Privacy Policy
Last updated: July 2026 · Operated by BME GROUP.
What we collect
Guests: name, email, phone (optional), booking details, answers to the operator's checkout questions, waiver signatures, and reviews you choose to leave.
Operators: account email, business details, catalog and booking data, and Stripe account identifiers.
Everyone: standard technical logs (IP address, browser) used for security and rate limiting.
Operators: account email, business details, catalog and booking data, and Stripe account identifiers.
Everyone: standard technical logs (IP address, browser) used for security and rate limiting.
What we don't collect
Card numbers never touch our servers — payment details go directly to Stripe. We don't sell personal data, run third-party ad trackers, or use your data to train AI models.
How data is used
To run bookings end to end: confirmations, reminders, review requests, waitlist alerts, manifests for the operator, and payment processing. Guest data is visible only to the operator you booked with — operators cannot see each other's customers.
Who we share with
Stripe (payments), Supabase (database hosting), Vercel (application hosting), Resend (transactional email), and Anthropic (AI chat features — conversation text only, when you use them). Each processes data solely to provide their service to us.
Retention & your rights
Booking records are kept for as long as the operator needs them for accounting and legal purposes. You can ask us — or the operator you booked with — to correct or delete your personal data at any time; write to support@ticketjelly.com and we'll respond within 30 days.
Security
Row-level security isolates every operator's data at the database layer; server-side price computation, signature-verified payment webhooks, and rate limiting protect the booking flow. No system is perfect — if a breach affects you, we'll notify you without undue delay.