Your data, straight up.
What we collect, why we collect it, and what we never do with it. Effective 5 August 2026.
Privacy Policy
How DOT TIX collects, uses, shares, secures and retains personal data.
|
Effective date |
5 August 2026 |
|
Operator |
The DOT360 Network, trading as DOT TIX |
|
Website |
https://tix.dot360.co |
|
Contact |
privacy@dot360.co |
1. Who is responsible
The DOT360 Network, trading as DOT TIX (DOT TIX, we, us or our), is the data controller for DOT ID accounts, Platform security, payment administration, ticket and merchandise order administration, waitlists, ticket delivery, support, platform analytics, seller onboarding and our own marketing.
The organizer or product seller identified on an event or product page is generally a separate controller for event administration, attendance, venue operations, merchandise fulfilment and its own lawful communications. We may process personal data for an organizer or seller to provide ticketing and commerce services. If The DOT360 Network is the organizer or seller, it is also controller for that event or sale.
Contact our Privacy Team or Data Protection Officer at privacy@dot360.co or at the postal address in section 18.
2. Scope
This Policy applies to the DOT TIX website, progressive web app, DOT ID, saved events and interests, ticket wallet, checkout, order lookup, event and merchandise storefronts, waitlists, seller dashboards, scanner and gate tools, WhatsApp commerce, support assistant and channels, event communications sent through DOT TIX and related services that link to it. A third-party website or service has its own policy.
3. Personal data we collect
|
Category |
Examples |
|
Identity and contact |
Name, email address, phone or WhatsApp number, country, DOT ID, username and age confirmation. |
|
Account and security |
Password hash, authentication settings, login history, selected interests, saved events, role, team membership, security alerts and recovery records. |
|
Order, ticket and waitlist |
Event, ticket tier, quantity, price, discount or promoter code, order code, ticket holder, complimentary or guest status, waitlist status, transfer or resale history, QR status, table or add-on request and refund request. |
|
Payment metadata |
Gateway, payment method type, amount, currency, transaction reference, authorization or settlement status and limited card metadata such as brand or last digits where provided by the gateway. We do not receive or store the full card number or PIN. |
|
Attendance and gate |
Check-in time, gate, scan result, assigned ticket, restriction or manual check-in audit. Scanner staff ordinarily receive only the information needed to validate entry. |
|
Seller and payout |
Legal or trading name, business details, authorized representative, identity or verification records, bank or settlement account, tax and payout records, event inventory, team permissions and promoter commissions. |
|
Support and communications |
Support-assistant or agent messages, call or chat content, attachments, subject, priority, complaint history, email or WhatsApp delivery status, conversation state, sales-enquiry name, work email, company, preferences and consent records. |
|
Device and usage |
IP address, device and browser, operating system, session identifiers, pages and searches, referral source, country preference, crash, performance and security logs. |
|
Content |
Event, collection, brand and product titles, descriptions, images, line-ups, programme, venue, merchandise details and other content a seller publishes or a user submits. |
|
Merchandise and fulfilment |
Product and variant, quantity, amount, collection or delivery option, shipping address, recipient contact, fulfilment status, return request and refund outcome. |
3.1 Sensitive data
DOT TIX does not ordinarily need sensitive personal data. We may receive limited health or hospitalization evidence for a statutory cancellation request, accessibility information voluntarily provided for event support, or identity documents for lawful seller verification. We use additional safeguards, limit access and delete or de-identify the information when it is no longer required.
4. How we collect data
1. Directly from you: when you register, buy, reserve, save an event, select interests, join a waitlist, transfer or resell where available, buy merchandise, use WhatsApp commerce, list or scan an event, contact support, request a refund or set preferences.
2. From organizers, sellers or purchasers: when an organizer issues a guest or complimentary ticket, a purchaser assigns a ticket to another holder, or a seller provides information needed to fulfil an order.
3. From service providers: when a payment gateway reports transaction status, a communications provider reports delivery, or an identity or banking provider verifies seller details.
4. Automatically: through necessary logs, cookies, local storage and, with consent where required, analytics or marketing technologies.
5. Why we use data and our lawful bases
|
Purpose |
Data and lawful basis |
|
Create and secure a DOT ID |
Identity, contact, account, saved-event, interest and security data. Necessary to perform the account contract and requested personalization, and for legitimate interests in account security and fraud prevention. |
|
Process orders and deliver tickets or merchandise |
Contact, order, ticket, merchandise, fulfilment and payment metadata. Necessary to perform the purchase and ticketing contract and comply with accounting obligations. |
|
Waitlists, transfer, resale, refund and support |
Waitlist, ticket, transaction, recipient, merchandise and support data. Necessary to perform requested services, comply with consumer law, resolve disputes and prevent double recovery. |
|
Run admission and event operations |
Ticket holder and scan data shared with the relevant organizer. Necessary to perform the ticket contract and for legitimate interests in secure, efficient admission. |
|
Onboard sellers and make payouts |
Business, identity, bank, tax and payout data. Necessary for the seller contract, fraud and risk controls, and legal or payment-partner obligations. |
|
Prevent fraud and protect the Platform |
Account, device, transaction and security data. Legitimate interests in safety, integrity and abuse prevention, and legal obligations where applicable. |
|
Send essential communications |
Contact, order, account, event, waitlist and fulfilment data. Necessary to perform contracts and provide ticket, offer, delivery, safety, change, receipt, refund and security notices. |
|
Improve and measure the Platform |
Aggregated or limited usage, search, performance and support data. Legitimate interests in product improvement; consent where non-essential cookies or tracking are used. |
|
Send event marketing |
Contact, interests, purchase or campaign data. Consent where required. You may opt out at any time. |
|
Meet legal, tax and regulatory duties |
Transaction, seller, support and compliance data. Necessary to comply with law, establish or defend claims and cooperate with competent authorities. |
6. Fraud signals and automated decisions
We use rules and automated signals to select or offer payment gateways, process gateway confirmations, issue and deliver tickets, attribute promoter sales and calculate configured commissions, offer released tickets to waitlists, route support requests, detect unusual purchasing, identify duplicated tickets, enforce limits and flag possible fraud. These routine operations do not normally produce a legal or similarly significant effect. Where an automated process materially rejects, cancels, suspends or withholds a transaction or account, you may request human review, explain your position and contest the decision through support.
7. When we share personal data
1. Relevant organizer, venue and product seller: attendee, ticket, purchaser and fulfilment information needed to administer the event, provide entry, supply an order, communicate operational changes, prevent fraud and handle a complaint, return or refund.
2. Payment and banking providers: including Paystack, Flutterwave, Zenith GlobalPay and settlement banks, to authorize, confirm, refund and reconcile payments and payouts.
3. Technology and operations providers: Vercel for hosting, serverless compute and file storage; Neon for the managed database; Resend for transactional email; Meta for the WhatsApp Cloud API; and providers of security, analytics, customer support, identity verification and professional advice, under appropriate instructions and safeguards.
4. Ticket transfer, any enabled resale and order-delivery parties: the minimum information needed to assign or deliver a ticket or order, complete the permitted transaction and prevent fraud. We do not disclose full payment details.
5. Authorities and legal recipients: where required or permitted by law, court order, regulatory request, protection of rights, investigation of fraud or an emergency involving safety.
6. Corporate transaction recipients: a genuine buyer, investor, lender or successor in a reorganization or sale, subject to confidentiality and continued protection of personal data.
We do not sell personal data. We do not allow an organizer to use an attendee list from DOT TIX for unrelated marketing unless the attendee has given valid consent or another lawful basis clearly applies.
8. Organizer and seller responsibilities
An organizer or seller may access data only for its event or order and must comply with data-protection law and the Organizer & Seller Terms. It must give any additional notice required for its own processing, keep attendee and purchaser data secure, limit access, honor rights and obtain separate consent before optional marketing. A seller may use shipping and recipient data only to fulfil and support the relevant order. Questions about an organizer's or seller's independent use may be directed to that party; we will assist where appropriate.
9. International transfers
Some providers or event participants may be outside Nigeria. Where personal data is transferred from Nigeria, we use a lawful transfer basis and assess safeguards such as applicable protection law, contractual clauses, binding rules, certification or another basis permitted by the Nigeria Data Protection Act 2023. Where consent is the required basis, we will explain the relevant risk and request it.
10. Retention
We keep personal data only for the period needed for the stated purpose, legal recordkeeping, security, disputes and enforcement. Our default schedule is:
|
Record |
Default retention |
|
Checkout hold |
Until the displayed hold expires; limited failed or abandoned checkout records may be kept for up to 30 days for reconciliation, support and fraud prevention. |
|
DOT ID profile, interests, saved events and waitlists |
While the account or selected feature is active and ordinarily 24 months after account closure, unless earlier deletion is appropriate or another record must be retained. |
|
Ticket and merchandise orders, invoices, fulfilment, refunds, chargebacks, payouts and tax records |
At least six years after the end of the relevant financial or assessment year, or longer where law, audit, dispute or investigation requires. |
|
Seller verification and payout records |
For the seller relationship and ordinarily six years after it ends, subject to payment, tax, fraud and legal requirements. |
|
Check-in and gate audit |
Ordinarily 24 months after the event, then deleted or de-identified unless needed for an active dispute, safety matter or legal requirement. |
|
Support and complaint records |
Ordinarily three years after closure, or longer for an unresolved claim or legal requirement. |
|
Security and access logs |
Ordinarily up to 12 months, with longer retention for a detected incident, fraud case or legal requirement. |
|
Marketing consent and suppression |
Until consent is withdrawn; a minimal suppression record may be retained as long as necessary to honor the opt-out. |
|
Cookies and similar identifiers |
As stated in the Cookie Policy; optional identifiers are generally no longer than 13 months before consent is refreshed. |
Deletion of a DOT ID does not automatically erase records we must retain for tax, accounting, fraud prevention, refunds, disputes or legal obligations. We restrict those records to the remaining purpose and delete or de-identify them when the period ends.
11. Security
We use technical and organizational measures proportionate to risk, which may include encryption in transit, password hashing, signed single-use QR codes, rotating QR codes where expressly enabled, role-based access, two-factor authentication for privileged roles, rate limiting, logging, backups, processor controls and periodic security review. No online service is completely secure. Keep credentials and one-time codes private and report suspicious activity promptly.
If a personal-data breach is likely to create a risk to individuals, we will notify the Nigeria Data Protection Commission within the legally required period. If it is likely to create a high risk, we will also notify affected people promptly in clear language and explain protective steps.
12. Your rights
Subject to applicable law, you may:
1. ask whether we process your personal data and obtain access and a copy;
2. correct inaccurate, incomplete, outdated or misleading data;
3. request deletion where the data is no longer needed and no lawful basis requires retention;
4. request restriction while a concern, objection or legal claim is resolved;
5. object to processing based on legitimate interests and object at any time to direct marketing;
6. withdraw consent as easily as it was given, without affecting earlier lawful processing;
7. request portability where applicable; and
8. request human intervention and contest a significant solely automated decision.
Use Settings to update your profile and interests or, where available, export or request deletion of your DOT ID and attached data. You may also email privacy@dot360.co. Describe the request and the account or order concerned. We may verify identity and authority before disclosing or changing data. Account deletion does not remove records that section 10 requires us to retain. We aim to respond without unreasonable delay and ordinarily within 30 days; complex or legally restricted requests may take longer, and we will explain why.
13. Marketing choices
Email or WhatsApp marketing is optional and is not bundled with a ticket or merchandise purchase. Consent choices must be affirmative and may be changed through the unsubscribe link, account preferences or privacy@dot360.co. Opting out does not stop essential order, ticket, security, refund, fulfilment or event-change notices.
14. Cookies and tracking
Necessary cookies and local storage keep accounts, checkout, saved-event preferences, ticket access and offline scanning working. Analytics and marketing technologies are optional and are used only after the required consent. The Cookie Policy explains categories, purposes, duration and controls.
15. Children
A person must be at least 18 to create a DOT ID or seller account. A parent or guardian may obtain a ticket for a minor. If we need consent to process a child's data, we will obtain and reasonably verify the consent of a parent or legal guardian. We do not knowingly use children's data for behavioral marketing.
16. Other countries
If you use DOT TIX from another country, mandatory local data-protection rights may apply in addition to this Policy. We will honor those rights where applicable. Event availability, payment methods and controller details may vary by market and will be shown in the relevant service or event notice.
17. Changes
We may update this Policy when our services, providers or legal obligations change. We will post the revised version and effective date, and give prominent notice or request renewed consent where a material change requires it.
18. Contact and complaints
Privacy Team /
Data Protection Officer
The DOT360 Network, trading as DOT TIX
Plot 5, House 3 Kunle Ogunba Street
Lekki Residential Scheme 1, Lagos, Nigeria
Email: privacy@dot360.co
If you are dissatisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission at https://ndpc.gov.ng or pursue another remedy available under applicable law.
