Privacy policy
Last updated 12 September 2026.
gTicket sells tickets for events in Kenya. This policy explains what personal data we collect when you use the site, why, who else sees it, how long we keep it, and the rights you have under the Data Protection Act 2019. gTicket is the data controller for the buyer data described here; the organizer of an event you attend is a separate controller for what they do with your name and contact details at their event.
What we collect, and why
| Data | Why we need it | Lawful basis |
|---|---|---|
| Your name, email address and phone number | To deliver your ticket, take payment, process refunds, and reach you if the event changes or is cancelled. We cannot sell you a ticket without these. | Performance of a contract |
| Attendee names, and for some events an ID document type and number | Some venues must verify who is admitted. The organizer tells us when an event requires it; we ask only then. | A legal obligation of the organizer; the contract with you |
| What you bought, what you paid and how, and whether the ticket was scanned | To issue and validate tickets, keep the financial record the law requires, and detect fraud. | Contract; legal obligation (financial records); legitimate interest (fraud) |
| Messages we sent you and whether they arrived | So we can help when a ticket did not arrive. | Legitimate interest |
| Marketing preferences | Only if you opt in, to tell you about events. Never assumed from buying a ticket. | Consent, which you can withdraw at any time |
We tell you what your email and phone are for at the moment we ask for them: your ticket is delivered to them. We do not ask for anything we do not need for that.
Who else sees it
- The organizer of the event you bought a ticket for sees your name and contact details and the attendee details for that order, so they can run the event and answer your questions. They never see your ID number in their lists or downloads.
- Safaricom (M-Pesa) receives your phone number and the amount to take payment, and to send a refund.
- Our SMS gateway and our email service receive your phone number or email address and the message, to deliver tickets, codes and event notices.
- Our storage provider holds the PDF of your ticket, which carries the attendee name.
Nobody else. We do not sell personal data and we do not use advertising networks.
How long we keep it
- ID document numbers: 30 days after the event ends. They are encrypted while we hold them and deleted automatically on that clock.
- Your name, email, phone and attendee details: 12 months after the event ends. After that they are removed from the order automatically.
- The order itself — reference, amounts, payment reference, M-Pesa receipt number and status: 7 years, because financial records must be kept that long. Once the personal details are removed it no longer identifies you.
- Marketing consent records: while consent stands, and 24 months after you withdraw it, as proof of what you agreed to and when.
- Your account, if you create one: until you delete it.
A scheduled job enforces these periods every night. They are not just a policy.
How it is protected
ID numbers are encrypted at rest and are never shown in lists, downloads or reports. Access is limited to people who need it: gate staff can check a ticket without seeing finances or other events; organizers see their own events only. Our analytics are aggregates — counts, sums, rates — with no names, emails or phone numbers in them. Codes and sign-in links are stored hashed and expire quickly.
Your rights, and how to use them
- Access. From your account you can download everything we hold about you as a file. We verify that the email or phone is yours before we release anything: an export sent to an unverified address would be a data breach, so there is no other way to get it.
- Rectification. Your name can be corrected in your account; a new email or phone is proven by signing in with it. An organizer can correct attendee names on an order.
- Erasure. From your account you can delete it. Your name, email, phone and attendee details are removed from every order at once, ID numbers are deleted, and marketing consent is withdrawn. What stays is the financial record — reference, amounts, payment reference — which the law requires us to keep for 7 years and which no longer identifies you. We say exactly what was kept when you do it.
- Objection and withdrawal of consent. Marketing can be switched off in your account at any time. Transactional messages — tickets, receipts, refunds, event changes — are part of the service and are sent regardless.
- Complaint. You can complain to the Office of the Data Protection Commissioner (odpc.go.ke) if you believe we have handled your data unlawfully.
Contact
Questions or requests: the support contact shown in the footer. We answer within the time the Act allows.
