Privacy Policy
Last updated: 2026-06-15
Privacy Policy — SLAM TICKETS
This Privacy Policy explains how SLAM TICKETS ("we", "us", the "Service") collects, uses and protects personal data when you use the Service. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable local law.
1. Data controller
1.1. The data controller is the operator of the SLAM TICKETS service.
1.2. For any privacy request you can contact us through the in-app support section.
2. What data we collect
2.1. Account data: your Telegram ID and username (you sign in with Telegram), display name, email, phone number and interface language.
2.2. Transaction data: tickets you buy or sell, listings, orders, prices, payment and payout status, and dispute correspondence.
2.3. Payout data: the USDT TRC-20 (TRON) wallet address you provide to receive manual crypto payouts. Bank details for Stripe payouts are collected and held by Stripe, not by us (see section 5).
2.4. Identity verification (KYC) data: for sellers and organizers paid via Stripe, identity and business details are collected and verified by Stripe (see section 5). We receive the verification status and limited account metadata, not your full identity documents.
2.5. Technical data: IP address, device and browser information, and cookies (see our Cookie Policy).
3. Why we process data and legal bases
3.1. To provide the Service and perform our contract with you — buying, selling, escrow, payouts and support (GDPR Art. 6(1)(b)).
3.2. To comply with legal obligations, including anti-money-laundering, tax and accounting requirements (Art. 6(1)(c)).
3.3. For our legitimate interests in preventing fraud, securing the platform and improving the Service (Art. 6(1)(f)).
3.4. On the basis of your consent where required, for example for any non-essential cookies (Art. 6(1)(a)). You can withdraw consent at any time.
4. Payments
4.1. Card payments are processed by Stripe and held in escrow until a transaction completes. Stripe acts as an independent controller for its own compliance purposes; see stripe.com/privacy.
4.2. Crypto payments are processed via @CryptoBot (CryptoPay). Crypto payouts are sent manually by our team to the wallet you provide.
5. Identity verification (KYC)
5.1. Sellers and organizers in Stripe-supported countries complete identity verification through Stripe Connect. Stripe collects and stores the identity documents; we do not.
5.2. In crypto-only countries we do not run document KYC; you provide a payout wallet only.
6. Cookies
6.1. We use only strictly necessary cookies to run the Service (your sign-in session, language and cookie choice). We do not use advertising or analytics trackers. The only third-party component is the Telegram login widget, loaded from telegram.org to sign you in (it may set Telegram's own cookies, governed by Telegram's terms). See the Cookie Policy for details.
7. Who we share data with
7.1. Payment and verification providers (Stripe, CryptoPay) to process payments and payouts.
7.2. Infrastructure providers that host the Service on our behalf, under data-processing terms.
7.3. Event organizers and counterparties, limited to what is needed to complete a transaction (for example ticket validity).
7.4. Authorities, where required by law or to prevent fraud.
7.5. We do not sell your personal data.
8. International transfers
8.1. Some providers (for example Stripe) may process data outside the European Economic Area. Where they do, transfers are protected by appropriate safeguards such as the EU Standard Contractual Clauses.
9. Data retention
9.1. We keep personal data while your account is active and afterwards only as long as needed to meet legal obligations (for example tax and anti-money-laundering retention), after which it is deleted or anonymised.
10. Your rights
10.1. Subject to law, you have the right to access, rectify, erase, restrict or object to the processing of your data, to data portability, and to withdraw consent.
10.2. To exercise any right, contact us through the in-app support section.
10.3. You also have the right to lodge a complaint with your local data protection supervisory authority.
11. Security
11.1. We use technical and organizational measures to protect personal data. No method of transmission or storage is completely secure, but we work to protect your information and to respond to incidents.
12. Children
12.1. The Service is for users aged 18 and over. We do not knowingly process the data of children.
13. Changes
13.1. We may update this Policy. Material changes are reflected by the "Last updated" date on this page.