Joe's Promos

Joe's Promos - Privacy Policy

Last updated: 2026-10-02

1. Who we are

1.1 This Privacy Policy describes how Joe Promos Ltd (“Joe's Promos”, “we”, “us”, “our”) collects, uses, and protects personal data when you buy a Ticket from our online store. We are the data controller for that data.

1.2 For any privacy question or data-rights request, contact us at info@joepromos.com.

2. Our role and our technology provider

2.1 We decide what personal data is collected, for what purpose, and how it is used - we are the controller. Our online store, checkout, and ticketing are operated for us by FoundTix Ltd, which acts as our processor: it handles this data only on our written instructions and only to provide the platform to us. Other processors we rely on are listed in clause 6.

3. The personal data we collect

3.1 When you buy a Ticket, we collect:

(a) Contact details - first name, last name, email address, postcode, country (from your payment details or, if they don't include it, worked out from your IP address), and (optionally) mobile phone number.

(b) Purchase details - the Events you bought Tickets for, quantity, price paid, purchase time, and the Stripe payment reference. We do not see or store your full payment-card number or security code - Stripe collects those directly from you.

(c) Consent records - where we offer optional marketing, we keep an immutable history of granted and revoked consents (with time, IP address, and the consent copy version) to demonstrate our lawful basis.

(d) Technical data - your IP address, browser type and the times of important actions, recorded in our systems’ logs for security, fixing faults and preventing abuse. If you arrive by clicking an ad, we also record the reference code the ad added to the link, with a scrambled version of your IP address and browser type, for up to fourteen (14) days. When you place an order, we also keep your IP address, browser type and any ad reference codes with it, as part of the order record.

4. How we use your data and our lawful bases

4.1 To deliver your purchase (contract). We use your name, email, phone, postcode, and purchase details to issue your Ticket(s), email your order confirmation, process refunds, and send any change-of-Event notifications.

4.2 To run the store (legitimate interest). We use technical data for security, fraud detection, debugging, and abuse prevention, balanced against the limited intrusiveness of these logs.

4.3 For marketing (consent). Where we offer marketing messages, we send them only to buyers who have explicitly opted in, and you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

4.4 To measure our advertising (legitimate interest). Where we have connected our own account with Meta (Facebook and Instagram), TikTok or Reddit, we send that platform a record of what you do in our store, such as viewing an Event, starting a checkout or buying a Ticket, and, only if you accept advertising cookies, its tools also run in your browser. This lets us see which ads lead to ticket sales and show our ads to the right people. It does not add you to any email or text marketing list, and your details are not shared with any other seller.

4.5 To meet legal obligations. We retain order and payment records as required by applicable tax and accounting law.

4.6 We do not sell your personal data, and we do not share it with any other seller or ticketing marketplace.

5. Retention

5.1 We keep order, refund, and payment-related records for as long as required by applicable tax and accounting law (typically at least six years). We keep consent records for as long as the related account or order data is retained. Data held solely for marketing is deleted within a reasonable period after you withdraw all marketing consents, unless we must retain it for the records above.

6. Third parties that process your data

6.1 We use the following processors and partners, each bound by a contract requiring them to handle personal data in line with applicable data protection law:

(a) FoundTix Ltd - the ticketing and platform technology that runs our online store, checkout, ticket issuance, and order management on our behalf.

(b) Stripe - payment processing on our account. Stripe collects your card data directly and processes any refunds we issue; we never see or store your card number, expiry, or security code.

(c) Email delivery - our transactional email provider, to which we pass your email address, the message, and (for ticket emails) the PDF attachment.

(d) Advertising platforms (Meta, TikTok and Reddit) - only where we have connected our own account with that platform (clause 4.4). We send it your contact details in scrambled form, together with your IP address and browser type, which its matching needs.

6.2 Wallet pass providers (Apple, Google) are not processors of your data: the wallet pass contains only the ticket code, event details, and our name - never your name, email, or phone.

7. Cookies

7.1 Cookies that the store needs to work, and a cookie that remembers your cookie choice, are always set. The only other cookies are advertising cookies: those of Meta, TikTok and Reddit, and our own cookie that notes for thirty (30) days which ad brought you to the store. They are set only if you accept them, and never if you decline or make no choice. The records in clause 4.4 are sent from our own systems whether or not you accept advertising cookies; if you have accepted them, they also include the codes those cookies hold. You can change your choice at any time with the Cookie settings link at the bottom of the store’s pages.

8. Your rights

8.1 Subject to applicable law, you have the right to access, rectify, or erase your personal data, to restrict or object to processing (including for direct marketing), to data portability, and to withdraw any consent at any time. To exercise any of these rights, email us at info@joepromos.com from the address associated with your purchase. You also have the right to complain to your local data protection authority.

9. Security and children

9.1 We hold personal data with access controls and encryption in transit (TLS). Payment-card data is handled entirely by Stripe’s PCI-DSS infrastructure and never rests on our systems. If we suffer a personal data breach likely to result in a risk to your rights, we will notify the relevant authority and, where required, you, without undue delay.

9.2 Our store is intended for adults. We do not knowingly collect personal data from children below the age of digital consent in your country. Age restrictions for individual Events are set by us and shown on the Event page.

10. Changes and governing law

10.1 We may update this Privacy Policy from time to time; the current version is indicated by the “Last updated” date shown with it. This policy is governed by the laws of England and Wales.