Privacy policy

Last updated: July 30, 2026

This policy explains what personal data we process when you use TicketPase, how we obtain it, what we use it for and who we share it with.

It is written to describe what the platform does today. If anything is unclear, write to us at the address shown at the end.

Who is responsible for your data

Trazo Labs SpA, a company incorporated in Chile, operates the TicketPase platform and is responsible for the processing of the personal data described in this policy.

You can contact us by email at any time.

[email protected]

Which services this policy covers

This policy applies to the following TicketPase services:

  • The public TicketPase website, including event pages and the purchase process.
  • The organizer panel, where each organizer manages their event, their tickets and their sales.
  • The TicketPase Acreditación mobile app, available for iOS and Android, used by event staff to validate tickets at the door.

It does not apply to third-party sites, apps or services you may reach from our platform. Each of those is governed by its own policy.

Our role and the organizer's role

In every event there are two parties processing personal data, with different responsibilities.

TicketPase
We operate the platform: we publish the event page, process the purchase, issue the tickets and provide the accreditation tools. We process the data in order to provide that service.
The event organizer
Decides which event to publish, what data is requested in the purchase form and what to do with the information of their attendees. Over that data the organizer acts as an independent controller, with their own obligations and their own privacy policy.

If your question is about the event itself, the organizer is the one who can resolve it. If it is about the platform or about this policy, write to us.

What data we collect

The data we ask for depends on the event, the payment method and what each organizer configures. These are the possible sets.

Buyer data
First name, last name and email address, which are required to complete the purchase. Phone number is optional.
Attendee data
First name, last name and email address for each ticket in the order. They may be yours or those of another person attending in your place.
Billing data
Requested only for purchases in Chilean pesos when the organizer issues a tax document: RUT (Chilean tax ID), company name, line of business, address and district.
Fields defined by the organizer
Each organizer configures additional fields in their event form. It is an open set that we do not restrict: it may include RUT, phone numbers, dates, options to choose from, confirmation checkboxes, free text and files you upload as attachments. What is requested, and why, is determined by the organizer.
Payment receipt
When the organizer enables payment by bank transfer or deposit, you upload the receipt file so that your purchase can be validated.
Account data
If you sign in to the platform, we process your email address and the password you sign in with.

Data about other people that you provide

If you buy tickets for other people, you are the one entering their first name, last name and email address. We need that data to issue each ticket in the name of the corresponding attendee, send it to them and validate it at the door.

When you provide us with data about another person, we understand that you have their authorization to do so and that you informed them that their ticket is managed through TicketPase.

It is also your responsibility that the data is correct. The ticket is issued and sent exactly as you entered it.

How we obtain the data

Data reaches us through three routes.

  • You type it into the purchase form, the billing form, the fields defined by the organizer and the sign-in form.
  • It is generated by your purchase: the tickets issued, the amount, the currency, the payment method, the status of the order and the moment a ticket is accredited at the door.
  • It is filled in from an external source based on the RUT: when you enter a RUT in the billing form, we query the taxpayer registry of our tax document provider and autocomplete the company name, line of business, address, district and, when available, a billing email associated with that RUT. Fields that come back with information from that query are locked in the form.

What we use the data for

We use personal data for the following purposes:

  • Issuing your tickets and delivering them to you by email.
  • Accrediting entry to the event: validating the ticket at the door and recording that it was used.
  • Issuing the tax document when the organizer requires it.
  • Answering your support requests.
  • Keeping the platform running and detecting failures.

Payments

Depending on what the organizer enables, you can pay with Transbank Webpay, PayPal, PagoFácil or bank transfer.

We never ask you for your card details: there is no field in TicketPase where you type your card number. When you confirm an online payment, your browser leaves our site towards the payment gateway domain, and the card data is entered there, under the policy of that provider.

With one caveat we prefer to state in writing: when the gateway reports the result of the transaction, it returns a detail of the card you paid with. That value is stored in our systems, exactly as the gateway hands it to us, alongside the record of the transaction.

If you pay by bank transfer or deposit, the receipt you upload is stored on the platform so that the payment can be validated.

Who we share data with

We share data only with those we need in order to provide the service. These are their names:

The event organizer
Receives the purchase data and the attendee data for their event, including the answers to the fields they configured themselves.
Transbank, PayPal and PagoFácil
Process online payments and report the result of each transaction to us. They receive the amount, the currency, the order reference and the card details you enter on the gateway site itself.
Haulmer, through OpenFactura
Issues the electronic tax documents with the billing data, and is the service we query with the RUT to autocomplete that data.
Postmark
Sends the platform emails, such as the purchase confirmation and the ticket delivery. It receives the recipient email address and the content of the message.
Amazon Web Services
Provides storage for the files uploaded to the platform and the queues for background processing.
Expo
Delivers push notifications in the event apps that use them. It receives the device notification identifier and the text of the message. The TicketPase Acreditación app does not send push notifications, so it does not use this service.
New Relic
Monitors how the platform is running. It receives technical and error logs.
TrazoEvents
A congress platform belonging to the same group. When the organizer enables synchronization for their event, it receives the first name, last name, email, ticket type and form answers of each registration.
Discord
Receives an internal notice every time a sale is completed. That notice includes the email addresses of the attendees in the order, the number of tickets and the amount.

Every third party with whom we share user data, including their parent entities, subsidiaries and affiliated companies, will provide the same or equal protection of user data as stated in this policy.

We may also disclose data when a law, a court order or a request from a competent authority requires us to. We do not sell your personal data.

Cookies and local storage

On the public site and in the purchase process, our code uses three cookies and does not use localStorage, sessionStorage or indexedDB. Apart from those three cookies, it does not store information in your browser.

ticketpase-token
Keeps your session open after you sign in. Without it you would have to authenticate on every page.
session_uuid
An identifier we generate to count visits to event pages with our own measurement, without third-party tools.
NEXT_LOCALE
Stores the language you chose so that the following pages are shown in that language.

We want to be precise about session_uuid: it is a pseudonymous identifier, not an anonymous one. It persists across events, so visits from the same browser to pages of different events are linked to the same identifier.

Today the platform does not show a cookie consent banner: these three cookies are set when you use the site. You can delete or block them from your browser settings. If you block the session cookie, you will not be able to stay signed in.

We do not do advertising tracking

We do not do advertising tracking or profiling for marketing purposes. Specifically:

  • We do not use third-party analytics tools.
  • We do not embed advertising pixels or tracking tags.
  • We do not work with ad networks.
  • We do not read device advertising identifiers, such as the iOS IDFA or the Android advertising ID.

The visit measurement we perform is our own and is limited to what is described in the cookies section.

Embedded third-party content

Some pages embed third-party content and features. In each case we tell you what the third party receives and when: some content sends data about your visit as soon as it loads, even if you do not interact with it, while other features act only when you click.

Google map
An event page may show the location on an embedded Google map. When it loads, Google receives your IP address and your browser data, and processes that information under its own policy.
Share buttons
Event pages include buttons to share the link on social networks and messaging apps. They act when you click: the link opens in the service you choose, under the rules of that service.

The TicketPase Acreditación app

The TicketPase Acreditación app is used by staff authorized by the organizer to validate entry to the event. These are the device capabilities it uses and what it uses them for.

Camera
Used only to read the QR code on the ticket. The code is decoded on the device itself: the app does not store or transmit photos or video.
NFC
Used to read and write the event wristbands, when the organizer works with them.
On-device storage
The app stores the event attendee list on the device, so that accreditation can work without an internet connection, and the record of the accreditations performed. That record stays on the device for as long as the app remains installed, even after signing out.

The app does not send push notifications, does not access your location and does not collect device identifiers.

The app does not allow account creation either. Staff sign in with a code provided by the event organizer.

Data retention and your rights

We keep the data for as long as the account and the associated event remain active and, after that, for as long as the legal, accounting and tax obligations that apply to us require. We do not set a single term, because it depends on the obligation that applies to each piece of data.

You may exercise the following rights over your personal data:

Access
To know what data of yours we process and to obtain a copy of it.
Rectification
To correct inaccurate, outdated or incomplete data.
Cancellation
To ask us to stop processing your data and to suppress it, when there is no longer a legal or contractual obligation requiring us to keep it.
Objection
To object to a particular processing of your data.

To exercise any of them, write to our contact address and tell us which right you want to exercise. If you made the purchase, write from the address you used for it. If your data was entered by the person who bought your ticket, write from the address the ticket was sent to, or tell us which purchase it belongs to. We may ask you for additional information to confirm your identity before responding.

[email protected]

When a processing activity is based on your consent, you can withdraw it at any time by the same means. Withdrawal does not affect processing carried out before you request it.

If the data was requested by the organizer through their own fields, we may forward your request to them, because they are the ones who decide about that information.

Security

We apply commercially reasonable technical and organizational measures to protect the data we process: established infrastructure providers, and card data entered directly on the payment gateway site.

No system is completely secure. We cannot guarantee in absolute terms that data will not be accessed, disclosed or altered by an event outside our control. If we detect a security incident affecting your personal data, we will act in accordance with applicable regulations.

In the accreditation app, the information stored on the device is under the control of the organizer and of whoever operates that device. We recommend using devices with a screen lock and signing out when the event ends.

Minors

TicketPase is not directed at people under 18 years of age, and we do not knowingly collect personal data from people under that age.

If a minor is going to attend an event, the purchase must be made by their parent or legal guardian, who provides the data and is responsible for it.

If you believe that a person under 18 has given us personal data, write to us and we will review the case.

International transfers

Part of the infrastructure we use is located outside Chile. The file storage and processing queue services we contract with Amazon Web Services operate in the United States, so the data that passes through those services is processed there.

Other providers named in this policy may also process data outside Chile. In every case we require them to provide protection equivalent to the one stated here.

Changes to this policy

We may update this policy when our services, our providers or the applicable regulations change. The version in force is always the one published on this page, and changes take effect from the moment they are published.

The date of the last update appears at the top of the document. We recommend reviewing it from time to time.

Contact

For any question about this policy or about the processing of your personal data, write to us at:

[email protected]

Trazo Labs SpA, Chile.