Privacy Policy
Last updated: 2026-05-20
1. Data Controller
Tickets Vienna operates this website. For the purposes of the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG), the data controller is:
Velora Digital Group e.U
Operator of Tickets Vienna
Email: [email protected]
2. What Personal Data We Collect
2.1 When You Purchase Tickets
- Full name
- Email address
- Phone number (optional)
- Postal address, city, and country if postal delivery, shipping, or invoice details are requested
- Company name and tax ID (if you request an invoice)
- Payment method chosen (we do not store card numbers; see section 5)
2.2 When You Create an Account
- Full name and email address
- Password (stored only as a secure, irreversible hash)
2.3 When You Use the Contact Form
- Name, email address, subject, and your message
2.4 When You Subscribe to the Newsletter
- Email address
2.5 When You Use the Live Chat
- Name and email (if you choose to provide them)
- Chat messages
- IP address and approximate location (country, city) for support purposes
2.6 When You Write a Review
- Name, email, city, rating, and review text
- Your explicit consent to publish, along with the consent timestamp and IP address (GDPR compliance)
- Your name is displayed in anonymized form (e.g. "Anna M.") on the website
2.7 Automatic Data Collection
- IP address
- Browser type and version (user agent)
- Pages visited and referring website
- Approximate location (country, city) derived from your IP address
- Date and time of your visit
2.8 When Vendors or Partners Use the Vendor Portal
- Business name, legal company name, contact person, email address, phone number, website, address, and VAT/tax information
- Bank and payout details, where required for commissions, invoices, or partner settlements
- Vendor portal login data, order-management actions, invoices, uploaded documents, and communication history
- Event, ticket, venue, and commission information needed to operate the marketplace and fulfill bookings
3. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6(1):
| Purpose | Legal Basis |
|---|---|
| Processing orders and delivering tickets | Performance of a contract (Art. 6(1)(b)) |
| Sending order confirmations and invoices | Performance of a contract (Art. 6(1)(b)) |
| Customer support and live chat | Legitimate interest (Art. 6(1)(f)) |
| Newsletter emails | Consent (Art. 6(1)(a)) |
| Analytics and website improvement | Legitimate interest (Art. 6(1)(f)) |
| Marketing cookies and tracking pixels | Consent (Art. 6(1)(a)) |
| Publishing reviews | Consent (Art. 6(1)(a)) |
| Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) |
| Tax and accounting records | Legal obligation (Art. 6(1)(c)) |
| Vendor portal, partner management, commissions, invoices, and settlements | Performance of a contract, legal obligation, and legitimate interest (Art. 6(1)(b), (c), and (f)) |
4. Cookies
We use cookies and similar technologies on our website. A cookie is a small text file stored on your device. You can manage your preferences at any time using our cookie banner.
4.1 Essential Cookies (Always Active)
These cookies are strictly necessary for the website to function and cannot be switched off.
| Cookie | Purpose | Duration |
|---|---|---|
| PHPSESSID | Session management (shopping cart, login state) | Browser session |
| tv_csrf | Security token to prevent cross-site request forgery | Browser session |
| lang | Saves your language preference | 1 year |
| cookie_consent | Stores your cookie consent choice | 1 year |
| cookie_consent_prefs | Stores your cookie category preferences | 1 year |
4.2 Functional Cookies
| Cookie | Purpose | Duration |
|---|---|---|
| tv_chat_device | Identifies your device for live chat support continuity | 180 days |
4.3 Statistics Cookies (Consent Required)
These cookies help us understand how visitors use our website by collecting information anonymously.
| Cookie | Purpose | Provider |
|---|---|---|
| _ga, _ga_* | Google Analytics 4 - website usage statistics | Google LLC |
4.4 Marketing Cookies (Consent Required)
These cookies are used to show you relevant advertisements and measure advertising effectiveness.
| Provider | Purpose |
|---|---|
| Meta (Facebook/Instagram) Pixel | Measures ad performance and enables retargeting |
| TikTok Pixel | Measures ad performance and enables retargeting |
| Google Tag Manager | Manages marketing tags and tracking scripts |
5. Payment Processing
We use third-party payment processors to handle transactions securely. We never store, process, or have access to your full credit card number, CVV, or bank login credentials.
- Stripe Payments Europe, Limited / Stripe, Inc. – Processes credit and debit card payments. Stripe is PCI-DSS Level 1 certified. When you pay, your card details are sent directly to Stripe via their secure payment form. We only receive a transaction reference. stripe.com/privacy
- PayPal (Europe) S.a r.l. et Cie, S.C.A. – Processes PayPal payments. You are redirected to PayPal to authorize payment. We only receive a transaction reference. paypal.com/privacy
6. Third-Party Services
We use the following third-party services in addition to payment processors:
| Service | Purpose | Data Shared |
|---|---|---|
| Google Analytics 4 | Website usage statistics | Page views, events, anonymized IP |
| Meta Pixel | Advertising measurement | Page views, purchase events |
| TikTok Pixel | Advertising measurement | Page views, purchase events |
| Meta, TikTok, and Google server-side conversion APIs | Purchase conversion measurement when enabled in the advertising settings | Order value, currency, order/event identifiers, purchase event details, and limited customer/contact data where required for matching and legally permitted |
| Google Fonts | Typography | IP address (via font loading request) |
| ip-api.com | Geolocation for analytics | IP address |
7. International Data Transfers
Some of our third-party service providers, including Stripe, PayPal, Google, Meta, and TikTok, may process data outside Austria or the European Economic Area. Where required, such transfers are protected by adequacy decisions, the EU-US Data Privacy Framework, standard contractual clauses, or other safeguards permitted under GDPR Chapter V.
8. How Long We Keep Your Data
| Data Type | Retention Period | Reason |
|---|---|---|
| Order and invoice data | 7 years | Austrian tax law (BAO §132) |
| User accounts | Until you delete your account | Contract performance |
| Newsletter subscriptions | Until you unsubscribe | Consent |
| Contact form messages | 12 months | Customer support |
| Live chat conversations | 12 months | Customer support |
| Analytics and page views | 26 months | Legitimate interest |
| Security logs and login attempts | 6 months | Fraud prevention |
9. Your Rights Under GDPR
As a data subject, you have the following rights. To exercise any of these rights, contact us at the email address above.
- Right of access – Request a copy of the personal data we hold about you.
- Right to rectification – Request correction of inaccurate or incomplete data.
- Right to erasure – Request deletion of your personal data where there is no legal obligation to retain it.
- Right to restriction – Request that we limit processing of your data in certain circumstances.
- Right to data portability – Receive your data in a structured, machine-readable format.
- Right to object – Object to processing based on legitimate interest, including direct marketing.
- Right to withdraw consent – Withdraw consent at any time (e.g. cookie consent, newsletter, review publication) without affecting the lawfulness of processing before withdrawal.
10. Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Austrian Data Protection Authority:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40-42, 1030 Vienna, Austria
www.dsb.gv.at
Email: [email protected]
11. Data Security
We implement appropriate technical and organisational measures to protect your data, including: SSL/TLS encryption for all data in transit, password hashing using industry-standard algorithms, CSRF protection on all forms, Content Security Policy headers, rate limiting against brute-force attacks, and regular security reviews. No credit card data is stored on our servers.
12. Contact
For any privacy-related questions or to exercise your rights, please use the contact details listed above.