Legal
Privacy Policy
How EasyEntry collects, uses, and protects your information.
Last updated: 10 July 2026
1. Overview
This Privacy Policy describes how EasyEntry ("we", "us", "our") collects, uses, and protects information in connection with easyentry.com.au and the EasyEntry ticketing and registration platform (the "Service"). It applies to visitors to our marketing site, ticket buyers and attendees, and authenticated organiser users of the Service.
For personal information about our own account holders, website visitors, and platform operations, EasyEntry is the organisation that determines how that information is handled. For personal information that organisers collect from attendees through registration forms and event management (for example, custom questions on an order), the organiser is responsible for that collection and EasyEntry processes it to operate the Service on the organiser's behalf, in accordance with our Terms of Service and the organiser's instructions.
We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth), and where other laws apply (including the GDPR or UK GDPR), we describe our approach below.
2. Information we collect
We collect information in these categories:
- Visitors — information you submit on marketing or support forms (such as name, email, and message), and technical data such as IP address, browser, and device type.
- Buyers and attendees — name, email, order and ticket details, payment status (processed by our payment provider; we do not store full card numbers), check-in records, and any registration answers the organiser requests.
- Organisers and team members — account profile, organisation details, membership roles, billing and payout connection status with our payment provider, API key metadata, and support communications.
- Usage and diagnostic data — request timing, error reports, security and audit events, and similar logs generated when you use the Service.
3. How we use information
- To provide, maintain, and improve the Service (including checkout, ticketing, check-in, reporting, and organiser tools).
- To process payments, fees, refunds, and payouts, and to issue related confirmations and tax documents where applicable.
- To deliver tickets and service-related messages, and to respond to support requests.
- To detect, investigate, and prevent abuse, fraud, or security incidents.
- To send product updates where you have opted in.
- To comply with legal obligations and to establish, exercise, or defend legal claims.
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service); legitimate interests (to secure, improve, and operate the Service, in a way that does not override your rights); legal obligation; and consent where required (for example, certain marketing), which you may withdraw at any time.
4. Sharing and sub-processors
We do not sell personal information and we do not share it for cross-context behavioural advertising. We share information with:
- The organiser of an event you book (so they can run the event and fulfil tickets).
- Service providers required to operate the Service (such as cloud hosting, payment processing via Stripe, and transactional email), under appropriate contractual safeguards.
- Authorities or other parties when compelled by law, legal process, or to protect the rights, safety, or property of EasyEntry, our users, or the public.
A current list of sub-processors is available on request from privacy@easyentry.com.au.
5. Cookies and tracking
We use strictly necessary cookies and similar technologies to operate the Service — for example, to keep organiser sessions signed in, protect against cross-site request forgery, and hold a guest checkout cart in a signed cookie. We do not use third-party advertising cookies or cross-site tracking on our marketing site or in the application for advertising purposes, and we do not deploy fingerprinting or session-replay tools for marketing. You can control cookies through your browser settings; disabling essential cookies may prevent parts of the Service from working.
6. Data retention
We retain personal information only as long as needed for the purposes described in this policy or as required by law. In particular:
- Order, ticket, payment, refund, and related financial records are retained for as long as needed for accounting, disputes, and legal obligations (typically up to seven years for financial and security audit records).
- Routine operational audit records that are not financial or security category are typically retained for about 90 days.
- Diagnostic and infrastructure logs are typically retained for a short period (on the order of 90 days) unless a longer period is required for security investigation.
- Account and organisation data is retained for the life of the account and for a short period after closure to support recovery and legal obligations, unless a longer period is required by law.
Aggregate, de-identified statistics that cannot reasonably be linked to an individual may be retained indefinitely.
7. Security
We take reasonable measures to protect personal information, including encryption in transit (TLS). We do not store full card numbers; card payments are handled by our payment provider. Access to production systems is restricted and logged. No system is perfectly secure; you are responsible for using strong, unique credentials and for safeguarding API keys. Report vulnerabilities to security@easyentry.com.au.
8. Data breach notification
If we become aware of a personal data breach affecting your information, we will notify affected individuals and/or organisers without undue delay and, where required by law (including under the Australian Notifiable Data Breaches scheme and Article 33 of the GDPR), within applicable statutory timeframes. Our notification will describe the nature of the breach, the categories of data affected where known, the likely consequences, and the steps we are taking in response.
9. Your rights
Depending on your jurisdiction (including under the Australian Privacy Principles, the GDPR, the UK GDPR, and the CCPA/CPRA), you may have the right to access, correct, port, restrict, object to, or delete your personal information, and to lodge a complaint with a supervisory authority (in Australia, the Office of the Australian Information Commissioner). To exercise these rights for information we control, contact privacy@easyentry.com.au. We will respond within the timeframes required by applicable law. We may need to verify your identity before acting on a request, and we will not discriminate against you for exercising a right.
You can opt out of product update and marketing emails at any time by using the unsubscribe link in those emails or by contacting us. We will continue to send service-related messages (such as ticket delivery, payment receipts, and security alerts) that are necessary to operate the Service.
If your personal information was collected by an organiser through their event or registration form, please contact that organiser first; we will support them in responding where we process that data on their behalf.
10. Children
The Service is not directed to children under 16 for account creation. Organisers may sell tickets to events that include minors; organisers are responsible for any age or consent requirements for their events. We do not knowingly collect personal information from children under 16 for our own marketing accounts. If you believe a child has provided us personal information inappropriately, contact privacy@easyentry.com.au and we will take appropriate steps.
11. Automated decision-making
EasyEntry does not make decisions based solely on automated processing of personal information that produce legal or similarly significant effects about you as a consumer. Operational automation (such as payment confirmation, inventory reservation, check-in scan results, and fraud or rate-limit controls) is used to run the Service and may affect ticket validity or access; it is not used to profile you for advertising.
12. International transfers
The Service is hosted primarily in AWS Sydney (ap-southeast-2). If you access the Service from outside Australia, your information will be transferred to and processed in Australia, which may provide different data protection standards from your home jurisdiction. Some sub-processors may process data in other regions as needed to provide their services. Where transfers are subject to the GDPR or UK GDPR, we rely on appropriate safeguards including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) with our sub-processors. A copy of the relevant transfer mechanism is available on request from privacy@easyentry.com.au.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-product notice at least 30 days before they take effect where practical. Non-material changes (such as clarifications) take effect when posted, and the "Last updated" date above will reflect the change.
14. Contact
Privacy questions and requests can be sent to privacy@easyentry.com.au or via Support.