StarrTix Privacy Policy
Learn how StarrTix collects, uses, and safeguards your personal information and transaction records.
Privacy Policy & Data Governance
StarrTix (SL) Ltd (“StarrTix,” “we,” “us,” or “our”) is committed to protecting the privacy, confidentiality, and security of our event organizers, ticket purchasers, attendees, and platform visitors. This Privacy Policy details how we collect, process, store, retain, and purge personal data across our web applications, mobile platforms, and verification hardware.
Our Strict Data Protection Pledge
StarrTix never sells personal data to third parties. All financial authorizations use bank-grade TLS 1.3 encryption, on-site scanning devices utilize encrypted local database caching, and event attendee data is subjected to strict post-event data purging schedules.
1. Information We Collect
We collect information to facilitate ticket sales, attendee check-in, organizer payouts, and regulatory compliance:
- Account & Identification Data: Name, email address, mobile phone number, physical address, and organizational details.
- Transaction & Payment Data: Payment method token, Mobile Money MSISDN, transaction reference numbers, ticket tier purchased, and purchase timestamps. (Full payment card numbers are processed directly by certified PCI-DSS payment gateways and are never stored on StarrTix servers).
- Access Control & Validation Telemetry: Barcode/QR token, gate scanning timestamp, scanning device identifier, operator ID, and ticket entry status.
- Technical & Device Logs: IP address, browser type, operating system, and crash diagnostics.
2. How We Use Your Information
We process collected information for the following legitimate purposes:
- Generating, delivering, and validating digital and physical event tickets.
- Executing real-time payments, refunds, and organizer revenue disbursements.
- Delivering automated SMS and email notifications containing tickets, receipts, and critical event updates.
- Detecting and mitigating fraud, duplicate ticket scanning, and unauthorized access.
- Providing post-event reconciliation reports and audit logs to authorized event organizers.
3. Legal Basis for Processing
Our processing of personal data rests upon:
- Contractual Necessity: To fulfill ticket purchases, facilitate admission, and execute organizer settlement agreements.
- Legal & Regulatory Compliance: To comply with financial accounting laws, anti-money laundering regulations, and lawful subpoenas.
- Legitimate Interests: To maintain platform security, prevent fraudulent entries, and optimize scanner performance.
4. Information Sharing & Third-Party Disclosure
We only share information with third parties under strict confidentiality and data protection safeguards:
- Event Organizers: The organizer of the specific event you booked receives attendee rosters for access management and event communication.
- Payment Providers & Mobile Network Operators: Encrypted transaction payloads are transmitted to Airtel Money, Orange Money, and banking partners to complete monetary authorizations.
- Telecommunications Gateways: Aggregated SMS providers to transmit digital tickets and verification OTPs.
5. Data Security & Offline Device Caching Protocols
We employ technical and organizational safeguards including 256-bit SSL/TLS encryption in transit and AES encryption at rest.
On-Site Verification Device Security: To allow rapid gate scanning during telecommunication or venue network outages, StarrTix mobile verification applications store attendee validation tokens inside a localized, encrypted SQLite cache. These local database records are cryptographically protected on the device, inaccessible to third-party apps, and automatically purged once asynchronous synchronization with the central database is verified.
6. Data Retention & Structured Purging Schedule
StarrTix maintains a tiered data lifecycle policy to minimize retention of personal data:
- Attendee PII & Validation Scans (90 Days): Transient gate scan timestamps, attendee entry logs, and associated ticket holder details are preserved for ninety (90) days following the conclusion of an event for reconciliation, refund validation, and dispute resolution. After 90 days, attendee PII is anonymized or securely purged.
- Financial Ledgers & Tax Records (7 Years): Aggregated financial settlement records, invoice summaries, and tax logs are retained for seven (7) years in accordance with statutory accounting and financial audit regulations.
- User Account Profiles: Active user profiles are retained until account deletion is requested by the user.
7. Post-Event Audit Log Delivery & Export Formats
To maintain full governance and transparency with event organizers, StarrTix provides standardized post-event audit log export mechanisms:
- Delivery Timeline: Exhaustive validation and attendance audit logs are made available via the Organizer Portal or secure API within twenty-four (24) to forty-eight (48) hours following event completion.
- Standard Export Formats: Logs are available for download in standard structured CSV (Comma Separated Values) and JSON (JavaScript Object Notation) formats.
- Log Schema: Audit datasets include Ticket Hash, Scan Timestamp (UTC), Verification Device Identifier, Operator ID, Check-in Gate, and Result Status (Approved, Duplicate, or Rejected).
8. Your Rights & Contact Information
Depending on your jurisdiction, you have the right to access, rectify, or request deletion of your personal data, or object to certain processing activities. To submit a data request or privacy inquiry, please contact our Data Governance Officer:
- Legal Desk Email: info@starrtix.com
- Support Hotline: +23274873450
- Postal Address: Freetown, Sierra Leone
StarrTix (SL) Ltd • Registration & Compliance
Freetown, Sierra Leone
Questions About Your Data or Privacy?
Our dedicated compliance and security team is available to assist you with data requests, account deletions, or compliance verifications.