In short: we collect what is needed to sell you a ticket, get you through the door and pay the organiser. We do not sell personal information, and we never see your full card number. Your rights and how to exercise them are set out in the
POPIA and PAIA notice.
Who you are dealing with
Teeckets is an online event ticketing and event management platform operated by Kanvas Creative Solutions in South Africa. We sell tickets on behalf of the organiser who lists an event, and we collect and settle the money for those ticket sales.
- Trading nameTeeckets (www.teeckets.co.za)
- Operated byKanvas Creative Solutions
- Registration number2019/136304/07
- Physical addressto be completed, South Africa
- Support emailsupport@teeckets.co.za
- Legal and privacy emaillegal@teeckets.co.za
- Telephoneto be completed
- Support hoursMonday to Friday, 09:00 to 17:00 (SAST), excluding public holidays
- CurrencyAll prices and payouts are in South African Rand (ZAR)
1. Scope and who is responsible
This Policy covers the Teeckets website, organiser accounts, public event pages, checkout, ticket delivery, admissions, organiser contact forms, refunds, payouts and support. Kanvas Creative Solutions, operating as Teeckets, is the responsible party for platform information under the Protection of Personal Information Act, 2013 (POPIA).
For the guest lists, attendee details and event content an organiser puts into the platform, the organiser is also a responsible party and must handle that information lawfully. Teeckets processes it on their behalf for the event.
2. What we collect
Organiser and account information
Name, email address, phone number, logo and profile photo, public profile details, login and session records, event records, payout bank details, verification documents where KYC applies, support messages and account activity.
Buyer, attendee and order information
Names, email addresses, phone numbers, ticket-holder details, order references, ticket PINs, ticket types, quantities, discounts and coupons, attendance and scan status.
Payment and refund information
Payment method, amount, status, gateway reference, processing fees, proof of payment uploaded for an EFT, payout ledger entries, payout history, approved refund status, and the bank details you give us for a repayment. We do not receive or store complete card numbers, expiry dates or card security codes.
Content and communications
Event descriptions, images, programmes, gallery submissions, contact-form messages, organiser notes, emails, SMS records and anything you send to support.
Device and usage information
IP address, browser and device information, timestamps, pages and actions used, security and error logs, and session identifiers. Where you scan a QR code or take an event photo, your browser asks for camera permission first; we never switch on a camera without it.
3. Why we use it
We process personal information where it is necessary to perform our contract with you, to comply with the law, for legitimate interests that do not override your rights, or on your consent. Specifically, to:
- create accounts, event pages, orders and R0 tickets;
- take payment and record it, handle proofs of payment, payouts, refunds and chargebacks;
- deliver tickets, receipts, PINs and transactional messages;
- run QR admissions, prevent a ticket being used twice and report attendance to the organiser;
- operate organiser profiles, contact forms, galleries and event communications;
- detect abuse, secure accounts, investigate errors and enforce our Terms;
- meet accounting, tax, consumer-protection and other legal duties; and
- improve reliability, usability and support.
4. Cookies
Teeckets uses essential session cookies to keep you signed in, protect forms against forgery and remember short-lived workflow state such as a cart or a seat hold. Blocking them will break sign-in and checkout.
If we ever add analytics or marketing technology that is not essential, we will give you the notice and the choice the law requires before it runs.
5. Who sees your information
We do not sell personal information. We share only what is needed, with:
- the organiser of the event you bought from, and their admissions staff, so they can run the event, check you in and contact ticket holders;
- payment gateways - PayFast and Yoco - and our bank, to take payment, verify it and settle money;
- service providers for hosting, email, SMS, support, security and analytics, under contract and only for those purposes;
- advisers, regulators, courts or law enforcement where the law requires it; and
- a buyer of the business in a lawful reorganisation, with equivalent protection.
Some providers process information outside South Africa. Where that happens we use providers or contract terms intended to give protection consistent with POPIA.
6. Card and banking information
Card payments are taken on the payment gateway's own secure page. Card details travel encrypted between you and the gateway; Teeckets is not in that path and holds no card number, expiry or CVV. We keep the outcome of the payment: amount, status, method, gateway reference and the last few digits where the gateway supplies them.
Bank details are handled in two places only: an organiser's payout account, and the account a buyer gives for an approved refund. Both are stored for payment purposes and are visible only to staff who need them for that payment.
Pages that carry personal or payment information are served over HTTPS with an up-to-date certificate.
7. How long we keep it
We keep information only as long as we reasonably need it for the event, ticket access, settlement, refunds, disputes, fraud prevention, accounting and legal compliance. As a guide:
- Order, ticket and payment records: at least five years, as tax and company law require.
- Account and event records: for as long as the account is open, then archived under the same five-year rule where they relate to money.
- Proofs of payment and refund bank details: as long as needed for the payment and any dispute period, then deleted.
- Support messages: normally two years.
- Security and error logs: normally twelve months.
Information may sit in restricted backups until those are overwritten in the ordinary cycle.
8. How we protect it
We use access controls and role separation, protected sessions, encrypted HTTPS transport, private directories that the web server refuses to serve, server-side price calculation so totals cannot be tampered with in a browser, gateway verification of payment notifications, and monitoring and logging.
No online service is risk-free. Please help: keep your PIN and ticket links private, use an email address only you can read, and tell us at once if you think an account or ticket has been misused.
If a breach ever affects your personal information, we will notify you and the Information Regulator as POPIA requires.
9. Public information and other people's data
Event pages, organiser profiles and enabled galleries are public. Do not put confidential information there. If you submit information about attendees, staff, guests or anyone else, you confirm you are allowed to and have given any notice required.
Gallery contributors need permission from identifiable people in their images. Organisers must respond properly to lawful requests about event content they control.
10. Your rights
Under POPIA you may ask whether we hold information about you, ask for a copy, ask us to correct or delete it, object to processing, withdraw consent where we relied on it, and complain to the Information Regulator.
How to make any of those requests, the forms, our response times and the Regulator's contact details are on the POPIA and PAIA page. We may need enough detail to confirm who you are and to find the right account, order or event, and some records must be kept where payment, tax, fraud or legal duties require it.
11. Children and direct marketing
Organiser accounts are not for children. Where an event collects information about a minor, the organiser and the purchaser must have the authority to give it. Tell us if a child's information has been submitted improperly.
Ticket and service messages are transactional, not marketing. Any direct marketing from Teeckets or an organiser must carry the choices the law requires, and opt-outs are honoured.
12. Contact and changes
Privacy questions and requests: legal@teeckets.co.za. Give us enough detail to find the account, order or event, and never send passwords or full card numbers.
We may update this Policy as the service or the law changes. The current version and its effective date stay on this page.