TicketCRM Security & Privacy
Last updated:
Event organizers trust TicketCRM with their sales, their audience and their buyers’ data. Here is how we protect it.
Payments and card data
Payments are processed by payment providers — LiqPay, WayForPay, plata by mono, Stripe, PayPal and others, depending on the organizer’s settings. Buyers enter their card details on the provider’s side, so TicketCRM does not receive or store card numbers or CVV codes. LiqPay, WayForPay, Stripe and PayPal are certified under the PCI DSS payment card security standard.
Infrastructure
The TicketCRM site, CRM, ticket-sales widget and API run through the Cloudflare network, which encrypts connections and protects them from DDoS attacks. Errors and failures are tracked by a monitoring system (Sentry), so our team reacts to them straight away.
Encryption and passwords
All data between your browser and TicketCRM travels over an encrypted HTTPS (TLS) connection. Passwords of CRM users and ticket buyers are stored only as one-way hashes (Argon2id, bcrypt): no one, including our team, can see them.
Access to data
Access in the CRM is managed by roles: each member of an organizer’s team sees only what their role allows. Important actions are recorded in an audit log, so it is always clear who changed what and when. Within our team, only the people who need it for support and maintenance have access to client data.
Development
Every code change goes through a merge request and a review before release. We carry out security audits and fix what they find.
Privacy and GDPR
For ticket buyers’ data, the event organizer is the controller and TicketCRM is the processor: we process this data only on the organizer’s instructions and to provide the service. For the data of our clients and visitors to this site, TicketCRM is the controller — see the Privacy Policy.
We do not sell personal data. Clients can get a data processing agreement (DPA) on request.
Buyers who want to use their rights — to find out, correct or delete their data — should contact the event organizer. We help organizers answer such requests.
Incidents
If an incident affects personal data, we investigate it immediately and, without undue delay, notify the clients concerned and, where the law requires it, the supervisory authority.
Report a vulnerability
Found a vulnerability in TicketCRM? Write to support@ticketsbox.com with the subject “Security report”: describe the problem, the steps to reproduce it and the address where it occurs. Please do not access other people’s data, do not disrupt the service and do not disclose the vulnerability publicly until we fix it. We will confirm receipt within 3 working days.
Documents
- Privacy Policy
- Cookie Policy
- Data processing agreement (DPA) — on request: support@ticketsbox.com
Questions about security or privacy: support@ticketsbox.com.