Legal
Privacy Policy
Effective: 27 May 2026 · Version v1.0-2026-05-27
This Privacy Policy explains how Bombay No 3 LLP ("we", "us") collects, uses, shares and protects your personal data when you use the Platform. It is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
1. Data we collect
- Identity & contact: name, email, mobile number, billing address (for invoicing).
- Authentication: password hash (we never store passwords in plain text), session tokens.
- Booking data: show, seats, payment reference, consent flags and timestamp, IP address at consent.
- Device & usage: IP address, browser/OS, pages visited, basic interaction events for security and product improvement.
- Cookies: see our cookie banner; only essential cookies are set by default.
2. Purpose & lawful basis
- Performance of contract — to complete your booking, deliver tickets, process refunds and provide support.
- Legal obligation — to issue tax invoices, maintain financial records, and respond to lawful requests.
- Legitimate use under DPDP Act §7(b)–(h) — to detect fraud, prevent scalping, secure the Platform, and operate the service.
- Consent — for marketing communications about upcoming shows, profile personalisation, and any other non-essential processing.
3. Sharing of data
We share personal data only with:
- Event organisers and venues, limited to the information needed to admit you (booking reference, name).
- Payment processors (e.g. Razorpay) to process your payment securely; we do not store full card numbers.
- Communication providers for sending email/SMS/WhatsApp tickets and updates.
- Government authorities, where required by law, subpoena, or valid order.
- Distribution partners (e.g. BookMyShow, PayTM Insider) when you book through their channels — strictly the booking details needed to fulfil the ticket.
We do not sell personal data. We do not transfer personal data outside India except to processors who comply with the standards required by the DPDP Act.
4. Your rights as a Data Principal
Under the DPDP Act, you have the right to:
- Access a summary of your personal data we hold;
- Correct, complete, or update inaccurate or incomplete data;
- Erase personal data that is no longer necessary, subject to legal retention obligations (e.g. tax records retained for 8 years);
- Withdraw consent for marketing or other consent-based processing;
- Nominate another individual to exercise your rights in case of incapacity or death;
- File a grievance with our Data Protection Officer (DPO), and thereafter with the Data Protection Board of India.
To exercise these rights, contact our DPO at dpo@tickets.example. We will respond within the timelines prescribed under the DPDP Act.
5. Retention
- Booking, billing and tax records — retained for 8 years from the financial year of the transaction (in line with the GST Act).
- Account data — retained until you delete your account; tombstoned for 90 days, then permanently erased.
- Logs (security, fraud detection) — retained up to 180 days.
6. Security
We use TLS in transit, encrypted at rest where appropriate, bcrypt for password hashing, role-based access, and audit logging for sensitive operations. While we follow industry best practices, no system is perfectly secure; we will notify you and the Data Protection Board in accordance with law in the event of a notifiable personal data breach.
7. Children
The Platform is not directed to children under 18. We do not knowingly collect personal data of children, and require verifiable parental consent before processing children's data as required by the DPDP Act.
8. Cookies
We use only strictly-necessary cookies by default (session, CSRF). We will request your consent before setting any analytics or advertising cookies. You can manage preferences via the cookie banner or your browser settings.
9. Grievance Officer
- Data Protection Officer: Chintan Pavlankar
- Email: dpo@tickets.example
- Address: Plot 21, 3rd Floor, Bandra West, Mumbai, Maharashtra 400050, India
10. Changes
We may update this Privacy Policy as the law and our services evolve. Material changes will be communicated by email or a banner on the Platform.
Bombay No 3 LLP
Plot 21, 3rd Floor, Bandra West, Mumbai, Maharashtra 400050, India
GSTIN: 27AAXFB8032G1Z4
support@tickets.example · +91 22 0000 0000
