Privacy Policy

Last updated: 6 July 2026  ·  Effective: 6 July 2026

This Privacy Policy explains how TicketPassport collects, holds, uses, discloses and protects your personal information, and how you can access, correct or complain about the way we handle it. We are committed to protecting your privacy and to handling personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).

Who we are This Policy is issued by [Operating entity — to be finalised: e.g. “Nicholas Jamou trading as TicketPassport (ABN ___ ___ ___)” or “TicketPassport Pty Ltd (ACN ___ ___ ___)”] (“TicketPassport”, “we”, “us” or “our”). It applies to the TicketPassport mobile app for iOS and Android, the website at ticketpassport.app, and our related email-ingestion, extraction and back-end services (together, the “Service”).
Plain-English summary (not a substitute for the full Policy) TicketPassport pulls your event tickets into one place by reading your ticket confirmation emails — only ones you forward to us, or in a mailbox you connect and then choose to scan. To do that we collect your email address and phone number, the content of ticket confirmation emails (including any PDF attachments and barcodes), and information about your friends and shared tickets if you use those features. We use a trusted AI provider (Anthropic’s Claude) to read ticket details out of your emails. We store your data primarily in Australia, we never reproduce app-locked (SafeTix) barcodes, and we don’t sell your personal information. You can access, correct or delete your data at any time. Full detail is below.

1.About this Policy & your consent

Personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, as defined in the Privacy Act 1988 (Cth). This Policy covers all personal information we handle through the Service.

By creating an account, connecting or forwarding email to us, or otherwise using the Service, you acknowledge this Policy and consent to us collecting, holding, using and disclosing your personal information as described here. If you do not agree, please do not use the Service. Our Terms of Service also apply to your use of the Service.

Because a core function of the Service is reading your ticket confirmation emails, some of the information we handle can be detailed. We only ever access the mail you choose to give us — by forwarding it, connecting a mailbox and then tapping Scan inbox, or configuring an inbox poll. We do not run any background or automatic mailbox scanning.

2.What the Service does

TicketPassport is a ticket wallet for event-goers. It brings tickets bought across many Australian ticketing platforms into a single “passport” by reading the confirmation emails those platforms send you, extracting the event and ticket details, and displaying them — either as a scannable QR code (for static-barcode tickets) or as details plus an “open the official app / view ticket” link (for app-locked or hosted tickets). It also has an optional social layer that lets you add friends, see who else is going, and share the visibility of a ticket with a friend (which is not a legal transfer of the ticket).

Understanding these functions helps explain why we collect what we collect. Where a purpose is optional (for example, connecting a mailbox, importing contacts, or using the social features), we tell you at the relevant point in the app and you can choose not to use it.

3.Personal information we collect

The kinds of personal information we collect depend on how you use the Service. They include:

3.1 Account & identity information

3.2 Phone number (required)

To help keep the community genuine and reduce duplicate or fake accounts, new accounts must verify a mobile phone number by SMS one-time code during onboarding. We store your verified number with our authentication provider. Your number is also used, if you enable it, to help friends who have your number in their contacts find you (see 3.4).

3.3 Ticket & email content

This is the core of the Service. Depending on which ingestion method you use, we collect:

App-locked (SafeTix) tickets For rotating, app-locked barcodes (such as Ticketmaster / Ticketek SafeTix), we do not and cannot extract, store or reproduce the gate barcode. We only keep the event details and provide a link to open the official vendor app. Any PDF receipt for such a ticket is never treated as a gate barcode.

3.4 Contacts (optional)

If you choose to use “Find friends from your contacts”, the app reads the phone numbers in your device’s contacts and converts each number into a one-way cryptographic hash on your device. Only these hashes are sent to us, to match against other members who have chosen to be discoverable. We never receive your contacts’ names or their plain-text phone numbers, and we do not build or keep a directory of your contacts. You can turn off “discoverable by phone” in your privacy settings at any time.

3.5 Mailbox connection data (optional)

If you connect a Gmail or Outlook mailbox, we store the OAuth access and refresh tokens that let us read your mail only when you ask us to scan, along with the connected email address and sync status. We request read-only mail access and use it solely to find ticket confirmation emails. You can disconnect a mailbox at any time, which invalidates the stored tokens.

3.6 Social & sharing information

3.7 Device & notification information

3.8 Technical, usage & diagnostic information

We take active measures so that ticket barcode numbers and QR/SafeTix payloads are never written to our logs, metrics or alerts.

4.How we collect your personal information

We collect personal information:

Directly from you
When you create an account, verify your phone, set up your profile, adjust settings, forward an email, connect or scan a mailbox, upload a ticket or attachment, add friends, share tickets, post activity, or contact us for support.
From your connected mailbox, with your consent
When you connect Gmail or Outlook and tap Scan inbox, or configure an email forward or inbox poll, we receive the ticket confirmation emails and attachments found by that method.
Automatically, through your use of the Service
Technical, log, device, usage and diagnostic information is generated when you interact with the app or our servers.
From other people
If a friend shares a ticket with you, adds a label naming you, sends you a friend or profile invite, or has your phone number in their contacts and you are discoverable, we may receive information that relates to you from them.

If we receive personal information we did not solicit — for example, if a forwarded email contains information that is not a ticket, or contains information about other people — we handle it in accordance with APP 4 and will destroy or de-identify it where it would not have been lawful for us to collect it and it is not contained in a Commonwealth record.

5.Sensitive information

We do not seek to collect “sensitive information” (as defined in the Privacy Act, such as information about health, racial or ethnic origin, political or religious beliefs, sexual orientation, or criminal record). However, because we process tickets to events, the fact that you hold a ticket to a particular event could reveal or imply sensitive information (for example, attendance at a political, religious, cultural or health-related event). By forwarding or connecting your tickets to the Service, you consent to us collecting and handling that information for the purpose of providing the Service to you (that is, storing, organising and displaying your tickets, and — only where you choose — sharing a ticket’s visibility with a friend). We do not use this information for any other purpose, and we apply the same protections described in this Policy.

6.How and why we use your personal information

We use personal information for the following purposes:

We will only use or disclose your personal information for a purpose you would reasonably expect, a purpose set out in this Policy, a purpose you have consented to, or as otherwise permitted or required by law.

7.Automated processing & artificial intelligence

To read ticket details out of the varied and often messy HTML of confirmation emails, we send the relevant email content to a third-party AI provider, Anthropic (the maker of Claude), which returns structured ticket data. The email content is transmitted to Anthropic’s systems for this processing (see section 9 on overseas disclosure). We send the content as inert data within safeguards designed to prevent it from being treated as instructions.

This processing is automated and may be imperfect — extracted details can be incomplete or incorrect. It is not automated decision-making that produces a legal or similarly significant effect about you; it simply structures your own ticket information for display. You are responsible for checking that your ticket details are correct and that you present a valid ticket at an event (see our Terms of Service).

8.When we disclose your personal information

We do not sell your personal information. We disclose it only as follows:

9.Overseas disclosure & our service providers

We store the core of your data — your account, tickets and files — in a database and file storage hosted in Australia (Sydney). However, some of our service providers operate or store/process data overseas, principally in the United States. That means that in the course of providing the Service, your personal information may be disclosed to, or accessible by, recipients located outside Australia. Before disclosing personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the APPs, but you acknowledge that overseas recipients may be subject to different privacy laws.

Provider Purpose Information involved Location
Supabase Authentication, database & file storage Account, phone, tickets, attachments, social graph Australia (hosting); provider USA
Railway Back-end API & processing Email content, ticket data, technical data United States
Anthropic (Claude) AI extraction of ticket details from email content Ticket-email subject & body content United States
Cloudflare Inbound email routing, website/CDN, bot protection (Turnstile) Forwarded email content, IP, technical data United States / global edge
Expo (EAS) Push-notification delivery Push token, notification content United States
Apple Sign in with Apple, push (APNs), App Store Identity token, device push token United States
Google Google sign-in, Gmail read access (if connected), push (FCM), Play Store Identity token, email content, push token United States
Microsoft Outlook mail read access (if connected) Email content United States
SMS provider Delivery of phone-verification codes Mobile phone number United States / global
Email delivery provider Authentication & transactional emails Email address United States
Sentry Crash & error reporting (masked) Diagnostic/technical data United States

This list may change as the Service evolves; we will keep this Policy up to date. Some providers are only engaged if you use the related optional feature (for example, mailbox providers, or the SMS provider once phone verification is enabled).

10.Notifications, messages & direct marketing

Most messages we send are transactional — verification codes, account and security notices, and the social/ticket notifications you have switched on. You can manage or turn off push notifications in the app’s notification settings or in your device settings.

We do not currently send marketing emails. If we ever send you promotional or marketing messages, we will do so consistent with the Spam Act 2003 (Cth) and APP 7: only with an appropriate basis to contact you, always identifying us as the sender, and always including a simple way to opt out or unsubscribe. You can also ask us at any time not to receive marketing communications by emailing support@ticketpassport.app.

11.How we protect your personal information

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, including:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You also play a part: keep your device, email account and login credentials secure, and be careful who you share tickets or public links with. If you believe your account has been compromised, contact us immediately.

12.Data retention & deletion

We keep personal information for as long as your account is active and for as long as we need it to provide the Service, and after that only as long as necessary to comply with our legal obligations, resolve disputes, prevent abuse and enforce our agreements. Ticket and event data is generally retained while it is useful to you (for example, past events remain in your passport history) unless you delete it.

You can delete individual tickets in the app, and you can delete your entire account from Profile → Delete account. Deleting your account removes your profile and associated database records and deletes your stored files (such as ticket PDFs, QR images and your avatar) from our storage. Some information may persist for a limited period in encrypted backups, or where we are required to retain it by law, before being overwritten or destroyed. De-identified and aggregated data that no longer identifies you may be retained.

Note about deletion & re-forwarding If you delete a ticket and later forward the same email again, it will be re-added as a new ticket. Deleting a ticket you had shared may cause the recipient’s copy to stop working.

13.Accessing, correcting & controlling your information

Under the APPs you have the right to:

Access your personal information (APP 12)
You can view and manage much of it directly in the app. You can also request a copy of the personal information we hold about you by emailing us.
Correct your personal information (APP 13)
You can update your profile, handle, avatar and settings in the app. If information we hold is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to correct it.
Control optional data uses
You can disconnect a mailbox, turn off “discoverable by phone”, change your activity/attendance visibility, block other users, revoke shares and public links, and manage notifications — all in the app.
Withdraw consent / delete
You can delete tickets or your whole account at any time. Withdrawing consent or deleting your account may mean we can no longer provide some or all of the Service.

To make an access or correction request, email support@ticketpassport.app. We may need to verify your identity first. We will respond within a reasonable period (usually within 30 days). Access and correction are generally free; if a request is complex we will tell you of any reasonable cost before proceeding. If we refuse access or correction, we will give you written reasons and information about how to complain.

14.Anonymity & pseudonymity

Where lawful and practicable, you may deal with us anonymously or by a pseudonym — for example, you present to other users under a chosen handle rather than your legal name. However, the core Service cannot function without an email address (to receive your tickets) and a verified phone number (to secure the account), so these are required to register.

15.Children & minors

The Service is intended for users aged 16 and over. It is not directed at children under 16, and we do not knowingly collect personal information from them. If you are a parent or guardian and believe a child under 16 has provided us with personal information, please contact us and we will take reasonable steps to delete it.

16.Third-party services & links

The Service works alongside third parties that have their own privacy policies and terms, including ticketing vendors (such as Ticketek, Ticketmaster, Moshtix, Megatix, Oztix, Humanitix, TryBooking, Eventbrite, Ticketbooth and others), mailbox providers (Google, Microsoft), and the Apple App Store and Google Play. When you open an official vendor app or a hosted ticket page, or sign in with a third-party provider, that party’s privacy policy governs its handling of your information. We are not responsible for the privacy practices of third parties. We are not affiliated with, or endorsed by, any ticketing vendor or event organiser.

17.Our website, cookies & analytics

Our marketing website (ticketpassport.app) is a simple, largely static site. We do not use advertising cookies or third-party ad trackers on it. Our hosting/CDN provider (Cloudflare) processes standard technical request data (such as IP address) to deliver and secure the site, and we use a privacy-respecting bot-protection challenge (Cloudflare Turnstile) on some sign-in flows. Within the app we use the limited, self-hosted analytics and crash diagnostics described in section 3.8.

18.Data breaches

We maintain processes to detect and respond to data security incidents. If a data breach occurs that is likely to result in serious harm to any individual whose personal information is involved, we will assess and respond in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.

19.Changes to this Policy

We may update this Policy from time to time to reflect changes to the Service, our providers, or the law. The “Last updated” date at the top shows when it last changed. If we make a material change, we will take reasonable steps to notify you — for example, by an in-app notice or by updating this page before the change takes effect. Your continued use of the Service after an update means you accept the revised Policy.

20.How to contact us & make a complaint

If you have a question about this Policy, want to access or correct your information, or wish to make a privacy complaint, contact us:

TicketPassport — Privacy
Email: support@ticketpassport.app
Operated by [Operating entity & ABN/ACN to be finalised], Victoria, Australia.

We take complaints seriously. Please give us enough detail to investigate. We will acknowledge your complaint, investigate it, and aim to respond within a reasonable period (usually within 30 days). If you are not satisfied with our response, you can refer your complaint to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au, phone 1300 363 992.