Legal
Privacy policy
Venuora is a ticketing platform. This page explains exactly what we collect when you browse, buy a ticket or run an event, why we collect it, and what you can ask us to do with it.
Last updated 8 September 2026
The short version
We collect the minimum we need to sell you a ticket and get you through the door. We do not sell your personal data. We share it with an organizer only when you buy a ticket to their event, and with the payment processor that takes your money. Your location is never read unless you tap a button asking us to find events near you.
What we collect
Information you give us
- Account details. Your name, email address and password. Passwords are stored as a one-way hash, never as readable text.
- Profile details. Anything else you choose to add, such as a display photo or the name shown to other guests.
- Order details. The events and ticket types you buy, quantities, promo codes and the order total.
- Organizer details. If you host events: your organizer name, description, payout details and the content of the events you publish.
- Content you post. Reviews, squad messages and reports you submit about an event.
- Assistant questions. If you use Ask Venuora, the text of that conversation is sent to our language-model provider so it can answer. Ticket lookups still run on our servers.
Information we collect automatically
- Usage. Which event pages you view, so organizers can see how many people looked at their event and so we can rank what is trending.
- Device and connection. IP address, browser type and operating system, recorded with page views and used for security and fraud prevention.
- Check-in records. When your ticket is scanned at a gate we record the time, the event and the staff member who scanned it. If the gate device shares its position, we store that too, as proof of where the scan happened.
Location and maps
We use Google Maps Platform for two things: helping organizers pin their venue accurately, and letting you find events near you.
- We never read your device location automatically. Your browser only asks for permission after you press a button such as Find events near me. If you decline, everything else on the site keeps working and you can still search by city.
- Your coordinates are not stored on our servers. They are held in your own browser's local storage for up to six hours so you are not asked again on every page, and sent to us only for the duration of a search. Pressing Stop using my location deletes them immediately.
- Venue addresses are sent to Google. When an organizer saves an event, we send the venue address to Google's Geocoding API to turn it into map coordinates. That is business address data, not personal data about you.
- Maps are loaded from Google. Where we embed a map, Google receives your IP address as part of serving it, and its own privacy policy applies to that.
How we use it
- To create and secure your account, and to sign you in.
- To take payment, issue your ticket and deliver its QR code.
- To let event staff verify your ticket at the gate and stamp your Event Passport.
- To email you order confirmations, event reminders and changes an organizer announces.
- To show you relevant events, including sorting by distance when you have asked us to.
- To give organizers aggregate figures about their own events: tickets sold, revenue, check-in rates.
- To answer questions you ask the on-site assistant, using only the listings and (if you are signed in) the tickets that belong to you.
- To meet our legal, tax and accounting obligations.
We do not use your personal data to train machine-learning models, and we do not run third-party advertising networks on this site.
Payments
Card payments are processed by Paystack. Your full card number never reaches our servers and we never store it. We keep a record of the transaction: amount, currency, status, reference and the last few digits of the instrument, which is what we need to reconcile orders, issue refunds and satisfy our accounting obligations. Wallet balances and payout requests are held on our own systems.
The installable app
Venuora can be installed to your home screen as a progressive web app. When installed, a service worker caches design assets and pages you have visited so the app opens quickly and still shows something useful when your connection drops. That cache lives on your device and is not transmitted anywhere. Uninstalling the app or clearing site data removes it.
Gate staff using offline check-in mode have scan records stored locally on their device until connectivity returns and they sync.
The assistant
Ask Venuora is optional. When you send a message, that text is forwarded to OpenAI so a model can draft a reply. We do not use those prompts to train a Venuora model. Lookups of published events, your tickets and your Event Passport run on our servers; only the summarized result is shown to the model, and another guest's tickets are never included.
Organizers who tap Draft with AI send the event name and any notes they have already typed. The draft is not published until they save the wizard themselves. If the assistant is turned off in our configuration, those controls disappear and nothing is sent.
How long we keep it
- Account data: while your account is open, and for a short wind-down period after you close it.
- Order and payment records: for as long as tax and accounting law requires us to keep them, even after an account closes.
- Passport stamps and check-ins: for the life of your account, because the passport is a permanent record by design.
- Page-view logs: kept in aggregate; individually identifying detail is not retained long term.
- Location coordinates: never written to our database.
Your rights
Under the Nigeria Data Protection Act and comparable laws elsewhere, you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that is wrong. Most of it you can edit yourself in your profile.
- Delete your account and the data we are not legally required to keep.
- Restrict or object to a particular use of your data.
- Export your data in a portable format.
- Withdraw a consent you previously gave, such as location access, at any time.
Write to us using the contact details below. We will respond within 30 days. If you are not satisfied with our answer you can complain to the Nigeria Data Protection Commission, or to the data protection authority where you live.
Security
Traffic is encrypted in transit. Passwords are hashed. Ticket QR codes are signed so a screenshot cannot be forged into a valid pass. Access to production data is limited to the people who need it. No system is perfectly secure, so if we ever discover a breach that puts you at risk we will tell you and the relevant regulator without undue delay.
Children
Venuora is not intended for children under 13, and we do not knowingly create accounts for them. If you believe a child has registered, contact us and we will remove the account. Some events carry their own age restrictions set by the organizer, which are enforced at the door.
Changes to this policy
If we change how we handle your data we will update this page and move the date at the top. Where a change materially affects you, we will tell you by email or with a notice in the app before it takes effect.
Contact us
For any privacy question, or to exercise the rights above, email privacy@venuora.com. For anything else, our about page explains who we are.