Privacy Policy

Last updated: 12 August 2026

CowTicket ("we", "us") provides an online ticketing service for event organizers: a web application at cow-ticket.dev and an API that powers ticket sales, payments and event check-in. This policy explains what personal data we handle, why, and the choices you have. It covers both organizers who use CowTicket to run events and attendees who buy tickets to those events.

Data we collect from organizers

When you create or join an organizer account, we store:

  • Your name, email address and a hashed password. We never store passwords in plain text.
  • If you enable two-factor authentication, the secret used to verify your one-time codes.
  • Team membership details: which accounts you belong to, your role in each, and an audit trail of significant actions (for example refunds and check-ins) attributed to the person who performed them.

Signing in with Google

If you choose "Sign in with Google", Google shares your name and email address with us. We use them only to create and sign you in to your CowTicket account. We do not request access to any other Google data, we do not use Google user data for advertising, and we never sell or share it with third parties. You can disconnect CowTicket at any time from your Google account's security settings; your CowTicket account will continue to work with email sign-in.

Data we handle about attendees

When someone buys a ticket, the event organizer collects the buyer's name, email address and any additional fields the organizer chooses to ask for (for example a phone number or T-shirt size). We process this data on the organizer's behalf so that we can deliver tickets by email, show the organizer their order list, and check tickets in at the event. For attendee data, the organizer is the data controller and CowTicket is a processor: if you bought a ticket and want your details corrected or deleted, the fastest route is the organizer of the event, but you can also contact us directly and we will help.

Payments

Payments are processed by Stripe. Card and payment details are entered on Stripe's hosted checkout page and go directly to Stripe — they never touch our servers and we cannot see them. We store only payment references (such as order and refund identifiers), amounts, and the payment method type (for example "card"), which we need for receipts, reports and refunds. Stripe's own privacy policy, available at stripe.com/privacy, applies to their processing.

Cookies

The application uses a single strictly necessary cookie that keeps you signed in. We do not use advertising or cross-site tracking cookies. Interface preferences such as theme and language hints are kept in your browser's local storage and are never sent to us.

Emails

We send transactional email only: order confirmations, ticket delivery, sign-in and password links, team invitations, and event reports that an organizer explicitly requests. We do not send marketing email.

How long we keep data

Order, ticket and payment records are kept for as long as the organizer's account is active, because organizers need them for accounting and because tickets can be refunded or audited long after an event. When an account is closed we delete or anonymize its data within a reasonable period, except where the law requires us to keep records longer.

Security

Data is stored on Amazon Web Services in the Asia Pacific (Singapore) region, encrypted in transit. Access within our team is limited to what is needed to operate and support the service. Passwords are hashed, API keys are stored only as hashes, and money-moving actions are restricted by per-user roles.

Your rights

Under Thailand's Personal Data Protection Act (PDPA) and similar laws, you can ask us for a copy of your personal data, ask us to correct it, or ask us to delete it. Write to support@cow-ticket.dev and we will respond within 30 days.

Changes and contact

If this policy changes in a meaningful way we will update this page and its date, and notify organizers by email for significant changes. Questions about privacy can be sent to support@cow-ticket.dev.