Privacy policy
HomeInvestor beta draft
This policy is published for the investor TestFlight beta and may change before public launch.
Last updated 19 July 2026
SuperTickets ("we", "us") operates a ticketing platform for live entertainment in Nigeria. This policy explains what personal data we collect, why we process it, who helps us process it, and the rights you have under the Nigeria Data Protection Act 2023 (NDPA).
For the Nigeria investor beta, payments run through Paystack in TEST mode on staging. SuperTickets never stores your full card number, CVV, or bank PIN — that data goes directly to Paystack over an encrypted connection. We store the transaction reference and outcome (paid, failed, refunded) needed to issue tickets and handle disputes. The Paystack webhook (server-verified) is the source of truth for payment success.
We do not sell your personal data to advertisers or unrelated third parties.
If you register as an organiser, we may ask for a government-issued ID and proof of business address before you can publish paid events. These documents are stored in a private Supabase Storage bucket accessible only to you and SuperTickets verification staff. We keep them while your organiser account is active and for as long afterwards as Nigerian AML, tax, or dispute obligations reasonably require — then delete or irreversibly anonymise them.
Some processors (for example Supabase, Cloudinary, Sentry, or Cloudflare) may process data outside Nigeria. Where that happens, we rely on contractual processor terms and appropriate safeguards consistent with the NDPA, and we only transfer what is needed for the purposes above.
Under the NDPA, you can ask us to:
We keep personal data only as long as needed for the purposes in this policy, including financial audit, dispute resolution, and applicable Nigerian legal obligations. When you delete your account, profile identifiers are removed or anonymised promptly; remaining order, ticket, and payment records stay in anonymised form so they can no longer be linked back to you except as required for that audit trail.
We may update this policy as the Service evolves. Material changes for the beta will be reflected on this page with a new "Last updated" date. Continued use after an update means you acknowledge the revised policy.
Privacy questions or NDPA requests can be sent through Support or the support email listed there.
Questions about this policy? Visit Support.