ads it runs for its events. Where it has, and you have not opted out:

  • In your browser, on that organizer’s event pages, checkout, and order confirmation, and on its organization page: the Meta pixel and Google tag load from Meta and Google, set their own cookies, and report the pages you view, the tickets you take to checkout, and your purchase — what you bought, what it cost, and your order number — together with your IP address and browser details.
  • From our servers, when you complete a purchase for that organizer’s event — including one made through its embedded widget — we send Meta your email address, and your phone number, name, city, state, and ZIP code where you gave them, each one-way hashed (SHA-256) so the value itself is not readable, together with your IP address, your browser’s user agent, Meta’s cookie identifiers, and what you bought and its value. Meta uses the hashes to match the purchase to a Meta account.

Meta and Google receive this as independent companies, and their own privacy policies govern what they do with it. The tags never run inside the widget an organizer embeds on its own website — tags there belong to that website — and never on our account, management, or check-in pages.

Opting out

Use the switch on Your Privacy Choices, or send a Global Privacy Control signal. Either one stops the tags loading in that browser and stops us sending your purchases to Meta. The switch is stored as a cookie, so it applies to the browser you set it in.

9.Email and your choices about it

Service email
Order confirmations, tickets, verification and password reset messages, event change and refund notices. These are part of the service and you cannot unsubscribe from them while you hold an active order — without them you would not receive your tickets.
Marketing email
Sent only where you have opted in. Every marketing message carries an unsubscribe link that works immediately, and you can also ask us to remove you at any time.
Event Organizer email
An Event Organizer may email you about its own event. Marketing from an Event Organizer is their responsibility and their unsubscribe link; we require them to honour opt-outs.
Suppression
If mail to your address hard-bounces or is reported as spam, we add it to a suppression list and stop sending to it. This protects delivery for everyone. Contact us to have an address reinstated.

10.How long we keep information

We keep personal information only as long as we need it for the purpose it was collected, plus any period the law requires.

InformationHow long
Order, ticket, refund, and payment recordsAt least 7 years after the event, for tax, accounting, audit, and dispute purposes. These records cannot be deleted on request while that obligation runs.
Your account and profileUntil you ask us to delete it, or until it has been inactive for 7 years. Deletion is completed within 45 days of a verified request, except for records we must keep.
Attendee details and answers to organizer questionsFor the life of the event plus the retention period the Event Organizer instructs, and in any case no longer than our order records.
Waivers and signaturesFor as long as a claim relating to the event could be brought, and at least 7 years.
Check-in and scan audit records12 months after the event.
Waitlist entriesUntil the event has passed, or until you ask to be removed.
Email suppression recordsIndefinitely. Deleting a suppression record would cause us to start mailing an address that rejects our mail.
Analytics and session replayGoverned by our analytics providers’ retention settings; replays are kept for a short window and are not linked to an identified person before purchase.
Security logs, rate-limit records, and request logsShort-lived — typically 30 to 90 days — unless retained for an active investigation.

Where we no longer need information but cannot delete it immediately, we isolate it from further use until deletion is possible. Where we keep information for reporting, we aggregate or anonymize it so it no longer identifies anyone.

11.How we protect information

  • All traffic is encrypted in transit with TLS, and data at rest is encrypted by our hosting and database providers.
  • Passwords are stored only as salted one-way hashes. We cannot read your password, and neither can anyone who obtains our database.
  • Payment credentials belonging to an Event Organizer are encrypted with AES-256-GCM using a key held outside the database.
  • Access to production data is limited to the people who need it, by role, and staff and organizer accounts are created by invitation rather than open registration.
  • Sensitive endpoints are rate limited, and every ticket scan is written to an audit record identifying the device and operator.
  • Card data never enters our systems, which materially reduces what an attacker could obtain.

No system is perfectly secure, and we cannot guarantee absolute security. If you believe your account has been compromised, or you have found a vulnerability, see our Security page or write to support@fomotickets.com.

12.Your privacy rights

Depending on where you live, you may have some or all of the following rights. Where a right is available to you under applicable law, we honour it — and where it is not, we will still generally try to help.

Know and access
Ask what personal information we hold about you, where it came from, why we have it, and who we have disclosed it to, and get a copy.
Correct
Ask us to fix information that is wrong or out of date. You can change most of your own details in your account.
Delete
Ask us to delete your information, subject to the records we are required to keep (see Retention).
Portability
Get a copy of the information you gave us in a portable, machine-readable format.
Opt out of sale, sharing, or targeted advertising
We do not sell personal information. To opt out of the sharing described in Event Organizers’ advertising tags, use the switch on Your Privacy Choices or send a Global Privacy Control signal.
Limit the use of sensitive personal information
We do not use sensitive personal information for any purpose beyond providing the service you asked for.
Non-discrimination
We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.
Withdraw consent
Where we rely on your consent, you can withdraw it at any time. That does not affect processing already carried out.
Appeal
If we decline a request, you may appeal by replying to our decision. We will review and respond in writing, and tell you how to contact your state Attorney General if you remain dissatisfied.
Complain to a regulator
You can lodge a complaint with your state Attorney General or, where the GDPR applies, your local supervisory authority.

How to exercise a right. Everything you need — what to send, how we verify you, how long we take, and how authorized agents work — is on Your Privacy Choices.

13.United States state privacy notices

This section supplements the rest of this policy for residents of U.S. states with comprehensive privacy laws, including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others as those laws come into effect. It applies to you where the relevant law applies to us.

Categories of personal information

Using the categories defined in the California Consumer Privacy Act, in the preceding 12 months we have collected the following. For each we list the sources, the business purposes (set out in How we use information), and the categories of recipient it is disclosed to for a business purpose.

CCPA categoryDo we collect it?Disclosed for a business purpose to
Identifiers (name, email, phone, postal address, IP address, account ID)YesEvent Organizers; hosting, database, email, payment, and analytics providers
Personal information under Cal. Civ. Code § 1798.80 (name, address, payment record)YesEvent Organizers; payment and database providers
Commercial information (orders, tickets, refunds, purchase history)YesEvent Organizers; payment, database, and analytics providers
Internet or network activity (pages viewed, referral source, campaign parameters, session replay)YesAnalytics and hosting providers
Geolocation dataApproximate only, inferred from IP address for security and fraud prevention. No precise locationHosting and security providers
Audio, electronic, visual, or similar informationNo—
Biometric informationNo—
Professional or employment informationOnly where an Event Organizer asks for it at checkoutThat Event Organizer
Education informationOnly where an Event Organizer asks for it at checkoutThat Event Organizer
Sensitive personal informationOnly where an Event Organizer asks for it, and account credentials, which are held as hashesThat Event Organizer; database provider
Inferences drawn to create a profileNo. We do not build behavioural profiles—

Sale and sharing

We have not sold personal information in the preceding 12 months. Where an Event Organizer connects Meta or Google advertising tags to its event pages, we share identifiers (hashed contact details, IP address, and advertising cookie identifiers), commercial information (what you bought and its value), and internet activity (the pages you view on that organizer’s event pages) with Meta Platforms, Inc. and Google LLC for cross-context behavioural advertising. You can opt out at any time on Your Privacy Choices. We do not have actual knowledge of selling or sharing the personal information of consumers under 16.

Global Privacy Control

We recognize a Global Privacy Control (GPC) signal sent by your browser as a valid opt-out request. Where we detect it, Event Organizers’ advertising tags do not load, we do not send your purchases to Meta, and we also switch off optional analytics and session replay for that browser.

Do Not Track

There is no common industry standard for responding to browser Do Not Track signals, so we do not respond to them. We do respond to Global Privacy Control, as described above.

California Shine the Light

California Civil Code § 1798.83 lets California residents ask about personal information disclosed to third parties for their direct marketing purposes. We do not make such disclosures.

Notice of financial incentive

We do not offer financial incentives in exchange for personal information.

14.Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. Accounts require you to be at least 13, and at least 18 unless a parent or guardian accepts the Terms of Use on your behalf.

Where a family attends an event together, a parent or guardian buys the tickets and may enter a child’s name as an attendee. That name is provided by the adult, is used only to admit the child to that event, and is held on the same basis as any other attendee detail.

If you believe a child under 13 has given us personal information, write to support@fomotickets.com and we will delete it.

15.Where information is held, and international users

The Service is operated from the United States, and all of the providers listed in this policy store data in the United States. Vadelis Labs Inc. is a Florida corporation.

If you access the Service from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those in your country. By using the Service you understand that this transfer takes place.

Where the GDPR or UK GDPR applies to a particular processing activity, we rely on appropriate safeguards for that transfer — the European Commission’s Standard Contractual Clauses, or the UK International Data Transfer Addendum — together with the technical and organizational measures described in How we protect information. Contact us for a copy of the relevant documentation.

16.Other sites and embedded widgets

Our ticket widget can be embedded in an Event Organizer’s own website. The purchase itself runs on our systems and is covered by this policy, but the surrounding page is not ours — its content, cookies, and analytics belong to whoever runs it, and their privacy policy applies to them.

When a purchase completes inside the widget, the widget tells the surrounding page so the Event Organizer can measure its sales: the order number, the tickets and other items bought, their prices, and the tax. It does not pass your name, email address, or payment details. If that page runs an analytics tool such as Google Tag Manager, the organizer’s own tags may send these details on to its analytics provider under their privacy policy.

Links from the Service to other websites are provided for convenience. We do not control those sites and are not responsible for their privacy practices.

17.Changes to this policy

We update this policy when our practices change or when the law requires it. The effective date at the top always reflects the current version.

Where a change is material — a new category of information, a new purpose, a new recipient — we will give you notice before it takes effect, by email or a prominent notice on the Service, and where the law requires it we will ask for your consent.

18.Contact us

Questions, requests, or complaints about privacy: support@fomotickets.com.

Vadelis Labs Inc.1784 NW Madrid WayBoca Raton, FL 33432United States

To exercise a privacy right, please use the instructions on Your Privacy Choices — it tells us what we need to verify you and gets your request handled faster.

This document is part of the TicketsByFomo legal collection. Each document links to the others where they overlap.

PreviousRefundsNextCookies