<!--
Notarized 31 Aug 2026 (Dome Nathan Obura, Commissioner for Oaths & Notary
Public, Nairobi). Live at /privacy — src/lib/legal-content.ts is the source
of truth for the rendered page; keep this file in sync if it changes.
-->

# Privacy Policy

**Last updated: 31st August 2026**

VibePass Tickets ("VibePass," "we," "us," or "our") operates the ticketing
platform at vibepasstickets.com (the "Service"). This Privacy Policy explains
what personal information we collect, why, how we use it, and the choices you
have.

By using the Service — whether buying a ticket, creating an organizer
account, or browsing events — you agree to the collection and use of
information as described here.

## 1. Who we are

VibePass Tickets ("VIBE PASS TICKETS") is a ticketing platform for live
events in Kenya and East Africa, connecting event organizers with ticket
buyers.

- **Contact:** vibepasstickets@gmail.com
- **Address:** Dereshe Towers, Murang'a Rd, Nairobi, Kenya
- **Phone:** +254 143 003000

## 2. Information we collect

### From ticket buyers
- Name, email address, and phone number, provided at checkout.
- Payment confirmation details (e.g. an M-Pesa receipt number or transaction
  reference) — **we do not collect or store your card number, M-Pesa PIN, or
  full payment credentials.** Those are handled directly by our payment
  processors (Section 5).
- The tickets you purchase, the events you attend, and check-in records
  (when a ticket is scanned at an event).

### From event organizers
- Name, email, phone number, and password (if you sign up with
  email/password) or your name and email as provided by Google, Facebook, or
  Apple (if you sign in that way).
- Business/event details you provide when creating an event (event name,
  description, venue, pricing, cover images).
- Payout details when you set up how you get paid (M-Pesa number, or bank
  account name/number/branch).
- Records of your platform activity — events created, orders received,
  refunds issued, payouts made, marketing campaigns sent to your customers.

### Automatically, from anyone using the Service
- Standard web request data (IP address, browser type, pages visited).
- Cookies for signing in and keeping you signed in, remembering your
  light/dark theme preference, and — if you arrived via an affiliate/referral
  link — a cookie recording which affiliate referred you, so we can credit
  them correctly.

We do not knowingly collect more personal information than the Service
needs to function.

## 3. How we use your information

We use the information above to:

- Process ticket purchases and deliver your tickets (including a QR code
  used for event check-in).
- Communicate with you about your order, event updates, or account activity.
- Let organizers manage their events, view their sales, and get paid.
- Send marketing messages (SMS or email) on behalf of an organizer to their
  own customers, if the organizer runs a campaign — you can opt out of these
  (Section 8).
- Detect and prevent fraud, abuse, and unauthorized access.
- Comply with our legal obligations, including tax and financial reporting
  requirements.

We do not sell your personal information to third parties.

## 4. Cookies

We use a small number of cookies:

| Cookie | Purpose | Duration |
|---|---|---|
| Session/authentication | Keeps you signed in | Session / until sign-out |
| Theme preference | Remembers light/dark mode | 1 year |
| Affiliate referral (`aff_ref`) | Credits the affiliate who referred you, if any | 30 days |

We don't currently use third-party advertising or cross-site tracking
cookies. If that changes, we'll update this policy and, where required by
law, ask for your consent first.

## 5. Third parties we share data with

We share the minimum information necessary with the following categories of
service providers, solely to operate the Service:

- **Payment processors** — M-Pesa (Safaricom Daraja), Paystack, and PayPal
  process your payment directly. We receive confirmation that a payment
  succeeded and a reference number, not your full payment credentials.
- **SMS delivery** — Africa's Talking, used to send OTP login codes and,
  where an organizer runs an SMS campaign, marketing messages to their
  customers.
- **Email delivery** — Resend, used to send ticket confirmations and other
  transactional email.
- **Sign-in providers** — Google, Facebook, and Apple, if you choose to sign
  in using one of those instead of email/password. We only receive the name
  and email address (or equivalent) that provider shares with us.
- **Hosting infrastructure** — our servers and database are hosted with our
  hosting provider in the ordinary course of running the Service.

We require that these providers only use your information to perform the
service they provide us, and not for their own independent purposes.

We may also disclose information if required by law, court order, or to
protect the rights, property, or safety of VibePass, our users, or others.

## 6. Data retention

We keep personal information for as long as your account is active or as
needed to provide the Service, and afterward for as long as necessary to
comply with legal obligations (e.g. financial record-keeping), resolve
disputes, and enforce our agreements. Order and payment records are retained
for 3 years for tax, accounting, legal, and dispute-resolution purposes.
Personal information that is no longer required for the provision of the
Service or for legal, regulatory, accounting, or dispute-resolution purposes
will be securely deleted or anonymized.

## 7. Data security

We take reasonable technical and organizational measures to protect your
personal information, including encrypting sensitive credentials at rest and
restricting access to production systems. No method of transmission or
storage is 100% secure, and we cannot guarantee absolute security.

## 8. Your rights

Under Kenya's Data Protection Act, 2019, you have the right to:

- Be informed of how your personal data is used (this policy).
- Access the personal data we hold about you.
- Request correction of inaccurate or outdated data.
- Request deletion of your data, subject to our legal obligation to retain
  certain records (e.g. financial transactions).
- Object to or restrict certain processing, including opting out of
  marketing communications.
- Data portability, where technically feasible.
- Lodge a complaint with the Office of the Data Protection Commissioner
  (ODPC) if you believe your rights have been violated.

To exercise any of these rights, contact us at vibepasstickets@gmail.com, or
our Data Protection Officer, Newton Ngure (A-Lit Digital Services Limited),
reachable via the same address.

Organizers can unsubscribe recipients from SMS/email campaigns at any time;
every campaign message includes an opt-out instruction.

## 9. Children's privacy

The Service is not directed at children under 18. We do not knowingly
collect personal information from children. If you believe a child has
provided us personal information, contact us and we will delete it.

## 10. International data transfers

VibePass's servers and database are hosted in Kenya, and personal
information is stored and processed within Kenya. We do not transfer
personal information outside Kenya, except to the extent a third-party
service provider (Section 5) — such as a payment processor — processes a
payment on our behalf in the ordinary course of that transaction.

## 11. Changes to this policy

We may update this Privacy Policy from time to time. We'll post the updated
version here with a new "Last updated" date, and for material changes we'll
make a reasonable effort to notify active organizer accounts by email.

## 12. Contact us

Questions about this policy or your data:

- **Email:** vibepasstickets@gmail.com
- **Address:** Dereshe Towers, Murang'a Rd, Nairobi, Kenya
- **Phone:** +254 143 003000
