Privacy notice: The exact controller, retention periods, legal bases and user rights for a live deployment must be completed for the operator's actual business, jurisdiction and technology stack.
Information we may collect
Depending on the enabled features, the platform may process registration information such as name and email address, account security information, ticket and order records, support enquiries, technical logs and preferences. Payment card information should be handled by the approved payment provider rather than stored directly by the application unless the operator has a compliant card-data environment.
Why information is used
Information can be used to create and secure accounts, process transactions, associate tickets with orders, provide customer support, publish permitted winner information, prevent fraud, maintain service security and meet legal or regulatory obligations.
Security
Security controls should include HTTPS, secure password hashing, CSRF protection, access control, least-privilege administration, protected secrets, logging and appropriate backup procedures. No internet service can guarantee absolute security.
Retention
Retention periods should be based on the purpose of processing and any applicable legal, tax, accounting, fraud-prevention or regulatory requirements. The production operator should document deletion and archival processes.
Sharing
Information may be shared with service providers only where necessary and appropriately controlled, for example payment providers, hosting providers, email services, fraud-prevention vendors or professional advisers.
Your choices
Depending on applicable law, users may have rights to access, correct, delete, restrict or object to certain processing. Contact support to start a privacy enquiry.
Contact
For privacy questions, email contact@tuveleeds.com. The final production notice should identify the legal data controller and applicable supervisory authority where required.