Features
ShopSell general admission, reserved seats, and add-ons in one shop.Wallet passesDesign a fully customizable Apple and Google Wallet pass buyers add to their phone.AppleGoogleDoor scanEasy to pair with a code. No CRM login. You can even sell tickets at the door with tap to pay.Tap to paySell at the door. They tap a card or phone. The ticket is theirs.FinanceSeamless onboarding for the payment systems. Then Finance shows gross, fee, and net, and pays out to your bank.CommunityList the night in the RaveDragons app. Ravers find festivals, crews, and your shop in one home base.
€0.49 + 2% per ticket · no subscription
Industries
RavesOne shop, Wallet passes, and door scan for a single rave.FestivalsWeekend tickets, day tickets, and add-ons, with one scan at the gate.VenuesOne company account for every night you run in the room.
Raves, festivals, and venues
Why us
Pricing€0.49 + 2%. Shop, door, payouts, and the RaveDragons app.Custom widgetA countdown they keep on the home screen. You manage it.Community mapPriority on the festival map when tickets sell through RaveDragons.
€0.49 + 2% per ticket · no subscription
About
Log inRegister

Legal

Privacy Policy

How RaveTickets collects, uses, shares and keeps personal data, and the rights you have under the GDPR (AVG). This policy covers the RaveTickets platform at ravetickets.nl and the RaveTickets scanner app, but not the RaveDragons website or the RaveDragons community app, which have their own policies.

Last updated: 2026-10-03

PrivacyCookiesTermsApp TermsTicket Buyer TermsAcceptable UseData ProcessingRefundsPricing & feesDAC7Accessibility

Who we are

RaveTickets is operated by RaveDragons V.O.F., Maasdijk 169, 4827 MA Breda, Netherlands. KVK 42007416, BTW NL869257110B01. You can reach us at info@ravedragons.com.

Our two roles

RaveTickets is a two-sided platform, so our role under the GDPR depends on whose data it is.

  • We are the controller for the personal data of organizers and their team members, for company and billing details, and for the data we need to run and secure the platform.
  • We are a processor for the personal data of ticket buyers. The organizer who sells the ticket is the controller of that data and decides how it is used. We process it on the organizer's behalf under our Data Processing Agreement.

Data we process about organizers

  • Account data: email address, name, password (stored only as a hash by our authentication provider), your two-step verification setting if you turn that on (the authenticator secret is stored by our authentication provider, not by us; of your recovery codes we store only a one-way hash), and the companies and roles you belong to.
  • Company and billing data: legal name, KVK number, VAT number, billing email, business address and phone number.
  • Identity and bank data for payouts (KYC): to enable paid ticket sales we create a Stripe Connect account for you and collect the verification details Stripe requires, such as the details of beneficial owners and a payout bank account (IBAN). Identity documents are uploaded directly to Stripe and are never stored on our servers or in our database. The bank account number (IBAN) you enter is passed on to Stripe and is not stored in our database; we keep only its last 4 characters in our audit log. Apart from that we only keep the Stripe account identifier and whether charges and payouts are enabled.
  • Support and email records: messages you send us and a record of the transactional emails we send you. When a payout bank account is added or a payout is requested, we email the company's owners and its billing address. That email names the team member who did it (by email address) and the last 4 characters of the IBAN or the payout amount.
  • Audit log: for security and accountability we record sensitive actions on money, team access and accounts, such as adding a payout bank account, requesting a payout, refunding an order, changing roles, or turning two-step verification on or off. Each entry holds the email address of the person who did it, the time, the IP address (the IPv4 address, or the /64 prefix of an IPv6 address), reference numbers, amounts and, for a bank account, the last 4 characters of the IBAN. Owners of a company can view the entries of their own company, without IP addresses.
  • Door staff: when an organizer creates a code for the scanner app, we store the name and email address of the person who will use it, send the code to that address, and show both to the organizer's team members who manage scanners.
  • Error reports from the website: when something goes wrong on the website or in the organizer dashboard, a technical error report (the error, where in our code it happened, the page address without personal details, and the type of browser) is sent to our own servers at errors.ravetickets.nl. Email addresses, names, tokens, bank account numbers and IP addresses are removed before the report is stored. Reports are kept for up to 90 days, and in our encrypted backups for up to about 14 months.
  • Security data: technical request data and IP addresses used for rate limiting and to protect the platform. To limit abuse, we keep short-lived counters per IP address (the IPv4 address, or the /64 prefix of an IPv6 address) and, for password resets and test emails, per one-way hash of the email address. These counters expire automatically within at most 24 hours.

Data we process about ticket buyers

When someone buys a ticket, we process the following on behalf of the organizer:

  • Order data: name, email address, the tickets and add-ons ordered, the amount paid and refunded, VAT, and whether an email we sent could not be delivered to that address.
  • Per-ticket personalization: where the organizer enables it, the first and last name of each attendee so the ticket and Wallet pass can be personalized before a QR code is issued.
  • Door scan data: the time a ticket is scanned at the entrance, used for access control and aggregate statistics.
  • Wallet pass data: when a ticket is added to Apple Wallet, we store a device identifier and push token supplied by Apple so the pass can be updated, for example after a scan or a refund. For Google Wallet, the pass details, including the ticket holder's name where the ticket is personalized, are sent to Google.

Payment data stays at Stripe. Card and payment details are entered in a payment form that Stripe provides inside our checkout page and are sent straight to Stripe. We never see or store full card or bank numbers.

Abuse protection counters. To limit abuse of the shop and checkout, we keep short-lived counters per IP address (the IPv4 address, or the /64 prefix of an IPv6 address) and, for free orders, per one-way hash of the buyer's email address. These counters expire automatically within at most 24 hours.

The RaveTickets scanner app

The scanner app used by event staff at the door processes some data on the device, including camera access to scan QR codes, NFC and location for in-person card payments, an offline cache of ticket identifiers, a one-way check value for each QR code (older app versions: the QR signature) and, for personalized tickets, the ticket holder's name, and local notifications. Card data is handled by Stripe and Apple and never reaches our servers. If the app crashes, it also sends a diagnostic report (the error and technical context such as app version, operating system and device model, with no ticket, payment or personal data) to our own servers at errors.ravetickets.nl, kept for up to 90 days, and in our encrypted backups for up to about 14 months. See the App Terms for the full list of app permissions and on-device data.

Offline guest names. So door staff can still check a ticket and, where needed, the guest's ID when the phone has no connection, the scanner app stores the first and last name of each valid personalized ticket for the event it is paired to, together with the ticket identifiers. Tickets are placed on the device from 24 hours before they become valid, so the door also works when the connection drops at opening time. The data is kept in the app's private storage on the device, in its cache directory (protected by the operating system's file protection and not included in iCloud or Android backups), and is refreshed while the device is online. It is limited to the event the device is paired to: when the app loads a different event, the earlier event's names are removed from the device, and this cached data is deleted when the door session ends (at log out, when the pairing is replaced or when the session expires). Scans that were accepted offline and not yet sent are the exception: they stay on the device, with the guest's name where the ticket is personalized, until they are sent or the user deletes them, also after the door session has ended. The names are shown only to staff using the paired scanner and are not used for any other purpose. We do not apply a separate time limit; the data stays on the device until one of these events occurs or the app is uninstalled.

App updates. So an urgent fix can reach door phones without waiting for an app store release, the scanner app asks the update service of Expo (expo.dev) each time it starts whether a newer version of the app code is available, and downloads it if there is one. With that request Expo receives the phone's IP address and technical details: the operating system (iOS or Android), the version of the app code and the update channel it uses, and a random identifier for the app installation that the app creates on the device. If an update failed to start, the next request also contains the technical error message of that failure. The request contains no ticket, guest, payment or account data, and we do not link the identifier to a person or a pair code.

Why we process it (legal bases)

  • Performance of a contract: to create and run your account, process ticket orders, deliver tickets and Wallet passes, and pay out organizers.
  • Legal obligation: to keep financial and tax records, to meet payment and anti-money-laundering rules through Stripe, and to report organizer income under the DAC7 directive (see our DAC7 Seller Reporting).
  • Legitimate interests: to secure the platform, prevent fraud and abuse, and keep the service working.

Service providers we use

RaveTickets is built on established third-party infrastructure. Each provider processes personal data only to deliver its function to us:

  • Stripe: payments, Connect payout accounts and identity verification (KYC).
  • Supabase: account authentication and our primary database, hosted in the EU (Ireland).
  • Vercel: hosting of the website, the organizer dashboard and the ticket shop. Requests to the platform, including order and account data, pass through Vercel. Our server functions run in the EU (Ireland).
  • A server in Germany (VPS): door-scan processing, the metrics dashboards and crash reports of the scanner app.
  • An off-site backup storage provider: storage of our backups. Backups are encrypted on our own server before they are uploaded, so the storage provider cannot read their contents.
  • Pushover (United States): operational alerts to our own team, for example when a payment or the door system needs attention. Alerts contain technical details such as event titles, organizer company names, amounts and reference numbers, and never names or email addresses of ticket buyers.
  • Expo (United States): delivery of updates to the scanner app. Expo receives the IP address of the door phone and technical details about the app and the device, and no ticket, guest or payment data.
  • Upstash: the short-lived abuse protection counters (rate limiting), in a Redis database hosted in the EU (Ireland).
  • Resend and our SMTP email provider: sending transactional email such as confirmations, tickets and invites.
  • Mapbox: showing and geocoding the venue location on event tickets.
  • Apple Wallet and Google Wallet: delivering and updating tickets as Wallet passes.
  • Our metrics stack (Grafana and InfluxDB): aggregate sales and scan dashboards for organizers.

We do not sell personal data and we do not use advertising networks.

International transfers

Your personal data is stored within the European Economic Area (EEA): on Supabase and Upstash in Ireland, on Vercel in Ireland and on a server in Germany. Encrypted backup copies are also stored with an off-site storage provider in a country the European Commission has recognised as providing an adequate level of data protection. Some of the service providers above, such as Stripe, Vercel, Mapbox, Apple, Google, Pushover, Expo and our email providers, may process limited data outside the EEA. Where that happens, the transfer is covered by appropriate safeguards, in particular the European Commission's Standard Contractual Clauses.

How long we keep data

  • Account and company data: for as long as your account is active, and a limited period afterwards to handle any follow-up.
  • Order, invoice and financial records: kept for 7 years to meet Dutch tax-retention law. This obligation overrides a request to erase that specific data until the period ends.
  • Security and operational logs: kept for a short period, typically up to 90 days.
  • Checkouts that were never paid: the name, email address and form answers are removed 60 days after the checkout. The order line itself stays, without personal data.
  • Team invitations: deleted 30 days after the invitation expired.
  • Door staff data (pair codes with the name and email address of a door staff member, and the name on a scanner session): removed 90 days after the event.
  • Apple Wallet registrations (the device identifier and push token of a phone that holds a pass): deleted 30 days after the event.
  • The record of who displayed a ticket's QR code: deleted after 90 days.
  • Audit log: kept for 7 years, also after the account or company is deleted, so that we can investigate fraud and disputes.
  • Backups: we make daily backups of our database and server. Encrypted copies are kept for up to about 14 months and then deleted. Data you have asked us to delete can therefore remain in a backup until that backup expires; it is not used for any other purpose.

Your rights

You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent where processing is based on it. For data where an organizer is the controller (ticket-buyer data), contact that organizer first; we will support them in answering your request. For other requests, email info@ravedragons.com. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Deleting your account and data

You can ask us to delete your account and the personal data we hold about you at any time. Organizers can request this from account settings where available, or by emailing info@ravedragons.com. If you are the only owner of a company that has ticket sales, payouts or fee invoices on record, the account cannot be deleted from account settings: the app tells you to contact support, which you can do at the same email address. Accounts of companies without that history can still be deleted from account settings. If you use the RaveTickets scanner app, the same email is the data deletion request route. For ticket-buyer data, contact the organizer who sold the ticket, or email us and we will assist them.

Once we confirm your request, we delete your account and associated personal data within a reasonable period. We must keep financial and invoice records for 7 years under Dutch tax law, and we keep audit log entries for 7 years and backups for up to about 14 months, so that specific data is retained until those periods end and then deleted.

Cookies

We use only strictly necessary and functional cookies, with no analytics or advertising trackers. See our Cookie Policy for details.

Age

Platform accounts are for organizers aged 18 or over who are authorized to act for their business. Any age limit on attending an event is set and enforced by the organizer.

Changes

We may update this policy from time to time. The date at the top shows when it was last reviewed. Material changes will be made clear on this page.

RaveDragons V.O.F. (RaveTickets), Maasdijk 169, 4827 MA Breda, Netherlands. KVK 42007416, BTW NL869257110B01. Contact: info@ravedragons.com.

RaveDragons

© 2026 RaveDragons Tickets

ShopPricingAbout
Privacy PolicyTerms of ServicePricing & feesCookie PolicyAccessibilityLegalContact