Privacy Policy (GDPR)

TicketFae and TicketFae Buddy are built on the principle of data minimisation: they work almost entirely without personal data, and we operate no server. This policy sums up what each app processes — and, above all, what it does not.

Data controller

Responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:

Alan Rickayzen
Thank you partner IT services
Münchäckerweg 26
69168 Wiesloch
Germany
Phone: +49 6222 5855844
Email: alan@thank-you-partner.com

Two apps, two statements

This page covers both apps. They are halves of one pair and handle data differently, so each has its own statement below.

The sections above and below the two statements — data controller, this website, your rights — apply to both.

The principle: data minimisation

Both apps are designed so that as little data as possible arises in the first place. There are no user accounts, no email sign-in and no server of ours storing your events, buddies or settlements. Your data stays on your iPhone, and anything exchanged between two paired devices travels through your own Apple account, never through us.

Cookies on this website

This website (ticketfae.com) sets no cookies and uses no analytics or tracking scripts. There is no recognition of returning visitors, and no data is stored in your browser. Since no non-essential cookies are set, no cookie consent banner is required.

What neither app stores


TicketFae — the organiser's app

What it stores on your device

Your events, buddy lists, ticket PDFs, expenses, settlements, ratings and event photos are stored on your iPhone. Copies of your ticket PDFs are also written to TicketFae's own folder in your iCloud Drive, so a ticket survives reinstalling the app. You can see and delete those in the Files app.

Camera

TicketFae asks for camera access only when you start a scan yourself — to read a pairing QR code shown on a buddy's iPhone. No photo or video is recorded, and no camera image is kept once the code has been read.

Photo library: access is add-only, and only when you tap “Save to Photos” on a picture a buddy shared with you. The app cannot see the rest of your library.

File access is used solely to import the ticket PDFs you select yourself. Notifications are optional — local reminders before your events — and calendar access is write-only, used only when you add an event yourself.

Payment details you enter yourself

If you want friends to be able to repay you, you can store your own IBAN, BIC and account holder name, and your own PayPal.me username. Both are optional and the app works fully without them. They are held in the device Keychain, encrypted and excluded from iCloud and from device backups.

They are never sent to us — we have no server to send them to. They are sent to the buddies you have paired with, through your own Apple account, so their app can show your payment QR code when they settle up. That is their only purpose, and it happens only for people you have explicitly paired with.

TicketFae moves no money. It has no payment processor, no card handling, and no connection to any bank or to PayPal. Any actual transfer happens in your own banking or PayPal app, outside TicketFae.

What is exchanged with paired buddies

Pairing is a one-time, in-person handshake: your app shows a QR code, the buddy's app reads it, and the two devices exchange a private share inside your own Apple account. There is no email address, no phone number and no account of ours involved.

Once paired, TicketFae can send that buddy: event details (title, date, venue), their ticket as a PDF, the costs they owe and how a bill was split, ratings collected after an event, photos you choose to share into an event's gallery, and the payment details described above. Nothing is sent to anyone you have not paired with.

Three things come back the other way, and nothing else: a buddy's rating of an event after it happens, a photo they choose to contribute to an event's gallery, and a request to resend the buddy list. Their app also confirms that a ticket or a bill arrived, so you can see who has theirs. A photo a buddy contributes is visible to you alone until you release it to the rest of the group.

Deleting your data

Settings → Advanced Settings → Danger Zone offers three choices, from clearing the app's data to deleting everything and unpairing the device. The strongest also removes the payment details from the Keychain and the records held in your iCloud account.

Two things are deliberately left: the ticket PDFs copied into your iCloud Drive folder, which you delete yourself in the Files app, and anything already delivered to a buddy, which is on their device and beyond this app's reach.


TicketFae Buddy — the recipient's app

What it stores on your device

The events, tickets, costs, ratings and photos an organiser has sent you are stored on your iPhone. Ticket PDFs are also copied into TicketFae Buddy's own folder in your iCloud Drive so they survive reinstalling the app, and you can see and delete those in the Files app.

TicketFae Buddy has no way to import tickets of its own: every event, ticket, cost and rating request it holds arrived from an organiser you paired with. The one thing you can add yourself is a photo — see below.

What it sends back

Your app sends the organiser three things, and nothing else: your rating of an event after it happens, a photo you choose to contribute to an event's gallery, and a request to resend the buddy list. It also confirms that a ticket or a bill arrived, so the organiser can see who has theirs.

A photo you contribute goes to the organiser first and is visible only to them. It reaches the rest of the group only if they release it. You pick the one picture yourself, and the app never sees the rest of your library.

Camera and permissions

Camera access is asked for only to read the pairing QR code the organiser shows you. No photo or video is recorded and no camera image is kept. Photo library access is add-only, for saving a shared picture to your own Photos. Notifications and write-only calendar access are optional.

The organiser's payment details

If your organiser has stored their own IBAN, BIC and account holder name, those arrive on your device and are held in the Keychain, encrypted and excluded from iCloud and from device backups. Their only purpose is to render a standard SEPA payment QR code (GiroCode, EPC069-12) that you scan with your own banking app.

TicketFae Buddy moves no money and initiates no payment. Any transfer happens in your own banking or PayPal app.

Deleting your data

Settings → Advanced Settings → Danger Zone offers the same three choices as the organiser's app, the strongest of which also removes the organiser's payment details from the Keychain, clears the records in your iCloud account and unpairs you. The ticket PDFs in your iCloud Drive folder are deliberately left for you to delete in Files.


iCloud (your own Apple account)

Both apps use iCloud, always scoped to your own Apple account. This is not a server we operate: we cannot read, access or analyse anything held there.

Anonymous usage and error data (telemetry)

To improve the apps, both collect anonymous, aggregated usage and error data. This lets us see which features are used and which are not — and where errors occur, so we can fix them.

This data is deliberately "bucketed": it is combined into anonymous groups and cannot be attributed to an individual person, a single device or a specific event. No names, no ticket contents, no contact data and no advertising IDs are collected. There is no cross-device tracking.

For this anonymous analysis we use TelemetryDeck, a privacy-focused provider based in Germany. The data is processed on servers in Germany; there is no transfer to third countries outside the EU. Provider: TelemetryDeck GmbH, Berlin.

Because this telemetry data has no personal reference and is collected only anonymously and in aggregate, it cannot be traced back to any person.

Crash reports (Sentry)

If an app crashes, it records a technical crash report and sends it the next time you open the app, so we can find and fix the cause.

A crash report contains only technical information: where in the program code the crash happened, the app version, the device model, the iOS version and the time of the crash. It also contains a random ID generated when the app was installed, so that repeated crashes on the same installation can be recognised. That ID is not connected to your name, your Apple ID or any other data about you. Not included: names, ticket contents, event details, photos, payment details, contact data, screenshots or advertising IDs. The app does not send your IP address, and IP addresses are not stored.

For this we use Sentry, provided by Functional Software, Inc., San Francisco, USA. Crash reports are stored in Sentry's EU data region in Germany and deleted automatically after 90 days. Because the provider is a US company, access from the USA cannot be ruled out; such transfers are covered by the EU–US Data Privacy Framework and the EU Standard Contractual Clauses in Sentry's data processing agreement.

The legal basis is our legitimate interest in a stable, working app (Art. 6(1)(f) GDPR).

Your rights

Under the GDPR you have, among others, the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21).

Because neither app sends your data to us — we hold none of it, the telemetry we do receive is anonymous, and crash reports identify no one — these rights apply mainly to data you hold yourself. You can exercise them without asking us: each app's Danger Zone deletes what it holds, on the device and in your iCloud account, and the copies in your iCloud Drive folder are deletable in the Files app. If you have any questions, you can reach us any time at alan@thank-you-partner.com.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for the controller is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg).

Changes to this privacy policy

We update this policy when the app or the legal requirements change. The version published here is the one that applies.

Last updated: September 2026 · See also our Legal Notice (Impressum).