Security and Data Protection
Last updated: 2026-09-04
At Tickets Vienna, the security of your personal data and financial information is our highest priority. This page describes the technical and organisational measures we implement to protect your information throughout the booking process.
Company and security information
This page brings together company, booking, payment, and security information for TicketsVienna, with links to official records and public policy pages.
| Fact | Current public status | Sources |
|---|---|---|
| Legal operator | TicketsVienna.com is operated by Velora Digital e.U., a publicly listed Austrian business in Vienna with FN 685204d, registered owner Hajriz Hyseni, and a Vienna registered office. | Legal NoticeeVI FirmenbuchJustizOnline FirmenbuchWKO Firmen A-Z |
| Firmenbuch / company-register extract | The official eVI record for FN 685204d lists Velora Digital e.U. as entered in the Austrian business register. The Austrian judiciary’s business-register query can also be used to obtain a current register extract. | eVI FirmenbuchJustizOnline Firmenbuch |
| Ticket-office trade listing | The official GISA public query can be used to verify GISA number 39725905; the WKO Firmen A-Z listing shows ticket-office trade activity (Betrieb eines Kartenbüros). | GISA Gewerbeinformationssystem AustriaWKO Firmen A-Z |
| Official contractual partner status | TicketsVienna works through direct contracts with selected event organizers, venues, and ticket inventory partners for inventory listed on the platform. | ContactTerms |
| Domain age | ticketsvienna.com was registered on 25 April 2018; 8+ years old according to public RDAP/WHOIS data. | RDAP / WHOIS |
| Platform role | TicketsVienna is a real Vienna-based ticket agency and direct ticket sales platform with contracts for selected event partners and ticket inventory. Event organizers remain responsible for the event itself. | TermsLegal Notice |
| Payment handling | Card and wallet payments are handled through Stripe and PayPal where enabled. TicketsVienna stores payment references, while full card numbers and CVV codes remain with the payment provider. | SecurityPrivacy Policy |
Company details are available through official Austrian public registers, including the Firmenbuch, GISA, and WKO. Tourism directories and comparison pages are curated editorial resources and may list only selected providers, so they should be read as additional context.
Review information is handled as a separate reputation signal. TicketsVienna publishes real moderated customer reviews and emits rating data only when such reviews exist.
1. SSL/TLS Encryption
All communication between your browser and our servers is encrypted using TLS (Transport Layer Security). This ensures that your personal details, login credentials, and payment information cannot be intercepted by third parties during transmission.
You can verify the secure connection by checking for the padlock icon in your browser's address bar and the "https://" prefix in the URL.
Live SSL certificate check
This check reads the current HTTPS certificate for www.ticketsvienna.com and confirms whether the browser trust chain is valid.
The certificate is trustworthy and valid for secure checkout.
| Common name | Details | Key length | Validity | Signature | Result |
|---|---|---|---|---|---|
| www.ticketsvienna.com | Google Trust Services | 256 Bit | 18.08.2026 to 16.11.2026 | ecdsa-with-SHA256 | Trusted |
| WE1 | Google Trust Services LLC | 256 Bit | 13.12.2023 to 20.02.2029 | ecdsa-with-SHA384 | Trusted |
| GTS Root R4 | GlobalSign nv-sa | 384 Bit | 15.11.2023 to 28.01.2028 | RSA-SHA256 | Trusted |
2. Payment Security
We do not store, process, or have access to your full credit card number, CVV code, or bank login credentials at any time. All payment processing is handled by certified third-party providers:
| Provider | Certification | How It Works |
|---|---|---|
| Stripe | PCI-DSS Level 1 (highest level) | Card details are entered directly in Stripe's secure embedded form. We only receive a transaction reference token. |
| PayPal | PCI-DSS Level 1 | You are redirected to PayPal's secure environment to authorize payment. We only receive a transaction confirmation. |
PCI-DSS (Payment Card Industry Data Security Standard) Level 1 is the most stringent certification for handling card payments, required for organizations processing millions of transactions annually.
3. Account Security
If you create an account, your password is protected using the following measures:
- Passwords are stored only as irreversible cryptographic hashes using industry-standard algorithms. Even our staff cannot view your password.
- Rate limiting is applied to login attempts to prevent brute-force attacks. Repeated failed attempts result in temporary lockout.
- Sessions expire automatically after a period of inactivity. You can log out at any time to end your session immediately.
We recommend using a strong, unique password for your account and keeping your login credentials confidential.
4. Website Protection
We implement multiple layers of defense to protect the integrity and security of our website:
| Measure | What It Protects Against |
|---|---|
| CSRF tokens on all forms | Prevents unauthorized actions submitted from other websites |
| Content Security Policy (CSP) headers | Blocks injection of unauthorized scripts and resources |
| Output escaping and input validation | Prevents cross-site scripting (XSS) and injection attacks |
| Parameterized database queries | Prevents SQL injection attacks |
| Rate limiting | Prevents brute-force attacks and abuse |
5. Cookie Security
Our website uses cookies to ensure essential functionality (session management, security tokens, language preference). Non-essential cookies (analytics and marketing) are only activated after you give your explicit consent through our cookie banner.
You can view and change your cookie preferences through the cookie banner or its settings panel. For a complete list of all cookies we use, please see section 4 of our Privacy Policy.
6. Data Storage and Access
- Access to personal data is restricted to authorized personnel who need it to provide customer support or fulfill orders.
- Administrative access is protected by secure authentication and limited to designated roles.
- Data is retained only for as long as necessary for its purpose or as required by law (see our Privacy Policy for retention periods).
- Regular data backups are maintained to ensure business continuity and data integrity.
7. Fraud Prevention and Monitoring
We monitor transactions and website activity for signs of fraud or abuse. Measures include:
- Automated monitoring of unusual ordering patterns
- Logging of security-relevant events (login attempts, administrative actions)
- Manual verification of suspicious orders to protect both buyers and sellers
- Cart hold system (30-minute reservation) to prevent overselling
8. Third-Party Services
Third-party services embedded in our website (payment processors, analytics, marketing tools) are only loaded according to your cookie consent preferences. Marketing and analytics scripts are blocked until you actively consent. For details on which third-party services we use and what data they receive, see our Privacy Policy.
9. What You Can Do
You can help keep your account and transactions secure by following these recommendations:
- Use a strong, unique password for your account.
- Do not share your login credentials with anyone.
- Always verify you are on our official website (check the URL and padlock icon) before entering personal data.
- Verify sender details before opening unexpected emails; we will never ask for your password by email.
- Log out of your account when using shared or public computers.
10. Security Questions and Reporting
If you discover a security vulnerability, notice suspicious activity on your account, or have any security-related questions, please contact us immediately at: