Data we collect
We collect first-party data you provide directly to TicketNexus: the email address, name and account metadata you submit when creating an account with Better Auth; the messages and contact details you send through the public contact form; the email and context you provide when joining the waitlist for a future product surface; and the application fields you fill out when applying for the invitation-only Elite tier. Each piece of data is collected for a specific purpose tied to a feature — sign-up, contact, waitlisting, or membership application — and we do not collect data we have no use for.
Public marketplace listings (event metadata, seat or section, price, description, optional photos) are user-supplied content: sellers fill them in, buyers read them, and we surface them through the listings browser without separately profiling them. The same rule applies to Elite application submissions — we read what you sent, evaluate it for membership, and keep it for the period the application requires.
Auth via Better Auth
Better Auth is the framework handling every credential check on TicketNexus. When you sign up or sign in, Better Auth stores the information needed to verify you on subsequent visits: a hashed representation of your credential material, the session tokens that keep you signed in across requests, and the account identifiers that link those sessions back to your profile. We never retain raw passwords on our servers — credential material is processed by Better Auth and never reaches our application database in plaintext.
Better Auth is the only gate for surfaces that show your personal data (the dashboard, your watchlist, your purchase history, your application status, the concierge desk). Anonymous visitors can browse the public listings, read marketing pages, and load the legal copy without ever touching Better Auth; the moment a page needs to know whose account it is rendering, it consults Better Auth first.
Stripe Connect payment metadata
Payments on TicketNexus go through Stripe Connect payment links and the hosted Stripe checkout — we do not collect card numbers, expiration dates, CVV codes or any other card data on our servers. Card payment information is collected by Stripe on the hosted checkout page and never crosses into TicketNexus infrastructure.
What we do receive is the metadata Stripe returns to us: the payment status (succeeded, failed, refunded, disputed), the amount and currency that cleared, the platform fee Stripe collected on the transaction, the last4 / billing reference Stripe associates with the buyer, and the dispute lifecycle events Stripe sends as a charge moves through any review. We persist this metadata so we can reconcile every transaction, respond to disputes, and meet the tax-relevant retention requirements of the jurisdictions you transact in. The Stripe-billing module verify route is the canonical place this reconciliation reads from.
Listings and application data
Sellers in the Standard marketplace fill in the fields a listing needs to be browsable: event metadata (the artist, team or production; the date and venue), the seat or section being offered, the asking price, a written description, and any photos the seller chooses to upload. We surface those fields to buyers through the public listings browser and retain them for the lifetime of the listing plus the period required to back up dispute resolution for that transaction.
Applicants for the Elite tier submit a separate set of fields: full name, contact information, the references an applicant chooses to provide, and the journey use case the applicant describes. We treat Elite application data as first-party content you supplied for a specific decision; we do not profile it for marketing, and we delete it on request once the application is closed unless retention is required to defend a decision we made on its basis.
Retention
Account records are retained for the life of your account plus the period the jurisdiction in which you transact mandates for transaction history, dispute records and tax-relevant invoices. We do not retain data beyond the period we need it for — once the legal retention period closes on a record, it is deleted from active systems and any backups run their normal rotation.
Contact-form submissions and waitlist sign-ups follow separate, documented lifetimes that are shorter than account records, and either can be erased on request without affecting the rest of your account. Payment events (the Stripe metadata described above) are retained for the period required to support reconciliation and tax, then deleted on the same rotation. Deletion-on-request is available for every category of personal data we hold, subject to the legal-hold exception for records we are required to preserve (an open dispute, an active tax audit, a regulator-mandated freeze).
Contact
Send data-protection requests (access, correction, deletion, portability) and privacy questions to our privacy mailbox through the contact form on this site (it posts to POST /api/contact and reaches the privacy desk) or directly to our privacy email address. We respond to every verifiable request within the timeline the relevant law requires.
For non-privacy questions (a listing dispute, an account problem, a membership question) please use the standard support queue rather than the privacy mailbox — the privacy desk is set up to handle data-protection requests specifically, and routing the right question to the right team gets you a faster answer.
Changes to this policy
We may update this Privacy Policy as the service evolves; the effective date at the top of this page reflects the version in force. Material changes are announced by email at least fourteen days before they take effect, except where the change is in your favour or required by law on a shorter timeline. A version history of every prior effective date is preserved alongside the current text so a reviewer can trace what changed and when.
Your continued use of TicketNexus after the effective date of an updated policy signals acceptance of the new terms. If you do not agree to an update, you may close your account before the effective date and we will handle your existing records under the policy that applied at the time you collected them.