The short version
A plain-English summary. The detail below is what actually applies.
- We collect what we need to sell you a ticket or run your event — name, email, phone, order details — and not much else.
- We never see or store your full card number. Card payments happen on our payment partner's own systems.
- We do not sell personal data, and we do not share it for anyone else's advertising.
- When you buy a ticket, the event organizer receives your details so they can run the event — they are responsible for what they do with them.
- You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Email hello@vibepass.co.ke.
01 Who we are
VibePass is an event ticketing platform operated by Cloudtrade Centralised Systems Limited, based in Nairobi, Kenya. In this policy, "we", "us" and "our" mean that company.
This policy covers vibepass.co.ke, tickets.vibepass.co.ke, our check-in tools, our embeddable ticket widget, our APIs, and the emails and SMS messages we send. It sits alongside our Terms of Service.
If you have any question about this policy or about how your data is handled, write to hello@vibepass.co.ke.
02 Controller or processor
The Data Protection Act 2019 distinguishes between the data controller, who decides why and how data is processed, and the data processor, who processes it on the controller's instructions. Which one we are depends on the data.
| Data | Our role | What that means |
|---|---|---|
| Your VibePass account — registration details, login activity, billing, support conversations, use of the platform | Controller | We decide how this is used and this policy governs it. |
| Ticket buyer and attendee data collected through an organizer's event — names, contact details, answers to their registration questions, check-in records | Processor for the organizer | The organizer is the controller. We handle it to run the platform on their behalf, and their own privacy notice governs what they do with it. |
| Fraud prevention, security, billing and platform integrity — including records of transactions we process | Controller | We use this to keep the platform safe and to meet our own legal duties. |
Where we act as a processor, and you want data corrected or erased, the organizer is usually the right person to ask. We will help you reach them and will act on their instructions.
03 What we collect
If you create an organizer account
- Name, email address, phone number, password (stored only as a cryptographic hash), preferred language and timezone.
- Organization or brand details you add: business name, logo, address, support email, social links, tax details you choose to put on invoices.
- Payout details you configure, such as an M-Pesa till, paybill or number, or bank details.
- Team members you invite and the role you give them.
If you buy a ticket or register for an event
- Name and email address, and phone number where the organizer asks for it or where you pay by M-Pesa.
- Attendee details for each ticket, which may differ from the buyer's.
- Answers to any registration questions the organizer has added to their checkout.
- Billing address, where the organizer requires one.
- Order records: what you bought, the amount, the currency, discounts or promo codes applied, and the resulting ticket and QR code.
- Check-in records: whether and when a ticket was scanned at the door.
Payment-related information
- For M-Pesa: the phone number the payment came from, the amount, and Safaricom's transaction reference and status.
- For card and bank payments: the payment reference, amount, status, the payment method type, and a confirmation code from our payment partner. We do not receive or store your full card number, expiry date or CVV.
- Refund and chargeback records where they arise.
Automatically, when you use the platform
- IP address, browser and device type, operating system, referring page and the pages you view.
- Session information needed to keep you logged in and to keep the checkout secure.
- Error and performance logs, which may include an IP address and the URL that failed.
When you contact us or subscribe
- Your messages to us by email, phone or WhatsApp, and our replies.
- Newsletter subscriptions and marketing preferences, including when and how you opted in.
We do not deliberately collect sensitive personal data as defined in the Act — such as health, religious belief, or biometric data. If an organizer's registration questions ask for anything of that kind, they are responsible for having a lawful basis to do so and for telling attendees why.
04 Where it comes from
- From you — when you register, create an event, buy a ticket, contact support or subscribe.
- Automatically — from your device as you use the platform, as described above.
- From organizers — where an organizer imports an attendee list or adds an order on your behalf.
- From payment providers — confirmation of a payment, its status, and the reference we need to reconcile it.
- From a person who bought a ticket for you — a buyer may enter your name and email as the attendee.
05 Why we use it, and our legal basis
| Purpose | Legal basis under the Act |
|---|---|
| Creating and administering your account | Performance of a contract with you |
| Processing orders, taking payment, issuing tickets and QR codes | Performance of a contract |
| Sending order confirmations, tickets, payment notifications and service alerts | Performance of a contract |
| Paying out ticket revenue to organizers and calculating our fees | Performance of a contract; legitimate interests |
| Check-in and admission control at events | Performance of a contract; the organizer's legitimate interests |
| Customer support and dispute resolution | Performance of a contract; legitimate interests |
| Fraud prevention, security monitoring and enforcing our terms | Legitimate interests; legal obligation |
| Keeping accounting, tax and transaction records | Legal obligation |
| Understanding how the platform is used, so we can improve it | Legitimate interests |
| Marketing emails and newsletters from VibePass | Consent |
| Responding to lawful requests from courts, regulators or law enforcement | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights and freedoms. You can object to that processing — see Your rights.
Where we rely on consent, you may withdraw it at any time. Withdrawing consent does not affect processing already carried out, and it does not stop transactional messages about an order you have placed.
06 Payment information
For M-Pesa payments, Safaricom sends us confirmation of the transaction. We store the paying phone number, the amount and Safaricom's reference so that we can match the payment to your order, re-issue a lost ticket, investigate a failed payment and meet our record-keeping obligations.
We store payout details that organizers configure, and credentials for any payment integration an organizer connects, in encrypted form.
07 Who we share it with
We do not sell personal data, and we do not share it for third-party advertising. We share it only in the circumstances below.
| Recipient | What they receive | Why |
|---|---|---|
| Event organizers | Buyer and attendee details for their own event, order and check-in records | So they can run the event you bought a ticket to |
| Safaricom (M-Pesa / Daraja) | Paying phone number, amount, order reference | To request and confirm mobile money payments |
| Pesapal | Name, email, amount, order reference; card details go directly to them | To process card and bank payments |
| Email delivery provider | Recipient name, email address, message content | To deliver tickets, receipts and notifications |
| SMS delivery provider | Recipient phone number and message content | To send payment confirmations by SMS where enabled |
| Hosting and infrastructure provider | All platform data, as stored on their servers | To host the platform and keep backups |
| Professional advisers | Only what is necessary | Auditors, accountants and lawyers, under duties of confidentiality |
| Authorities | Only what is legally required | Where we must comply with a court order, regulator or law |
| A buyer or successor | Data forming part of the business | If the business is sold or reorganised; we would notify you |
Our service providers act on our instructions, are bound by confidentiality and security obligations, and may not use the data for their own purposes.
08 Data held by organizers
When you buy a ticket, the organizer of that event receives your details so they can admit you, contact you about the event and meet their own obligations. From that point the organizer is an independent controller of that copy of your data.
Our Terms of Service require organizers to use attendee data only to run and communicate about their event, prohibit selling it, and prohibit unsolicited marketing. We are not, however, able to control what an organizer does with data once they have it.
09 Where your data is stored
VibePass is operated from Kenya, but our servers and several of our service providers are located outside Kenya, including in the United States and Europe. This means personal data processed through the platform is transferred to and stored in those countries.
Where we transfer personal data outside Kenya, we do so on the basis of appropriate safeguards as required by sections 48 and 49 of the Data Protection Act 2019 — contractual commitments with our providers requiring security and confidentiality equivalent to Kenyan standards, and, where relevant, your consent to the transfer as necessary for the performance of your contract with us.
You may ask us for more detail about the safeguards that apply to a particular transfer by writing to hello@vibepass.co.ke.
10 Cookies and analytics
We keep our use of cookies deliberately small.
- Strictly necessary cookies keep you signed in, hold your ticket selection through checkout, and protect against cross-site request forgery. The platform cannot work without them.
- Preference storage remembers choices such as your language or whether you have dismissed a notice.
- Analytics. We use a self-hosted, privacy-oriented analytics tool operated by CloudTrade on our own infrastructure. It records aggregate page views, referrers and approximate country, and does not use advertising cookies or build a profile of you across other websites.
We do not use third-party advertising cookies of our own. Most browsers let you block or delete cookies; blocking strictly necessary cookies will break checkout and login.
11 Organizer tracking tools
Organizers can add their own tracking tools — for example a social media advertising pixel — to their own event pages, so that they can measure their marketing.
Where an organizer has done this, that third party may set cookies or receive information about your visit to that event page, under the third party's own privacy policy and the organizer's. The organizer is responsible for the lawfulness of the tool and for obtaining any consent required. We restrict which tools may be used and can remove any that we consider unsafe.
This does not apply to VibePass's own marketing site.
12 How long we keep it
We keep personal data only as long as we need it for the purpose we collected it, or as long as the law requires.
| Data | Retention |
|---|---|
| Organizer account and organization details | While the account is active, then up to 24 months after closure |
| Orders, tickets, payments, refunds and invoices | At least 7 years, to meet tax and accounting obligations |
| Attendee records and check-in data | Held for the organizer while their account is active; deleted on their instruction, subject to the financial records above |
| Support conversations | Up to 3 years from the last message |
| Marketing subscriptions | Until you unsubscribe, plus a suppression record so we do not contact you again |
| Server, security and error logs | Typically up to 12 months |
| Backups | Rolling backups, overwritten on a defined cycle |
When data reaches the end of its retention period we delete it or irreversibly anonymise it. Deletion from live systems can take slightly longer to propagate through backups.
13 How we protect it
- All traffic to our websites and APIs is encrypted in transit using TLS.
- Passwords are stored only as salted cryptographic hashes; we cannot read them.
- Payment credentials and integration secrets are encrypted at rest.
- Access to production data is limited to the people who need it, and administrative access is restricted and logged.
- Backups are taken regularly and stored separately from the live system.
- Card data never touches our systems — see Payment information.
No system is perfectly secure. We keep our measures under review, but we cannot guarantee absolute security, and you are responsible for keeping your own password and devices safe.
14 Data breaches
If a personal data breach occurs and there is a real risk of harm to the people affected, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, so far as that is practicable, and we will inform the affected individuals without undue delay, in line with section 43 of the Act.
Where we act as a processor for an organizer, we will notify that organizer without undue delay so that they can meet their own obligations.
15 Your rights
Under the Data Protection Act 2019 you have the right to:
- Be informed of how your data is used — this policy is part of that.
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate, out of date or incomplete.
- Delete data where it is no longer needed, or where you withdraw consent and there is no other basis to keep it.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Restrict processing while a dispute about accuracy or lawfulness is resolved.
- Portability — receive data you gave us in a structured, commonly used format, where technically feasible.
- Withdraw consent where consent was our basis for processing.
How to exercise them
Email hello@vibepass.co.ke with the request and enough information for us to find your records — the email address or phone number you used, and the event name if your request concerns a ticket.
We may ask you to verify your identity before we act, so that we do not disclose someone else's data. We will acknowledge your request promptly and respond within 30 days. If a request is complex we may extend that period and will tell you why. Requests are free, unless they are manifestly unfounded or excessive.
Organizers can export their own account and event data at any time from within the platform.
16 Marketing choices
We send marketing emails only to people who have opted in. Every marketing email has an unsubscribe link, and unsubscribing takes effect promptly.
Transactional messages are different: order confirmations, tickets, payment notifications, refund notices and security alerts are part of the service and continue while you have an active order or account.
Messages sent by an organizer to their own attendees are controlled by that organizer. Use the unsubscribe or opt-out they provide, or contact them directly. Tell us if an organizer ignores an opt-out request.
17 Children
The platform is not intended for children under 18, and organizer accounts may only be created by adults. We do not knowingly collect data from a child without the consent of a parent or guardian.
A parent or guardian may buy tickets for a child, in which case they are responsible for the child's details they provide. If you believe we hold a child's data without proper consent, contact us and we will delete it.
18 Automated decisions
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
We do use automated checks to flag suspicious transactions, duplicate orders and possible fraud. Where such a check results in a payment being declined or an account being held, a person reviews the case, and you can ask us to explain and to reconsider by writing to hello@vibepass.co.ke.
19 Changes to this policy
We may update this policy as our services, our providers or the law change. The current version is always at this address, with its effective date at the top.
Where a change materially affects how we use your data, we will give notice — by email or by a notice on the platform — before it takes effect.
20 Complaints
If you are unhappy with how we have handled your personal data, tell us first at hello@vibepass.co.ke. We take complaints seriously and will investigate.
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), the Kenyan supervisory authority, whose contact details and complaint procedure are published at www.odpc.go.ke.
21 Contact us
Cloudtrade Centralised Systems Limited
Trading as VibePass · Nairobi, Kenya
For privacy requests, please put "Data request" in the subject line so it reaches the right person quickly. Support hours are on our contact page.