Security and Data Protection
Last updated: 2026-05-20
At Tickets Vienna, the security of your personal data and financial information is our highest priority. This page describes the technical and organisational measures we implement to protect your information throughout the booking process.
1. SSL/TLS Encryption
All communication between your browser and our servers is encrypted using TLS (Transport Layer Security). This ensures that your personal details, login credentials, and payment information cannot be intercepted by third parties during transmission.
You can verify the secure connection by checking for the padlock icon in your browser's address bar and the "https://" prefix in the URL.
2. Payment Security
We do not store, process, or have access to your full credit card number, CVV code, or bank login credentials at any time. All payment processing is handled by certified third-party providers:
| Provider | Certification | How It Works |
|---|---|---|
| Stripe | PCI-DSS Level 1 (highest level) | Card details are entered directly in Stripe's secure embedded form. We only receive a transaction reference token. |
| PayPal | PCI-DSS Level 1 | You are redirected to PayPal's secure environment to authorize payment. We only receive a transaction confirmation. |
PCI-DSS (Payment Card Industry Data Security Standard) Level 1 is the most stringent certification for handling card payments, required for organizations processing millions of transactions annually.
3. Account Security
If you create an account, your password is protected using the following measures:
- Passwords are stored only as irreversible cryptographic hashes using industry-standard algorithms. Even our staff cannot view your password.
- Rate limiting is applied to login attempts to prevent brute-force attacks. Repeated failed attempts result in temporary lockout.
- Sessions expire automatically after a period of inactivity. You can log out at any time to end your session immediately.
We recommend using a strong, unique password for your account and keeping your login credentials confidential.
4. Website Protection
We implement multiple layers of defense to protect the integrity and security of our website:
| Measure | What It Protects Against |
|---|---|
| CSRF tokens on all forms | Prevents unauthorized actions submitted from other websites |
| Content Security Policy (CSP) headers | Blocks injection of unauthorized scripts and resources |
| Output escaping and input validation | Prevents cross-site scripting (XSS) and injection attacks |
| Parameterized database queries | Prevents SQL injection attacks |
| Rate limiting | Prevents brute-force attacks and abuse |
5. Cookie Security
Our website uses cookies to ensure essential functionality (session management, security tokens, language preference). Non-essential cookies (analytics and marketing) are only activated after you give your explicit consent through our cookie banner.
You can view and change your cookie preferences through the cookie banner or its settings panel. For a complete list of all cookies we use, please see section 4 of our Privacy Policy.
6. Data Storage and Access
- Access to personal data is restricted to authorized personnel who need it to provide customer support or fulfill orders.
- Administrative access is protected by secure authentication and limited to designated roles.
- Data is retained only for as long as necessary for its purpose or as required by law (see our Privacy Policy for retention periods).
- Regular data backups are maintained to ensure business continuity and data integrity.
7. Fraud Prevention and Monitoring
We monitor transactions and website activity for signs of fraud or abuse. Measures include:
- Automated monitoring of unusual ordering patterns
- Logging of security-relevant events (login attempts, administrative actions)
- Manual verification of suspicious orders to protect both buyers and sellers
- Cart hold system (30-minute reservation) to prevent overselling
8. Third-Party Services
Third-party services embedded in our website (payment processors, analytics, marketing tools) are only loaded according to your cookie consent preferences. Marketing and analytics scripts are blocked until you actively consent. For details on which third-party services we use and what data they receive, see our Privacy Policy.
9. What You Can Do
You can help keep your account and transactions secure by following these recommendations:
- Use a strong, unique password for your account.
- Do not share your login credentials with anyone.
- Always verify you are on our official website (check the URL and padlock icon) before entering personal data.
- Be cautious of phishing emails - we will never ask for your password by email.
- Log out of your account when using shared or public computers.
10. Security Questions and Reporting
If you discover a security vulnerability, notice suspicious activity on your account, or have any security-related questions, please contact us immediately at: